Hi,
I’m creating a custom CData REST RSD for the Cynet API and consuming it through Incorta.
The RSD performs two calls: first a POST to obtain the access token, then a GET to the Alerts endpoint using the Bearer token.
The login works and the token is populated (length is 857 characters). I also confirmed that httpGet retrieves the raw response body from the Alerts endpoint. However, jsonproviderGet returns 0 rows.
The response from the Alerts endpoint is structured like:
{
"SyncTimeUtc": "2026-09-28T06:28:02.0628506Z",
"Entities": [
{
"ClientDbId": 166,
"Uniqueness": "...",
"IncidentName": "Host Was Not Scanned",
"IncidentDescription": "..."
}
]
}
Here is the relevant RSD:
<api:script xmlns:api="http://apiscript.com/ns?v1"
xmlns:xs="http://www.w3.org/2001/XMLSchema">
<api:info title="CynetAlerts"
desc="Cynet alerts - rolling last 30 days"
xmlns:other="http://apiscript.com/ns?v1">
<attr name="ClientDbId"
xs:type="long"
columnsize="20"
readonly="true"
other:xPath="/json/Entities/ClientDbId" />
<attr name="Uniqueness"
xs:type="string"
columnsize="2000"
readonly="true"
other:xPath="/json/Entities/Uniqueness" />
<!-- additional attributes -->
</api:info>
<!-- Login configuration -->
<api:set attr="loginin.DataModel" value="DOCUMENT" />
<api:set attr="loginin.ConnectionType" value="HTTPS" />
<api:set attr="loginin.URI" value="access_token_uri" />
<api:set attr="loginin.AuthScheme" value="NONE" />
<api:set attr="loginin.ContentType" value="application/json" />
<api:set attr="loginin.EncodePostData" value="false" />
<api:set attr="loginin.XPath" value="/json" />
<api:set attr="loginin.ElementMapPath#1" value="/json/access" />
<api:set attr="loginin.ElementMapName#1" value="access" />
<api:set attr="loginin.data">
{
"accessKey": "XXXXX",
"secretKey": "XXXXX"
}
</api:set>
<api:set attr="tmp.token" value="" />
<api:set attr="loginin.method" value="POST" />
<api:call op="jsonproviderGet" in="loginin" out="loginout">
<api:set attr="tmp.token" value="[loginout.access]" />
</api:call>
<!-- Alerts -->
<api:set attr="alertsin.DataModel" value="DOCUMENT" />
<api:set attr="alertsin.ConnectionType" value="HTTPS" />
<api:set attr="alertsin.URI"
value="base_uri?LastSeen=2026-09-26%2000:00:00" />
<api:set attr="alertsin.JSONPath" value="$.Entities" />
<api:set attr="alertsin.method" value="GET" />
<api:set attr="alertsin.Header:Name#1" value="Authorization" />
<api:set attr="alertsin.Header:Value#1"
value="Bearer [tmp.token]" />
<api:set attr="alertsin.Header:Name#2" value="client_id" />
<api:set attr="alertsin.Header:Value#2" value="XXXXX" />
<api:call op="jsonproviderGet" in="alertsin" out="alertsout">
<api:push />
</api:call>
</api:script>
Could someone advise what is causing jsonproviderGet to return zero rows?
Specifically, I would like to confirm:
-
Is
alertsin.JSONPath = "$.Entities"correct whenEntitiesis an array? -
Should the
other:xPathvalues be/json/Entities/ClientDbId, etc., or should they be relative to each entity? -
Should
api:pushexplicitly referencealertsout? -
Is using
in="alertsin"withjsonproviderGetcorrect in this structure?
The HTTP GET itself is successful; the issue appears to be the JSON parsing/row generation.
Thanks.

