generated: '2026-08-02' method: generated source: openapi/anaconda-ai-navigator-openapi-original.json, openapi/anaconda-audit-logs-openapi-original.json, openapi/anaconda-desktop-openapi-original.json, openapi/anaconda-org-management-openapi-original.json, openapi/anaconda-server-openapi-original.json description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 223 by_action_class: connected: 126 acting: 97 by_consequence: read: 126 write: 90 safety-critical: 7 human_in_the_loop_required: 7 operations: - path: /api method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/models/health method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/models method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/models/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /models/{modelId}/files method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/models/{modelId}/files/{fileId} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/models/{modelId}/files/{fileId} method: patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/models/{modelId}/files/{fileId} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/servers/health method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/servers method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/servers method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/servers/{serverId} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/servers/{serverId} method: patch x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /api/servers/{serverId} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/vector-db/health method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/vector-db method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/vector-db method: patch x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /api/vector-db/tables method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/vector-db/tables method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/vector-db/tables/{tableName} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/audit-logs method: get operationId: get_audit_logs__get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/audit-logs/{audit_log_id} method: get operationId: get_audit_log__audit_log_id__get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/audit-logs/export method: post operationId: create_export_job_export_post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/audit-logs/export/{job_id} method: get operationId: get_export_job_status_export__job_id__get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/audit-logs/export/{job_id}/download method: get operationId: download_export_export__job_id__download_get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/models/health method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/models method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/models/{id} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /models/{modelId}/files method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/models/{modelId}/files/{fileId} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/models/{modelId}/files/{fileId} method: patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/models/{modelId}/files/{fileId} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/servers/health method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/servers method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/servers method: post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/servers/{serverId} method: get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/servers/{serverId} method: patch x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /api/servers/{serverId} method: delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/organizations/{org_id}/service-accounts method: post operationId: create_service_account x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/organizations/{org_id}/service-accounts method: get operationId: list_service_accounts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/organizations/{org_id}/service-accounts/{client_id} method: delete operationId: delete_service_account x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/organizations/{org_id}/users_auto_registration method: post operationId: auto_register_users x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/organizations/{org_id}/users method: post operationId: add_user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/organizations/{org_id}/users method: get operationId: list_users x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/organizations/{org_id}/users/{user_id} method: delete operationId: remove_user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/organizations/{org_id}/users/{user_id}/seats method: post operationId: assign_seat x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/organizations/{org_id}/users/{user_id}/seats method: delete operationId: revoke_seat x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /api/v1/organizations/{org_id}/users/{user_id}/token method: post operationId: create_user_token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/organizations/{org_id}/users/{user_id}/token method: patch operationId: update_user_token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /api/v1/organizations/{org_id}/users/{user_id}/tokens method: get operationId: list_user_tokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /api/v1/organizations/{org_id}/users/{user_id}/tokens/{token_id} method: delete operationId: revoke_user_token x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /installers method: get operationId: repo.endpoints.installers.list_installers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /installers/{installer_name} method: get operationId: repo.endpoints.installers.download_installer x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /external-docs method: get operationId: repo.endpoints.system.get_external_docs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /system method: get operationId: repo.endpoints.system.health x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /system/stats method: get operationId: repo.endpoints.system.stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /system/metrics method: get operationId: repo.endpoints.system.metrics x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /system/history method: get operationId: repo.endpoints.system.history x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /system/scopes method: get operationId: repo.endpoints.system.scopes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /system/resource_types method: get operationId: repo.endpoints.system.resource_types x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /system/license method: get operationId: repo.endpoints.system.get_license x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /system/license method: post operationId: repo.endpoints.system.post_license x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /system/license method: put operationId: repo.endpoints.system.put_license x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /system/settings method: get operationId: repo.endpoints.system.get_settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /system/settings method: put operationId: repo.endpoints.system.update_settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /diagnose/blobs method: post operationId: repo.endpoints.diagnosis.blobs.troubleshoot_routes_blobs x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /auth/login method: post operationId: repo.endpoints.auth.login x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /auth/logout method: get operationId: repo.endpoints.auth.logout_get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /auth/authorize method: get operationId: repo.endpoints.auth.openidc_authorize x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /auth/callback/kc method: get operationId: repo.endpoints.auth.openidc_callback_keycloak x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/register method: post operationId: repo.endpoints.account.register x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /account/register/{account_id} method: get operationId: repo.endpoints.account.register_confirm x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/unregister method: post operationId: repo.endpoints.account.unregister x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /account/unregister/{account_id} method: get operationId: repo.endpoints.account.unregister_confirm x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account method: get operationId: repo.endpoints.account.get_account x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account method: put operationId: repo.endpoints.account.edit_account x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /account method: delete operationId: repo.endpoints.account.delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /account/tokens method: get operationId: repo.endpoints.tokens.user_tokens.list_tokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/tokens method: post operationId: repo.endpoints.tokens.user_tokens.post_token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /account/token-info method: get operationId: repo.endpoints.tokens.user_tokens.info x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/tokens/{token_id} method: put operationId: repo.endpoints.tokens.user_tokens.put_token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /account/tokens/{token_id} method: delete operationId: repo.endpoints.tokens.user_tokens.delete_token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /account/tokens/{token_id}/metadata method: put operationId: repo.endpoints.tokens.user_tokens.put_token_metadata x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{user_id}/tokens method: get operationId: repo.endpoints.tokens.admin_user_tokens.list_tokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{user_id}/tokens method: post operationId: repo.endpoints.tokens.admin_user_tokens.post_token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/tokens method: post operationId: repo.endpoints.tokens.admin_user_tokens.list_users_tokens x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/tokens method: put operationId: repo.endpoints.tokens.admin_user_tokens.put_tokens x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{user_id}/tokens/{token_id} method: put operationId: repo.endpoints.tokens.admin_user_tokens.put_token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{user_id}/tokens/{token_id} method: delete operationId: repo.endpoints.tokens.admin_user_tokens.delete_token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{user_id}/tokens/{token_id}/metadata method: put operationId: repo.endpoints.tokens.admin_user_tokens.put_token_metadata x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /account/history method: get operationId: repo.endpoints.account.history x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/history/ws method: get operationId: repo.endpoints.account.publish_events x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/logs method: get operationId: repo.endpoints.account.logs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/channels method: get operationId: repo.endpoints.channels.channels.list_my_channels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/permissions method: get operationId: repo.endpoints.account.get_user_permissions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account/scopes method: get operationId: repo.endpoints.account.get_user_scopes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users method: get operationId: repo.endpoints.users.list_users x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users method: post operationId: repo.endpoints.users.post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{user_id} method: get operationId: repo.endpoints.users.get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{user_id} method: put operationId: repo.endpoints.users.put x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{user_id} method: delete operationId: repo.endpoints.users.delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{user_id}/activity method: get operationId: repo.endpoints.users.logs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /roles method: get operationId: repo.endpoints.roles.list_roles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /roles method: post operationId: repo.endpoints.roles.post_role x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /roles/{role_id} method: put operationId: repo.endpoints.roles.put_role x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /roles/{role_id} method: delete operationId: repo.endpoints.roles.delete_role x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /mirrors method: get operationId: repo.endpoints.mirrors.get_all x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels method: get operationId: repo.endpoints.channels.channels.list_channels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels method: post operationId: repo.endpoints.channels.channels.post_channel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name} method: get operationId: repo.endpoints.channels.channels.get_channel x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name} method: put operationId: repo.endpoints.channels.channels.put_channel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name} method: delete operationId: repo.endpoints.channels.channels.delete_channel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/permissions method: get operationId: repo.endpoints.channels.channels.channel_permissions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/groups method: get operationId: repo.endpoints.channels.channel_groups.list_groups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/groups method: post operationId: repo.endpoints.channels.channel_groups.post_group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/groups/{group_id} method: put operationId: repo.endpoints.channels.channel_groups.change_group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/groups/{group_id} method: delete operationId: repo.endpoints.channels.channel_groups.delete_group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/history method: get operationId: repo.endpoints.channels.channels.channel_history x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/cves_history method: get operationId: repo.endpoints.channels.channels_cve_history.get_cve_channel_history x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/cves_history method: post operationId: repo.endpoints.channels.channels_cve_history.generate_cve_notifications x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/stats method: get operationId: repo.endpoints.channels.channels.channel_stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/virtual-channels method: get operationId: repo.endpoints.channels.channels.list_virtual_channels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/artifacts method: get operationId: repo.endpoints.channels.channel_artifacts.list_artifacts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/artifacts method: post operationId: repo.endpoints.channels.channel_artifacts.upload_placeholder x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/artifacts/bulk method: put operationId: repo.endpoints.channels.channel_artifacts.bulk x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/artifacts/{artifact_family} method: put operationId: repo.endpoints.channels.channel_artifacts.refresh_artifact_family_index x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name} method: get operationId: repo.endpoints.channels.channel_artifacts.get_artifact x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name} method: delete operationId: repo.endpoints.channels.channel_artifacts.delete_artifact x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name}/readme method: get operationId: repo.endpoints.channels.channel_artifacts.get_artifact_readme x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/cves method: get operationId: repo.endpoints.channels.channel_artifacts.list_channel_cves x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/cves/ws method: get operationId: repo.endpoints.channels.channel_artifacts.cve_report_batched x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/cves/{cve_id} method: get operationId: repo.endpoints.channels.channel_artifacts.get_channel_cve_details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/cves/{cve_id}/files method: get operationId: repo.endpoints.channels.channel_artifacts.list_channel_cve_files x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name}/cves method: get operationId: repo.endpoints.channels.channel_artifacts.list_artifact_cves x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name}/cves/{cve_id} method: get operationId: repo.endpoints.channels.channel_artifacts.get_artifact_cve_details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name}/cves/{cve_id}/files method: get operationId: repo.endpoints.channels.channel_artifacts.list_artifact_cve_files x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name}/files method: get operationId: repo.endpoints.channels.channel_artifacts.list_artifact_files x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name}/files/{ckey:[^/].*?} method: get operationId: repo.endpoints.channels.channel_artifacts.artifact_file x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name}/file-cves/{ckey:[^/].*?} method: get operationId: repo.endpoints.channels.channel_artifacts.list_file_cves x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /signature-verification/{artifact_family} method: post operationId: repo.endpoints.signature_verification.is_verified x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name}/dependencies method: get operationId: repo.endpoints.channels.channel_artifacts.list_artifact_dependencies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name}/dependants method: get operationId: repo.endpoints.channels.channel_artifacts.list_artifact_dependants x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name}/move method: put operationId: repo.endpoints.channels.channel_artifacts.move_artifact x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/artifacts/{artifact_family}/{artifact_name}/copy method: put operationId: repo.endpoints.channels.channel_artifacts.copy_artifact x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/mirrors method: get operationId: repo.endpoints.channels.channel_mirrors.list_mirrors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/mirrors method: post operationId: repo.endpoints.channels.channel_mirrors.post_mirror x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/mirrors/{mirror_id}/stop_mirror_sync method: post operationId: repo.endpoints.channels.channel_mirrors.stop_mirror_sync x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /channels/{channel_name}/mirrors/{mirror_id} method: get operationId: repo.endpoints.channels.channel_mirrors.get_mirror x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/mirrors/{mirror_id} method: put operationId: repo.endpoints.channels.channel_mirrors.put_mirror x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/mirrors/{mirror_id} method: delete operationId: repo.endpoints.channels.channel_mirrors.delete_mirror x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/files-filtered method: get operationId: repo.endpoints.channels.channels_routes_filtered.list_routes_filtered x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels method: get operationId: repo.endpoints.channels.subchannels.list_subchannels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels method: post operationId: repo.endpoints.channels.subchannels.post_subchannel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name} method: get operationId: repo.endpoints.channels.subchannels.get_subchannel x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name} method: put operationId: repo.endpoints.channels.subchannels.put_subchannel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name} method: delete operationId: repo.endpoints.channels.subchannels.delete_subchannel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/cves_history method: get operationId: repo.endpoints.channels.subchannels_cve_history.get_cve_subchannel_history x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/cves_history method: post operationId: repo.endpoints.channels.subchannels_cve_history.generate_cve_notifications x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/mirrors/{mirror_id}/stop_mirror_sync method: post operationId: repo.endpoints.channels.subchannel_mirrors.stop_mirror_sync x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/permissions method: get operationId: repo.endpoints.channels.subchannels.subchannel_permissions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts method: get operationId: repo.endpoints.channels.subchannel_artifacts.list_artifacts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts method: post operationId: repo.endpoints.channels.subchannel_artifacts.upload_placeholder x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/stats method: get operationId: repo.endpoints.channels.subchannels.subchannel_stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/virtual-channels method: get operationId: repo.endpoints.channels.subchannels.list_virtual_channels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/bulk method: put operationId: repo.endpoints.channels.subchannel_artifacts.bulk x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family} method: put operationId: repo.endpoints.channels.subchannel_artifacts.refresh_artifact_family_index x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name} method: get operationId: repo.endpoints.channels.subchannel_artifacts.get_artifact x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name} method: delete operationId: repo.endpoints.channels.subchannel_artifacts.delete_artifact x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name}/readme method: get operationId: repo.endpoints.channels.subchannel_artifacts.get_artifact_readme x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/cves method: get operationId: repo.endpoints.channels.subchannel_artifacts.list_subchannel_cves x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/cves/ws method: get operationId: repo.endpoints.channels.subchannel_artifacts.cve_report_batched x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/cves/{cve_id} method: get operationId: repo.endpoints.channels.subchannel_artifacts.get_subchannel_cve_details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/cves/{cve_id}/files method: get operationId: repo.endpoints.channels.subchannel_artifacts.list_subchannel_cve_files x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name}/cves method: get operationId: repo.endpoints.channels.subchannel_artifacts.list_artifact_cves x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name}/cves/{cve_id} method: get operationId: repo.endpoints.channels.subchannel_artifacts.get_artifact_cve_details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name}/cves/{cve_id}/files method: get operationId: repo.endpoints.channels.subchannel_artifacts.list_artifact_cve_files x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name}/files method: get operationId: repo.endpoints.channels.subchannel_artifacts.list_artifact_files x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name}/files/{ckey:[^/].*?} method: get operationId: repo.endpoints.channels.subchannel_artifacts.artifact_file x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name}/file-cves/{ckey:[^/].*?} method: get operationId: repo.endpoints.channels.subchannel_artifacts.list_file_cves x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name}/dependencies method: get operationId: repo.endpoints.channels.subchannel_artifacts.list_artifact_dependencies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name}/dependants method: get operationId: repo.endpoints.channels.subchannel_artifacts.list_artifact_dependants x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name}/move method: put operationId: repo.endpoints.channels.subchannel_artifacts.move_artifact x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name}/copy method: put operationId: repo.endpoints.channels.subchannel_artifacts.copy_artifact x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/artifacts/{artifact_family}/{artifact_name}/download method: get operationId: repo.endpoints.channels.subchannel_artifacts.download_artifact_file x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/mirrors method: get operationId: repo.endpoints.channels.subchannel_mirrors.list_mirrors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/mirrors method: post operationId: repo.endpoints.channels.subchannel_mirrors.post_mirror x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/mirrors/{mirror_id} method: get operationId: repo.endpoints.channels.subchannel_mirrors.get_mirror x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/mirrors/{mirror_id} method: put operationId: repo.endpoints.channels.subchannel_mirrors.put_mirror x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/mirrors/{mirror_id} method: delete operationId: repo.endpoints.channels.subchannel_mirrors.delete_mirror x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/groups method: get operationId: repo.endpoints.channels.subchannel_groups.list_groups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /channels/{channel_name}/subchannels/{subchannel_name}/groups method: post operationId: repo.endpoints.channels.subchannel_groups.post_group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/groups/{group_id} method: put operationId: repo.endpoints.channels.subchannel_groups.change_group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/groups/{group_id} method: delete operationId: repo.endpoints.channels.subchannel_groups.delete_group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /channels/{channel_name}/subchannels/{subchannel_name}/history method: get operationId: repo.endpoints.channels.subchannels.subchannel_history x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups method: get operationId: repo.endpoints.groups.list_all_groups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups method: post operationId: repo.endpoints.groups.post_group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /groups/{group_id} method: get operationId: repo.endpoints.groups.get_group x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{group_id} method: put operationId: repo.endpoints.groups.put_group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /groups/{group_id} method: delete operationId: repo.endpoints.groups.delete_group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /groups/{group_id}/users method: post operationId: repo.endpoints.groups.add_user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /groups/{group_id}/users/{user_id} method: delete operationId: repo.endpoints.groups.delete_user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /groups/{group_id}/channels method: get operationId: repo.endpoints.groups.list_channels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /artifacts method: get operationId: repo.endpoints.artifacts.search_artifacts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /artifacts/{artifact_family}/ method: get operationId: repo.endpoints.artifacts.get_all_by_type x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /artifacts/{artifact_family}/{artifact_name} method: get operationId: repo.endpoints.artifacts.get_all_by_type_and_name x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /artifacts/{artifact_family}/{artifact_name}/channels method: get operationId: repo.endpoints.artifacts.artifact_channels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /artifacts/{artifact_family}/{artifact_name}/{artifact_file}/download method: get operationId: repo.endpoints.artifacts.download_artifact x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /artifacts/{artifact_family}/{artifact_name}/versions method: get operationId: repo.endpoints.artifacts.versions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cves method: get operationId: repo.endpoints.cves.list_cves x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cves/{cve_id} method: get operationId: repo.endpoints.cves.get_cve x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cves/{cve_id}/files method: get operationId: repo.endpoints.cves.list_cve_files x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cves-report method: get operationId: repo.endpoints.cves.list_cves_for_packages x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /cves-report method: post operationId: repo.endpoints.cves.list_cves_for_packages_post_query x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /system/blob_cleanup method: delete operationId: repo.endpoints.system.blob_cleanup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /system/blob_cleanup method: post operationId: repo.endpoints.system.cleanup_specified_orphan_blobs x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repo/upload method: post operationId: repo.endpoints.artifacts.upload_artifact x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repo/docker/events method: post operationId: repo.endpoints.docker.publish_events x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repo/docker/repositories/{channel_id}/{image_name} method: get operationId: repo.endpoints.docker.get_repository x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repo/{channel_name}/{ckey:[^/].*?} method: get operationId: repo.endpoints.artifacts.get_artifact x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repo/{channel_name}/{ckey:[^/].*?} method: patch operationId: repo.endpoints.artifacts.patch_artifact_metadata x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repo/{root_version:\d+}.root.json method: get operationId: repo.endpoints.signatures.root_json x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repo/key_mgr.json method: get operationId: repo.endpoints.signatures.key_mgr_json x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /reports/artifact_downloads method: post operationId: repo.endpoints.audit_logs.artifact_download.generate_artifact_downloads_report x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required