Note : This endpoint is in preview and is subject to change.
If you have any feedback, contact Datadog support .
GET https://api.ap1.datadoghq.com/api/v2/security_monitoring/configuration/integration_config https://api.ap2.datadoghq.com/api/v2/security_monitoring/configuration/integration_config https://api.datadoghq.eu/api/v2/security_monitoring/configuration/integration_config https://api.ddog-gov.com/api/v2/security_monitoring/configuration/integration_config https://api.us2.ddog-gov.com/api/v2/security_monitoring/configuration/integration_config https://api.datadoghq.com/api/v2/security_monitoring/configuration/integration_config https://api.us3.datadoghq.com/api/v2/security_monitoring/configuration/integration_config https://api.us5.datadoghq.com/api/v2/security_monitoring/configuration/integration_config
Overview List the entity context sync configurations for Cloud SIEM. Each configuration connects Cloud SIEM
to an external source that provides entities (for example, users from an identity provider) for use
in signals and the entity explorer.
This endpoint requires the integrations_read permission.
OAuth apps require the integrations_read authorization scope to access this endpoint.
Arguments Query Strings Filter the entity context sync configurations by source type. Allowed enum values: GOOGLE_WORKSPACE, OKTA, ENTRA_ID
Response OK
Response containing a list of entity context sync configurations.
Expand All
The list of integration configurations.
The attributes of an entity context sync configuration as returned by the API.
The time at which the entity context sync configuration was created.
The domain associated with the external entity source (for example, the customer's identity provider domain).
Whether the sync is enabled and actively ingesting entities into Cloud SIEM.
integration_type [required ]
The type of external source that provides entities to Cloud SIEM.
Allowed enum values: GOOGLE_WORKSPACE,OKTA,ENTRA_ID
The time at which the entity context sync configuration was last modified.
The display name of the entity context sync configuration.
Free-form, non-sensitive settings for the entity context sync. The accepted keys depend on the source type.
The state of the credentials configured on the entity context sync.
Allowed enum values: valid,invalid,initializing
The unique identifier of the integration configuration.
The type of the resource. The value should always be integration_config.
Allowed enum values: integration_config
default: integration_config
{
"data" : [
{
"attributes" : {
"created_at" : "2026-05-01T12:00:00Z" ,
"domain" : "siem-test.com" ,
"enabled" : true ,
"integration_type" : "GOOGLE_WORKSPACE" ,
"modified_at" : "2026-05-01T12:00:00Z" ,
"name" : "My GWS Integration" ,
"settings" : {
"setting1" : "value1"
},
"state" : "valid"
},
"id" : "11111111-2222-3333-4444-555555555555" ,
"type" : "integration_config"
}
]
} Not Authorized
{
"errors" : [
"Bad Request"
]
} Too many requests
{
"errors" : [
"Bad Request"
]
} Code Example Copy
# Curl command curl -X GET "https://api.ap1.datadoghq.com "https://api.ap2.datadoghq.com "https://api.datadoghq.eu "https://api.ddog-gov.com "https://api.us2.ddog-gov.com "https://api.datadoghq.com "https://api.us3.datadoghq.com "https://api.us5.datadoghq.com /api/v2/security_monitoring/configuration/integration_config " \
-H "Accept: application/json" \
-H "DD-API-KEY: ${DD_API_KEY} " \
-H "DD-APPLICATION-KEY: ${DD_APP_KEY} "