GraphQL API
Use the Platform ConsoleGraphQLAPIla /api/console/v1/graphqlto query and move records, with authentication, organization purpose, and copy and insert examples.
Platform and Automation Console customers useGraphQLAPI the /api/console/v1/graphql. Its scheme covers organizations, frameworks, controls, measures, risks, audits, privacy, access reviews, Compliance Portal, consent for cookies, devices, and other product resources.
For the endpoint aspect, identifiers and error classes shared between interfaces, see API fundamentals.
Authentication
Section entitled “Authentication”Create a scalable access token from your account menu. OAuth tokensSend it as a carrier credential to each application:
POST /api/console/v1/graphql HTTP/1.1Host: eu.probo.comAuthorization: Bearer <oauth-token>Content-Type: application/jsonUse the source that matches the token implementation (https://eu.probo.com, https://us.probo.com, or your self-host source).
Interactive clients can instead use supported OAuth authorization streams. SSO sessions and SCIM tokens are not substitutes for an OAuth access token.
Request shape
Section entitled “Request shape”Send authenticated GraphQLca documents POST requests with a JSON body that contains query and, when necessary, variables. Use variables for IDs and user entries instead of interpolating values into a string of queries.
{ "query": "query Viewer { viewer { id } }", "variables": {}}The scheme is the contract for field nullity, entry types, entries, and page marks. Introspect the supported implementation, rather than copy fields from a non-related version.
Organization scope
Section entitled “Organization scope”Most compliance records belong to an organization. List the organizations that the token can access, then submit an organization ID to the fields and mutations covered by the organization. Do not assume that a logged-in user can access each organization on implementation.
query ListOrganizations { organizations { nodes { id name } }}query Organization($id: ID!) { organization(id: $id) { id name }}{ "query": "query Organization($id: ID!) { organization(id: $id) { id name } }", "variables": { "id": "org_01EXAMPLE" }}The platform uses globally unique IDs that encode an entity type; treat them as opaque strings.
Connections
Section entitled “Connections”List fields use GraphQL connections. Only request the required integration fields, pass a limited value first and follow pageInfo.endCursor while pageInfo.hasNextPage is true.
The embedded lists under organization(id:) are organized; top-level list fields such as organizations only return the records that the token can access.
Mutations and errors
“Mutations and Errors”Mutations valid authorization and current record status. A successful HTTP response may still contain GraphQL errors, so check both ___ZBT_I18N_RUNTIME_BLOCK_188__ and errors. Do not repeat invalid, prohibited or conflicting errors without changing the application.
Try a request
Section entitled “Try a request”With curl:
curl https://eu.probo.com/api/console/v1/graphql \ --header "Authorization: Bearer $PROBO_OAUTH_TOKEN" \ --header "Content-Type: application/json" \ --data '{"query":"query Viewer { viewer { id } }"}'About the CLI:
prb api 'query { organizations { nodes { id name } } }'prb api 'query($id: ID!) { organization(id: $id) { name } }' -f id=org_01EXAMPLESee prb api and CLI configuration pentru utilizarea steagurilor şi stdin.
Compatibility
Section entitled ‘Compatibility’GraphQL is a version endpoint, but its scheme evolves with the launch of the platform. Generate client types from the deployment you are targeting and review scheme changes during upgrades.MCP, CLI and CLI operations areined alongside GraphQL, but shipping-specific capabilities and launch times may vary.
When a top-level interface already covers the workflow, prefer CLI, MCP, or n8n references for everyday automation, and useGraphQLwhen you need a custom client or query form.