SNMP Credential Profiles
Engineer or admin CRUD for reusable SNMP credential profiles. Profiles decouple credentials from individual SNMP targets, allowing multiple targets to share a single set of credentials. When a profile is deleted, linked targets revert to their inline credentials (ON DELETE SET NULL).
Create SNMP Credential Profile
POST /api/v1/snmp-credential-profiles
Request body:
{
"name": "campus-v2c",
"description": "SNMPv2c community for campus routers",
"version": "v2c",
"community": "public"
}
SNMPv3 example:
{
"name": "dc-v3-authpriv",
"description": "SNMPv3 auth+priv for datacenter switches",
"version": "v3",
"v3_user": "snmpuser",
"v3_auth_proto": "SHA",
"v3_auth_pass": "authpass123",
"v3_priv_proto": "AES",
"v3_priv_pass": "privpass123"
}
Validation:
name is required, must be unique
version is required (valid values: "v2c", "v3" — the snmp-targets endpoint speaks the same canonical vocabulary and additionally normalizes the bare "2c"/"3" spellings)
community is required for version "v2c"
v3_user, v3_auth_proto, v3_auth_pass are required for version "v3"
v3_priv_proto and v3_priv_pass are optional for version "v3" (omit for authNoPriv)
description is optional
Response: 201 Created
{
"id": "uuid",
"name": "campus-v2c",
"description": "SNMPv2c community for campus routers",
"version": "v2c",
"community": "public",
"v3_user": null,
"v3_auth_proto": null,
"v3_auth_pass": null,
"v3_priv_proto": null,
"v3_priv_pass": null,
"created_at": "2026-02-24T12:00:00Z",
"updated_at": "2026-02-24T12:00:00Z"
}
Error responses:
400 Bad Request -- Missing required fields, invalid version, or duplicate name
403 Forbidden -- Non-admin user
List SNMP Credential Profiles
GET /api/v1/snmp-credential-profiles
List all credential profiles. Each profile includes a computed target_count field indicating how many SNMP targets reference it.
Response: 200 OK
[
{
"id": "uuid",
"name": "campus-v2c",
"description": "SNMPv2c community for campus routers",
"version": "2c",
"community": "public",
"v3_user": null,
"v3_auth_proto": null,
"v3_auth_pass": null,
"v3_priv_proto": null,
"v3_priv_pass": null,
"target_count": 14,
"created_at": "2026-02-24T12:00:00Z",
"updated_at": "2026-02-24T12:00:00Z"
}
]
Notes:
target_count is computed at query time via a LEFT JOIN count on snmp_target.credential_profile_id.
- Credential secrets (
community, v3_auth_pass, v3_priv_pass) are always masked to "***" in responses for every role, including admins. These endpoints require the engineer or admin role.
Error responses:
403 Forbidden -- Insufficient role (the operator role is not permitted; engineer or admin required)
Get SNMP Credential Profile
GET /api/v1/snmp-credential-profiles/{profileID}
Get a single credential profile by ID.
Path parameters:
profileID (required) -- UUID of the credential profile
Response: 200 OK (single credential profile object, includes target_count)
Error responses:
403 Forbidden -- Non-admin user
404 Not Found -- Credential profile does not exist
Update SNMP Credential Profile
PUT /api/v1/snmp-credential-profiles/{profileID}
Partial update of a credential profile. Uses read-merge-write -- only fields present in the request body are updated; other fields are preserved.
Path parameters:
profileID (required) -- UUID of the credential profile
Request body (all fields optional):
{
"name": "campus-v2c-updated",
"description": "Updated description",
"version": "3",
"community": null,
"v3_user": "newuser",
"v3_auth_proto": "SHA",
"v3_auth_pass": "newauthpass",
"v3_priv_proto": "AES",
"v3_priv_pass": "newprivpass"
}
Notes:
- When changing
version from "2c" to "3", the v3 fields must be provided in the same request.
- Changes propagate to all linked SNMP targets on their next poll cycle.
Response: 200 OK (updated credential profile object)
Error responses:
400 Bad Request -- Invalid request body or duplicate name
403 Forbidden -- Non-admin user
404 Not Found -- Credential profile does not exist
Delete SNMP Credential Profile
DELETE /api/v1/snmp-credential-profiles/{profileID}
Delete a credential profile. Linked SNMP targets have their credential_profile_id set to NULL (ON DELETE SET NULL), reverting them to inline credentials.
Path parameters:
profileID (required) -- UUID of the credential profile
Response: 204 No Content
Error responses:
403 Forbidden -- Non-admin user
404 Not Found -- Credential profile does not exist