generated: '2026-09-09' method: generated source: openapi/aembit-cloud-api-openapi.yml, openapi/aembit-edge-api-openapi.yml, mcp/aembit-mcp.yml note: >- Packaged Agent Skills generated by API Evangelist from Aembit's own published OpenAPI contracts and documentation. Every operationId referenced in every skill was verified to exist verbatim in the contract before the skill was written (28/28 confirmed). These are NOT provider-published skills — see provider_published below for what Aembit actually ships. provider_published: found: partial files: - url: https://github.com/Aembit/edge-sdks/blob/main/AGENTS.md type: AGENTS.md scope: repository-contributor guidance note: >- Aembit DOES publish an AGENTS.md, but it instructs coding agents on how to CONTRIBUTE to the Edge SDK repository — repo layout, terminology rules ("use Trust Provider as the canonical term"), the TypeScript SDK as reference implementation, where pinned OpenAPI snapshots live. It is not an operating guide for calling the Aembit API, so it is recorded here rather than saved as an API skill. A second AGENTS.md exists at py/AGENTS.md for the Python SDK. - url: https://docs.aembit.io/ai-guide/prompt-library/ type: prompt library scope: MCP Server event-log querying note: Aembit publishes curated prompts for querying event logs through its MCP Server. skills: - file: aembit-provision-workload-access.md name: Provision secretless workload access api: openapi/aembit-cloud-api-openapi.yml operations: [post-trust-provider, post-client-workload, post-server-workload, post-credential-provider2, get-credential-provider-verification-v2, post-access-policy-v2, get-access-policy-by-workloads-v2] - file: aembit-retrieve-workload-credential.md name: Retrieve a credential from the Edge API api: openapi/aembit-edge-api-openapi.yml operations: [edge-api-auth, edge-api-get-credentials] - file: aembit-audit-access-decisions.md name: Audit access decisions and workload activity api: openapi/aembit-cloud-api-openapi.yml operations: [get-audit-logs, get-audit-log, get-access-authorization-events, get-access-authorization-event, get-workload-events, get-workload-event] - file: aembit-stream-events-to-siem.md name: Stream Aembit events to a SIEM or bucket api: openapi/aembit-cloud-api-openapi.yml operations: [get-log-streams, post-log-stream, get-log-stream, put-log-stream, patch-log-stream, delete-log-stream] - file: aembit-govern-mcp-agent-access.md name: Govern AI agent access to MCP servers api: openapi/aembit-cloud-api-openapi.yml operations: [post-client-workload, post-server-workload, post-access-condition2, post-content-security, get-content-security-list, post-access-policy-v2, get-workload-events] cross_cutting_rules_embedded_in_every_skill: - 'Idempotency: none — no Idempotency-Key on any of 96 mutating operations; list-and-match before retrying a POST.' - 'Reversibility: no restore/undelete endpoint; prefer PATCH isActive:false over DELETE.' - 'Errors: vendor GenericResponseDTO envelope, not RFC 9457; branch on HTTP status.' - 'Rate limits: 429 declared on the Edge API with no Retry-After and no published number; supply your own backoff.' - 'Tenancy: set X-Aembit-ResourceSet explicitly rather than inheriting the default Resource Set.' - 'Host: tenant-templated https://{tenant}.aembit.io — resolve the tenant before building a URL.'