generated: '2026-07-18' method: generated source: openapi/border0-openapi.json description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 89 by_action_class: acting: 53 connected: 36 by_consequence: write: 49 read: 36 safety-critical: 4 human_in_the_loop_required: 4 operations: - path: /organization/identity_provider/{name} method: delete operationId: delete_organization-identity-provider-name x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organization/identity_provider/{name} method: get operationId: get_organization-identity-provider-name x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/customdomains method: delete operationId: delete_organizations-customdomains x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/customdomains method: get operationId: get_organizations-customdomains x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/customdomains method: post operationId: post_organizations-customdomains x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/customdomains method: put operationId: put_organizations-customdomains x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/iam/service_accounts/{name}/tokens/{token_id} method: delete operationId: delete_organizations-iam-service-accounts-name-tokens-token-id x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/iam/service_accounts/{name} method: delete operationId: delete_organizations-iam-service-accounts-name x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/iam/service_accounts/{name} method: get operationId: get_organizations-iam-service-accounts-name x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/iam/service_accounts/{name} method: put operationId: put_organizations-iam-service-accounts-name x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/notifications/{name} method: delete operationId: delete_organizations-notifications-name x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/notifications/{name} method: get operationId: get_organizations-notifications-name x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/notifications/{name} method: put operationId: put_organizations-notifications-name x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/recording_storage method: delete operationId: delete_organizations-recording-storage x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/recording_storage method: get operationId: get_organizations-recording-storage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/recording_storage method: post operationId: post_organizations-recording-storage x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/tokens method: delete operationId: delete_organizations-tokens x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /organizations/tokens method: get operationId: get_organizations-tokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/tokens method: post operationId: post_organizations-tokens x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policy/{uuid} method: delete operationId: delete_policy-uuid x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policy/{uuid} method: get operationId: get_policy-uuid x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /policy/{uuid} method: put operationId: put_policy-uuid x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /socket/{socket_id_or_name}/tunnel/{tunnel_id} method: delete operationId: delete_socket-socket-id-or-name-tunnel-tunnel-id x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /socket/{socket_id_or_name}/tunnel/{tunnel_id} method: get operationId: get_socket-socket-id-or-name-tunnel-tunnel-id x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /socket/{socket_id_or_name} method: delete operationId: delete_socket-socket-id-or-name x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /socket/{socket_id_or_name} method: get operationId: get_socket-socket-id-or-name x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /socket/{socket_id_or_name} method: put operationId: put_socket-socket-id-or-name x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /audit_actions/actors method: get operationId: get_audit-actions-actors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /audit_actions method: get operationId: get_audit-actions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /client/auth/org/{slug} method: get operationId: get_client-auth-org-slug x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /client/cda/get_token method: get operationId: get_client-cda-get-token x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /client/resources method: get operationId: get_client-resources x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /connect method: get operationId: get_connect x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /connect method: post operationId: post_connect x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /mtls-ca/socket/{socket_dnsname}/auth method: get operationId: get_mtls-ca-socket-socket-dnsname-auth x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organization/identity_providers method: get operationId: get_organization-identity-providers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/iam/service_accounts/{name}/tokens method: get operationId: get_organizations-iam-service-accounts-name-tokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/iam/service_accounts/{name}/tokens method: post operationId: post_organizations-iam-service-accounts-name-tokens x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/iam/service_accounts method: get operationId: get_organizations-iam-service-accounts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/iam/service_accounts method: post operationId: post_organizations-iam-service-accounts x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/notifications method: get operationId: get_organizations-notifications x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/notifications method: post operationId: post_organizations-notifications x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /policies/find method: get operationId: get_policies-find x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /policies method: get operationId: get_policies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /policies method: post operationId: post_policies x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /session/{socket_id}/{session_id}/session_log method: get operationId: get_session-socket-id-session-id-session-log x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /session/{socket_id}/{session_id} method: get operationId: get_session-socket-id-session-id x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /session/{socket_id}/{session_id} method: put operationId: put_session-socket-id-session-id x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /session/{socket_id} method: get operationId: get_session-socket-id x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /sessions/stats/{stats_type} method: get operationId: get_sessions-stats-stats-type x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /sessions method: get operationId: get_sessions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /socket/{socket_id_or_name}/customcert method: get operationId: get_socket-socket-id-or-name-customcert x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /socket/{socket_id_or_name}/tunnel method: get operationId: get_socket-socket-id-or-name-tunnel x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /socket/{socket_id_or_name}/tunnel method: post operationId: post_socket-socket-id-or-name-tunnel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /socket/{socket_id}/sessions method: get operationId: get_socket-socket-id-sessions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /socket method: get operationId: get_socket x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /socket method: post operationId: post_socket x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /stats/{socket_id}/bandwidth method: get operationId: get_stats-socket-id-bandwidth x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /stats/{socket_id}/requests method: get operationId: get_stats-socket-id-requests x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/confirm/{token} method: get operationId: get_user-confirm-token x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/{user_id} method: get operationId: get_user-user-id x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/{user_id} method: put operationId: put_user-user-id x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/mfa_setup method: get operationId: get_users-mfa-setup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organization/identity_provider method: patch operationId: patch_organization-identity-provider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organization/identity_provider method: post operationId: post_organization-identity-provider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /client/ai_assistants/database method: post operationId: post_client-ai-assistants-database x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /client/cda/authorize method: post operationId: post_client-cda-authorize x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /client/device_authorizations method: post operationId: post_client-device-authorizations x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /login/refresh method: post operationId: post_login-refresh x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /login method: post operationId: post_login x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /mtls-ca/socket/{socket_dnsname}/csr method: post operationId: post_mtls-ca-socket-socket-dnsname-csr x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /mtls-ca/socket/{socket_dnsname}/ssh method: post operationId: post_mtls-ca-socket-socket-dnsname-ssh x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/csr method: post operationId: post_organizations-csr x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/sign_ssh method: post operationId: post_organizations-sign-ssh x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/switch method: post operationId: post_organizations-switch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations method: post operationId: post_organizations x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /socket/{socket_id_or_name}/evaluate method: post operationId: post_socket-socket-id-or-name-evaluate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /socket/{socket_id_or_name}/signkey method: post operationId: post_socket-socket-id-or-name-signkey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /socket/{socket_id_or_name}/tunnel/{tunnel_id}/signkey method: post operationId: post_socket-socket-id-or-name-tunnel-tunnel-id-signkey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /socket/{socket_id_or_name}/update_session method: post operationId: post_socket-socket-id-or-name-update-session x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user method: post operationId: post_user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/mfa_challenge method: post operationId: post_users-mfa-challenge x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/mfa_confirm method: post operationId: post_users-mfa-confirm x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/organizations/switch method: post operationId: post_users-organizations-switch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organization/identity_provider_status method: put operationId: put_organization-identity-provider-status x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /organizations/settings method: put operationId: put_organizations-settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/users/leave method: put operationId: put_organizations-users-leave x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/password method: put operationId: put_user-password x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/mfa_disabled method: put operationId: put_users-mfa-disabled x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required