Skip to content

Instantly share code, notes, and snippets.

@0xSojalSec
Forked from win3zz/zendesk_endpoints.txt
Created July 30, 2023 18:28
Show Gist options
  • Star 1 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save 0xSojalSec/3d3479d55a754551a2779dc3f7318ff0 to your computer and use it in GitHub Desktop.
Save 0xSojalSec/3d3479d55a754551a2779dc3f7318ff0 to your computer and use it in GitHub Desktop.
List of Zendesk API Endpoints for Fuzzing [Penetration Testing]
POST /api/v2/accounts
GET /api/v2/activities?since=cstest
GET /api/v2/audit_logs?filter[source_type]=cstest&filter[source_id]=1&filter[actor_id]=1&filter[ip_address]=cstest&filter[created_at]=cstest&filter[action]=cstest&sort_by=cstest&sort_order=cstest&sort=cstest
GET /api/v2/automations
POST /api/v2/automations
GET /api/v2/bookmarks
POST /api/v2/bookmarks
GET /api/v2/brands
POST /api/v2/brands
GET /api/v2/custom_objects
POST /api/v2/custom_objects
GET /api/v2/custom_roles
POST /api/v2/custom_roles
GET /api/v2/custom_statuses?status_categories=cstest&active=true&default=true
POST /api/v2/custom_statuses
GET /api/v2/deleted_tickets?sort_by=id&sort_order=asc
GET /api/v2/deleted_users
GET /api/v2/group_memberships
POST /api/v2/group_memberships
GET /api/v2/groups
POST /api/v2/groups
GET /api/v2/job_statuses
GET /api/v2/locales
GET /api/v2/macros?include=cstest&access=cstest&active=true&category=1&group_id=1&only_viewable=true&sort_by=cstest&sort_order=cstest
POST /api/v2/macros
GET /api/v2/organization_fields
POST /api/v2/organization_fields
GET /api/v2/organization_memberships
POST /api/v2/organization_memberships
GET /api/v2/organization_subscriptions
POST /api/v2/organization_subscriptions
GET /api/v2/organizations
POST /api/v2/organizations
GET /api/v2/problems
GET /api/v2/recipient_addresses
POST /api/v2/recipient_addresses
GET /api/v2/requests
POST /api/v2/requests
GET /api/v2/resource_collections
POST /api/v2/resource_collections
GET /api/v2/satisfaction_ratings
GET /api/v2/satisfaction_reasons
GET /api/v2/search?query=cstest&sort_by=cstest&sort_order=cstest
GET /api/v2/sessions
GET /api/v2/sharing_agreements
POST /api/v2/sharing_agreements
POST /api/v2/skips
GET /api/v2/suspended_tickets?sort_by=cstest&sort_order=cstest
GET /api/v2/tags
GET /api/v2/target_failures
GET /api/v2/targets
POST /api/v2/targets
GET /api/v2/ticket_audits?limit=1
GET /api/v2/ticket_fields?locale=cstest
POST /api/v2/ticket_fields
GET /api/v2/ticket_forms?active=true&end_user_visible=true&fallback_to_default=true&associated_to_brand=true
POST /api/v2/ticket_forms
GET /api/v2/ticket_metrics
GET /api/v2/tickets?external_id=cstest
POST /api/v2/tickets
GET /api/v2/trigger_categories?page[after]=cstest&page[before]=cstest&page[size]=1&sort=-created_at&include=rule_counts
POST /api/v2/trigger_categories
GET /api/v2/triggers?active=true&sort_by=cstest&sort_order=cstest&category_id=cstest
POST /api/v2/triggers
POST /api/v2/uploads
GET /api/v2/user_fields
POST /api/v2/user_fields
GET /api/v2/users?role=admin&role[]=cstest&permission_set=1&external_id=cstest
POST /api/v2/users
GET /api/v2/views?access=cstest&active=true&group_id=1&sort_by=cstest&sort_order=cstest
POST /api/v2/views
GET /api/v2/workspaces
POST /api/v2/workspaces
GET /api/v2/account/settings
PUT /api/v2/account/settings
GET /api/v2/accounts/available?subdomain=cstest
GET /api/v2/activities/1
GET /api/v2/activities/count
GET /api/v2/attachments/1
PUT /api/v2/attachments/1
GET /api/v2/audit_logs/1
POST /api/v2/audit_logs/export?filter[source_type]=cstest&filter[source_id]=1&filter[actor_id]=1&filter[ip_address]=cstest&filter[created_at]=cstest&filter[action]=cstest
GET /api/v2/autocomplete/tags?name=cstest
GET /api/v2/automations/1
PUT /api/v2/automations/1
DELETE /api/v2/automations/1
GET /api/v2/automations/active
DELETE /api/v2/automations/destroy_many?ids=1&ids=1
GET /api/v2/automations/search?query=cstest&active=true&sort_by=cstest&sort_order=cstest&include=cstest
PUT /api/v2/automations/update_many
DELETE /api/v2/bookmarks/1
GET /api/v2/brands/1
PUT /api/v2/brands/1
DELETE /api/v2/brands/1
GET /api/v2/brands/check_host_mapping?host_mapping=cstest&subdomain=cstest
PUT /api/v2/chat_file_redactions/1
PUT /api/v2/chat_redactions/1
PUT /api/v2/comment_redactions/1
GET /api/v2/custom_objects/:custom_object_key
PATCH /api/v2/custom_objects/:custom_object_key
DELETE /api/v2/custom_objects/:custom_object_key
GET /api/v2/custom_roles/1
PUT /api/v2/custom_roles/1
DELETE /api/v2/custom_roles/1
PUT /api/v2/custom_status/default
GET /api/v2/custom_statuses/1
PUT /api/v2/custom_statuses/1
DELETE /api/v2/deleted_tickets/1
DELETE /api/v2/deleted_tickets/destroy_many?ids=cstest
PUT /api/v2/deleted_tickets/restore_many?ids=cstest
GET /api/v2/deleted_users/1
DELETE /api/v2/deleted_users/1
GET /api/v2/deleted_users/count
GET /api/v2/dynamic_content/items
POST /api/v2/dynamic_content/items
GET /api/v2/group_memberships/1
DELETE /api/v2/group_memberships/1
GET /api/v2/group_memberships/assignable
POST /api/v2/group_memberships/create_many
DELETE /api/v2/group_memberships/destroy_many?ids=cstest
GET /api/v2/group_slas/policies
POST /api/v2/group_slas/policies
GET /api/v2/groups/1
PUT /api/v2/groups/1
DELETE /api/v2/groups/1
GET /api/v2/groups/assignable
GET /api/v2/groups/count
POST /api/v2/imports/tickets?archive_immediately=true
GET /api/v2/incremental/organizations?start_time=1
GET /api/v2/incremental/ticket_events?start_time=1
GET /api/v2/incremental/ticket_metric_events?start_time=1
GET /api/v2/incremental/tickets?start_time=1
GET /api/v2/incremental/users?start_time=1&per_page=1
GET /api/v2/job_statuses/1
GET /api/v2/job_statuses/show_many?ids=cstest
GET /api/v2/locales/1
GET /api/v2/locales/agent
GET /api/v2/locales/current
GET /api/v2/locales/detect_best_locale
GET /api/v2/locales/public
GET /api/v2/macros/1
PUT /api/v2/macros/1
DELETE /api/v2/macros/1
GET /api/v2/macros/actions
GET /api/v2/macros/active?include=cstest&access=cstest&category=1&group_id=1&sort_by=cstest&sort_order=cstest
POST /api/v2/macros/attachments
GET /api/v2/macros/categories
GET /api/v2/macros/definitions
DELETE /api/v2/macros/destroy_many?ids=1&ids=1
GET /api/v2/macros/new?macro_id=1&ticket_id=1
GET /api/v2/macros/search?include=cstest&access=cstest&active=true&category=1&group_id=1&only_viewable=true&sort_by=cstest&sort_order=cstest&query=cstest
PUT /api/v2/macros/update_many
GET /api/v2/organization_fields/1
PUT /api/v2/organization_fields/1
DELETE /api/v2/organization_fields/1
PUT /api/v2/organization_fields/reorder
GET /api/v2/organization_memberships/1
DELETE /api/v2/organization_memberships/1
POST /api/v2/organization_memberships/create_many
DELETE /api/v2/organization_memberships/destroy_many?ids=1&ids=1
GET /api/v2/organization_subscriptions/1
DELETE /api/v2/organization_subscriptions/1
GET /api/v2/organizations/1
PUT /api/v2/organizations/1
DELETE /api/v2/organizations/1
GET /api/v2/organizations/autocomplete?name=cstest&field_id=cstest&source=cstest
GET /api/v2/organizations/count
POST /api/v2/organizations/create_many
POST /api/v2/organizations/create_or_update
DELETE /api/v2/organizations/destroy_many?ids=cstest&external_ids=cstest
GET /api/v2/organizations/search?external_id=1
GET /api/v2/organizations/show_many?ids=cstest&external_ids=cstest
PUT /api/v2/organizations/update_many?ids=cstest&external_ids=cstest
POST /api/v2/problems/autocomplete?text=cstest
POST /api/v2/push_notification_devices/destroy_many
GET /api/v2/recipient_addresses/1
PUT /api/v2/recipient_addresses/1
DELETE /api/v2/recipient_addresses/1
GET /api/v2/requests/1
PUT /api/v2/requests/1
GET /api/v2/requests/search
GET /api/v2/resource_collections/1
PUT /api/v2/resource_collections/1
DELETE /api/v2/resource_collections/1
GET /api/v2/routing/attributes
POST /api/v2/routing/attributes
GET /api/v2/satisfaction_ratings/1
GET /api/v2/satisfaction_ratings/count
GET /api/v2/satisfaction_reasons/1
GET /api/v2/search/count?query=cstest
GET /api/v2/search/export?query=cstest&page[size]=1&filter[type]=cstest
GET /api/v2/sharing_agreements/1
PUT /api/v2/sharing_agreements/1
DELETE /api/v2/sharing_agreements/1
GET /api/v2/slas/policies
POST /api/v2/slas/policies
GET /api/v2/suspended_tickets/1
DELETE /api/v2/suspended_tickets/1
POST /api/v2/suspended_tickets/attachments
DELETE /api/v2/suspended_tickets/destroy_many?ids=cstest
POST /api/v2/suspended_tickets/export
PUT /api/v2/suspended_tickets/recover_many?ids=cstest
GET /api/v2/tags/count
GET /api/v2/target_failures/1
GET /api/v2/targets/1
PUT /api/v2/targets/1
DELETE /api/v2/targets/1
GET /api/v2/ticket_fields/1
PUT /api/v2/ticket_fields/1
DELETE /api/v2/ticket_fields/1
GET /api/v2/ticket_fields/count
GET /api/v2/ticket_forms/1
PUT /api/v2/ticket_forms/1
DELETE /api/v2/ticket_forms/1
PUT /api/v2/ticket_forms/reorder
GET /api/v2/ticket_forms/show_many?ids=cstest&active=true&end_user_visible=true&fallback_to_default=true&associated_to_brand=true
GET /api/v2/ticket_metrics/1
GET /api/v2/tickets/1
PUT /api/v2/tickets/1
DELETE /api/v2/tickets/1
GET /api/v2/tickets/count
POST /api/v2/tickets/create_many
DELETE /api/v2/tickets/destroy_many?ids=cstest
PUT /api/v2/tickets/mark_many_as_spam?ids=cstest
GET /api/v2/tickets/show_many?ids=cstest
PUT /api/v2/tickets/update_many?ids=cstest
GET /api/v2/trigger_categories/1
PATCH /api/v2/trigger_categories/1
DELETE /api/v2/trigger_categories/1
POST /api/v2/trigger_categories/jobs
GET /api/v2/triggers/1
PUT /api/v2/triggers/1
DELETE /api/v2/triggers/1
GET /api/v2/triggers/active?sort_by=cstest&sort_order=cstest&category_id=cstest
GET /api/v2/triggers/definitions
DELETE /api/v2/triggers/destroy_many?ids=cstest
PUT /api/v2/triggers/reorder
GET /api/v2/triggers/search?query=cstest&json=[object Object]&active=true&sort_by=cstest&sort_order=cstest&include=cstest
PUT /api/v2/triggers/update_many
DELETE /api/v2/uploads/:token
GET /api/v2/user_fields/1
PUT /api/v2/user_fields/1
DELETE /api/v2/user_fields/1
PUT /api/v2/user_fields/reorder
GET /api/v2/users/1
PUT /api/v2/users/1
DELETE /api/v2/users/1
GET /api/v2/users/autocomplete?name=cstest&field_id=cstest&source=cstest
GET /api/v2/users/count?role=admin&role[]=cstest&permission_set=1
POST /api/v2/users/create_many
POST /api/v2/users/create_or_update
POST /api/v2/users/create_or_update_many
DELETE /api/v2/users/destroy_many?ids=cstest&external_ids=cstest
POST /api/v2/users/logout_many?ids=cstest
GET /api/v2/users/me
POST /api/v2/users/request_create
GET /api/v2/users/search?query=cstest&external_id=cstest
GET /api/v2/users/show_many?ids=cstest&external_ids=cstest
PUT /api/v2/users/update_many?ids=cstest&external_ids=cstest
GET /api/v2/views/1
PUT /api/v2/views/1
DELETE /api/v2/views/1
GET /api/v2/views/active?access=cstest&group_id=1&sort_by=cstest&sort_order=cstest
GET /api/v2/views/compact
GET /api/v2/views/count
GET /api/v2/views/count_many?ids=cstest
DELETE /api/v2/views/destroy_many?ids=cstest
POST /api/v2/views/preview
GET /api/v2/views/search?query=cstest&access=cstest&active=true&group_id=1&sort_by=cstest&sort_order=cstest&include=cstest
GET /api/v2/views/show_many?ids=cstest&active=true
PUT /api/v2/views/update_many
GET /api/v2/workspaces/1
PUT /api/v2/workspaces/1
DELETE /api/v2/workspaces/1
DELETE /api/v2/workspaces/destroy_many?ids=1&ids=1
PUT /api/v2/workspaces/reorder
GET /api/v2/brands/1/check_host_mapping
POST /api/v2/channels/voice/tickets
GET /api/v2/custom_objects/:custom_object_key/fields
POST /api/v2/custom_objects/:custom_object_key/fields
PUT /api/v2/custom_objects/:custom_object_key/fields
GET /api/v2/custom_objects/:custom_object_key/records?external_ids[]=cstest&external_ids[]=cstest
POST /api/v2/custom_objects/:custom_object_key/records
GET /api/v2/custom_objects/limits/object_limit
GET /api/v2/custom_objects/limits/record_limit
PUT /api/v2/deleted_tickets/1/restore
GET /api/v2/dynamic_content/items/1
PUT /api/v2/dynamic_content/items/1
DELETE /api/v2/dynamic_content/items/1
GET /api/v2/dynamic_content/items/show_many?identifiers=cstest
GET /api/v2/group_slas/policies/1
PUT /api/v2/group_slas/policies/1
DELETE /api/v2/group_slas/policies/1
GET /api/v2/group_slas/policies/definitions
PUT /api/v2/group_slas/policies/reorder?group_sla_policy_ids=cstest&group_sla_policy_ids=cstest
POST /api/v2/imports/tickets/create_many?archive_immediately=true
GET /api/v2/incremental/:incremental_resource/sample?start_time=1
GET /api/v2/incremental/routing/attribute_values
GET /api/v2/incremental/routing/attributes
GET /api/v2/incremental/routing/instance_values
GET /api/v2/incremental/tickets/cursor?start_time=1&cursor=cstest
GET /api/v2/incremental/users/cursor?start_time=1&cursor=cstest&per_page=1
GET /api/v2/macros/1/apply
GET /api/v2/macros/1/attachments
POST /api/v2/macros/1/attachments
GET /api/v2/macros/attachments/1
GET /api/v2/organizations/1/related
PUT /api/v2/recipient_addresses/1/verify
GET /api/v2/relationships/definitions/:target_type
GET /api/v2/requests/1/comments?since=cstest&role=cstest
GET /api/v2/routing/attributes/1
PUT /api/v2/routing/attributes/1
DELETE /api/v2/routing/attributes/1
GET /api/v2/routing/attributes/definitions
GET /api/v2/routing/requirements/fulfilled
GET /api/v2/slas/policies/1
PUT /api/v2/slas/policies/1
DELETE /api/v2/slas/policies/1
GET /api/v2/slas/policies/definitions
PUT /api/v2/slas/policies/reorder?sla_policy_ids=1&sla_policy_ids=1
PUT /api/v2/suspended_tickets/1/recover
GET /api/v2/ticket_fields/1/options
POST /api/v2/ticket_fields/1/options
POST /api/v2/ticket_forms/1/clone
GET /api/v2/tickets/1/audits
GET /api/v2/tickets/1/collaborators
GET /api/v2/tickets/1/comments?include_inline_images=true&include=cstest
GET /api/v2/tickets/1/email_ccs
GET /api/v2/tickets/1/followers
GET /api/v2/tickets/1/incidents
PUT /api/v2/tickets/1/mark_as_spam
POST /api/v2/tickets/1/merge
GET /api/v2/tickets/1/related
POST /api/v2/tickets/1/satisfaction_rating
GET /api/v2/tickets/1/tags
POST /api/v2/tickets/1/tags
PUT /api/v2/tickets/1/tags
DELETE /api/v2/tickets/1/tags
GET /api/v2/triggers/1/revisions
GET /api/v2/user_fields/1/options
POST /api/v2/user_fields/1/options
GET /api/v2/users/1/compliance_deletion_statuses?application=cstest
GET /api/v2/users/1/identities
POST /api/v2/users/1/identities
PUT /api/v2/users/1/merge
POST /api/v2/users/1/password
PUT /api/v2/users/1/password
GET /api/v2/users/1/related
DELETE /api/v2/users/1/sessions
GET /api/v2/users/1/skips?sort_order=asc
GET /api/v2/users/me/logout
GET /api/v2/users/me/session
GET /api/v2/views/1/count
GET /api/v2/views/1/execute?sort_by=cstest&sort_order=cstest
GET /api/v2/views/1/export
GET /api/v2/views/1/tickets?sort_by=cstest&sort_order=cstest
POST /api/v2/views/preview/count
GET /api/v2/custom_objects/:custom_object_key/fields/1
PATCH /api/v2/custom_objects/:custom_object_key/fields/1
DELETE /api/v2/custom_objects/:custom_object_key/fields/1
GET /api/v2/custom_objects/:custom_object_key/limits/field_limit
GET /api/v2/custom_objects/:custom_object_key/records/1
PATCH /api/v2/custom_objects/:custom_object_key/records/1
DELETE /api/v2/custom_objects/:custom_object_key/records/1
GET /api/v2/custom_objects/:custom_object_key/records/autocomplete?name=cstest
GET /api/v2/custom_objects/:custom_object_key/records/count
GET /api/v2/custom_objects/:custom_object_key/records/show_many?ids=cstest&ids=cstest
GET /api/v2/dynamic_content/items/1/variants
POST /api/v2/dynamic_content/items/1/variants
GET /api/v2/requests/1/comments/1
GET /api/v2/routing/agents/1/instance_values
POST /api/v2/routing/agents/1/instance_values
GET /api/v2/routing/attributes/1/values
POST /api/v2/routing/attributes/1/values
GET /api/v2/routing/tickets/1/instance_values
POST /api/v2/routing/tickets/1/instance_values
GET /api/v2/ticket_fields/1/options/1
DELETE /api/v2/ticket_fields/1/options/1
GET /api/v2/tickets/1/audits/1
GET /api/v2/tickets/1/audits/count
GET /api/v2/tickets/1/comments/count
GET /api/v2/triggers/1/revisions/1
GET /api/v2/user_fields/1/options/1
DELETE /api/v2/user_fields/1/options/1
GET /api/v2/users/1/identities/1
PUT /api/v2/users/1/identities/1
DELETE /api/v2/users/1/identities/1
DELETE /api/v2/users/1/organizations/1
GET /api/v2/users/1/password/requirements
GET /api/v2/users/1/sessions/1
DELETE /api/v2/users/1/sessions/1
GET /api/v2/users/me/session/renew
GET /api/v2/:target_type/1/relationship_fields/1/:source_type
GET /api/v2/dynamic_content/items/1/variants/1
PUT /api/v2/dynamic_content/items/1/variants/1
DELETE /api/v2/dynamic_content/items/1/variants/1
POST /api/v2/dynamic_content/items/1/variants/create_many
PUT /api/v2/dynamic_content/items/1/variants/update_many
GET /api/v2/routing/attributes/1/values/1
PATCH /api/v2/routing/attributes/1/values/1
DELETE /api/v2/routing/attributes/1/values/1
PUT /api/v2/tickets/1/audits/1/make_private
PUT /api/v2/tickets/1/comments/1/make_private
PUT /api/v2/tickets/1/comments/1/redact
GET /api/v2/tickets/1/macros/1/apply
PUT /api/v2/users/1/group_memberships/1/make_default
PUT /api/v2/users/1/identities/1/make_primary
PUT /api/v2/users/1/identities/1/request_verification
PUT /api/v2/users/1/identities/1/verify
PUT /api/v2/users/1/organization_memberships/1/make_default
PUT /api/v2/users/1/organizations/1/make_default
POST /api/v2/channels/voice/agents/1/tickets/1/display
POST /api/v2/channels/voice/agents/1/users/1/display
PUT /api/v2/tickets/1/comments/1/attachments/1/redact
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment