> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.itential.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.itential.com/_mcp/server.

# List all profiles

GET https://example.itential.io/profiles

Returns all the profiles in Itential Platform.

Reference: https://docs.itential.com/itential-cloud/api-reference/profiles/get-profiles

## Authentication

- `Authorization` header (basic auth, required) — Basic authentication of the form `Basic <base64(username:password)>`.

## Request

### Query parameters

- `contains` (string, optional) — contains
- `containsField` (string, optional) — containsField
- `equals` (string, optional) — equals
- `equalsField` (string, optional) — equalsField
- `startsWith` (string, optional) — startsWith
- `startsWithField` (string, optional) — startsWithField
- `skip` (integer, optional, default: 0) — skip
- `limit` (integer, optional, default: 25) — limit
- `sort` (enum, optional, default: name) — sort
  - Allowed values: `name`
- `order` (enum, optional, default: 1) — order
  - Allowed values: `-1`, `1`

## Response

### 200

Contains the data of a profile.

- `results` (list of object, optional)
  - `metadata` (object, optional)
    - `isActive` (boolean, optional) — Is profile the active profile.
    - `activeSync` (boolean, optional) — Is active profile in sync with the system.
  - `profile` (object, optional) — The root schema comprises the entire JSON document.
    - `uiProps` (object, optional)
      - `description` (string, optional)
      - `layout` (string, optional)
      - `home` (string, optional)
      - `login` (string, optional)
      - `profile` (string, optional)
      - `fav_icon` (string, optional)
    - `authenticationProps` (object, optional)
      - `description` (string, optional)
      - `logoutTime` (integer, optional) — The maximum number of time IAP has to make an api call before the user is logged out, in minutes.
      - `principalTimeout` (integer, optional) — The cache time of a given user's principal, in minutes.
      - `relayStateTimeout` (integer, optional) — The time before an SSO login callback expires, in seconds.
      - `uniqueSession` (boolean, optional) — When uniqueSession is set to true, only one session may be enabled for a given user.
      - `admins` (list of object, optional) — Members of these groups will be implicitly assigned with admin permissions
        - `provenance` (string, optional) — The name of the AAA adapter in which the groups reside.
        - `group` (string, optional) — The name of a user group which will have Pronghorn user management capabilities.
      - `cookieName` (string, optional) — The name used by Pronghorn to identify cookies for user session data
      - `brokerPrincipal` (boolean, optional) — When brokerPrincipal is set to true, the AAA adapter will be responsible for creating a principal.
    - `expressProps` (object, optional)
      - `description` (string, optional)
      - `cacheControl` (boolean, optional) — A boolean flag indicating whether Pronghorn will send the Cache-Control header. This can be useful in environments that leverage caching proxy servers.
      - `timeout` (integer, optional) — The maximum number of milliseconds Pronghorn has to respond to a request before a timeout will be returned to the client.
      - `access_control_allow_origin` (string, optional) — The configured domain name for the Access-Control-Allow-Origin header used for security.
      - `express_http` (object, optional)
        - `enable` (boolean, optional) — A boolean flag indicating whether Pronghorn will listen for incoming HTTP requests.
        - `port` (integer, optional)
      - `express_https` (object, optional)
        - `enable` (boolean, optional) — A boolean flag indicating whether Pronghorn will listen for incoming HTTPS requests.
        - `port` (integer, optional)
        - `key` (string, optional) — The server's private key to use for all https transactions. If the private key is encrypted with a passphrase, you should also include the express_https.passphrase property.
        - `passphrase` (string, optional) — The passphrase for the server's private key. You should only include this property if the private key is encrypted with a passphrase.
        - `cert` (string, optional) — The server's public certificate to use for all HTTPS transactions.
        - `secureProtocol` (enum, optional) — The secureProtocol can be used to configure the set of allowed SSL/TLS protocol versions. Ignored when either tlsMinVersion or tlsMaxVersion is given.
          - Allowed values: `TLS_method`, `TLSv1_2_method`, `TLSv1_1_method`, `TLSv1_method`
        - `tlsMinVersion` (enum, optional) — Minimum permitted TLS version. Overrides secureProtocol.
          - Allowed values: `TLSv1.3`, `TLSv1.2`, `TLSv1.1`, `TLSv1`
        - `tlsMaxVersion` (enum, optional) — Maximum permitted TLS version. Overrides secureProtocol.
          - Allowed values: `TLSv1.3`, `TLSv1.2`, `TLSv1.1`, `TLSv1`
        - `ciphers` (string, optional) — The set of ciphers to allow when establishing an encrypted session.
        - `client_reneg_limit` (integer, optional) — The maximum number of client renegotiations allowed per renegotiation window.
        - `client_reneg_window` (integer, optional) — The renegotiation window allows a limited number of client renegotiation requests within a configured number of seconds.
      - `allowedHttpOptionalVerbs` (list of enum, optional) — An array of optional HTTP verbs that are allowed to be used in requests to IAP
        - Allowed values: `ACL`, `BIND`, `CHECKOUT`, `CONNECT`, `COPY`, `LINK`, `LOCK`, `MERGE`, `MKACTIVITY`, `MKCALENDAR`, `MKCOL`, `MOVE`, `M-SEARCH`, `NOTIFY`, `PROPFIND`, `PROPPATCH`, `PURGE`, `REBIND`, `REPORT`, `SEARCH`, `SUBSCRIBE`, `TRACE`, `UNBIND`, `UNLINK`, `UNLOCK`, `UNSUBSCRIBE`
    - `loggerProps` (object, optional)
      - `description` (string, optional)
      - `log_directory` (string, optional) — The directory to store Pronghorn log files.
      - `log_filename` (string, optional) — The name of the current Pronghorn log file.
      - `log_max_file_size` (integer, optional) — The maximum size of each Pronghorn log file in bytes.
      - `log_max_files` (integer, optional) — The maximum number of log files maintained on the server.
      - `log_level` (enum, optional)
        - Allowed values: `error`, `warn`, `info`, `debug`, `trace`, `spam`
      - `console_level` (enum, optional)
        - Allowed values: `error`, `warn`, `info`, `debug`, `trace`, `spam`
      - `log_format_json` (boolean, optional, default: false) — If true, log entries will be written in JSON format. Otherwise, log entries will be written in plaintext.
      - `console_format_json` (boolean, optional, default: false) — If true, console logs will be written in JSON format. Otherwise, they will be written in plaintext.
      - `webserver` (object, optional) — Determines how to set up the web server access log.
        - `log_directory` (string, optional) — The directory to store web server access log files.
        - `log_filename` (string, optional) — The name for the web server access log file.
      - `syslog` (object, optional) — Allows Pronghorn to send log messages to a local or remote syslog daemon.
        - `level` (enum, optional)
          - Allowed values: `debug`, `info`, `warning`, `error`
        - `host` (string, optional) — The host running syslogd.
        - `port` (integer, optional) — The port on the host that syslog is running on.
        - `protocol` (enum, optional) — The network protocol to log over. Can be one of tcp4, udp4, unix or unix-connect.
          - Allowed values: `tcp4`, `udp4`, `unix`, `unix-connect`
        - `facility` (string, optional) — The syslog facility to use.
        - `type` (enum, optional) — The type of syslog protocol to use. Possible values are BSD and 5424.
          - Allowed values: `BSD`, `5424`
        - `path` (string, optional) — The path to the syslog dgram socket (i.e. /dev/log or /var/run/syslog for OS X). If path is used, host, port and protocol do not need to be configured.
        - `pid` (string, optional) — Process identifier (PID) of the process that log messages are coming from (Default is process.pid).
        - `localhost` (string, optional) — The host to indicate that log messages are coming from.
        - `app_name` (string, optional) — The name of the application.
        - `eol` (string, optional) — The end of line character to be added to the end of the message.
        - `format_json` (boolean, optional, default: false) — If true, syslog logs will be written in JSON format. Otherwise, they will be written in plaintext.
    - `redisProps` (object or object, optional)
      - object
        - `host` (string, required) — The IP or hostname of the server running the Redis service.
        - `port` (integer, required)
      - object
        - `sentinels` (list of object, required) — The list of Redis hosts for sentinel configuration.
          - `host` (string, optional)
          - `port` (integer, optional)
        - `name` (string, required) — The name of the master node in the Redis sentinel group.
    - `auditProps` (object, optional)
      - `description` (string, optional)
      - `audit` (boolean, optional)
      - `brokerValidation` (boolean, optional)
    - `pathProps` (object, optional)
      - `description` (string, optional)
      - `encrypted` (boolean, optional) — A boolean flag indicating Pronghorn core is encrypted.
    - `alarmProps` (list of object, optional)
      - `description` (string, optional)
      - `ip` (string, optional) — The IP address of the remote alarm receiver. FQDNs are also supported in this field.
      - `community` (string, optional) — The SNMP community to apply to the outgoing trap or inform.
      - `properties` (object, optional) — Remote SNMP destination config.
      - `type` (enum, optional) — The type can be configured as either a trap or inform.
        - Allowed values: `trap`, `inform`
    - `id` (string, optional)
    - `services` (list of string, optional)
    - `description` (string, optional)
    - `adapterStrategy` (object, optional)
      - `device` (object, optional) — Defines the order in which southbound systems are called.
        - `adapterTypes` (list of enum, optional) — A list of adapter types that manages the devices.
          - Allowed values: `NSO`, `AutomationGateway`
        - `exceptions` (object, optional) — An override for the runCommand's preference to a southbound system.
          - `runCommand` (string, optional) — Runs a command on a device.
    - `systemProps` (object, optional) — Properties used to configure IAP process.
      - `shutdownTimeout` (integer, optional) — The amount of time a service should wait before shutting down, in seconds.
      - `servicesBlacklist` (list of string, optional) — An array of services that blocks CRUD operation access for each service listed.
      - `launchDelay` (integer, optional) — The application/adapter launch delay, in seconds.
      - `launchTimeout` (integer, optional) — The application/adapter launch timeout, in seconds.
      - `serviceHealthCheckInterval` (integer, optional) — How often to update service health, measured in seconds.
      - `serviceHealthCheckUnhealthyThreshold` (integer, optional) — Health data staleness threshhold, measured in number of missed health checks. Services which fail to report health data will be assumed to be offline.
      - `deadProcessCheck` (boolean, optional) — Enable/disable IAP check for dead applications/adapters.
      - `deadProcessCheckInterval` (integer, optional) — How often to check if application/adapter stopped sending healthcheck pings, in seconds.
      - `deadProcessMaxPeriod` (integer, optional) — Maximum time period for application/adapter without sending healthcheck ping, in seconds.
      - `externalRequestTimeout` (integer, optional) — The timeout for external API requests, in seconds.
      - `deviceCountPollingInterval` (integer, optional) — The interval for how often IAP polls for the number of devices, in hours.
      - `serverIdStrategy` (enum, optional) — Strategy used to generate server ID, if one is not set using the server_id property. Selecting mac:port will generate a server_id using a combination of MAC address and port, while random will generate a random ID on each startup.
        - Allowed values: `mac:port`, `random`
      - `eventWorkerCount` (integer, optional, default: 3) — The number of worker threads available for event processing.
      - `transformationWorkerCount` (integer, optional, default: 3) — The number of worker threads available for transformation processing.
      - `taskWorkerThreadCount` (integer, optional, default: 1) — The number of background threads available for task processing. Maximum value of 4.
      - `taskWorkerRateLimit` (integer, optional, default: 0) — The maximum number of tasks to run per period. The value 0 disables the rate limiter.
      - `taskWorkerRateLimitPeriod` (integer, optional, default: 1) — The time period in seconds for the task worker rate limit.
    - `prebuiltProps` (object, optional)
      - `repoConfigs` (object, optional) — The configurations used to fetch Prebuilts from different repositories.
        - `@itentialopensource` (object, optional)
          - `enabled` (boolean, optional) — A flag that denotes if the repository configuration is connected
          - `type` (enum, optional) — The type of Repository
            - Allowed values: `gitlab`
          - `hostname` (string, optional) — The hostname of the Respository endpoint
          - `path` (string, optional) — The path of the Repository endpoint
          - `credentials` (object, optional)
            - `token` (string, optional) — An access token used to make HTTP requests
    - `integrationProps` (object, optional)
      - `threadCount` (integer, optional) — The number of threads available for API requests.
      - `timeout` (integer, optional) — The number of milliseconds until an integration request times out.
    - `retryStrategy` (object, optional) — Properties used to configure the strategy services use on crash.
      - `maxRetries` (integer, optional) — Specifies the amount of times services will retry on crash before stopping.
      - `retryResetTimer` (integer, optional) — Specifies the amount of times between each retry before the count will reset in milliseconds.
    - `serviceDirectory` (string, optional) — Directory at which to find additional services.
- `total` (integer, optional) — The total number of documents

## Errors

### 500 Internal Server Error

Error response from API

- `any`

## Examples

**Response**

```json
{
  "results": [
    {
      "metadata": {
        "isActive": true,
        "activeSync": true
      },
      "profile": {
        "uiProps": {
          "description": "UI",
          "layout": "node_modules/@itential/pronghorn-core/ui/views/layout.jade",
          "home": "node_modules/@itential/pronghorn-core/ui/views/home.jade",
          "login": "node_modules/@itential/pronghorn-core/ui/views/login.jade",
          "profile": "node_modules/@itential/pronghorn-core/ui/views/profile.jade",
          "fav_icon": "node_modules/@itential/pronghorn-core/ui/img/favicon.ico"
        },
        "authenticationProps": {
          "description": "Authentication",
          "logoutTime": 20,
          "principalTimeout": 20,
          "relayStateTimeout": 600,
          "uniqueSession": false,
          "admins": [
            {
              "provenance": "Local AAA",
              "group": "admin"
            }
          ],
          "cookieName": "pronghorn_token",
          "brokerPrincipal": false
        },
        "expressProps": {
          "description": "Express Server",
          "cacheControl": false,
          "timeout": 300000,
          "access_control_allow_origin": "*",
          "express_http": {
            "enable": false,
            "port": 1
          },
          "express_https": {
            "enable": true,
            "port": 1,
            "key": "/opt/pronghorn/current/keys/key.pem",
            "passphrase": "string",
            "cert": "/opt/pronghorn/current/keys/cert.pem",
            "secureProtocol": "TLSv1_2_method",
            "tlsMinVersion": "TLSv1.3",
            "tlsMaxVersion": "TLSv1.3",
            "ciphers": "ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256",
            "client_reneg_limit": 1,
            "client_reneg_window": 600
          },
          "allowedHttpOptionalVerbs": [
            "ACL"
          ]
        },
        "loggerProps": {
          "description": "Logging",
          "log_directory": "/var/log/pronghorn",
          "log_filename": "pronghorn.log",
          "log_max_file_size": 1048576,
          "log_max_files": 100,
          "log_level": "error",
          "console_level": "error",
          "log_format_json": false,
          "console_format_json": false,
          "webserver": {
            "log_directory": "/var/log/pronghorn",
            "log_filename": "webserver.log"
          },
          "syslog": {
            "level": "debug",
            "host": "localhost",
            "port": 514,
            "protocol": "udp4",
            "facility": "local0",
            "type": "5424",
            "path": "/dev/log",
            "pid": "process.pid",
            "localhost": "localhost",
            "app_name": "process.title",
            "eol": "CR",
            "format_json": false
          }
        },
        "redisProps": {
          "host": "127.0.0.1",
          "port": 6379
        },
        "auditProps": {
          "description": "Audit",
          "audit": true,
          "brokerValidation": true
        },
        "pathProps": {
          "description": "string",
          "encrypted": true
        },
        "alarmProps": [
          {
            "description": "string",
            "ip": "127.0.0.1",
            "community": "public",
            "properties": {
              "retries": 1,
              "timeout": 5000,
              "transport": "udp4",
              "trapPort": 162,
              "version": "V1"
            },
            "type": "trap"
          }
        ],
        "id": "profile1",
        "services": [
          "WorkflowBuilder"
        ],
        "description": "An IAP Profile",
        "adapterStrategy": {
          "device": {
            "adapterTypes": [
              "NSO"
            ],
            "exceptions": {
              "runCommand": "string"
            }
          }
        },
        "systemProps": {
          "shutdownTimeout": 3,
          "servicesBlacklist": [
            "Local AAA"
          ],
          "launchDelay": 5,
          "launchTimeout": 60,
          "serviceHealthCheckInterval": 1,
          "serviceHealthCheckUnhealthyThreshold": 1,
          "deadProcessCheck": false,
          "deadProcessCheckInterval": 5,
          "deadProcessMaxPeriod": 15,
          "externalRequestTimeout": 5,
          "deviceCountPollingInterval": 24,
          "serverIdStrategy": "mac:port",
          "eventWorkerCount": 3,
          "transformationWorkerCount": 3,
          "taskWorkerThreadCount": 1,
          "taskWorkerRateLimit": 0,
          "taskWorkerRateLimitPeriod": 1
        },
        "prebuiltProps": {
          "repoConfigs": {
            "@itentialopensource": {
              "enabled": true,
              "type": "gitlab",
              "hostname": "gitlab.com",
              "path": "itentialopensource/pre-built-automations",
              "credentials": {
                "token": "uTc_P4pnMAEsLbQHmyOt"
              }
            }
          }
        },
        "integrationProps": {
          "threadCount": 5,
          "timeout": 15000
        },
        "retryStrategy": {
          "maxRetries": 5,
          "retryResetTimer": 30000
        },
        "serviceDirectory": "string"
      }
    }
  ],
  "total": 1
}
```

**SDK Code**

```python
import requests

url = "https://example.itential.io/profiles"

response = requests.get(url)

print(response.json())
```

```javascript
const url = 'https://example.itential.io/profiles';
const options = {method: 'GET'};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://example.itential.io/profiles"

	req, _ := http.NewRequest("GET", url, nil)

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://example.itential.io/profiles")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://example.itential.io/profiles")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://example.itential.io/profiles');

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://example.itential.io/profiles");
var request = new RestRequest(Method.GET);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let request = NSMutableURLRequest(url: NSURL(string: "https://example.itential.io/profiles")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```