openapi: 3.0.1 info: title: Coveo Activity Activities Item API description: API for Coveo Platform termsOfService: https://www.coveo.com/en/support/terms-agreements contact: name: Coveo url: https://connect.coveo.com/s/discussions version: 1.0.0 servers: - url: https://platform.cloud.coveo.com description: Coveo public API endpoint security: - oauth2: - full tags: - description: Manage items in a Push source name: Item paths: /organizations/{organizationId}/sources/{sourceId}/documents: delete: description: Deletes a specific item from a Push source. Optionally, the items of that item can also be deleted. externalDocs: description: Delete an item and optionally, its children in a Push source url: https://docs.coveo.com/en/171/ parameters: - description: "A value indicating the order of arrival of the Push operation in the Coveo Cloud V2 indexing pipeline. A lower value corresponds to an older operation. \nBy default, the service automatically sets this parameter to the current number of milliseconds since Unix Epoch. \nSpecifying a custom `orderingId` value is typically not recommended unless you know what you are doing and have a good reason to do so (see [About the orderingId parameter](https://docs.coveo.com/en/147/)). \n**Example:** `1506700606240`" format: int64 in: query name: orderingId required: false type: integer - default: false description: Whether to also delete the children of the item. in: query name: deleteChildren required: false type: boolean - description: "The unique identifier of the target Push source (see [Creating a Push Source](https://developers.coveo.com/x/34s9Ag)). \n**Example:** `rp5rxzbdz753uhndklv2ztkfgy-mycoveocloudv2organizationg8tp8wu3`" in: path name: sourceId required: true type: string - description: "The unique identifier of the item. The Coveo item URI (see [Request parameters](https://docs.coveo.com/en/78/#query-parameters-add-update)). \n**Example:** `file://folder/my-file.html`" in: query name: documentId required: true type: string - description: "The unique identifier of the target Coveo Cloud V2 organization. \n**Example:** `mycoveocloudv2organizationg8tp8wu3`" in: path name: organizationId required: true type: string produces: - application/json responses: '202': description: Success headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string '400': description: Bad request headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '401': description: Unauthorized headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '403': description: Forbidden headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '404': description: Not found headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '412': description: Precondition Failed headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '415': description: Unsupported Media Type headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '429': description: Too many Requests headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Retry-After: type: number Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '500': description: Internal Server Error headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' security: - oauth2: - full summary: Delete an Item and Optionally Its Children tags: - Item x-pretty-name: deleteDocument put: consumes: - application/json description: Adds or updates an individual item in a Push source. externalDocs: description: Add or update a single item in a Push source url: https://docs.coveo.com/en/133/ parameters: - description: "A value indicating the order of arrival of the Push operation in the Coveo Cloud V2 indexing pipeline. A lower value corresponds to an older operation. \nBy default, the service automatically sets this parameter to the current number of milliseconds since Unix Epoch. \nSpecifying a custom `orderingId` value is typically not recommended unless you know what you are doing and have a good reason to do so (see [About the orderingId parameter](https://docs.coveo.com/en/147/)). \n**Example:** `1506700606240`" format: int64 in: query name: orderingId required: false type: integer - description: "The unique identifier of the target Push source (see [Creating a Push Source](https://developers.coveo.com/x/34s9Ag)). \n**Example:** `rp5rxzbdz753uhndklv2ztkfgy-mycoveocloudv2organizationg8tp8wu3`" in: path name: sourceId required: true type: string - description: "The unique identifier of the item. The Coveo item URI (see [Request parameters](https://docs.coveo.com/en/78/#query-parameters-add-update)). \n**Example:** `file://folder/my-file.html`" in: query name: documentId required: true type: string - description: "The unique identifier of the target Coveo Cloud V2 organization. \n**Example:** `mycoveocloudv2organizationg8tp8wu3`" in: path name: organizationId required: true type: string - description: "The algorithm that was used to compress the item data. \nSpecifying a value for this parameter is only necessary when using the `compressedBinaryData` or the `compressedBinaryDataFileId` property to push item data (see [Push source item data](https://docs.coveo.com/en/73/)). \nThe possible values are: `Uncompressed`, `ZLib`, `GZip`, `LZMA`, and `Deflate`. \n**Example:** `ZLib`" enum: - UNCOMPRESSED - ZLIB - GZIP - LZMA - DEFLATE in: query name: compressionType required: false type: string - description: A JSON describing a single item to add or update in a Push source. in: body name: documentBody required: true schema: $ref: '#/definitions/DocumentBody' produces: - application/json responses: '202': description: Success headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string '400': description: Bad request headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '401': description: Unauthorized headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '403': description: Forbidden headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '404': description: Not found headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '412': description: Precondition Failed headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '415': description: Unsupported Media Type headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '429': description: Too many Requests headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Retry-After: type: number Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '500': description: Internal Server Error headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' security: - oauth2: - full summary: Add or Update an Item tags: - Item x-pretty-name: addUpdateDocument /organizations/{organizationId}/sources/{sourceId}/documents/batch: put: consumes: - application/json description: Manages a batch of items in a Push source. externalDocs: description: Manage batches of items in a Push source url: https://docs.coveo.com/en/90/ parameters: - description: "A value indicating the order of arrival of the Push operation in the Coveo Cloud V2 indexing pipeline. A lower value corresponds to an older operation. \nBy default, the service automatically sets this parameter to the current number of milliseconds since Unix Epoch. \nSpecifying a custom `orderingId` value is typically not recommended unless you know what you are doing and have a good reason to do so (see [About the orderingId parameter](https://docs.coveo.com/en/147/)). \n**Example:** `1506700606240`" format: int64 in: query name: orderingId required: false type: integer - description: "The unique identifier of the target Push source (see [Creating a Push Source](https://developers.coveo.com/x/34s9Ag)). \n**Example:** `rp5rxzbdz753uhndklv2ztkfgy-mycoveocloudv2organizationg8tp8wu3`" in: path name: sourceId required: true type: string - description: "The unique identifier of the Amazon S3 file container into which the JSON definition of the content update was previously uploaded (see [Create a file container](https://docs.coveo.com/en/43/)). \n**Example:** d22778ca-7f42-4e13-9d9a-47d01bce866c" in: query name: fileId required: true type: string - description: "The unique identifier of the target Coveo Cloud V2 organization. \n**Example:** `mycoveocloudv2organizationg8tp8wu3`" in: path name: organizationId required: true type: string produces: - application/json responses: '202': description: Success headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string '400': description: Bad request headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '401': description: Unauthorized headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '403': description: Forbidden headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '404': description: Not found headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '412': description: Precondition Failed headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '415': description: Unsupported Media Type headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '429': description: Too many Requests headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Retry-After: type: number Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '500': description: Internal Server Error headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' security: - oauth2: - full summary: Add, Update, and/or Delete a Batch of Items tags: - Item x-pretty-name: addUpdateDeleteBatchedDocument /organizations/{organizationId}/sources/{sourceId}/documents/olderthan: delete: consumes: - application/json description: In a specific Push source, deletes all items whose last update was made by a Push API operation whose `orderingId` is strictly lower than a specified value. externalDocs: description: Delete old items in a Push source url: https://docs.coveo.com/en/131/ parameters: - description: "The unique identifier of the target Push source (see [Creating a Push Source](https://developers.coveo.com/x/34s9Ag)). \n**Example:** `rp5rxzbdz753uhndklv2ztkfgy-mycoveocloudv2organizationg8tp8wu3`" in: path name: sourceId required: true type: string - description: "The lowest Push API operation timestamp value an item must be associated to in order not to be deleted from the Push source. \n**Example:** `1506700606240`" format: int64 in: query name: orderingId required: true type: integer - description: "A grace period (in minutes) whose purpose is to give the Coveo Cloud V2 indexing pipeline enough time to finish processing any previously enqueued operation that would affect the target Push source. Default value is 15 minutes. \n**Example:** `5`" format: int32 in: query minimum: 0 name: queueDelay required: false type: integer - description: "The unique identifier of the target Coveo Cloud V2 organization. \n**Example:** `mycoveocloudv2organizationg8tp8wu3`" in: path name: organizationId required: true type: string produces: - application/json responses: '202': description: Success headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string '400': description: Bad request headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '401': description: Unauthorized headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '403': description: Forbidden headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '404': description: Not found headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '412': description: Precondition Failed headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '415': description: Unsupported Media Type headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '429': description: Too many Requests headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Retry-After: type: number Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' '500': description: Internal Server Error headers: Access-Control-Allow-Headers: type: string Access-Control-Allow-Methods: type: string Access-Control-Allow-Origin: type: string Content-Security-Policy: type: string Referrer-Policy: type: string Strict-Transport-Security: type: string X-Content-Type-Options: type: string X-Frame-Options: type: string X-XSS-Protection: type: string schema: $ref: '#/definitions/Error' security: - oauth2: - full summary: Delete Old Items tags: - Item x-pretty-name: deleteDocumentsOlderThan components: securitySchemes: oauth2: type: oauth2 flows: authorizationCode: authorizationUrl: https://platform.cloud.coveo.com/oauth/authorize tokenUrl: https://platform.cloud.coveo.com/oauth/token scopes: full: required definitions: PermissionIdentityModel: properties: identity: description: "The unique name of the security identity (see [Manage security identities in a security identity provider](https://docs.coveo.com/en/132/)). \n**Example:** `\"asmith@example.com\"`" type: string identityType: description: "The type of the security identity (see [Manage security identities in a security identity provider](https://docs.coveo.com/en/132/)). \n**Example:** `\"User\"`" enum: - User - Group - VirtualGroup - Unknown type: string securityProvider: description: "The unique name of the security identity provider in which the security identity is defined. Defaults to the first security identity provider associated with the target Push source (see [Creating a Security Identity Provider for a Secured Push Source](https://docs.coveo.com/en/85/). \n**Example:** `My Secured Push Source Security Identity Provider`" type: string type: object PermissionSetsModel: properties: allowAnonymous: description: Whether this permission set allows anonymous users to see the item in their query results. type: boolean allowedPermissions: items: $ref: '#/definitions/PermissionIdentityModel' description: "The security identities that are explicitly allowed to see the item by this permission set. \n**Note:** \n> You must push those security identities in the security identity provider of the target Push source, otherwise they will be in error (see [Manage security identities in a security identity provider](https://docs.coveo.com/en/132/))." type: array deniedPermissions: items: $ref: '#/definitions/PermissionIdentityModel' description: "The security identities that are explicitly denied to see the item by this permission set. \n**Note:** \n> You must push those security identities in the security identity provider of the target Push source, otherwise they will be in error (see [Manage security identities in a security identity provider](https://docs.coveo.com/en/132/))." type: array type: object Error: properties: errorCode: type: string message: type: string type: object DocumentBody: additionalProperties: description: "The metadata key-value pairs to push along with the item (see [Push source item metadata](https://docs.coveo.com/en/115/)). \n**Note:** \nThis specification indicates that metadata values must be of the string type, but other types of metadata values are also actually supported (see [Allowed metadata types](https://docs.coveo.com/en/162/))." type: string properties: compressedBinaryData: description: "The Base64-encoded item data. \nDepending on your specific needs, you can either use the `data`, `compressedBinaryData`, or `compressedBinaryDataFileId` property to push item data (see [Push source item data](https://docs.coveo.com/en/73/)). \n**Example:** `\"H4sIAAAAAAAA/0utSMwtyEkFAJ+b7G4HAAAA\"`" type: string compressedBinaryDataFileId: description: "The unique identifier of the file container where the compressed or uncompressed, binary or non-binary item data was previously uploaded (see [Create a file container](https://docs.coveo.com/en/43/)). \nDepending on your specific needs, you can either use the `data`, `compressedBinaryData`, or `compressedBinaryDataFileId` property to push item data (see [Push source item data](https://docs.coveo.com/en/73/)). \n**Example:** `\"b5e8767e-8f0d-4a89-9095-1127915c89c7\"`" type: string data: description: "The raw textual item data. \nDepending on your specific needs, you can either use the `data`, `compressedBinaryData`, or `compressedBinaryDataFileId` property to push item data (see [Push source item data](https://docs.coveo.com/en/73/)). \n**Example:** `\"
My raw textual item data
\"`" type: string fileExtension: description: "The file extension of the item data you are pushing. \nValue must include a preceding `.` character. \nSpecifying a value for this property is typically only useful when using the `compressedBinaryData` or `compressedBinaryDataFileId` property to push compressed item data. \n**Example:** `\".html\"`" type: string parentId: description: "The URI of the parent item (see [Understanding the parentId Property](https://docs.coveo.com/en/57/)). \n**Example:** `\"file://folder/\"`" type: string permissions: items: $ref: '#/definitions/PermissionSetsModel' description: "The permission sets for this item. \nThis is only useful when pushing items in a secured Push source. \nA security identity must be explicitly allowed in **all** permission sets, and not be explicitly denied in **any** permission set to be allowed to see the item. \n**Note:** \n> The permission model described in this specification is flexible enough to allow you to faithfully replicate most secured enterprise systems (see [Simplified permission model](https://docs.coveo.com/en/107/)). However, the Push API also accepts a more complex permission model which allows you to define multiple permission levels and sets (see [Complete permission model](https://docs.coveo.com/en/25/))." type: array type: object