generated: '2026-07-15' method: generated source: openapi/aws-api-gateway-openapi-original.yml, openapi/aws-iam-openapi-original.yml, openapi/aws-lambda-openapi-original.yml, openapi/cloudflare-openapi-original.yml, openapi/github-openapi-original.yml, openapi/microsoft-cognitive-news-search-openapi-original.yml, openapi/microsoft-cognitive-video-search-openapi-original.yml, openapi/microsoft-cognitive-web-search-openapi-original.yml, openapi/postman-openapi-original.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 2757 by_action_class: acting: 1382 connected: 1375 by_consequence: write: 1288 read: 1375 physical: 58 safety-critical: 36 human_in_the_loop_required: 36 operations: - path: /apikeys method: post operationId: CreateApiKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apikeys method: get operationId: GetApiKeys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/authorizers method: post operationId: CreateAuthorizer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/authorizers method: get operationId: GetAuthorizers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /domainnames/{domain_name}/basepathmappings method: post operationId: CreateBasePathMapping x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /domainnames/{domain_name}/basepathmappings method: get operationId: GetBasePathMappings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/deployments method: post operationId: CreateDeployment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/deployments method: get operationId: GetDeployments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/documentation/parts method: post operationId: CreateDocumentationPart x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/documentation/parts method: get operationId: GetDocumentationParts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/documentation/parts method: put operationId: ImportDocumentationParts x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/documentation/versions method: post operationId: CreateDocumentationVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/documentation/versions method: get operationId: GetDocumentationVersions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /domainnames method: post operationId: CreateDomainName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /domainnames method: get operationId: GetDomainNames x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/models method: post operationId: CreateModel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/models method: get operationId: GetModels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/requestvalidators method: post operationId: CreateRequestValidator x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/requestvalidators method: get operationId: GetRequestValidators x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/resources/{parent_id} method: post operationId: CreateResource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis method: post operationId: CreateRestApi x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis method: get operationId: GetRestApis x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/stages method: post operationId: CreateStage x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/stages method: get operationId: GetStages x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /usageplans method: post operationId: CreateUsagePlan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /usageplans method: get operationId: GetUsagePlans x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /usageplans/{usageplanId}/keys method: post operationId: CreateUsagePlanKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /usageplans/{usageplanId}/keys method: get operationId: GetUsagePlanKeys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vpclinks method: post operationId: CreateVpcLink x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vpclinks method: get operationId: GetVpcLinks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apikeys/{api_Key} method: delete operationId: DeleteApiKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apikeys/{api_Key} method: get operationId: GetApiKey x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apikeys/{api_Key} method: patch operationId: UpdateApiKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/authorizers/{authorizer_id} method: delete operationId: DeleteAuthorizer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/authorizers/{authorizer_id} method: get operationId: GetAuthorizer x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/authorizers/{authorizer_id} method: post operationId: TestInvokeAuthorizer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/authorizers/{authorizer_id} method: patch operationId: UpdateAuthorizer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /domainnames/{domain_name}/basepathmappings/{base_path} method: delete operationId: DeleteBasePathMapping x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /domainnames/{domain_name}/basepathmappings/{base_path} method: get operationId: GetBasePathMapping x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /domainnames/{domain_name}/basepathmappings/{base_path} method: patch operationId: UpdateBasePathMapping x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /clientcertificates/{clientcertificate_id} method: delete operationId: DeleteClientCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /clientcertificates/{clientcertificate_id} method: get operationId: GetClientCertificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /clientcertificates/{clientcertificate_id} method: patch operationId: UpdateClientCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/deployments/{deployment_id} method: delete operationId: DeleteDeployment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/deployments/{deployment_id} method: get operationId: GetDeployment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/deployments/{deployment_id} method: patch operationId: UpdateDeployment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/documentation/parts/{part_id} method: delete operationId: DeleteDocumentationPart x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/documentation/parts/{part_id} method: get operationId: GetDocumentationPart x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/documentation/parts/{part_id} method: patch operationId: UpdateDocumentationPart x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/documentation/versions/{doc_version} method: delete operationId: DeleteDocumentationVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/documentation/versions/{doc_version} method: get operationId: GetDocumentationVersion x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/documentation/versions/{doc_version} method: patch operationId: UpdateDocumentationVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /domainnames/{domain_name} method: delete operationId: DeleteDomainName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /domainnames/{domain_name} method: get operationId: GetDomainName x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /domainnames/{domain_name} method: patch operationId: UpdateDomainName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/gatewayresponses/{response_type} method: delete operationId: DeleteGatewayResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/gatewayresponses/{response_type} method: get operationId: GetGatewayResponse x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/gatewayresponses/{response_type} method: put operationId: PutGatewayResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/gatewayresponses/{response_type} method: patch operationId: UpdateGatewayResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method}/integration method: delete operationId: DeleteIntegration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method}/integration method: get operationId: GetIntegration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method}/integration method: put operationId: PutIntegration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method}/integration method: patch operationId: UpdateIntegration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method}/integration/responses/{status_code} method: delete operationId: DeleteIntegrationResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method}/integration/responses/{status_code} method: get operationId: GetIntegrationResponse x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method}/integration/responses/{status_code} method: put operationId: PutIntegrationResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method}/integration/responses/{status_code} method: patch operationId: UpdateIntegrationResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method} method: delete operationId: DeleteMethod x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method} method: get operationId: GetMethod x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method} method: put operationId: PutMethod x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method} method: post operationId: TestInvokeMethod x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method} method: patch operationId: UpdateMethod x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method}/responses/{status_code} method: delete operationId: DeleteMethodResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method}/responses/{status_code} method: get operationId: GetMethodResponse x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method}/responses/{status_code} method: put operationId: PutMethodResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id}/methods/{http_method}/responses/{status_code} method: patch operationId: UpdateMethodResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/models/{model_name} method: delete operationId: DeleteModel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/models/{model_name} method: get operationId: GetModel x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/models/{model_name} method: patch operationId: UpdateModel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/requestvalidators/{requestvalidator_id} method: delete operationId: DeleteRequestValidator x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/requestvalidators/{requestvalidator_id} method: get operationId: GetRequestValidator x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/requestvalidators/{requestvalidator_id} method: patch operationId: UpdateRequestValidator x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id} method: delete operationId: DeleteResource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/resources/{resource_id} method: get operationId: GetResource x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/resources/{resource_id} method: patch operationId: UpdateResource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id} method: delete operationId: DeleteRestApi x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id} method: get operationId: GetRestApi x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id} method: put operationId: PutRestApi x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id} method: patch operationId: UpdateRestApi x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/stages/{stage_name} method: delete operationId: DeleteStage x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/stages/{stage_name} method: get operationId: GetStage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/stages/{stage_name} method: patch operationId: UpdateStage x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /usageplans/{usageplanId} method: delete operationId: DeleteUsagePlan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /usageplans/{usageplanId} method: get operationId: GetUsagePlan x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /usageplans/{usageplanId} method: patch operationId: UpdateUsagePlan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /usageplans/{usageplanId}/keys/{keyId} method: delete operationId: DeleteUsagePlanKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /usageplans/{usageplanId}/keys/{keyId} method: get operationId: GetUsagePlanKey x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vpclinks/{vpclink_id} method: delete operationId: DeleteVpcLink x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vpclinks/{vpclink_id} method: get operationId: GetVpcLink x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vpclinks/{vpclink_id} method: patch operationId: UpdateVpcLink x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/stages/{stage_name}/cache/authorizers method: delete operationId: FlushStageAuthorizersCache x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/stages/{stage_name}/cache/data method: delete operationId: FlushStageCache x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /clientcertificates method: post operationId: GenerateClientCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /clientcertificates method: get operationId: GetClientCertificates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account method: get operationId: GetAccount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account method: patch operationId: UpdateAccount x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis/{restapi_id}/stages/{stage_name}/exports/{export_type} method: get operationId: GetExport x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/gatewayresponses method: get operationId: GetGatewayResponses x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/models/{model_name}/default_template method: get operationId: GetModelTemplate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/resources method: get operationId: GetResources x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /restapis/{restapi_id}/stages/{stage_name}/sdks/{sdk_type} method: get operationId: GetSdk x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /sdktypes/{sdktype_id} method: get operationId: GetSdkType x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /sdktypes method: get operationId: GetSdkTypes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tags/{resource_arn} method: get operationId: GetTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tags/{resource_arn} method: put operationId: TagResource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /usageplans/{usageplanId}/usage#startDate&endDate method: get operationId: GetUsage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apikeys#mode=import&format method: post operationId: ImportApiKeys x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /restapis#mode=import method: post operationId: ImportRestApi x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tags/{resource_arn}#tagKeys method: delete operationId: UntagResource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /usageplans/{usageplanId}/keys/{keyId}/usage method: patch operationId: UpdateUsage x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=AddClientIDToOpenIDConnectProvider method: get operationId: GET_AddClientIDToOpenIDConnectProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=AddClientIDToOpenIDConnectProvider method: post operationId: POST_AddClientIDToOpenIDConnectProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=AddRoleToInstanceProfile method: get operationId: GET_AddRoleToInstanceProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=AddRoleToInstanceProfile method: post operationId: POST_AddRoleToInstanceProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=AddUserToGroup method: get operationId: GET_AddUserToGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=AddUserToGroup method: post operationId: POST_AddUserToGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=AttachGroupPolicy method: get operationId: GET_AttachGroupPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=AttachGroupPolicy method: post operationId: POST_AttachGroupPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=AttachRolePolicy method: get operationId: GET_AttachRolePolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=AttachRolePolicy method: post operationId: POST_AttachRolePolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=AttachUserPolicy method: get operationId: GET_AttachUserPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=AttachUserPolicy method: post operationId: POST_AttachUserPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ChangePassword method: get operationId: GET_ChangePassword x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ChangePassword method: post operationId: POST_ChangePassword x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreateAccessKey method: get operationId: GET_CreateAccessKey x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreateAccessKey method: post operationId: POST_CreateAccessKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreateAccountAlias method: get operationId: GET_CreateAccountAlias x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreateAccountAlias method: post operationId: POST_CreateAccountAlias x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreateGroup method: get operationId: GET_CreateGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreateGroup method: post operationId: POST_CreateGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreateInstanceProfile method: get operationId: GET_CreateInstanceProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreateInstanceProfile method: post operationId: POST_CreateInstanceProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreateLoginProfile method: get operationId: GET_CreateLoginProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreateLoginProfile method: post operationId: POST_CreateLoginProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreateOpenIDConnectProvider method: get operationId: GET_CreateOpenIDConnectProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreateOpenIDConnectProvider method: post operationId: POST_CreateOpenIDConnectProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreatePolicy method: get operationId: GET_CreatePolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreatePolicy method: post operationId: POST_CreatePolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreatePolicyVersion method: get operationId: GET_CreatePolicyVersion x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreatePolicyVersion method: post operationId: POST_CreatePolicyVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreateRole method: get operationId: GET_CreateRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreateRole method: post operationId: POST_CreateRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreateSAMLProvider method: get operationId: GET_CreateSAMLProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreateSAMLProvider method: post operationId: POST_CreateSAMLProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreateServiceLinkedRole method: get operationId: GET_CreateServiceLinkedRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreateServiceLinkedRole method: post operationId: POST_CreateServiceLinkedRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreateServiceSpecificCredential method: get operationId: GET_CreateServiceSpecificCredential x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreateServiceSpecificCredential method: post operationId: POST_CreateServiceSpecificCredential x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreateUser method: get operationId: GET_CreateUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreateUser method: post operationId: POST_CreateUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=CreateVirtualMFADevice method: get operationId: GET_CreateVirtualMFADevice x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=CreateVirtualMFADevice method: post operationId: POST_CreateVirtualMFADevice x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeactivateMFADevice method: get operationId: GET_DeactivateMFADevice x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeactivateMFADevice method: post operationId: POST_DeactivateMFADevice x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteAccessKey method: get operationId: GET_DeleteAccessKey x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteAccessKey method: post operationId: POST_DeleteAccessKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteAccountAlias method: get operationId: GET_DeleteAccountAlias x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteAccountAlias method: post operationId: POST_DeleteAccountAlias x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteAccountPasswordPolicy method: get operationId: GET_DeleteAccountPasswordPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteAccountPasswordPolicy method: post operationId: POST_DeleteAccountPasswordPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteGroup method: get operationId: GET_DeleteGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteGroup method: post operationId: POST_DeleteGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteGroupPolicy method: get operationId: GET_DeleteGroupPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteGroupPolicy method: post operationId: POST_DeleteGroupPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteInstanceProfile method: get operationId: GET_DeleteInstanceProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteInstanceProfile method: post operationId: POST_DeleteInstanceProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteLoginProfile method: get operationId: GET_DeleteLoginProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteLoginProfile method: post operationId: POST_DeleteLoginProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteOpenIDConnectProvider method: get operationId: GET_DeleteOpenIDConnectProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteOpenIDConnectProvider method: post operationId: POST_DeleteOpenIDConnectProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeletePolicy method: get operationId: GET_DeletePolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeletePolicy method: post operationId: POST_DeletePolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeletePolicyVersion method: get operationId: GET_DeletePolicyVersion x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeletePolicyVersion method: post operationId: POST_DeletePolicyVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteRole method: get operationId: GET_DeleteRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteRole method: post operationId: POST_DeleteRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteRolePermissionsBoundary method: get operationId: GET_DeleteRolePermissionsBoundary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteRolePermissionsBoundary method: post operationId: POST_DeleteRolePermissionsBoundary x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteRolePolicy method: get operationId: GET_DeleteRolePolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteRolePolicy method: post operationId: POST_DeleteRolePolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteSAMLProvider method: get operationId: GET_DeleteSAMLProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteSAMLProvider method: post operationId: POST_DeleteSAMLProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteSSHPublicKey method: get operationId: GET_DeleteSSHPublicKey x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteSSHPublicKey method: post operationId: POST_DeleteSSHPublicKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteServerCertificate method: get operationId: GET_DeleteServerCertificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteServerCertificate method: post operationId: POST_DeleteServerCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteServiceLinkedRole method: get operationId: GET_DeleteServiceLinkedRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteServiceLinkedRole method: post operationId: POST_DeleteServiceLinkedRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteServiceSpecificCredential method: get operationId: GET_DeleteServiceSpecificCredential x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteServiceSpecificCredential method: post operationId: POST_DeleteServiceSpecificCredential x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteSigningCertificate method: get operationId: GET_DeleteSigningCertificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteSigningCertificate method: post operationId: POST_DeleteSigningCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteUser method: get operationId: GET_DeleteUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteUser method: post operationId: POST_DeleteUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteUserPermissionsBoundary method: get operationId: GET_DeleteUserPermissionsBoundary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteUserPermissionsBoundary method: post operationId: POST_DeleteUserPermissionsBoundary x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteUserPolicy method: get operationId: GET_DeleteUserPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteUserPolicy method: post operationId: POST_DeleteUserPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DeleteVirtualMFADevice method: get operationId: GET_DeleteVirtualMFADevice x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DeleteVirtualMFADevice method: post operationId: POST_DeleteVirtualMFADevice x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DetachGroupPolicy method: get operationId: GET_DetachGroupPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DetachGroupPolicy method: post operationId: POST_DetachGroupPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DetachRolePolicy method: get operationId: GET_DetachRolePolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DetachRolePolicy method: post operationId: POST_DetachRolePolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=DetachUserPolicy method: get operationId: GET_DetachUserPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=DetachUserPolicy method: post operationId: POST_DetachUserPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=EnableMFADevice method: get operationId: GET_EnableMFADevice x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=EnableMFADevice method: post operationId: POST_EnableMFADevice x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GenerateCredentialReport method: get operationId: GET_GenerateCredentialReport x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GenerateCredentialReport method: post operationId: POST_GenerateCredentialReport x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GenerateOrganizationsAccessReport method: get operationId: GET_GenerateOrganizationsAccessReport x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GenerateOrganizationsAccessReport method: post operationId: POST_GenerateOrganizationsAccessReport x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GenerateServiceLastAccessedDetails method: get operationId: GET_GenerateServiceLastAccessedDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GenerateServiceLastAccessedDetails method: post operationId: POST_GenerateServiceLastAccessedDetails x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetAccessKeyLastUsed method: get operationId: GET_GetAccessKeyLastUsed x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetAccessKeyLastUsed method: post operationId: POST_GetAccessKeyLastUsed x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetAccountAuthorizationDetails method: get operationId: GET_GetAccountAuthorizationDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetAccountAuthorizationDetails method: post operationId: POST_GetAccountAuthorizationDetails x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetAccountPasswordPolicy method: get operationId: GET_GetAccountPasswordPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetAccountPasswordPolicy method: post operationId: POST_GetAccountPasswordPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetAccountSummary method: get operationId: GET_GetAccountSummary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetAccountSummary method: post operationId: POST_GetAccountSummary x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetContextKeysForCustomPolicy method: get operationId: GET_GetContextKeysForCustomPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetContextKeysForCustomPolicy method: post operationId: POST_GetContextKeysForCustomPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetContextKeysForPrincipalPolicy method: get operationId: GET_GetContextKeysForPrincipalPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetContextKeysForPrincipalPolicy method: post operationId: POST_GetContextKeysForPrincipalPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetCredentialReport method: get operationId: GET_GetCredentialReport x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetCredentialReport method: post operationId: POST_GetCredentialReport x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetGroup method: get operationId: GET_GetGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetGroup method: post operationId: POST_GetGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetGroupPolicy method: get operationId: GET_GetGroupPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetGroupPolicy method: post operationId: POST_GetGroupPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetInstanceProfile method: get operationId: GET_GetInstanceProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetInstanceProfile method: post operationId: POST_GetInstanceProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetLoginProfile method: get operationId: GET_GetLoginProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetLoginProfile method: post operationId: POST_GetLoginProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetOpenIDConnectProvider method: get operationId: GET_GetOpenIDConnectProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetOpenIDConnectProvider method: post operationId: POST_GetOpenIDConnectProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetOrganizationsAccessReport method: get operationId: GET_GetOrganizationsAccessReport x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetOrganizationsAccessReport method: post operationId: POST_GetOrganizationsAccessReport x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetPolicy method: get operationId: GET_GetPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetPolicy method: post operationId: POST_GetPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetPolicyVersion method: get operationId: GET_GetPolicyVersion x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetPolicyVersion method: post operationId: POST_GetPolicyVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetRole method: get operationId: GET_GetRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetRole method: post operationId: POST_GetRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetRolePolicy method: get operationId: GET_GetRolePolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetRolePolicy method: post operationId: POST_GetRolePolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetSAMLProvider method: get operationId: GET_GetSAMLProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetSAMLProvider method: post operationId: POST_GetSAMLProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetSSHPublicKey method: get operationId: GET_GetSSHPublicKey x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetSSHPublicKey method: post operationId: POST_GetSSHPublicKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetServerCertificate method: get operationId: GET_GetServerCertificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetServerCertificate method: post operationId: POST_GetServerCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetServiceLastAccessedDetails method: get operationId: GET_GetServiceLastAccessedDetails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetServiceLastAccessedDetails method: post operationId: POST_GetServiceLastAccessedDetails x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetServiceLastAccessedDetailsWithEntities method: get operationId: GET_GetServiceLastAccessedDetailsWithEntities x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetServiceLastAccessedDetailsWithEntities method: post operationId: POST_GetServiceLastAccessedDetailsWithEntities x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetServiceLinkedRoleDeletionStatus method: get operationId: GET_GetServiceLinkedRoleDeletionStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetServiceLinkedRoleDeletionStatus method: post operationId: POST_GetServiceLinkedRoleDeletionStatus x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetUser method: get operationId: GET_GetUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetUser method: post operationId: POST_GetUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=GetUserPolicy method: get operationId: GET_GetUserPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=GetUserPolicy method: post operationId: POST_GetUserPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListAccessKeys method: get operationId: GET_ListAccessKeys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListAccessKeys method: post operationId: POST_ListAccessKeys x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListAccountAliases method: get operationId: GET_ListAccountAliases x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListAccountAliases method: post operationId: POST_ListAccountAliases x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListAttachedGroupPolicies method: get operationId: GET_ListAttachedGroupPolicies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListAttachedGroupPolicies method: post operationId: POST_ListAttachedGroupPolicies x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListAttachedRolePolicies method: get operationId: GET_ListAttachedRolePolicies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListAttachedRolePolicies method: post operationId: POST_ListAttachedRolePolicies x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListAttachedUserPolicies method: get operationId: GET_ListAttachedUserPolicies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListAttachedUserPolicies method: post operationId: POST_ListAttachedUserPolicies x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListEntitiesForPolicy method: get operationId: GET_ListEntitiesForPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListEntitiesForPolicy method: post operationId: POST_ListEntitiesForPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListGroupPolicies method: get operationId: GET_ListGroupPolicies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListGroupPolicies method: post operationId: POST_ListGroupPolicies x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListGroups method: get operationId: GET_ListGroups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListGroups method: post operationId: POST_ListGroups x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListGroupsForUser method: get operationId: GET_ListGroupsForUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListGroupsForUser method: post operationId: POST_ListGroupsForUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListInstanceProfileTags method: get operationId: GET_ListInstanceProfileTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListInstanceProfileTags method: post operationId: POST_ListInstanceProfileTags x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListInstanceProfiles method: get operationId: GET_ListInstanceProfiles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListInstanceProfiles method: post operationId: POST_ListInstanceProfiles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListInstanceProfilesForRole method: get operationId: GET_ListInstanceProfilesForRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListInstanceProfilesForRole method: post operationId: POST_ListInstanceProfilesForRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListMFADeviceTags method: get operationId: GET_ListMFADeviceTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListMFADeviceTags method: post operationId: POST_ListMFADeviceTags x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListMFADevices method: get operationId: GET_ListMFADevices x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListMFADevices method: post operationId: POST_ListMFADevices x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListOpenIDConnectProviderTags method: get operationId: GET_ListOpenIDConnectProviderTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListOpenIDConnectProviderTags method: post operationId: POST_ListOpenIDConnectProviderTags x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /#Action=ListOpenIDConnectProviders method: get operationId: GET_ListOpenIDConnectProviders x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListOpenIDConnectProviders method: post operationId: POST_ListOpenIDConnectProviders x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /#Action=ListPolicies method: get operationId: GET_ListPolicies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListPolicies method: post operationId: POST_ListPolicies x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListPoliciesGrantingServiceAccess method: get operationId: GET_ListPoliciesGrantingServiceAccess x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListPoliciesGrantingServiceAccess method: post operationId: POST_ListPoliciesGrantingServiceAccess x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListPolicyTags method: get operationId: GET_ListPolicyTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListPolicyTags method: post operationId: POST_ListPolicyTags x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListPolicyVersions method: get operationId: GET_ListPolicyVersions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListPolicyVersions method: post operationId: POST_ListPolicyVersions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListRolePolicies method: get operationId: GET_ListRolePolicies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListRolePolicies method: post operationId: POST_ListRolePolicies x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListRoleTags method: get operationId: GET_ListRoleTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListRoleTags method: post operationId: POST_ListRoleTags x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListRoles method: get operationId: GET_ListRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListRoles method: post operationId: POST_ListRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListSAMLProviderTags method: get operationId: GET_ListSAMLProviderTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListSAMLProviderTags method: post operationId: POST_ListSAMLProviderTags x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListSAMLProviders method: get operationId: GET_ListSAMLProviders x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListSAMLProviders method: post operationId: POST_ListSAMLProviders x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListSSHPublicKeys method: get operationId: GET_ListSSHPublicKeys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListSSHPublicKeys method: post operationId: POST_ListSSHPublicKeys x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListServerCertificateTags method: get operationId: GET_ListServerCertificateTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListServerCertificateTags method: post operationId: POST_ListServerCertificateTags x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListServerCertificates method: get operationId: GET_ListServerCertificates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListServerCertificates method: post operationId: POST_ListServerCertificates x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListServiceSpecificCredentials method: get operationId: GET_ListServiceSpecificCredentials x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListServiceSpecificCredentials method: post operationId: POST_ListServiceSpecificCredentials x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListSigningCertificates method: get operationId: GET_ListSigningCertificates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListSigningCertificates method: post operationId: POST_ListSigningCertificates x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListUserPolicies method: get operationId: GET_ListUserPolicies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListUserPolicies method: post operationId: POST_ListUserPolicies x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListUserTags method: get operationId: GET_ListUserTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListUserTags method: post operationId: POST_ListUserTags x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListUsers method: get operationId: GET_ListUsers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListUsers method: post operationId: POST_ListUsers x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ListVirtualMFADevices method: get operationId: GET_ListVirtualMFADevices x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ListVirtualMFADevices method: post operationId: POST_ListVirtualMFADevices x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=PutGroupPolicy method: get operationId: GET_PutGroupPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=PutGroupPolicy method: post operationId: POST_PutGroupPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=PutRolePermissionsBoundary method: get operationId: GET_PutRolePermissionsBoundary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=PutRolePermissionsBoundary method: post operationId: POST_PutRolePermissionsBoundary x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=PutRolePolicy method: get operationId: GET_PutRolePolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=PutRolePolicy method: post operationId: POST_PutRolePolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=PutUserPermissionsBoundary method: get operationId: GET_PutUserPermissionsBoundary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=PutUserPermissionsBoundary method: post operationId: POST_PutUserPermissionsBoundary x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=PutUserPolicy method: get operationId: GET_PutUserPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=PutUserPolicy method: post operationId: POST_PutUserPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=RemoveClientIDFromOpenIDConnectProvider method: get operationId: GET_RemoveClientIDFromOpenIDConnectProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=RemoveClientIDFromOpenIDConnectProvider method: post operationId: POST_RemoveClientIDFromOpenIDConnectProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=RemoveRoleFromInstanceProfile method: get operationId: GET_RemoveRoleFromInstanceProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=RemoveRoleFromInstanceProfile method: post operationId: POST_RemoveRoleFromInstanceProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=RemoveUserFromGroup method: get operationId: GET_RemoveUserFromGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=RemoveUserFromGroup method: post operationId: POST_RemoveUserFromGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=ResetServiceSpecificCredential method: get operationId: GET_ResetServiceSpecificCredential x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ResetServiceSpecificCredential method: post operationId: POST_ResetServiceSpecificCredential x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /#Action=ResyncMFADevice method: get operationId: GET_ResyncMFADevice x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=ResyncMFADevice method: post operationId: POST_ResyncMFADevice x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=SetDefaultPolicyVersion method: get operationId: GET_SetDefaultPolicyVersion x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=SetDefaultPolicyVersion method: post operationId: POST_SetDefaultPolicyVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=SetSecurityTokenServicePreferences method: get operationId: GET_SetSecurityTokenServicePreferences x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=SetSecurityTokenServicePreferences method: post operationId: POST_SetSecurityTokenServicePreferences x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=SimulateCustomPolicy method: get operationId: GET_SimulateCustomPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=SimulateCustomPolicy method: post operationId: POST_SimulateCustomPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=SimulatePrincipalPolicy method: get operationId: GET_SimulatePrincipalPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=SimulatePrincipalPolicy method: post operationId: POST_SimulatePrincipalPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=TagInstanceProfile method: get operationId: GET_TagInstanceProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=TagInstanceProfile method: post operationId: POST_TagInstanceProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=TagMFADevice method: get operationId: GET_TagMFADevice x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=TagMFADevice method: post operationId: POST_TagMFADevice x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=TagOpenIDConnectProvider method: get operationId: GET_TagOpenIDConnectProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=TagOpenIDConnectProvider method: post operationId: POST_TagOpenIDConnectProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=TagPolicy method: get operationId: GET_TagPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=TagPolicy method: post operationId: POST_TagPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=TagRole method: get operationId: GET_TagRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=TagRole method: post operationId: POST_TagRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=TagSAMLProvider method: get operationId: GET_TagSAMLProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=TagSAMLProvider method: post operationId: POST_TagSAMLProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=TagServerCertificate method: get operationId: GET_TagServerCertificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=TagServerCertificate method: post operationId: POST_TagServerCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=TagUser method: get operationId: GET_TagUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=TagUser method: post operationId: POST_TagUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UntagInstanceProfile method: get operationId: GET_UntagInstanceProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UntagInstanceProfile method: post operationId: POST_UntagInstanceProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UntagMFADevice method: get operationId: GET_UntagMFADevice x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UntagMFADevice method: post operationId: POST_UntagMFADevice x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UntagOpenIDConnectProvider method: get operationId: GET_UntagOpenIDConnectProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UntagOpenIDConnectProvider method: post operationId: POST_UntagOpenIDConnectProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UntagPolicy method: get operationId: GET_UntagPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UntagPolicy method: post operationId: POST_UntagPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UntagRole method: get operationId: GET_UntagRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UntagRole method: post operationId: POST_UntagRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UntagSAMLProvider method: get operationId: GET_UntagSAMLProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UntagSAMLProvider method: post operationId: POST_UntagSAMLProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UntagServerCertificate method: get operationId: GET_UntagServerCertificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UntagServerCertificate method: post operationId: POST_UntagServerCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UntagUser method: get operationId: GET_UntagUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UntagUser method: post operationId: POST_UntagUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateAccessKey method: get operationId: GET_UpdateAccessKey x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateAccessKey method: post operationId: POST_UpdateAccessKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateAccountPasswordPolicy method: get operationId: GET_UpdateAccountPasswordPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateAccountPasswordPolicy method: post operationId: POST_UpdateAccountPasswordPolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateAssumeRolePolicy method: get operationId: GET_UpdateAssumeRolePolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateAssumeRolePolicy method: post operationId: POST_UpdateAssumeRolePolicy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateGroup method: get operationId: GET_UpdateGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateGroup method: post operationId: POST_UpdateGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateLoginProfile method: get operationId: GET_UpdateLoginProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateLoginProfile method: post operationId: POST_UpdateLoginProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateOpenIDConnectProviderThumbprint method: get operationId: GET_UpdateOpenIDConnectProviderThumbprint x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateOpenIDConnectProviderThumbprint method: post operationId: POST_UpdateOpenIDConnectProviderThumbprint x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateRole method: get operationId: GET_UpdateRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateRole method: post operationId: POST_UpdateRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateRoleDescription method: get operationId: GET_UpdateRoleDescription x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateRoleDescription method: post operationId: POST_UpdateRoleDescription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateSAMLProvider method: get operationId: GET_UpdateSAMLProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateSAMLProvider method: post operationId: POST_UpdateSAMLProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateSSHPublicKey method: get operationId: GET_UpdateSSHPublicKey x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateSSHPublicKey method: post operationId: POST_UpdateSSHPublicKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateServerCertificate method: get operationId: GET_UpdateServerCertificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateServerCertificate method: post operationId: POST_UpdateServerCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateServiceSpecificCredential method: get operationId: GET_UpdateServiceSpecificCredential x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateServiceSpecificCredential method: post operationId: POST_UpdateServiceSpecificCredential x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateSigningCertificate method: get operationId: GET_UpdateSigningCertificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateSigningCertificate method: post operationId: POST_UpdateSigningCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UpdateUser method: get operationId: GET_UpdateUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UpdateUser method: post operationId: POST_UpdateUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UploadSSHPublicKey method: get operationId: GET_UploadSSHPublicKey x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UploadSSHPublicKey method: post operationId: POST_UploadSSHPublicKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UploadServerCertificate method: get operationId: GET_UploadServerCertificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UploadServerCertificate method: post operationId: POST_UploadServerCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /#Action=UploadSigningCertificate method: get operationId: GET_UploadSigningCertificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /#Action=UploadSigningCertificate method: post operationId: POST_UploadSigningCertificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2018-10-31/layers/{LayerName}/versions/{VersionNumber}/policy method: post operationId: AddLayerVersionPermission x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2018-10-31/layers/{LayerName}/versions/{VersionNumber}/policy method: get operationId: GetLayerVersionPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2015-03-31/functions/{FunctionName}/policy method: post operationId: AddPermission x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/functions/{FunctionName}/policy method: get operationId: GetPolicy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2015-03-31/functions/{FunctionName}/aliases method: post operationId: CreateAlias x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/functions/{FunctionName}/aliases method: get operationId: ListAliases x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2020-04-22/code-signing-configs/ method: post operationId: CreateCodeSigningConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2020-04-22/code-signing-configs/ method: get operationId: ListCodeSigningConfigs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2015-03-31/event-source-mappings/ method: post operationId: CreateEventSourceMapping x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/event-source-mappings/ method: get operationId: ListEventSourceMappings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2015-03-31/functions method: post operationId: CreateFunction x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2021-10-31/functions/{FunctionName}/url method: post operationId: CreateFunctionUrlConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2021-10-31/functions/{FunctionName}/url method: delete operationId: DeleteFunctionUrlConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2021-10-31/functions/{FunctionName}/url method: get operationId: GetFunctionUrlConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2021-10-31/functions/{FunctionName}/url method: put operationId: UpdateFunctionUrlConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/functions/{FunctionName}/aliases/{Name} method: delete operationId: DeleteAlias x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/functions/{FunctionName}/aliases/{Name} method: get operationId: GetAlias x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2015-03-31/functions/{FunctionName}/aliases/{Name} method: put operationId: UpdateAlias x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2020-04-22/code-signing-configs/{CodeSigningConfigArn} method: delete operationId: DeleteCodeSigningConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2020-04-22/code-signing-configs/{CodeSigningConfigArn} method: get operationId: GetCodeSigningConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2020-04-22/code-signing-configs/{CodeSigningConfigArn} method: put operationId: UpdateCodeSigningConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/event-source-mappings/{UUID} method: delete operationId: DeleteEventSourceMapping x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/event-source-mappings/{UUID} method: get operationId: GetEventSourceMapping x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2015-03-31/event-source-mappings/{UUID} method: put operationId: UpdateEventSourceMapping x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/functions/{FunctionName} method: delete operationId: DeleteFunction x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/functions/{FunctionName} method: get operationId: GetFunction x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2020-06-30/functions/{FunctionName}/code-signing-config method: delete operationId: DeleteFunctionCodeSigningConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2020-06-30/functions/{FunctionName}/code-signing-config method: get operationId: GetFunctionCodeSigningConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2020-06-30/functions/{FunctionName}/code-signing-config method: put operationId: PutFunctionCodeSigningConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2017-10-31/functions/{FunctionName}/concurrency method: delete operationId: DeleteFunctionConcurrency x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2017-10-31/functions/{FunctionName}/concurrency method: put operationId: PutFunctionConcurrency x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2019-09-25/functions/{FunctionName}/event-invoke-config method: delete operationId: DeleteFunctionEventInvokeConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2019-09-25/functions/{FunctionName}/event-invoke-config method: get operationId: GetFunctionEventInvokeConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2019-09-25/functions/{FunctionName}/event-invoke-config method: put operationId: PutFunctionEventInvokeConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2019-09-25/functions/{FunctionName}/event-invoke-config method: post operationId: UpdateFunctionEventInvokeConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2018-10-31/layers/{LayerName}/versions/{VersionNumber} method: delete operationId: DeleteLayerVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2018-10-31/layers/{LayerName}/versions/{VersionNumber} method: get operationId: GetLayerVersion x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2019-09-30/functions/{FunctionName}/provisioned-concurrency#Qualifier method: delete operationId: DeleteProvisionedConcurrencyConfig x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2019-09-30/functions/{FunctionName}/provisioned-concurrency#Qualifier method: get operationId: GetProvisionedConcurrencyConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2019-09-30/functions/{FunctionName}/provisioned-concurrency#Qualifier method: put operationId: PutProvisionedConcurrencyConfig x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2016-08-19/account-settings/ method: get operationId: GetAccountSettings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2019-09-30/functions/{FunctionName}/concurrency method: get operationId: GetFunctionConcurrency x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2015-03-31/functions/{FunctionName}/configuration method: get operationId: GetFunctionConfiguration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2015-03-31/functions/{FunctionName}/configuration method: put operationId: UpdateFunctionConfiguration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2018-10-31/layers#find=LayerVersion&Arn method: get operationId: GetLayerVersionByArn x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2021-07-20/functions/{FunctionName}/runtime-management-config method: get operationId: GetRuntimeManagementConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2021-07-20/functions/{FunctionName}/runtime-management-config method: put operationId: PutRuntimeManagementConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/functions/{FunctionName}/invocations method: post operationId: Invoke x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2014-11-13/functions/{FunctionName}/invoke-async/ method: post operationId: InvokeAsync x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2021-11-15/functions/{FunctionName}/response-streaming-invocations method: post operationId: InvokeWithResponseStream x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2019-09-25/functions/{FunctionName}/event-invoke-config/list method: get operationId: ListFunctionEventInvokeConfigs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2021-10-31/functions/{FunctionName}/urls method: get operationId: ListFunctionUrlConfigs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2015-03-31/functions/ method: get operationId: ListFunctions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2020-04-22/code-signing-configs/{CodeSigningConfigArn}/functions method: get operationId: ListFunctionsByCodeSigningConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2018-10-31/layers/{LayerName}/versions method: get operationId: ListLayerVersions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2018-10-31/layers/{LayerName}/versions method: post operationId: PublishLayerVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2018-10-31/layers method: get operationId: ListLayers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2019-09-30/functions/{FunctionName}/provisioned-concurrency#List=ALL method: get operationId: ListProvisionedConcurrencyConfigs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2017-03-31/tags/{ARN} method: get operationId: ListTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2017-03-31/tags/{ARN} method: post operationId: TagResource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/functions/{FunctionName}/versions method: get operationId: ListVersionsByFunction x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /2015-03-31/functions/{FunctionName}/versions method: post operationId: PublishVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2018-10-31/layers/{LayerName}/versions/{VersionNumber}/policy/{StatementId} method: delete operationId: RemoveLayerVersionPermission x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/functions/{FunctionName}/policy/{StatementId} method: delete operationId: RemovePermission x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2017-03-31/tags/{ARN}#tagKeys method: delete operationId: UntagResource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /2015-03-31/functions/{FunctionName}/code method: put operationId: UpdateFunctionCode x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts method: get operationId: accounts-list-accounts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts method: post operationId: account-creation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id} method: delete operationId: account-deletion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id} method: get operationId: accounts-account-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id} method: put operationId: accounts-update-account x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/apps method: get operationId: access-applications-list-access-applications x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/apps method: post operationId: access-applications-add-an-application x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/apps/{app_id} method: delete operationId: access-applications-delete-an-access-application x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/apps/{app_id} method: get operationId: access-applications-get-an-access-application x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/apps/{app_id} method: put operationId: access-applications-update-an-access-application x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/apps/{app_id}/ca method: delete operationId: access-short-lived-certificate-c-as-delete-a-short-lived-certificate-ca x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/apps/{app_id}/ca method: get operationId: access-short-lived-certificate-c-as-get-a-short-lived-certificate-ca x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/apps/{app_id}/ca method: post operationId: access-short-lived-certificate-c-as-create-a-short-lived-certificate-ca x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/apps/{app_id}/policies method: get operationId: access-policies-list-access-app-policies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/apps/{app_id}/policies method: post operationId: access-policies-create-an-access-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/apps/{app_id}/policies/{policy_id} method: delete operationId: access-policies-delete-an-access-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/apps/{app_id}/policies/{policy_id} method: get operationId: access-policies-get-an-access-policy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/apps/{app_id}/policies/{policy_id} method: put operationId: access-policies-update-an-access-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/apps/{app_id}/revoke_tokens method: post operationId: access-applications-revoke-service-tokens x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/access/apps/{app_id}/user_policy_checks method: get operationId: access-applications-test-access-policies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/apps/ca method: get operationId: access-short-lived-certificate-c-as-list-short-lived-certificate-c-as x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/bookmarks method: get operationId: access-bookmark-applications-(-deprecated)-list-bookmark-applications x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/bookmarks/{bookmark_id} method: delete operationId: access-bookmark-applications-(-deprecated)-delete-a-bookmark-application x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/bookmarks/{bookmark_id} method: get operationId: access-bookmark-applications-(-deprecated)-get-a-bookmark-application x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/bookmarks/{bookmark_id} method: post operationId: access-bookmark-applications-(-deprecated)-create-a-bookmark-application x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/bookmarks/{bookmark_id} method: put operationId: access-bookmark-applications-(-deprecated)-update-a-bookmark-application x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/certificates method: get operationId: access-mtls-authentication-list-mtls-certificates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/certificates method: post operationId: access-mtls-authentication-add-an-mtls-certificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/certificates/{certificate_id} method: delete operationId: access-mtls-authentication-delete-an-mtls-certificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/certificates/{certificate_id} method: get operationId: access-mtls-authentication-get-an-mtls-certificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/certificates/{certificate_id} method: put operationId: access-mtls-authentication-update-an-mtls-certificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/certificates/settings method: get operationId: access-mtls-authentication-list-mtls-certificates-hostname-settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/certificates/settings method: put operationId: access-mtls-authentication-update-an-mtls-certificate-settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/custom_pages method: get operationId: access-custom-pages-list-custom-pages x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/custom_pages method: post operationId: access-custom-pages-create-a-custom-page x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/custom_pages/{custom_page_id} method: delete operationId: access-custom-pages-delete-a-custom-page x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/custom_pages/{custom_page_id} method: get operationId: access-custom-pages-get-a-custom-page x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/custom_pages/{custom_page_id} method: put operationId: access-custom-pages-update-a-custom-page x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/groups method: get operationId: access-groups-list-access-groups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/groups method: post operationId: access-groups-create-an-access-group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/groups/{group_id} method: delete operationId: access-groups-delete-an-access-group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/groups/{group_id} method: get operationId: access-groups-get-an-access-group x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/groups/{group_id} method: put operationId: access-groups-update-an-access-group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/identity_providers method: get operationId: access-identity-providers-list-access-identity-providers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/identity_providers method: post operationId: access-identity-providers-add-an-access-identity-provider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/identity_providers/{identity_provider_id} method: delete operationId: access-identity-providers-delete-an-access-identity-provider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/identity_providers/{identity_provider_id} method: get operationId: access-identity-providers-get-an-access-identity-provider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/identity_providers/{identity_provider_id} method: put operationId: access-identity-providers-update-an-access-identity-provider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/keys method: get operationId: access-key-configuration-get-the-access-key-configuration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/keys method: put operationId: access-key-configuration-update-the-access-key-configuration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/keys/rotate method: post operationId: access-key-configuration-rotate-access-keys x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/logs/access_requests method: get operationId: access-authentication-logs-get-access-authentication-logs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/organizations method: get operationId: zero-trust-organization-get-your-zero-trust-organization x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/organizations method: post operationId: zero-trust-organization-create-your-zero-trust-organization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/organizations method: put operationId: zero-trust-organization-update-your-zero-trust-organization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/organizations/doh method: get operationId: zero-trust-organization-get-your-zero-trust-organization-doh-settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/organizations/doh method: put operationId: zero-trust-organization-update-your-zero-trust-organization-doh-settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/organizations/revoke_user method: post operationId: zero-trust-organization-revoke-all-access-tokens-for-a-user x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/access/policies method: get operationId: access-policies-list-access-reusable-policies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/policies method: post operationId: access-policies-create-an-access-reusable-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/policies/{policy_id} method: delete operationId: access-policies-delete-an-access-reusable-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/policies/{policy_id} method: get operationId: access-policies-get-an-access-reusable-policy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/policies/{policy_id} method: put operationId: access-policies-update-an-access-reusable-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/policy-tests method: post operationId: access-policy-tests x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/policy-tests/{policy_test_id} method: get operationId: access-policy-tests-get-an-update x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/policy-tests/{policy_test_id}/users method: get operationId: access-policy-tests-get-a-user-page x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/seats method: patch operationId: zero-trust-seats-update-a-user-seat x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/service_tokens method: get operationId: access-service-tokens-list-service-tokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/service_tokens method: post operationId: access-service-tokens-create-a-service-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/service_tokens/{service_token_id} method: delete operationId: access-service-tokens-delete-a-service-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/service_tokens/{service_token_id} method: get operationId: access-service-tokens-get-a-service-token x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/service_tokens/{service_token_id} method: put operationId: access-service-tokens-update-a-service-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/service_tokens/{service_token_id}/refresh method: post operationId: access-service-tokens-refresh-a-service-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/service_tokens/{service_token_id}/rotate method: post operationId: access-service-tokens-rotate-a-service-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/tags method: get operationId: access-tags-list-tags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/tags method: post operationId: access-tags-create-tag x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/tags/{tag_name} method: delete operationId: access-tags-delete-a-tag x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/tags/{tag_name} method: get operationId: access-tags-get-a-tag x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/tags/{tag_name} method: put operationId: access-tags-update-a-tag x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/access/users method: get operationId: zero-trust-users-get-users x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/users/{user_id}/active_sessions method: get operationId: zero-trust-users-get-active-sessions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/users/{user_id}/active_sessions/{nonce} method: get operationId: zero-trust-users-get-active-session x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/users/{user_id}/failed_logins method: get operationId: zero-trust-users-get-failed-logins x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/access/users/{user_id}/last_seen_identity method: get operationId: zero-trust-users-get-last-seen-identity x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/address_maps method: get operationId: ip-address-management-address-maps-list-address-maps x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/address_maps method: post operationId: ip-address-management-address-maps-create-address-map x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/address_maps/{address_map_id} method: delete operationId: ip-address-management-address-maps-delete-address-map x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/address_maps/{address_map_id} method: get operationId: ip-address-management-address-maps-address-map-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/address_maps/{address_map_id} method: patch operationId: ip-address-management-address-maps-update-address-map x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/address_maps/{address_map_id}/accounts/{account_id} method: delete operationId: ip-address-management-address-maps-remove-an-account-membership-from-an-address-map x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/address_maps/{address_map_id}/accounts/{account_id} method: put operationId: ip-address-management-address-maps-add-an-account-membership-to-an-address-map x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/address_maps/{address_map_id}/ips/{ip_address} method: delete operationId: ip-address-management-address-maps-remove-an-ip-from-an-address-map x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/address_maps/{address_map_id}/ips/{ip_address} method: put operationId: ip-address-management-address-maps-add-an-ip-to-an-address-map x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/address_maps/{address_map_id}/zones/{zone_id} method: delete operationId: ip-address-management-address-maps-remove-a-zone-membership-from-an-address-map x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/address_maps/{address_map_id}/zones/{zone_id} method: put operationId: ip-address-management-address-maps-add-a-zone-membership-to-an-address-map x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/loa_documents method: post operationId: ip-address-management-prefixes-upload-loa-document x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/loa_documents/{loa_document_id}/download method: get operationId: ip-address-management-prefixes-download-loa-document x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/prefixes method: get operationId: ip-address-management-prefixes-list-prefixes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/prefixes method: post operationId: ip-address-management-prefixes-add-prefix x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/prefixes/{prefix_id} method: delete operationId: ip-address-management-prefixes-delete-prefix x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/prefixes/{prefix_id} method: get operationId: ip-address-management-prefixes-prefix-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/prefixes/{prefix_id} method: patch operationId: ip-address-management-prefixes-update-prefix-description x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/prefixes/{prefix_id}/bgp/prefixes method: get operationId: ip-address-management-prefixes-list-bgp-prefixes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/prefixes/{prefix_id}/bgp/prefixes/{bgp_prefix_id} method: get operationId: ip-address-management-prefixes-fetch-bgp-prefix x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/prefixes/{prefix_id}/bgp/prefixes/{bgp_prefix_id} method: patch operationId: ip-address-management-prefixes-update-bgp-prefix x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/prefixes/{prefix_id}/bgp/status method: get operationId: ip-address-management-dynamic-advertisement-get-advertisement-status x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/prefixes/{prefix_id}/bgp/status method: patch operationId: ip-address-management-dynamic-advertisement-update-prefix-dynamic-advertisement-status x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/prefixes/{prefix_id}/bindings method: get operationId: ip-address-management-service-bindings-list-service-bindings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/prefixes/{prefix_id}/bindings method: post operationId: ip-address-management-service-bindings-create-service-binding x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/prefixes/{prefix_id}/bindings/{binding_id} method: delete operationId: ip-address-management-service-bindings-delete-service-binding x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/prefixes/{prefix_id}/bindings/{binding_id} method: get operationId: ip-address-management-service-bindings-get-service-binding x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/prefixes/{prefix_id}/delegations method: get operationId: ip-address-management-prefix-delegation-list-prefix-delegations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/prefixes/{prefix_id}/delegations method: post operationId: ip-address-management-prefix-delegation-create-prefix-delegation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/prefixes/{prefix_id}/delegations/{delegation_id} method: delete operationId: ip-address-management-prefix-delegation-delete-prefix-delegation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/addressing/regional_hostnames/regions method: get operationId: dls-account-regional-hostnames-account-list-regions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/addressing/services method: get operationId: ip-address-management-service-bindings-list-services x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/ai-gateway/gateways method: get operationId: aig-config-list-gateway x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/ai-gateway/gateways method: post operationId: aig-config-create-gateway x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai-gateway/gateways/{gateway_id}/logs method: get operationId: aig-config-list-gateway-logs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/ai-gateway/gateways/{id} method: delete operationId: aig-config-delete-gateway x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai-gateway/gateways/{id} method: get operationId: aig-config-fetch-gateway x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/ai-gateway/gateways/{id} method: put operationId: aig-config-update-gateway x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/authors/search method: get operationId: workers-ai-search-author x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/ai/finetunes method: get operationId: workers-ai-list-finetunes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/ai/finetunes method: post operationId: workers-ai-create-finetune x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/finetunes/{finetune_id}/finetune-assets method: post operationId: workers-ai-upload-finetune-asset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/finetunes/public method: get operationId: workers-ai-list-public-finetunes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/ai/models/schema method: get operationId: workers-ai-get-model-schema x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/ai/models/search method: get operationId: workers-ai-search-model x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/ai/run/@cf/baai/bge-base-en-v1.5 method: post operationId: workers-ai-post-run-cf-baai-bge-base-en-v1-5 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/baai/bge-large-en-v1.5 method: post operationId: workers-ai-post-run-cf-baai-bge-large-en-v1-5 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/baai/bge-small-en-v1.5 method: post operationId: workers-ai-post-run-cf-baai-bge-small-en-v1-5 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/bytedance/stable-diffusion-xl-lightning method: post operationId: workers-ai-post-run-cf-bytedance-stable-diffusion-xl-lightning x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/deepseek-ai/deepseek-math-7b-instruct method: post operationId: workers-ai-post-run-cf-deepseek-ai-deepseek-math-7b-instruct x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/defog/sqlcoder-7b-2 method: post operationId: workers-ai-post-run-cf-defog-sqlcoder-7b-2 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/facebook/bart-large-cnn method: post operationId: workers-ai-post-run-cf-facebook-bart-large-cnn x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/facebook/detr-resnet-50 method: post operationId: workers-ai-post-run-cf-facebook-detr-resnet-50 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/fblgit/una-cybertron-7b-v2-bf16 method: post operationId: workers-ai-post-run-cf-fblgit-una-cybertron-7b-v2-bf16 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/google/gemma-2b-it-lora method: post operationId: workers-ai-post-run-cf-google-gemma-2b-it-lora x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/google/gemma-7b-it-lora method: post operationId: workers-ai-post-run-cf-google-gemma-7b-it-lora x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/huggingface/distilbert-sst-2-int8 method: post operationId: workers-ai-post-run-cf-huggingface-distilbert-sst-2-int8 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/lykon/dreamshaper-8-lcm method: post operationId: workers-ai-post-run-cf-lykon-dreamshaper-8-lcm x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/meta-llama/llama-2-7b-chat-hf-lora method: post operationId: workers-ai-post-run-cf-meta-llama-llama-2-7b-chat-hf-lora x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/meta/llama-2-7b-chat-fp16 method: post operationId: workers-ai-post-run-cf-meta-llama-2-7b-chat-fp16 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/meta/llama-3-8b-instruct method: post operationId: workers-ai-post-run-cf-meta-llama-3-8b-instruct x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/meta/llama-3-8b-instruct-awq method: post operationId: workers-ai-post-run-cf-meta-llama-3-8b-instruct-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/meta/llama-3.1-8b-instruct method: post operationId: workers-ai-post-run-cf-meta-llama-3-1-8b-instruct x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/meta/llama-3.1-8b-instruct-awq method: post operationId: workers-ai-post-run-cf-meta-llama-3-1-8b-instruct-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/meta/llama-3.1-8b-instruct-fp8 method: post operationId: workers-ai-post-run-cf-meta-llama-3-1-8b-instruct-fp8 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/meta/m2m100-1.2b method: post operationId: workers-ai-post-run-cf-meta-m2m100-1-2b x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/microsoft/phi-2 method: post operationId: workers-ai-post-run-cf-microsoft-phi-2 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/microsoft/resnet-50 method: post operationId: workers-ai-post-run-cf-microsoft-resnet-50 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/mistral/mistral-7b-instruct-v0.2-lora method: post operationId: workers-ai-post-run-cf-mistral-mistral-7b-instruct-v0-2-lora x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/openai/whisper method: post operationId: workers-ai-post-run-cf-openai-whisper x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/openai/whisper-tiny-en method: post operationId: workers-ai-post-run-cf-openai-whisper-tiny-en x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/openchat/openchat-3.5-0106 method: post operationId: workers-ai-post-run-cf-openchat-openchat-3-5-0106 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/qwen/qwen1.5-0.5b-chat method: post operationId: workers-ai-post-run-cf-qwen-qwen1-5-0-5b-chat x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/qwen/qwen1.5-1.8b-chat method: post operationId: workers-ai-post-run-cf-qwen-qwen1-5-1-8b-chat x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/qwen/qwen1.5-7b-chat-awq method: post operationId: workers-ai-post-run-cf-qwen-qwen1-5-7b-chat-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/qwen/qwen1.5-14b-chat-awq method: post operationId: workers-ai-post-run-cf-qwen-qwen1-5-14b-chat-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/runwayml/stable-diffusion-v1-5-img2img method: post operationId: workers-ai-post-run-cf-runwayml-stable-diffusion-v1-5-img2img x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/runwayml/stable-diffusion-v1-5-inpainting method: post operationId: workers-ai-post-run-cf-runwayml-stable-diffusion-v1-5-inpainting x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/stabilityai/stable-diffusion-xl-base-1.0 method: post operationId: workers-ai-post-run-cf-stabilityai-stable-diffusion-xl-base-1-0 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/thebloke/discolm-german-7b-v1-awq method: post operationId: workers-ai-post-run-cf-thebloke-discolm-german-7b-v1-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/tiiuae/falcon-7b-instruct method: post operationId: workers-ai-post-run-cf-tiiuae-falcon-7b-instruct x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@cf/tinyllama/tinyllama-1.1b-chat-v1.0 method: post operationId: workers-ai-post-run-cf-tinyllama-tinyllama-1-1b-chat-v1-0 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@hf/meta-llama/meta-llama-3-8b-instruct method: post operationId: workers-ai-post-run-hf-meta-llama-meta-llama-3-8b-instruct x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@hf/mistral/mistral-7b-instruct-v0.2 method: post operationId: workers-ai-post-run-hf-mistral-mistral-7b-instruct-v0-2 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@hf/nexusflow/starling-lm-7b-beta method: post operationId: workers-ai-post-run-hf-nexusflow-starling-lm-7b-beta x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@hf/nousresearch/hermes-2-pro-mistral-7b method: post operationId: workers-ai-post-run-hf-nousresearch-hermes-2-pro-mistral-7b x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@hf/thebloke/deepseek-coder-6.7b-base-awq method: post operationId: workers-ai-post-run-hf-thebloke-deepseek-coder-6-7b-base-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@hf/thebloke/deepseek-coder-6.7b-instruct-awq method: post operationId: workers-ai-post-run-hf-thebloke-deepseek-coder-6-7b-instruct-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@hf/thebloke/llama-2-13b-chat-awq method: post operationId: workers-ai-post-run-hf-thebloke-llama-2-13b-chat-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@hf/thebloke/llamaguard-7b-awq method: post operationId: workers-ai-post-run-hf-thebloke-llamaguard-7b-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@hf/thebloke/mistral-7b-instruct-v0.1-awq method: post operationId: workers-ai-post-run-hf-thebloke-mistral-7b-instruct-v0-1-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@hf/thebloke/neural-chat-7b-v3-1-awq method: post operationId: workers-ai-post-run-hf-thebloke-neural-chat-7b-v3-1-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@hf/thebloke/openhermes-2.5-mistral-7b-awq method: post operationId: workers-ai-post-run-hf-thebloke-openhermes-2-5-mistral-7b-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/@hf/thebloke/zephyr-7b-beta-awq method: post operationId: workers-ai-post-run-hf-thebloke-zephyr-7b-beta-awq x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/run/{model_name} method: post operationId: workers-ai-post-run-model x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/ai/tasks/search method: get operationId: workers-ai-search-task x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/alerting/v3/available_alerts method: get operationId: notification-alert-types-get-alert-types x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/alerting/v3/destinations/eligible method: get operationId: notification-mechanism-eligibility-get-delivery-mechanism-eligibility x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/alerting/v3/destinations/pagerduty method: delete operationId: notification-destinations-with-pager-duty-delete-pager-duty-services x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/alerting/v3/destinations/pagerduty method: get operationId: notification-destinations-with-pager-duty-list-pager-duty-services x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/alerting/v3/destinations/pagerduty/connect method: post operationId: notification-destinations-with-pager-duty-connect-pager-duty x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/alerting/v3/destinations/pagerduty/connect/{token_id} method: get operationId: notification-destinations-with-pager-duty-connect-pager-duty-token x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/alerting/v3/destinations/webhooks method: get operationId: notification-webhooks-list-webhooks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/alerting/v3/destinations/webhooks method: post operationId: notification-webhooks-create-a-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/alerting/v3/destinations/webhooks/{webhook_id} method: delete operationId: notification-webhooks-delete-a-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/alerting/v3/destinations/webhooks/{webhook_id} method: get operationId: notification-webhooks-get-a-webhook x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/alerting/v3/destinations/webhooks/{webhook_id} method: put operationId: notification-webhooks-update-a-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/alerting/v3/history method: get operationId: notification-history-list-history x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/alerting/v3/policies method: get operationId: notification-policies-list-notification-policies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/alerting/v3/policies method: post operationId: notification-policies-create-a-notification-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/alerting/v3/policies/{policy_id} method: delete operationId: notification-policies-delete-a-notification-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/alerting/v3/policies/{policy_id} method: get operationId: notification-policies-get-a-notification-policy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/alerting/v3/policies/{policy_id} method: put operationId: notification-policies-update-a-notification-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/audit_logs method: get operationId: audit-logs-get-account-audit-logs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/billing/profile method: get operationId: account-billing-profile-(-deprecated)-billing-profile-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/botnet_feed/asn/{asn_id}/day_report method: get operationId: botnet-threat-feed-get-day-report x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/botnet_feed/asn/{asn_id}/full_report method: get operationId: botnet-threat-feed-get-full-report x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/botnet_feed/configs/asn method: get operationId: botnet-threat-feed-list-asn x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/botnet_feed/configs/asn/{asn_id} method: delete operationId: botnet-threat-feed-delete-asn x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/brand-protection/submit method: post operationId: phishing-url-scanner-submit-suspicious-url-for-scanning x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/brand-protection/url-info method: get operationId: phishing-url-information-get-results-for-a-url-scan x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/calls/apps method: get operationId: calls-apps-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/calls/apps method: post operationId: calls-apps-create-a-new-app x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/calls/apps/{app_id} method: delete operationId: calls-apps-delete-app x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/calls/apps/{app_id} method: get operationId: calls-apps-retrieve-app-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/calls/apps/{app_id} method: put operationId: calls-apps-update-app-details x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/calls/turn_keys method: get operationId: calls-turn-key-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/calls/turn_keys method: post operationId: calls-turn-key-create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/calls/turn_keys/{key_id} method: delete operationId: calls-delete-turn-key x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/calls/turn_keys/{key_id} method: get operationId: calls-retrieve-turn-key-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/calls/turn_keys/{key_id} method: put operationId: calls-update-turn-key x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/cfd_tunnel method: get operationId: cloudflare-tunnel-list-cloudflare-tunnels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/cfd_tunnel method: post operationId: cloudflare-tunnel-create-a-cloudflare-tunnel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/cfd_tunnel/{tunnel_id} method: delete operationId: cloudflare-tunnel-delete-a-cloudflare-tunnel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/cfd_tunnel/{tunnel_id} method: get operationId: cloudflare-tunnel-get-a-cloudflare-tunnel x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/cfd_tunnel/{tunnel_id} method: patch operationId: cloudflare-tunnel-update-a-cloudflare-tunnel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/cfd_tunnel/{tunnel_id}/configurations method: get operationId: cloudflare-tunnel-configuration-get-configuration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/cfd_tunnel/{tunnel_id}/configurations method: put operationId: cloudflare-tunnel-configuration-put-configuration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/cfd_tunnel/{tunnel_id}/connections method: delete operationId: cloudflare-tunnel-clean-up-cloudflare-tunnel-connections x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/cfd_tunnel/{tunnel_id}/connections method: get operationId: cloudflare-tunnel-list-cloudflare-tunnel-connections x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/cfd_tunnel/{tunnel_id}/connectors/{connector_id} method: get operationId: cloudflare-tunnel-get-cloudflare-tunnel-connector x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/cfd_tunnel/{tunnel_id}/management method: post operationId: cloudflare-tunnel-get-a-cloudflare-tunnel-management-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/cfd_tunnel/{tunnel_id}/token method: get operationId: cloudflare-tunnel-get-a-cloudflare-tunnel-token x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/challenges/widgets method: get operationId: accounts-turnstile-widgets-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/challenges/widgets method: post operationId: accounts-turnstile-widget-create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/challenges/widgets/{sitekey} method: delete operationId: accounts-turnstile-widget-delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/challenges/widgets/{sitekey} method: get operationId: accounts-turnstile-widget-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/challenges/widgets/{sitekey} method: put operationId: accounts-turnstile-widget-update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/challenges/widgets/{sitekey}/rotate_secret method: post operationId: accounts-turnstile-widget-rotate-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/custom_ns method: get operationId: account-level-custom-nameservers-list-account-custom-nameservers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/custom_ns method: post operationId: account-level-custom-nameservers-add-account-custom-nameserver x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/custom_ns/{custom_ns_id} method: delete operationId: account-level-custom-nameservers-delete-account-custom-nameserver x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/custom_ns/availability method: get operationId: account-level-custom-nameservers-get-eligible-zones-for-account-custom-nameservers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/d1/database method: get operationId: cloudflare-d1-list-databases x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/d1/database method: post operationId: cloudflare-d1-create-database x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/d1/database/{database_id} method: delete operationId: cloudflare-d1-delete-database x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/d1/database/{database_id} method: get operationId: cloudflare-d1-get-database x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/d1/database/{database_id}/export method: post operationId: cloudflare-d1-export-database x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/d1/database/{database_id}/import method: post operationId: cloudflare-d1-import-database x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/d1/database/{database_id}/query method: post operationId: cloudflare-d1-query-database x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/d1/database/{database_id}/raw method: post operationId: cloudflare-d1-raw-database-query x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices method: get operationId: devices-list-devices x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/{device_id} method: get operationId: devices-device-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/{device_id}/override_codes method: get operationId: devices-list-admin-override-code-for-device x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/dex_tests method: get operationId: device-dex-test-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/dex_tests method: post operationId: device-dex-test-create-device-dex-test x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/dex_tests/{dex_test_id} method: delete operationId: device-dex-test-delete-device-dex-test x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/dex_tests/{dex_test_id} method: get operationId: device-dex-test-get-device-dex-test x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/dex_tests/{dex_test_id} method: put operationId: device-dex-test-update-device-dex-test x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/networks method: get operationId: device-managed-networks-list-device-managed-networks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/networks method: post operationId: device-managed-networks-create-device-managed-network x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/networks/{network_id} method: delete operationId: device-managed-networks-delete-device-managed-network x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/networks/{network_id} method: get operationId: device-managed-networks-device-managed-network-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/networks/{network_id} method: put operationId: device-managed-networks-update-device-managed-network x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/policies method: get operationId: devices-list-device-settings-policies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/policy method: get operationId: devices-get-default-device-settings-policy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/policy method: patch operationId: devices-update-default-device-settings-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/policy method: post operationId: devices-create-device-settings-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/policy/{policy_id} method: delete operationId: devices-delete-device-settings-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/policy/{policy_id} method: get operationId: devices-get-device-settings-policy-by-id x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/policy/{policy_id} method: patch operationId: devices-update-device-settings-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/policy/{policy_id}/exclude method: get operationId: devices-get-split-tunnel-exclude-list-for-a-device-settings-policy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/policy/{policy_id}/exclude method: put operationId: devices-set-split-tunnel-exclude-list-for-a-device-settings-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/policy/{policy_id}/fallback_domains method: get operationId: devices-get-local-domain-fallback-list-for-a-device-settings-policy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/policy/{policy_id}/fallback_domains method: put operationId: devices-set-local-domain-fallback-list-for-a-device-settings-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/policy/{policy_id}/include method: get operationId: devices-get-split-tunnel-include-list-for-a-device-settings-policy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/policy/{policy_id}/include method: put operationId: devices-set-split-tunnel-include-list-for-a-device-settings-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/policy/exclude method: get operationId: devices-get-split-tunnel-exclude-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/policy/exclude method: put operationId: devices-set-split-tunnel-exclude-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/policy/fallback_domains method: get operationId: devices-get-local-domain-fallback-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/policy/fallback_domains method: put operationId: devices-set-local-domain-fallback-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/policy/include method: get operationId: devices-get-split-tunnel-include-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/policy/include method: put operationId: devices-set-split-tunnel-include-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/posture method: get operationId: device-posture-rules-list-device-posture-rules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/posture method: post operationId: device-posture-rules-create-device-posture-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/posture/{rule_id} method: delete operationId: device-posture-rules-delete-device-posture-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/posture/{rule_id} method: get operationId: device-posture-rules-device-posture-rules-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/posture/{rule_id} method: put operationId: device-posture-rules-update-device-posture-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/posture/integration method: get operationId: device-posture-integrations-list-device-posture-integrations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/posture/integration method: post operationId: device-posture-integrations-create-device-posture-integration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/posture/integration/{integration_id} method: delete operationId: device-posture-integrations-delete-device-posture-integration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/posture/integration/{integration_id} method: get operationId: device-posture-integrations-device-posture-integration-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/posture/integration/{integration_id} method: patch operationId: device-posture-integrations-update-device-posture-integration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/revoke method: post operationId: devices-revoke-devices x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/devices/settings method: get operationId: zero-trust-accounts-get-device-settings-for-zero-trust-account x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/devices/settings method: patch operationId: zero-trust-accounts-patch-device-settings-for-the-zero-trust-account x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/settings method: put operationId: zero-trust-accounts-update-device-settings-for-the-zero-trust-account x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/devices/unrevoke method: post operationId: devices-unrevoke-devices x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/dex/colos method: get operationId: dex-endpoints-list-colos x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dex/fleet-status/devices method: get operationId: dex-fleet-status-devices x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dex/fleet-status/live method: get operationId: dex-fleet-status-live x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dex/fleet-status/over-time method: get operationId: dex-fleet-status-over-time x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dex/http-tests/{test_id} method: get operationId: dex-endpoints-http-test-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dex/http-tests/{test_id}/percentiles method: get operationId: dex-endpoints-http-test-percentiles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dex/tests/overview method: get operationId: dex-endpoints-list-tests-overview x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dex/tests/unique-devices method: get operationId: dex-endpoints-tests-unique-devices x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dex/traceroute-test-results/{test_result_id}/network-path method: get operationId: dex-endpoints-traceroute-test-result-network-path x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dex/traceroute-tests/{test_id} method: get operationId: dex-endpoints-traceroute-test-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dex/traceroute-tests/{test_id}/network-path method: get operationId: dex-endpoints-traceroute-test-network-path x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dex/traceroute-tests/{test_id}/percentiles method: get operationId: dex-endpoints-traceroute-test-percentiles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/diagnostics/traceroute method: post operationId: diagnostics-traceroute x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/datasets method: get operationId: dlp-datasets-read-all x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dlp/datasets method: post operationId: dlp-datasets-create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/datasets/{dataset_id} method: delete operationId: dlp-datasets-delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/datasets/{dataset_id} method: get operationId: dlp-datasets-read x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dlp/datasets/{dataset_id} method: put operationId: dlp-datasets-update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/datasets/{dataset_id}/upload method: post operationId: dlp-datasets-create-version x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/datasets/{dataset_id}/upload/{version} method: post operationId: dlp-datasets-upload-version x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/datasets/{dataset_id}/versions/{version} method: post operationId: dlp-datasets-define-columns x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/datasets/{dataset_id}/versions/{version}/entries/{entry_id} method: post operationId: dlp-datasets-upload-dataset-column x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/limits method: get operationId: dlp-limits-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dlp/patterns/validate method: post operationId: dlp-pattern-validate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/payload_log method: get operationId: dlp-payload-log-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dlp/payload_log method: put operationId: dlp-payload-log-put x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/profiles method: get operationId: dlp-profiles-list-all-profiles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dlp/profiles/{profile_id} method: get operationId: dlp-profiles-get-dlp-profile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dlp/profiles/custom method: post operationId: dlp-profiles-create-custom-profiles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/profiles/custom/{profile_id} method: delete operationId: dlp-profiles-delete-custom-profile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/profiles/custom/{profile_id} method: get operationId: dlp-profiles-get-custom-profile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dlp/profiles/custom/{profile_id} method: put operationId: dlp-profiles-update-custom-profile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dlp/profiles/predefined/{profile_id} method: get operationId: dlp-profiles-get-predefined-profile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dlp/profiles/predefined/{profile_id} method: put operationId: dlp-profiles-update-predefined-profile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dns_firewall method: get operationId: dns-firewall-list-dns-firewall-clusters x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dns_firewall method: post operationId: dns-firewall-create-dns-firewall-cluster x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dns_firewall/{dns_firewall_id} method: delete operationId: dns-firewall-delete-dns-firewall-cluster x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dns_firewall/{dns_firewall_id} method: get operationId: dns-firewall-dns-firewall-cluster-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dns_firewall/{dns_firewall_id} method: patch operationId: dns-firewall-update-dns-firewall-cluster x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dns_firewall/{dns_firewall_id}/dns_analytics/report method: get operationId: dns-firewall-analytics-table x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dns_firewall/{dns_firewall_id}/dns_analytics/report/bytime method: get operationId: dns-firewall-analytics-by-time x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dns_firewall/{dns_firewall_id}/reverse_dns method: get operationId: dns-firewall-show-dns-firewall-cluster-reverse-dns x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dns_firewall/{dns_firewall_id}/reverse_dns method: patch operationId: dns-firewall-update-dns-firewall-cluster-reverse-dns x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/dns_settings method: get operationId: dns-settings-for-an-account-list-dns-settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/dns_settings method: patch operationId: dns-settings-for-an-account-update-dns-settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/investigate method: get operationId: email_security_investigate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/investigate/{postfix_id} method: get operationId: email_security_get_message x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/investigate/{postfix_id}/detections method: get operationId: email_security_get_message_detections x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/investigate/{postfix_id}/preview method: get operationId: email_security_get_message_preview x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/investigate/{postfix_id}/raw method: get operationId: email_security_get_message_raw x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/investigate/{postfix_id}/trace method: get operationId: email_security_get_message_trace x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/phishguard/reports method: get operationId: email_security_get_phishguard_reports x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/settings/allow_patterns method: delete operationId: email_security_delete_allow_patterns x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/allow_patterns method: get operationId: email_security_list_allow_patterns x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/settings/allow_patterns method: post operationId: email_security_create_allow_pattern x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/allow_patterns/{pattern_id} method: delete operationId: email_security_delete_allow_pattern x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/allow_patterns/{pattern_id} method: get operationId: email_security_get_allow_pattern x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/settings/allow_patterns/{pattern_id} method: patch operationId: email_security_update_allow_pattern x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/block_senders method: delete operationId: email_security_delete_blocked_senders x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/block_senders method: get operationId: email_security_list_blocked_senders x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/settings/block_senders method: post operationId: email_security_create_blocked_sender x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/block_senders/{pattern_id} method: delete operationId: email_security_delete_blocked_sender x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/block_senders/{pattern_id} method: get operationId: email_security_get_blocked_sender x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/settings/block_senders/{pattern_id} method: patch operationId: email_security_update_blocked_sender x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/domains method: delete operationId: email_security_delete_domains x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/domains method: get operationId: email_security_list_domains x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/settings/domains/{domain_id} method: delete operationId: email_security_delete_domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/domains/{domain_id} method: patch operationId: email_security_update_domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/impersonation_registry method: delete operationId: email_security_delete_display_names x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/impersonation_registry method: get operationId: email_security_list_display_names x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/settings/impersonation_registry method: post operationId: email_security_create_display_name x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/impersonation_registry/{display_name_id} method: delete operationId: email_security_delete_display_name x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/impersonation_registry/{display_name_id} method: get operationId: email_security_get_display_name x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/settings/impersonation_registry/{display_name_id} method: patch operationId: email_security_update_display_name x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/trusted_domains method: delete operationId: email_security_delete_trusted_domains x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/trusted_domains method: get operationId: email_security_list_trusted_domains x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/settings/trusted_domains method: post operationId: email_security_create_trusted_domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/trusted_domains/{pattern_id} method: delete operationId: email_security_delete_trusted_domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email-security/settings/trusted_domains/{pattern_id} method: get operationId: email_security_get_trusted_domain x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email-security/settings/trusted_domains/{pattern_id} method: patch operationId: email_security_update_trusted_domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email/routing/addresses method: get operationId: email-routing-destination-addresses-list-destination-addresses x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/email/routing/addresses method: post operationId: email-routing-destination-addresses-create-a-destination-address x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email/routing/addresses/{destination_address_identifier} method: delete operationId: email-routing-destination-addresses-delete-destination-address x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/email/routing/addresses/{destination_address_identifier} method: get operationId: email-routing-destination-addresses-get-a-destination-address x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/event_notifications/r2/{bucket_name}/configuration method: get operationId: event-notification-get-r2-bucket-configs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/event_notifications/r2/{bucket_name}/configuration/queues/{queue_id} method: delete operationId: event-notification-delete-queue-config x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/event_notifications/r2/{bucket_name}/configuration/queues/{queue_id} method: put operationId: event-notification-create-queue-config x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway method: get operationId: zero-trust-accounts-get-zero-trust-account-information x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway method: post operationId: zero-trust-accounts-create-zero-trust-account x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/app_types method: get operationId: zero-trust-gateway-application-and-application-type-mappings-list-application-and-application-type-mappings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/audit_ssh_settings method: get operationId: zero-trust-get-audit-ssh-settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/audit_ssh_settings method: put operationId: zero-trust-update-audit-ssh-settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/categories method: get operationId: zero-trust-gateway-categories-list-categories x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/certificates method: get operationId: zero-trust-certificates-list-zero-trust-certificates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/certificates method: post operationId: zero-trust-certificates-create-zero-trust-certificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/certificates/{certificate_id} method: delete operationId: zero-trust-certificates-delete-zero-trust-certificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/certificates/{certificate_id} method: get operationId: zero-trust-certificates-zero-trust-certificate-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/certificates/{certificate_id}/activate method: post operationId: zero-trust-certificates-activate-zero-trust-certificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/certificates/{certificate_id}/deactivate method: post operationId: zero-trust-certificates-deactivate-zero-trust-certificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/configuration method: get operationId: zero-trust-accounts-get-zero-trust-account-configuration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/configuration method: patch operationId: zero-trust-accounts-patch-zero-trust-account-configuration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/configuration method: put operationId: zero-trust-accounts-update-zero-trust-account-configuration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/configuration/custom_certificate method: get operationId: zero-trust-accounts-get-zero-trust-certificate-configuration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/lists method: get operationId: zero-trust-lists-list-zero-trust-lists x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/lists method: post operationId: zero-trust-lists-create-zero-trust-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/lists/{list_id} method: delete operationId: zero-trust-lists-delete-zero-trust-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/lists/{list_id} method: get operationId: zero-trust-lists-zero-trust-list-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/lists/{list_id} method: patch operationId: zero-trust-lists-patch-zero-trust-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/lists/{list_id} method: put operationId: zero-trust-lists-update-zero-trust-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/lists/{list_id}/items method: get operationId: zero-trust-lists-zero-trust-list-items x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/locations method: get operationId: zero-trust-gateway-locations-list-zero-trust-gateway-locations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/locations method: post operationId: zero-trust-gateway-locations-create-zero-trust-gateway-location x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/locations/{location_id} method: delete operationId: zero-trust-gateway-locations-delete-zero-trust-gateway-location x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/locations/{location_id} method: get operationId: zero-trust-gateway-locations-zero-trust-gateway-location-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/locations/{location_id} method: put operationId: zero-trust-gateway-locations-update-zero-trust-gateway-location x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/logging method: get operationId: zero-trust-accounts-get-logging-settings-for-the-zero-trust-account x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/logging method: put operationId: zero-trust-accounts-update-logging-settings-for-the-zero-trust-account x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/proxy_endpoints method: get operationId: zero-trust-gateway-proxy-endpoints-list-proxy-endpoints x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/proxy_endpoints method: post operationId: zero-trust-gateway-proxy-endpoints-create-proxy-endpoint x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/proxy_endpoints/{proxy_endpoint_id} method: delete operationId: zero-trust-gateway-proxy-endpoints-delete-proxy-endpoint x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/proxy_endpoints/{proxy_endpoint_id} method: get operationId: zero-trust-gateway-proxy-endpoints-proxy-endpoint-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/proxy_endpoints/{proxy_endpoint_id} method: patch operationId: zero-trust-gateway-proxy-endpoints-update-proxy-endpoint x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/rules method: get operationId: zero-trust-gateway-rules-list-zero-trust-gateway-rules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/rules method: post operationId: zero-trust-gateway-rules-create-zero-trust-gateway-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/rules/{rule_id} method: delete operationId: zero-trust-gateway-rules-delete-zero-trust-gateway-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/gateway/rules/{rule_id} method: get operationId: zero-trust-gateway-rules-zero-trust-gateway-rule-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/gateway/rules/{rule_id} method: put operationId: zero-trust-gateway-rules-update-zero-trust-gateway-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/hyperdrive/configs method: get operationId: list-hyperdrive x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/hyperdrive/configs method: post operationId: create-hyperdrive x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/hyperdrive/configs/{hyperdrive_id} method: delete operationId: delete-hyperdrive x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/hyperdrive/configs/{hyperdrive_id} method: get operationId: get-hyperdrive x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/hyperdrive/configs/{hyperdrive_id} method: patch operationId: patch-hyperdrive x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/hyperdrive/configs/{hyperdrive_id} method: put operationId: update-hyperdrive x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/iam/permission_groups method: get operationId: account-permission-group-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/iam/permission_groups/{permission_group_id} method: get operationId: account-permission-group-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/iam/resource_groups method: get operationId: account-resource-group-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/iam/resource_groups method: post operationId: account-resource-group-create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/iam/resource_groups/{resource_group_id} method: delete operationId: account-resource-group-delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/iam/resource_groups/{resource_group_id} method: get operationId: account-resource-group-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/iam/resource_groups/{resource_group_id} method: put operationId: account-resource-group-update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/images/v1 method: get operationId: cloudflare-images-list-images x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/images/v1 method: post operationId: cloudflare-images-upload-an-image-via-url x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/images/v1/{image_id} method: delete operationId: cloudflare-images-delete-image x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/images/v1/{image_id} method: get operationId: cloudflare-images-image-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/images/v1/{image_id} method: patch operationId: cloudflare-images-update-image x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/images/v1/{image_id}/blob method: get operationId: cloudflare-images-base-image x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/images/v1/keys method: get operationId: cloudflare-images-keys-list-signing-keys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/images/v1/keys/{signing_key_name} method: delete operationId: cloudflare-images-keys-delete-signing-key x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/images/v1/keys/{signing_key_name} method: put operationId: cloudflare-images-keys-add-signing-key x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/images/v1/stats method: get operationId: cloudflare-images-images-usage-statistics x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/images/v1/variants method: get operationId: cloudflare-images-variants-list-variants x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/images/v1/variants method: post operationId: cloudflare-images-variants-create-a-variant x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/images/v1/variants/{variant_id} method: delete operationId: cloudflare-images-variants-delete-a-variant x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/images/v1/variants/{variant_id} method: get operationId: cloudflare-images-variants-variant-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/images/v1/variants/{variant_id} method: patch operationId: cloudflare-images-variants-update-a-variant x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/images/v2 method: get operationId: cloudflare-images-list-images-v2 x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/images/v2/direct_upload method: post operationId: cloudflare-images-create-authenticated-direct-upload-url-v-2 x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/infrastructure/targets method: get operationId: infra-targets-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/infrastructure/targets method: post operationId: infra-targets-post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/infrastructure/targets/{target_id} method: delete operationId: infra-targets-delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/infrastructure/targets/{target_id} method: get operationId: infra-targets-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/infrastructure/targets/{target_id} method: put operationId: infra-targets-put x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/intel/asn/{asn} method: get operationId: asn-intelligence-get-asn-overview x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/asn/{asn}/subnets method: get operationId: asn-intelligence-get-asn-subnets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/attack-surface-report/{issue_id}/dismiss method: put operationId: archive-security-center-insight x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/intel/attack-surface-report/issue-types method: get operationId: get-security-center-issue-types x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/attack-surface-report/issues method: get operationId: get-security-center-issues x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/attack-surface-report/issues/class method: get operationId: get-security-center-issue-counts-by-class x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/attack-surface-report/issues/severity method: get operationId: get-security-center-issue-counts-by-severity x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/attack-surface-report/issues/type method: get operationId: get-security-center-issue-counts-by-type x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/dns method: get operationId: passive-dns-by-ip-get-passive-dns-by-ip x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/domain method: get operationId: domain-intelligence-get-domain-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/domain-history method: get operationId: domain-history-get-domain-history x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/domain/bulk method: get operationId: domain-intelligence-get-multiple-domain-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/indicator-feeds method: get operationId: custom-indicator-feeds-get-indicator-feeds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/indicator-feeds method: post operationId: custom-indicator-feeds-create-indicator-feeds x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/intel/indicator-feeds/{feed_id} method: get operationId: custom-indicator-feeds-get-indicator-feed-metadata x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/indicator-feeds/{feed_id} method: put operationId: custom-indicator-feeds-update-indicator-feed-metadata x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/intel/indicator-feeds/{feed_id}/data method: get operationId: custom-indicator-feeds-get-indicator-feed-data x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/indicator-feeds/{feed_id}/snapshot method: put operationId: custom-indicator-feeds-update-indicator-feed-data x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/intel/indicator-feeds/permissions/add method: put operationId: custom-indicator-feeds-add-permission x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/intel/indicator-feeds/permissions/remove method: put operationId: custom-indicator-feeds-remove-permission x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/intel/indicator-feeds/permissions/view method: get operationId: custom-indicator-feeds-view-permissions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/indicator_feeds/{feed_id}/download method: get operationId: custom-indicator-feeds-download-indicator-feed-data x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/ip method: get operationId: ip-intelligence-get-ip-overview x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/ip-list method: get operationId: ip-list-get-ip-lists x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/miscategorization method: post operationId: miscategorization-create-miscategorization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/intel/sinkholes method: get operationId: sinkhole-config-get-sinkholes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/intel/whois method: get operationId: whois-record-get-whois-record x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/load_balancers/monitors method: get operationId: account-load-balancer-monitors-list-monitors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/load_balancers/monitors method: post operationId: account-load-balancer-monitors-create-monitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/load_balancers/monitors/{monitor_id} method: delete operationId: account-load-balancer-monitors-delete-monitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/load_balancers/monitors/{monitor_id} method: get operationId: account-load-balancer-monitors-monitor-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/load_balancers/monitors/{monitor_id} method: patch operationId: account-load-balancer-monitors-patch-monitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/load_balancers/monitors/{monitor_id} method: put operationId: account-load-balancer-monitors-update-monitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/load_balancers/monitors/{monitor_id}/preview method: post operationId: account-load-balancer-monitors-preview-monitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/load_balancers/monitors/{monitor_id}/references method: get operationId: account-load-balancer-monitors-list-monitor-references x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/load_balancers/pools method: get operationId: account-load-balancer-pools-list-pools x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/load_balancers/pools method: patch operationId: account-load-balancer-pools-patch-pools x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/load_balancers/pools method: post operationId: account-load-balancer-pools-create-pool x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/load_balancers/pools/{pool_id} method: delete operationId: account-load-balancer-pools-delete-pool x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/load_balancers/pools/{pool_id} method: get operationId: account-load-balancer-pools-pool-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/load_balancers/pools/{pool_id} method: patch operationId: account-load-balancer-pools-patch-pool x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/load_balancers/pools/{pool_id} method: put operationId: account-load-balancer-pools-update-pool x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/load_balancers/pools/{pool_id}/health method: get operationId: account-load-balancer-pools-pool-health-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/load_balancers/pools/{pool_id}/preview method: post operationId: account-load-balancer-pools-preview-pool x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/load_balancers/pools/{pool_id}/references method: get operationId: account-load-balancer-pools-list-pool-references x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/load_balancers/preview/{preview_id} method: get operationId: account-load-balancer-monitors-preview-result x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/load_balancers/regions method: get operationId: load-balancer-regions-list-regions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/load_balancers/regions/{region_id} method: get operationId: load-balancer-regions-get-region x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/load_balancers/search method: get operationId: account-load-balancer-search-search-resources x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/logpush/datasets/{dataset_id}/fields method: get operationId: get-accounts-account_id-logpush-datasets-dataset_id-fields x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/logpush/datasets/{dataset_id}/jobs method: get operationId: get-accounts-account_id-logpush-datasets-dataset_id-jobs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/logpush/jobs method: get operationId: get-accounts-account_id-logpush-jobs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/logpush/jobs method: post operationId: post-accounts-account_id-logpush-jobs x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/logpush/jobs/{job_id} method: delete operationId: delete-accounts-account_id-logpush-jobs-job_id x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/logpush/jobs/{job_id} method: get operationId: get-accounts-account_id-logpush-jobs-job_id x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/logpush/jobs/{job_id} method: put operationId: put-accounts-account_id-logpush-jobs-job_id x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/logpush/ownership method: post operationId: post-accounts-account_id-logpush-ownership x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/logpush/ownership/validate method: post operationId: post-accounts-account_id-logpush-ownership-validate x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/logpush/validate/destination/exists method: post operationId: delete-accounts-account_id-logpush-validate-destination-exists x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/logpush/validate/origin method: post operationId: post-accounts-account_id-logpush-validate-origin x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/logs/control/cmb/config method: delete operationId: delete-accounts-account_id-logs-control-cmb-config x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/logs/control/cmb/config method: get operationId: get-accounts-account_id-logs-control-cmb-config x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/logs/control/cmb/config method: post operationId: post-accounts-account_id-logs-control-cmb-config x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/magic/apps method: get operationId: magic-account-apps-list-apps x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/apps method: post operationId: magic-account-apps-add-app x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/apps/{account_app_id} method: delete operationId: magic-account-apps-delete-app x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/apps/{account_app_id} method: put operationId: magic-account-apps-update-app x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/cf_interconnects method: get operationId: magic-interconnects-list-interconnects x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/cf_interconnects method: put operationId: magic-interconnects-update-multiple-interconnects x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/cf_interconnects/{cf_interconnect_id} method: get operationId: magic-interconnects-list-interconnect-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/cf_interconnects/{cf_interconnect_id} method: put operationId: magic-interconnects-update-interconnect x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/connectors method: get operationId: mconn-connector-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/connectors/{connector_id} method: get operationId: mconn-connector-fetch x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/connectors/{connector_id} method: patch operationId: mconn-connector-update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/connectors/{connector_id} method: put operationId: mconn-connector-replace x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/gre_tunnels method: get operationId: magic-gre-tunnels-list-gre-tunnels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/gre_tunnels method: post operationId: magic-gre-tunnels-create-gre-tunnels x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/gre_tunnels method: put operationId: magic-gre-tunnels-update-multiple-gre-tunnels x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/gre_tunnels/{gre_tunnel_id} method: delete operationId: magic-gre-tunnels-delete-gre-tunnel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/gre_tunnels/{gre_tunnel_id} method: get operationId: magic-gre-tunnels-list-gre-tunnel-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/gre_tunnels/{gre_tunnel_id} method: put operationId: magic-gre-tunnels-update-gre-tunnel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/ipsec_tunnels method: get operationId: magic-ipsec-tunnels-list-ipsec-tunnels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/ipsec_tunnels method: post operationId: magic-ipsec-tunnels-create-ipsec-tunnels x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/ipsec_tunnels method: put operationId: magic-ipsec-tunnels-update-multiple-ipsec-tunnels x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id} method: delete operationId: magic-ipsec-tunnels-delete-ipsec-tunnel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id} method: get operationId: magic-ipsec-tunnels-list-ipsec-tunnel-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id} method: put operationId: magic-ipsec-tunnels-update-ipsec-tunnel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/ipsec_tunnels/{ipsec_tunnel_id}/psk_generate method: post operationId: magic-ipsec-tunnels-generate-pre-shared-key-(-psk)-for-ipsec-tunnels x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/routes method: delete operationId: magic-static-routes-delete-many-routes x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/routes method: get operationId: magic-static-routes-list-routes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/routes method: post operationId: magic-static-routes-create-routes x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/routes method: put operationId: magic-static-routes-update-many-routes x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/routes/{route_id} method: delete operationId: magic-static-routes-delete-route x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/routes/{route_id} method: get operationId: magic-static-routes-route-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/routes/{route_id} method: put operationId: magic-static-routes-update-route x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites method: get operationId: magic-sites-list-sites x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/sites method: post operationId: magic-sites-create-site x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id} method: delete operationId: magic-sites-delete-site x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id} method: get operationId: magic-sites-site-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/sites/{site_id} method: patch operationId: magic-sites-patch-site x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id} method: put operationId: magic-sites-update-site x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/acls method: get operationId: magic-site-acls-list-acls x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/sites/{site_id}/acls method: post operationId: magic-site-acls-create-acl x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/acls/{acl_id} method: delete operationId: magic-site-acls-delete-acl x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/acls/{acl_id} method: get operationId: magic-site-acls-acl-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/sites/{site_id}/acls/{acl_id} method: patch operationId: magic-site-acls-patch-acl x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/acls/{acl_id} method: put operationId: magic-site-acls-update-acl x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/app_configs method: get operationId: magic-site-app-configs-list-app-configs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/sites/{site_id}/app_configs method: post operationId: magic-site-app-configs-add-app-config x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/app_configs/{app_config_id} method: delete operationId: magic-site-app-configs-delete-app-config x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/app_configs/{app_config_id} method: put operationId: magic-site-app-configs-update-app-config x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/lans method: get operationId: magic-site-lans-list-lans x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/sites/{site_id}/lans method: post operationId: magic-site-lans-create-lan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/lans/{lan_id} method: delete operationId: magic-site-lans-delete-lan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/lans/{lan_id} method: get operationId: magic-site-lans-lan-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/sites/{site_id}/lans/{lan_id} method: patch operationId: magic-site-lans-patch-lan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/lans/{lan_id} method: put operationId: magic-site-lans-update-lan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/wans method: get operationId: magic-site-wans-list-wans x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/sites/{site_id}/wans method: post operationId: magic-site-wans-create-wan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/wans/{wan_id} method: delete operationId: magic-site-wans-delete-wan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/wans/{wan_id} method: get operationId: magic-site-wans-wan-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/magic/sites/{site_id}/wans/{wan_id} method: patch operationId: magic-site-wans-patch-wan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/magic/sites/{site_id}/wans/{wan_id} method: put operationId: magic-site-wans-update-wan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/members method: get operationId: account-members-list-members x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/members method: post operationId: account-members-add-member x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/members/{member_id} method: delete operationId: account-members-remove-member x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/members/{member_id} method: get operationId: account-members-member-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/members/{member_id} method: put operationId: account-members-update-member x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/mnm/config method: delete operationId: magic-network-monitoring-configuration-delete-account-configuration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/mnm/config method: get operationId: magic-network-monitoring-configuration-list-account-configuration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/mnm/config method: patch operationId: magic-network-monitoring-configuration-update-account-configuration-fields x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/mnm/config method: post operationId: magic-network-monitoring-configuration-create-account-configuration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/mnm/config method: put operationId: magic-network-monitoring-configuration-update-an-entire-account-configuration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/mnm/config/full method: get operationId: magic-network-monitoring-configuration-list-rules-and-account-configuration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/mnm/rules method: get operationId: magic-network-monitoring-rules-list-rules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/mnm/rules method: post operationId: magic-network-monitoring-rules-create-rules x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/mnm/rules method: put operationId: magic-network-monitoring-rules-update-rules x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/mnm/rules/{rule_id} method: delete operationId: magic-network-monitoring-rules-delete-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/mnm/rules/{rule_id} method: get operationId: magic-network-monitoring-rules-get-rule x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/mnm/rules/{rule_id} method: patch operationId: magic-network-monitoring-rules-update-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/mnm/rules/{rule_id}/advertisement method: patch operationId: magic-network-monitoring-rules-update-advertisement-for-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/mtls_certificates method: get operationId: m-tls-certificate-management-list-m-tls-certificates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/mtls_certificates method: post operationId: m-tls-certificate-management-upload-m-tls-certificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/mtls_certificates/{mtls_certificate_id} method: delete operationId: m-tls-certificate-management-delete-m-tls-certificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/mtls_certificates/{mtls_certificate_id} method: get operationId: m-tls-certificate-management-get-m-tls-certificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/mtls_certificates/{mtls_certificate_id}/associations method: get operationId: m-tls-certificate-management-list-m-tls-certificate-associations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/pages/projects method: get operationId: pages-project-get-projects x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/pages/projects method: post operationId: pages-project-create-project x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pages/projects/{project_name} method: delete operationId: pages-project-delete-project x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pages/projects/{project_name} method: get operationId: pages-project-get-project x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/pages/projects/{project_name} method: patch operationId: pages-project-update-project x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pages/projects/{project_name}/deployments method: get operationId: pages-deployment-get-deployments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/pages/projects/{project_name}/deployments method: post operationId: pages-deployment-create-deployment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pages/projects/{project_name}/deployments/{deployment_id} method: delete operationId: pages-deployment-delete-deployment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pages/projects/{project_name}/deployments/{deployment_id} method: get operationId: pages-deployment-get-deployment-info x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/pages/projects/{project_name}/deployments/{deployment_id}/history/logs method: get operationId: pages-deployment-get-deployment-logs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/pages/projects/{project_name}/deployments/{deployment_id}/retry method: post operationId: pages-deployment-retry-deployment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pages/projects/{project_name}/deployments/{deployment_id}/rollback method: post operationId: pages-deployment-rollback-deployment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pages/projects/{project_name}/domains method: get operationId: pages-domains-get-domains x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/pages/projects/{project_name}/domains method: post operationId: pages-domains-add-domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pages/projects/{project_name}/domains/{domain_name} method: delete operationId: pages-domains-delete-domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pages/projects/{project_name}/domains/{domain_name} method: get operationId: pages-domains-get-domain x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/pages/projects/{project_name}/domains/{domain_name} method: patch operationId: pages-domains-patch-domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pages/projects/{project_name}/purge_build_cache method: post operationId: pages-purge-build-cache x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pcaps method: get operationId: magic-pcap-collection-list-packet-capture-requests x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/pcaps method: post operationId: magic-pcap-collection-create-pcap-request x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pcaps/{pcap_id} method: get operationId: magic-pcap-collection-get-pcap-request x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/pcaps/{pcap_id}/download method: get operationId: magic-pcap-collection-download-simple-pcap x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/pcaps/ownership method: get operationId: magic-pcap-collection-list-pca-ps-bucket-ownership x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/pcaps/ownership method: post operationId: magic-pcap-collection-add-buckets-for-full-packet-captures x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pcaps/ownership/{ownership_id} method: delete operationId: magic-pcap-collection-delete-buckets-for-full-packet-captures x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/pcaps/ownership/validate method: post operationId: magic-pcap-collection-validate-buckets-for-full-packet-captures x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/queues method: get operationId: queue-v2-list-queues x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/queues method: post operationId: queue-v2-create-queue x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/queues/{queue_id} method: delete operationId: queue-v2-delete-queue x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/queues/{queue_id} method: get operationId: queue-v2-queue-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/queues/{queue_id} method: put operationId: queue-v2-update-queue x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/queues/{queue_id}/consumers method: get operationId: queue-v2-list-queue-consumers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/queues/{queue_id}/consumers method: post operationId: queue-v2-create-queue-consumer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/queues/{queue_id}/consumers/{consumer_id} method: delete operationId: queue-v2-delete-queue-consumer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/queues/{queue_id}/consumers/{consumer_id} method: put operationId: queue-v2-update-queue-consumer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/queues/{queue_id}/messages/ack method: post operationId: queue-v2-messages-ack x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/queues/{queue_id}/messages/pull method: post operationId: queue-v2-messages-pull x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/r2/buckets method: get operationId: r2-list-buckets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/r2/buckets method: post operationId: r2-create-bucket x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/r2/buckets/{bucket_name} method: delete operationId: r2-delete-bucket x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/r2/buckets/{bucket_name} method: get operationId: r2-get-bucket x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/r2/buckets/{bucket_name}/domains/custom method: get operationId: r2-list-custom-domains x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/r2/buckets/{bucket_name}/domains/custom method: post operationId: r2-add-custom-domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/r2/buckets/{bucket_name}/domains/custom/{domain_name} method: delete operationId: r2-delete-custom-domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/r2/buckets/{bucket_name}/domains/custom/{domain_name} method: put operationId: r2-edit-custom-domain-settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/r2/buckets/{bucket_name}/domains/managed method: get operationId: r2-get-bucket-public-policy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/r2/buckets/{bucket_name}/domains/managed method: put operationId: r2-put-bucket-public-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/r2/buckets/{bucket_name}/sippy method: delete operationId: r2-delete-bucket-sippy-config x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/r2/buckets/{bucket_name}/sippy method: get operationId: r2-get-bucket-sippy-config x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/r2/buckets/{bucket_name}/sippy method: put operationId: r2-put-bucket-sippy-config x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/r2/temp-access-credentials method: post operationId: r2-create-temp-access-credentials x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/registrar/domains method: get operationId: registrar-domains-list-domains x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/registrar/domains/{domain_name} method: get operationId: registrar-domains-get-domain x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/registrar/domains/{domain_name} method: put operationId: registrar-domains-update-domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/request-tracer/trace method: post operationId: account-request-tracer-request-trace x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/roles method: get operationId: account-roles-list-roles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/roles/{role_id} method: get operationId: account-roles-role-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rules/lists method: get operationId: lists-get-lists x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rules/lists method: post operationId: lists-create-a-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rules/lists/{list_id} method: delete operationId: lists-delete-a-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rules/lists/{list_id} method: get operationId: lists-get-a-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rules/lists/{list_id} method: put operationId: lists-update-a-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rules/lists/{list_id}/items method: delete operationId: lists-delete-list-items x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rules/lists/{list_id}/items method: get operationId: lists-get-list-items x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rules/lists/{list_id}/items method: post operationId: lists-create-list-items x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rules/lists/{list_id}/items method: put operationId: lists-update-all-list-items x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rulesets method: get operationId: listAccountRulesets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rulesets method: post operationId: createAccountRuleset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rulesets/{ruleset_id} method: delete operationId: deleteAccountRuleset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rulesets/{ruleset_id} method: get operationId: getAccountRuleset x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rulesets/{ruleset_id} method: put operationId: updateAccountRuleset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rulesets/{ruleset_id}/rules method: post operationId: createAccountRulesetRule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rulesets/{ruleset_id}/rules/{rule_id} method: delete operationId: deleteAccountRulesetRule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rulesets/{ruleset_id}/rules/{rule_id} method: patch operationId: updateAccountRulesetRule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rulesets/{ruleset_id}/versions method: get operationId: listAccountRulesetVersions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rulesets/{ruleset_id}/versions/{ruleset_version} method: delete operationId: deleteAccountRulesetVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rulesets/{ruleset_id}/versions/{ruleset_version} method: get operationId: getAccountRulesetVersion x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rulesets/{ruleset_id}/versions/{ruleset_version}/by_tag/{rule_tag} method: get operationId: listAccountRulesetVersionRulesByTag x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rulesets/phases/{ruleset_phase}/entrypoint method: get operationId: getAccountEntrypointRuleset x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rulesets/phases/{ruleset_phase}/entrypoint method: put operationId: updateAccountEntrypointRuleset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rulesets/phases/{ruleset_phase}/entrypoint/versions method: get operationId: listAccountEntrypointRulesetVersions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rulesets/phases/{ruleset_phase}/entrypoint/versions/{ruleset_version} method: get operationId: getAccountEntrypointRulesetVersion x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rum/site_info method: post operationId: web-analytics-create-site x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rum/site_info/{site_id} method: delete operationId: web-analytics-delete-site x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rum/site_info/{site_id} method: get operationId: web-analytics-get-site x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rum/site_info/{site_id} method: put operationId: web-analytics-update-site x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rum/site_info/list method: get operationId: web-analytics-list-sites x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rum/v2/{ruleset_id}/rule method: post operationId: web-analytics-create-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rum/v2/{ruleset_id}/rule/{rule_id} method: delete operationId: web-analytics-delete-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rum/v2/{ruleset_id}/rule/{rule_id} method: put operationId: web-analytics-update-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/rum/v2/{ruleset_id}/rules method: get operationId: web-analytics-list-rules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/rum/v2/{ruleset_id}/rules method: post operationId: web-analytics-modify-rules x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/secondary_dns/acls method: get operationId: secondary-dns-(-acl)-list-ac-ls x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/secondary_dns/acls method: post operationId: secondary-dns-(-acl)-create-acl x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/secondary_dns/acls/{acl_id} method: delete operationId: secondary-dns-(-acl)-delete-acl x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/secondary_dns/acls/{acl_id} method: get operationId: secondary-dns-(-acl)-acl-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/secondary_dns/acls/{acl_id} method: put operationId: secondary-dns-(-acl)-update-acl x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/secondary_dns/peers method: get operationId: secondary-dns-(-peer)-list-peers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/secondary_dns/peers method: post operationId: secondary-dns-(-peer)-create-peer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/secondary_dns/peers/{peer_id} method: delete operationId: secondary-dns-(-peer)-delete-peer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/secondary_dns/peers/{peer_id} method: get operationId: secondary-dns-(-peer)-peer-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/secondary_dns/peers/{peer_id} method: put operationId: secondary-dns-(-peer)-update-peer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/secondary_dns/tsigs method: get operationId: secondary-dns-(-tsig)-list-tsi-gs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/secondary_dns/tsigs method: post operationId: secondary-dns-(-tsig)-create-tsig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/secondary_dns/tsigs/{tsig_id} method: delete operationId: secondary-dns-(-tsig)-delete-tsig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/secondary_dns/tsigs/{tsig_id} method: get operationId: secondary-dns-(-tsig)-tsig-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/secondary_dns/tsigs/{tsig_id} method: put operationId: secondary-dns-(-tsig)-update-tsig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/storage/analytics method: get operationId: workers-kv-request-analytics-query-request-analytics x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/storage/analytics/stored method: get operationId: workers-kv-stored-data-analytics-query-stored-data-analytics x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/storage/kv/namespaces method: get operationId: workers-kv-namespace-list-namespaces x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/storage/kv/namespaces method: post operationId: workers-kv-namespace-create-a-namespace x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/storage/kv/namespaces/{namespace_id} method: delete operationId: workers-kv-namespace-remove-a-namespace x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/storage/kv/namespaces/{namespace_id} method: get operationId: workers-kv-namespace-get-a-namespace x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/storage/kv/namespaces/{namespace_id} method: put operationId: workers-kv-namespace-rename-a-namespace x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/bulk method: delete operationId: workers-kv-namespace-delete-multiple-key-value-pairs-deprecated x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/bulk method: put operationId: workers-kv-namespace-write-multiple-key-value-pairs x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/bulk/delete method: post operationId: workers-kv-namespace-delete-multiple-key-value-pairs x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/keys method: get operationId: workers-kv-namespace-list-a-namespace'-s-keys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/metadata/{key_name} method: get operationId: workers-kv-namespace-read-the-metadata-for-a-key x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/values/{key_name} method: delete operationId: workers-kv-namespace-delete-key-value-pair x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/values/{key_name} method: get operationId: workers-kv-namespace-read-key-value-pair x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/storage/kv/namespaces/{namespace_id}/values/{key_name} method: put operationId: workers-kv-namespace-write-key-value-pair-with-metadata x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream method: get operationId: stream-videos-list-videos x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream method: post operationId: stream-videos-initiate-video-uploads-using-tus x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/{identifier} method: delete operationId: stream-videos-delete-video x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/{identifier} method: get operationId: stream-videos-retrieve-video-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/{identifier} method: post operationId: stream-videos-update-video-details x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/{identifier}/audio method: get operationId: list-audio-tracks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/{identifier}/audio/{audio_identifier} method: delete operationId: delete-audio-tracks x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/{identifier}/audio/{audio_identifier} method: patch operationId: edit-audio-tracks x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/{identifier}/audio/copy method: post operationId: add-audio-track x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/{identifier}/captions method: get operationId: stream-subtitles/-captions-list-captions-or-subtitles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/{identifier}/captions/{language} method: delete operationId: stream-subtitles/-captions-delete-captions-or-subtitles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/{identifier}/captions/{language} method: get operationId: stream-subtitles/-captions-get-caption-or-subtitle-for-language x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/{identifier}/captions/{language} method: put operationId: stream-subtitles/-captions-upload-captions-or-subtitles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/{identifier}/captions/{language}/generate method: post operationId: stream-subtitles/-captions-generate-caption-or-subtitle-for-language x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/{identifier}/captions/{language}/vtt method: get operationId: stream-subtitles/-captions-get-vtt-caption-or-subtitle x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/{identifier}/downloads method: delete operationId: stream-m-p-4-downloads-delete-downloads x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/{identifier}/downloads method: get operationId: stream-m-p-4-downloads-list-downloads x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/{identifier}/downloads method: post operationId: stream-m-p-4-downloads-create-downloads x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/{identifier}/embed method: get operationId: stream-videos-retreieve-embed-code-html x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/{identifier}/token method: post operationId: stream-videos-create-signed-url-tokens-for-videos x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/clip method: post operationId: stream-video-clipping-clip-videos-given-a-start-and-end-time x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/copy method: post operationId: stream-videos-upload-videos-from-a-url x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/direct_upload method: post operationId: stream-videos-upload-videos-via-direct-upload-ur-ls x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/keys method: get operationId: stream-signing-keys-list-signing-keys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/keys method: post operationId: stream-signing-keys-create-signing-keys x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/keys/{identifier} method: delete operationId: stream-signing-keys-delete-signing-keys x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/live_inputs method: get operationId: stream-live-inputs-list-live-inputs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/live_inputs method: post operationId: stream-live-inputs-create-a-live-input x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/live_inputs/{live_input_identifier} method: delete operationId: stream-live-inputs-delete-a-live-input x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/live_inputs/{live_input_identifier} method: get operationId: stream-live-inputs-retrieve-a-live-input x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/live_inputs/{live_input_identifier} method: put operationId: stream-live-inputs-update-a-live-input x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/live_inputs/{live_input_identifier}/outputs method: get operationId: stream-live-inputs-list-all-outputs-associated-with-a-specified-live-input x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/live_inputs/{live_input_identifier}/outputs method: post operationId: stream-live-inputs-create-a-new-output,-connected-to-a-live-input x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/live_inputs/{live_input_identifier}/outputs/{output_identifier} method: delete operationId: stream-live-inputs-delete-an-output x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/live_inputs/{live_input_identifier}/outputs/{output_identifier} method: put operationId: stream-live-inputs-update-an-output x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/storage-usage method: get operationId: stream-videos-storage-usage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/watermarks method: get operationId: stream-watermark-profile-list-watermark-profiles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/watermarks method: post operationId: stream-watermark-profile-create-watermark-profiles-via-basic-upload x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/watermarks/{identifier} method: delete operationId: stream-watermark-profile-delete-watermark-profiles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/watermarks/{identifier} method: get operationId: stream-watermark-profile-watermark-profile-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/webhook method: delete operationId: stream-webhook-delete-webhooks x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/stream/webhook method: get operationId: stream-webhook-view-webhooks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/stream/webhook method: put operationId: stream-webhook-create-webhooks x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/subscriptions method: get operationId: account-subscriptions-list-subscriptions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/subscriptions method: post operationId: account-subscriptions-create-subscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/subscriptions/{subscription_identifier} method: delete operationId: account-subscriptions-delete-subscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/subscriptions/{subscription_identifier} method: put operationId: account-subscriptions-update-subscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/teamnet/routes method: get operationId: tunnel-route-list-tunnel-routes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/teamnet/routes method: post operationId: tunnel-route-create-a-tunnel-route x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/teamnet/routes/{route_id} method: delete operationId: tunnel-route-delete-a-tunnel-route x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/teamnet/routes/{route_id} method: get operationId: tunnel-route-get-tunnel-route x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/teamnet/routes/{route_id} method: patch operationId: tunnel-route-update-a-tunnel-route x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/teamnet/routes/ip/{ip} method: get operationId: tunnel-route-get-tunnel-route-by-ip x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/teamnet/routes/network/{ip_network_encoded} method: delete operationId: tunnel-route-delete-a-tunnel-route-with-cidr x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/teamnet/routes/network/{ip_network_encoded} method: patch operationId: tunnel-route-update-a-tunnel-route-with-cidr x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/teamnet/routes/network/{ip_network_encoded} method: post operationId: tunnel-route-create-a-tunnel-route-with-cidr x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/teamnet/virtual_networks method: get operationId: tunnel-virtual-network-list-virtual-networks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/teamnet/virtual_networks method: post operationId: tunnel-virtual-network-create-a-virtual-network x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/teamnet/virtual_networks/{virtual_network_id} method: delete operationId: tunnel-virtual-network-delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/teamnet/virtual_networks/{virtual_network_id} method: get operationId: tunnel-virtual-network-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/teamnet/virtual_networks/{virtual_network_id} method: patch operationId: tunnel-virtual-network-update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/tunnels method: get operationId: cloudflare-tunnel-list-all-tunnels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/vectorize/indexes method: get operationId: vectorize-(-deprecated)-list-vectorize-indexes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/vectorize/indexes method: post operationId: vectorize-(-deprecated)-create-vectorize-index x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/indexes/{index_name} method: delete operationId: vectorize-(-deprecated)-delete-vectorize-index x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/indexes/{index_name} method: get operationId: vectorize-(-deprecated)-get-vectorize-index x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/vectorize/indexes/{index_name} method: put operationId: vectorize-(-deprecated)-update-vectorize-index x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/indexes/{index_name}/delete-by-ids method: post operationId: vectorize-(-deprecated)-delete-vectors-by-id x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/indexes/{index_name}/get-by-ids method: post operationId: vectorize-(-deprecated)-get-vectors-by-id x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/indexes/{index_name}/insert method: post operationId: vectorize-(-deprecated)-insert-vector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/indexes/{index_name}/query method: post operationId: vectorize-(-deprecated)-query-vector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/indexes/{index_name}/upsert method: post operationId: vectorize-(-deprecated)-upsert-vector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/v2/indexes method: get operationId: vectorize-list-vectorize-indexes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/vectorize/v2/indexes method: post operationId: vectorize-create-vectorize-index x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/v2/indexes/{index_name} method: delete operationId: vectorize-delete-vectorize-index x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/v2/indexes/{index_name} method: get operationId: vectorize-get-vectorize-index x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/vectorize/v2/indexes/{index_name}/delete_by_ids method: post operationId: vectorize-delete-vectors-by-id x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/v2/indexes/{index_name}/get_by_ids method: post operationId: vectorize-get-vectors-by-id x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/v2/indexes/{index_name}/info method: get operationId: vectorize-index-info x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/vectorize/v2/indexes/{index_name}/insert method: post operationId: vectorize-insert-vector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/v2/indexes/{index_name}/metadata_index/create method: post operationId: vectorize-create-metadata-index x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/v2/indexes/{index_name}/metadata_index/delete method: post operationId: vectorize-delete-metadata-index x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/v2/indexes/{index_name}/metadata_index/list method: get operationId: vectorize-list-metadata-indexes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/vectorize/v2/indexes/{index_name}/query method: post operationId: vectorize-query-vector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/vectorize/v2/indexes/{index_name}/upsert method: post operationId: vectorize-upsert-vector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/warp_connector method: get operationId: cloudflare-tunnel-list-warp-connector-tunnels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/warp_connector method: post operationId: cloudflare-tunnel-create-a-warp-connector-tunnel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/warp_connector/{tunnel_id} method: delete operationId: cloudflare-tunnel-delete-a-warp-connector-tunnel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/warp_connector/{tunnel_id} method: get operationId: cloudflare-tunnel-get-a-warp-connector-tunnel x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/warp_connector/{tunnel_id} method: patch operationId: cloudflare-tunnel-update-a-warp-connector-tunnel x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/warp_connector/{tunnel_id}/token method: get operationId: cloudflare-tunnel-get-a-warp-connector-tunnel-token x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/account-settings method: get operationId: worker-account-settings-fetch-worker-account-settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/account-settings method: put operationId: worker-account-settings-create-worker-account-settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/deployments/by-script/{script_id} method: get operationId: worker-deployments-(-deprecated)-list-deployments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/deployments/by-script/{script_id}/detail/{deployment_id} method: get operationId: worker-deployments-(-deprecated)-get-deployment-detail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/dispatch/namespaces method: get operationId: namespace-worker-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/dispatch/namespaces method: post operationId: namespace-worker-create x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace} method: delete operationId: namespace-worker-delete-namespace x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace} method: get operationId: namespace-worker-get-namespace x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name} method: delete operationId: namespace-worker-script-delete-worker x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name} method: get operationId: namespace-worker-script-worker-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name} method: put operationId: namespace-worker-script-upload-worker-module x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name}/bindings method: get operationId: namespace-worker-get-script-bindings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name}/content method: get operationId: namespace-worker-get-script-content x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name}/content method: put operationId: namespace-worker-put-script-content x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name}/secrets method: get operationId: namespace-worker-list-script-secrets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name}/secrets method: put operationId: namespace-worker-put-script-secrets x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name}/secrets/{secret_name} method: get operationId: namespace-worker-get-script-secrets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name}/settings method: get operationId: namespace-worker-get-script-settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name}/settings method: patch operationId: namespace-worker-patch-script-settings x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name}/tags method: get operationId: namespace-worker-get-script-tags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name}/tags method: put operationId: namespace-worker-put-script-tags x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name}/tags/{tag} method: delete operationId: namespace-worker-delete-script-tag x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/workers/dispatch/namespaces/{dispatch_namespace}/scripts/{script_name}/tags/{tag} method: put operationId: namespace-worker-put-script-tag x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/workers/domains method: get operationId: worker-domain-list-domains x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/domains method: put operationId: worker-domain-attach-to-domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/domains/{domain_id} method: delete operationId: worker-domain-detach-from-domain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/domains/{domain_id} method: get operationId: worker-domain-get-a-domain x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/durable_objects/namespaces method: get operationId: durable-objects-namespace-list-namespaces x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/durable_objects/namespaces/{id}/objects method: get operationId: durable-objects-namespace-list-objects x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/scripts method: get operationId: worker-script-list-workers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/scripts/{script_name} method: delete operationId: worker-script-delete-worker x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/scripts/{script_name} method: get operationId: worker-script-download-worker x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/scripts/{script_name} method: put operationId: worker-script-upload-worker-module x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/scripts/{script_name}/content method: put operationId: worker-script-put-content x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/scripts/{script_name}/content/v2 method: get operationId: worker-script-get-content x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/scripts/{script_name}/deployments method: get operationId: worker-deployments-list-deployments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/scripts/{script_name}/deployments method: post operationId: worker-deployments-create-deployment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/scripts/{script_name}/schedules method: get operationId: worker-cron-trigger-get-cron-triggers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/scripts/{script_name}/schedules method: put operationId: worker-cron-trigger-update-cron-triggers x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/scripts/{script_name}/script-settings method: get operationId: worker-script-settings-get-settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/scripts/{script_name}/script-settings method: patch operationId: worker-script-settings-patch-settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/scripts/{script_name}/settings method: get operationId: worker-script-get-settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/scripts/{script_name}/settings method: patch operationId: worker-script-patch-settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/scripts/{script_name}/tails method: get operationId: worker-tail-logs-list-tails x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/scripts/{script_name}/tails method: post operationId: worker-tail-logs-start-tail x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/scripts/{script_name}/tails/{id} method: delete operationId: worker-tail-logs-delete-tail x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/scripts/{script_name}/usage-model method: get operationId: worker-script-fetch-usage-model x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/scripts/{script_name}/usage-model method: put operationId: worker-script-update-usage-model x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/scripts/{script_name}/versions method: get operationId: worker-versions-list-versions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/scripts/{script_name}/versions method: post operationId: worker-versions-upload-version x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/scripts/{script_name}/versions/{version_id} method: get operationId: worker-versions-get-version-detail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/services/{service_name}/environments/{environment_name}/content method: get operationId: worker-environment-get-script-content x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/services/{service_name}/environments/{environment_name}/content method: put operationId: worker-environment-put-script-content x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/services/{service_name}/environments/{environment_name}/settings method: get operationId: worker-script-environment-get-settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/services/{service_name}/environments/{environment_name}/settings method: patch operationId: worker-script-environment-patch-settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/workers/subdomain method: get operationId: worker-subdomain-get-subdomain x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/workers/subdomain method: put operationId: worker-subdomain-create-subdomain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/zerotrust/connectivity_settings method: get operationId: zero-trust-accounts-get-connectivity-settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/zerotrust/connectivity_settings method: patch operationId: zero-trust-accounts-patch-connectivity-settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/zt_risk_scoring/{user_id} method: get operationId: dlp-risk-score-summary-get-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/zt_risk_scoring/{user_id}/reset method: post operationId: dlp-risk-score-reset-post x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /accounts/{account_id}/zt_risk_scoring/behaviors method: get operationId: dlp-risk-score-behaviors-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/zt_risk_scoring/behaviors method: put operationId: dlp-risk-score-behaviors-put x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/zt_risk_scoring/integrations method: get operationId: dlp-zt-risk-score-integration-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/zt_risk_scoring/integrations method: post operationId: dlp-zt-risk-score-integration-create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/zt_risk_scoring/integrations/{integration_id} method: delete operationId: dlp-zt-risk-score-integration-delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/zt_risk_scoring/integrations/{integration_id} method: get operationId: dlp-zt-risk-score-integration-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/zt_risk_scoring/integrations/{integration_id} method: put operationId: dlp-zt-risk-score-integration-update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_id}/zt_risk_scoring/integrations/reference_id/{reference_id} method: get operationId: dlp-zt-risk-score-integration-get-by-reference-id x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_id}/zt_risk_scoring/summary method: get operationId: dlp-risk-score-summary-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/cloudforce-one/requests method: post operationId: cloudforce-one-request-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/{request_identifier} method: delete operationId: cloudforce-one-request-delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/{request_identifier} method: get operationId: cloudforce-one-request-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/cloudforce-one/requests/{request_identifier} method: put operationId: cloudforce-one-request-update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/{request_identifier}/asset method: post operationId: cloudforce-one-request-asset-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/{request_identifier}/asset/{asset_identifer} method: delete operationId: cloudforce-one-request-asset-delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/{request_identifier}/asset/{asset_identifer} method: get operationId: cloudforce-one-request-asset-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/cloudforce-one/requests/{request_identifier}/asset/{asset_identifer} method: put operationId: cloudforce-one-request-asset-update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/{request_identifier}/asset/new method: post operationId: cloudforce-one-request-asset-new x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/{request_identifier}/message method: post operationId: cloudforce-one-request-message-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/{request_identifier}/message/{message_identifer} method: delete operationId: cloudforce-one-request-message-delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/{request_identifier}/message/{message_identifer} method: put operationId: cloudforce-one-request-message-update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/{request_identifier}/message/new method: post operationId: cloudforce-one-request-message-new x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/constants method: get operationId: cloudforce-one-request-constants x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/cloudforce-one/requests/new method: post operationId: cloudforce-one-request-new x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/priority method: post operationId: cloudforce-one-priority-list x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/priority/{priority_identifer} method: delete operationId: cloudforce-one-priority-delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/priority/{priority_identifer} method: get operationId: cloudforce-one-priority-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/cloudforce-one/requests/priority/{priority_identifer} method: put operationId: cloudforce-one-priority-update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/priority/new method: post operationId: cloudforce-one-priority-new x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/cloudforce-one/requests/priority/quota method: get operationId: cloudforce-one-priority-quota x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/cloudforce-one/requests/quota method: get operationId: cloudforce-one-request-quota x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/cloudforce-one/requests/types method: get operationId: cloudforce-one-request-types x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/custom_pages method: get operationId: custom-pages-for-an-account-list-custom-pages x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/custom_pages/{identifier} method: get operationId: custom-pages-for-an-account-get-a-custom-page x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/custom_pages/{identifier} method: put operationId: custom-pages-for-an-account-update-a-custom-page x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/firewall/access_rules/rules method: get operationId: ip-access-rules-for-an-account-list-ip-access-rules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/firewall/access_rules/rules method: post operationId: ip-access-rules-for-an-account-create-an-ip-access-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/firewall/access_rules/rules/{identifier} method: delete operationId: ip-access-rules-for-an-account-delete-an-ip-access-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/firewall/access_rules/rules/{identifier} method: get operationId: ip-access-rules-for-an-account-get-an-ip-access-rule x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/firewall/access_rules/rules/{identifier} method: patch operationId: ip-access-rules-for-an-account-update-an-ip-access-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{account_identifier}/rules/lists/{list_id}/items/{item_id} method: get operationId: lists-get-a-list-item x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{account_identifier}/rules/lists/bulk_operations/{operation_id} method: get operationId: lists-get-bulk-operation-status x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/urlscanner/scan method: get operationId: urlscanner-search-scans x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/urlscanner/scan method: post operationId: urlscanner-create-scan x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /accounts/{accountId}/urlscanner/scan/{scanId} method: get operationId: urlscanner-get-scan x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/urlscanner/scan/{scanId}/har method: get operationId: urlscanner-get-scan-har x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/urlscanner/scan/{scanId}/screenshot method: get operationId: urlscanner-get-scan-screenshot x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /certificates method: get operationId: origin-ca-list-certificates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /certificates method: post operationId: origin-ca-create-certificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /certificates/{certificate_id} method: delete operationId: origin-ca-revoke-certificate x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /certificates/{certificate_id} method: get operationId: origin-ca-get-certificate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /ips method: get operationId: cloudflare-i-ps-cloudflare-ip-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /memberships method: get operationId: user'-s-account-memberships-list-memberships x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /memberships/{membership_id} method: delete operationId: user'-s-account-memberships-delete-membership x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /memberships/{membership_id} method: get operationId: user'-s-account-memberships-membership-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /memberships/{membership_id} method: put operationId: user'-s-account-memberships-update-membership x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/{organization_id}/audit_logs method: get operationId: audit-logs-get-organization-audit-logs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/ai/gateway/summary/provider method: get operationId: radar-get-ai-gateway-summary-by-provider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/ai/gateway/timeseries_groups/provider method: get operationId: radar-get-ai-gateway-timeseries-group-by-provider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/ai/inference/summary/model method: get operationId: radar-get-ai-inference-summary-by-model x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/ai/inference/summary/task method: get operationId: radar-get-ai-inference-summary-by-task x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/ai/inference/timeseries_groups/model method: get operationId: radar-get-ai-inference-timeseries-group-by-model x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/ai/inference/timeseries_groups/task method: get operationId: radar-get-ai-inference-timeseries-group-by-task x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/annotations method: get operationId: radar-get-annotations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/annotations/outages method: get operationId: radar-get-annotations-outages x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/annotations/outages/locations method: get operationId: radar-get-annotations-outages-top x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/summary/dnssec method: get operationId: radar-get-dns-as112-timeseries-by-dnssec x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/summary/edns method: get operationId: radar-get-dns-as112-timeseries-by-edns x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/summary/ip_version method: get operationId: radar-get-dns-as112-timeseries-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/summary/protocol method: get operationId: radar-get-dns-as112-timeseries-by-protocol x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/summary/query_type method: get operationId: radar-get-dns-as112-timeseries-by-query-type x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/summary/response_codes method: get operationId: radar-get-dns-as112-timeseries-by-response-codes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/timeseries method: get operationId: radar-get-dns-as112-timeseries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/timeseries_groups/dnssec method: get operationId: radar-get-dns-as112-timeseries-group-by-dnssec x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/timeseries_groups/edns method: get operationId: radar-get-dns-as112-timeseries-group-by-edns x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/timeseries_groups/ip_version method: get operationId: radar-get-dns-as112-timeseries-group-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/timeseries_groups/protocol method: get operationId: radar-get-dns-as112-timeseries-group-by-protocol x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/timeseries_groups/query_type method: get operationId: radar-get-dns-as112-timeseries-group-by-query-type x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/timeseries_groups/response_codes method: get operationId: radar-get-dns-as112-timeseries-group-by-response-codes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/top/locations method: get operationId: radar-get-dns-as112-top-locations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/top/locations/dnssec/{dnssec} method: get operationId: radar-get-dns-as112-top-locations-by-dnssec x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/top/locations/edns/{edns} method: get operationId: radar-get-dns-as112-top-locations-by-edns x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/as112/top/locations/ip_version/{ip_version} method: get operationId: radar-get-dns-as112-top-locations-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/summary method: get operationId: radar-get-attacks-layer3-summary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/summary/bitrate method: get operationId: radar-get-attacks-layer3-summary-by-bitrate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/summary/duration method: get operationId: radar-get-attacks-layer3-summary-by-duration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/summary/ip_version method: get operationId: radar-get-attacks-layer3-summary-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/summary/protocol method: get operationId: radar-get-attacks-layer3-summary-by-protocol x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/summary/vector method: get operationId: radar-get-attacks-layer3-summary-by-vector x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/timeseries method: get operationId: radar-get-attacks-layer3-timeseries-by-bytes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/timeseries_groups method: get operationId: radar-get-attacks-layer3-timeseries-groups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/timeseries_groups/bitrate method: get operationId: radar-get-attacks-layer3-timeseries-group-by-bitrate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/timeseries_groups/duration method: get operationId: radar-get-attacks-layer3-timeseries-group-by-duration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/timeseries_groups/industry method: get operationId: radar-get-attacks-layer3-timeseries-group-by-industry x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/timeseries_groups/ip_version method: get operationId: radar-get-attacks-layer3-timeseries-group-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/timeseries_groups/protocol method: get operationId: radar-get-attacks-layer3-timeseries-group-by-protocol x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/timeseries_groups/vector method: get operationId: radar-get-attacks-layer3-timeseries-group-by-vector x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/timeseries_groups/vertical method: get operationId: radar-get-attacks-layer3-timeseries-group-by-vertical x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/top/attacks method: get operationId: radar-get-attacks-layer3-top-attacks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/top/industry method: get operationId: radar-get-attacks-layer3-top-industries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/top/locations/origin method: get operationId: radar-get-attacks-layer3-top-origin-locations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/top/locations/target method: get operationId: radar-get-attacks-layer3-top-target-locations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer3/top/vertical method: get operationId: radar-get-attacks-layer3-top-verticals x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/summary method: get operationId: radar-get-attacks-layer7-summary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/summary/http_method method: get operationId: radar-get-attacks-layer7-summary-by-http-method x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/summary/http_version method: get operationId: radar-get-attacks-layer7-summary-by-http-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/summary/ip_version method: get operationId: radar-get-attacks-layer7-summary-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/summary/managed_rules method: get operationId: radar-get-attacks-layer7-summary-by-managed-rules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/summary/mitigation_product method: get operationId: radar-get-attacks-layer7-summary-by-mitigation-product x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/timeseries method: get operationId: radar-get-attacks-layer7-timeseries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/timeseries_groups method: get operationId: radar-get-attacks-layer7-timeseries-group x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/timeseries_groups/http_method method: get operationId: radar-get-attacks-layer7-timeseries-group-by-http-method x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/timeseries_groups/http_version method: get operationId: radar-get-attacks-layer7-timeseries-group-by-http-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/timeseries_groups/industry method: get operationId: radar-get-attacks-layer7-timeseries-group-by-industry x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/timeseries_groups/ip_version method: get operationId: radar-get-attacks-layer7-timeseries-group-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/timeseries_groups/managed_rules method: get operationId: radar-get-attacks-layer7-timeseries-group-by-managed-rules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/timeseries_groups/mitigation_product method: get operationId: radar-get-attacks-layer7-timeseries-group-by-mitigation-product x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/timeseries_groups/vertical method: get operationId: radar-get-attacks-layer7-timeseries-group-by-vertical x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/top/ases/origin method: get operationId: radar-get-attacks-layer7-top-origin-as x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/top/attacks method: get operationId: radar-get-attacks-layer7-top-attacks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/top/industry method: get operationId: radar-get-attacks-layer7-top-industries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/top/locations/origin method: get operationId: radar-get-attacks-layer7-top-origin-location x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/top/locations/target method: get operationId: radar-get-attacks-layer7-top-target-location x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/attacks/layer7/top/vertical method: get operationId: radar-get-attacks-layer7-top-verticals x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/bgp/hijacks/events method: get operationId: radar-get-bgp-hijacks-events x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/bgp/ips/timeseries method: get operationId: radar-get-bgp-ips-timeseries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/bgp/leaks/events method: get operationId: radar-get-bgp-route-leak-events x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/bgp/routes/ases method: get operationId: radar-get-bgp-routes-asns x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/bgp/routes/moas method: get operationId: radar-get-bgp-pfx2as-moas x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/bgp/routes/pfx2as method: get operationId: radar-get-bgp-pfx2as x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/bgp/routes/stats method: get operationId: radar-get-bgp-routes-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/bgp/timeseries method: get operationId: radar-get-bgp-timeseries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/bgp/top/ases method: get operationId: radar-get-bgp-top-ases x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/bgp/top/ases/prefixes method: get operationId: radar-get-bgp-top-asns-by-prefixes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/bgp/top/prefixes method: get operationId: radar-get-bgp-top-prefixes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/datasets method: get operationId: radar-get-reports-datasets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/datasets/{alias} method: get operationId: radar-get-reports-dataset-download x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/datasets/download method: post operationId: radar-post-reports-dataset-download-url x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /radar/dns/top/ases method: get operationId: radar-get-dns-top-ases x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/dns/top/locations method: get operationId: radar-get-dns-top-locations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/routing/summary/arc method: get operationId: radar-get-email-routing-summary-by-arc x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/routing/summary/dkim method: get operationId: radar-get-email-routing-summary-by-dkim x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/routing/summary/dmarc method: get operationId: radar-get-email-routing-summary-by-dmarc x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/routing/summary/encrypted method: get operationId: radar-get-email-routing-summary-by-encrypted x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/routing/summary/ip_version method: get operationId: radar-get-email-routing-summary-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/routing/summary/spf method: get operationId: radar-get-email-routing-summary-by-spf x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/routing/timeseries_groups/arc method: get operationId: radar-get-email-routing-timeseries-group-by-arc x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/routing/timeseries_groups/dkim method: get operationId: radar-get-email-routing-timeseries-group-by-dkim x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/routing/timeseries_groups/dmarc method: get operationId: radar-get-email-routing-timeseries-group-by-dmarc x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/routing/timeseries_groups/encrypted method: get operationId: radar-get-email-routing-timeseries-group-by-encrypted x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/routing/timeseries_groups/ip_version method: get operationId: radar-get-email-routing-timeseries-group-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/routing/timeseries_groups/spf method: get operationId: radar-get-email-routing-timeseries-group-by-spf x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/summary/arc method: get operationId: radar-get-email-security-summary-by-arc x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/summary/dkim method: get operationId: radar-get-email-security-summary-by-dkim x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/summary/dmarc method: get operationId: radar-get-email-security-summary-by-dmarc x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/summary/malicious method: get operationId: radar-get-email-security-summary-by-malicious x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/summary/spam method: get operationId: radar-get-email-security-summary-by-spam x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/summary/spf method: get operationId: radar-get-email-security-summary-by-spf x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/summary/spoof method: get operationId: radar-get-email-security-summary-by-spoof x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/summary/threat_category method: get operationId: radar-get-email-security-summary-by-threat-category x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/summary/tls_version method: get operationId: radar-get-email-security-summary-by-tls-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/timeseries_groups/arc method: get operationId: radar-get-email-security-timeseries-group-by-arc x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/timeseries_groups/dkim method: get operationId: radar-get-email-security-timeseries-group-by-dkim x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/timeseries_groups/dmarc method: get operationId: radar-get-email-security-timeseries-group-by-dmarc x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/timeseries_groups/malicious method: get operationId: radar-get-email-security-timeseries-group-by-malicious x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/timeseries_groups/spam method: get operationId: radar-get-email-security-timeseries-group-by-spam x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/timeseries_groups/spf method: get operationId: radar-get-email-security-timeseries-group-by-spf x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/timeseries_groups/spoof method: get operationId: radar-get-email-security-timeseries-group-by-spoof x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/timeseries_groups/threat_category method: get operationId: radar-get-email-security-timeseries-group-by-threat-category x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/timeseries_groups/tls_version method: get operationId: radar-get-email-security-timeseries-group-by-tls-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/top/tlds method: get operationId: radar-get-email-security-top-tlds-by-messages x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/top/tlds/malicious/{malicious} method: get operationId: radar-get-email-security-top-tlds-by-malicious x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/top/tlds/spam/{spam} method: get operationId: radar-get-email-security-top-tlds-by-spam x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/email/security/top/tlds/spoof/{spoof} method: get operationId: radar-get-email-security-top-tlds-by-spoof x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/entities/asns method: get operationId: radar-get-entities-asn-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/entities/asns/{asn} method: get operationId: radar-get-entities-asn-by-id x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/entities/asns/{asn}/rel method: get operationId: radar-get-asns-rel x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/entities/asns/ip method: get operationId: radar-get-entities-asn-by-ip x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/entities/ip method: get operationId: radar-get-entities-ip x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/entities/locations method: get operationId: radar-get-entities-locations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/entities/locations/{location} method: get operationId: radar-get-entities-location-by-alpha2 x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/summary/bot_class method: get operationId: radar-get-http-summary-by-bot-class x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/summary/device_type method: get operationId: radar-get-http-summary-by-device-type x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/summary/http_protocol method: get operationId: radar-get-http-summary-by-http-protocol x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/summary/http_version method: get operationId: radar-get-http-summary-by-http-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/summary/ip_version method: get operationId: radar-get-http-summary-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/summary/os method: get operationId: radar-get-http-summary-by-operating-system x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/summary/post_quantum method: get operationId: radar-get-http-summary-by-post-quantum x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/summary/tls_version method: get operationId: radar-get-http-summary-by-tls-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/timeseries method: get operationId: radar-get-http-timeseries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/timeseries_groups/bot_class method: get operationId: radar-get-http-timeseries-group-by-bot-class x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/timeseries_groups/browser method: get operationId: radar-get-http-timeseries-group-by-browsers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/timeseries_groups/browser_family method: get operationId: radar-get-http-timeseries-group-by-browser-families x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/timeseries_groups/device_type method: get operationId: radar-get-http-timeseries-group-by-device-type x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/timeseries_groups/http_protocol method: get operationId: radar-get-http-timeseries-group-by-http-protocol x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/timeseries_groups/http_version method: get operationId: radar-get-http-timeseries-group-by-http-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/timeseries_groups/ip_version method: get operationId: radar-get-http-timeseries-group-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/timeseries_groups/os method: get operationId: radar-get-http-timeseries-group-by-operating-system x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/timeseries_groups/post_quantum method: get operationId: radar-get-http-timeseries-group-by-post-quantum x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/timeseries_groups/tls_version method: get operationId: radar-get-http-timeseries-group-by-tls-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/ases method: get operationId: radar-get-http-top-ases-by-http-requests x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/ases/bot_class/{bot_class} method: get operationId: radar-get-http-top-ases-by-bot-class x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/ases/browser_family/{browser_family} method: get operationId: radar-get-http-top-ases-by-browser-family x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/ases/device_type/{device_type} method: get operationId: radar-get-http-top-ases-by-device-type x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/ases/http_protocol/{http_protocol} method: get operationId: radar-get-http-top-ases-by-http-protocol x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/ases/http_version/{http_version} method: get operationId: radar-get-http-top-ases-by-http-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/ases/ip_version/{ip_version} method: get operationId: radar-get-http-top-ases-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/ases/os/{os} method: get operationId: radar-get-http-top-ases-by-operating-system x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/ases/tls_version/{tls_version} method: get operationId: radar-get-http-top-ases-by-tls-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/browser method: get operationId: radar-get-http-top-browsers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/browser_family method: get operationId: radar-get-http-top-browser-families x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/locations method: get operationId: radar-get-http-top-locations-by-http-requests x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/locations/bot_class/{bot_class} method: get operationId: radar-get-http-top-locations-by-bot-class x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/locations/browser_family/{browser_family} method: get operationId: radar-get-http-top-locations-by-browser-family x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/locations/device_type/{device_type} method: get operationId: radar-get-http-top-locations-by-device-type x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/locations/http_protocol/{http_protocol} method: get operationId: radar-get-http-top-locations-by-http-protocol x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/locations/http_version/{http_version} method: get operationId: radar-get-http-top-locations-by-http-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/locations/ip_version/{ip_version} method: get operationId: radar-get-http-top-locations-by-ip-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/locations/os/{os} method: get operationId: radar-get-http-top-locations-by-operating-system x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/http/top/locations/tls_version/{tls_version} method: get operationId: radar-get-http-top-locations-by-tls-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/netflows/summary method: get operationId: radar-get-netflows-summary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/netflows/timeseries method: get operationId: radar-get-netflows-timeseries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/netflows/top/ases method: get operationId: radar-get-netflows-top-ases x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/netflows/top/locations method: get operationId: radar-get-netflows-top-locations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/quality/iqi/summary method: get operationId: radar-get-quality-index-summary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/quality/iqi/timeseries_groups method: get operationId: radar-get-quality-index-timeseries-group x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/quality/speed/histogram method: get operationId: radar-get-quality-speed-histogram x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/quality/speed/summary method: get operationId: radar-get-quality-speed-summary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/quality/speed/top/ases method: get operationId: radar-get-quality-speed-top-ases x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/quality/speed/top/locations method: get operationId: radar-get-quality-speed-top-locations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/ranking/domain/{domain} method: get operationId: radar-get-ranking-domain-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/ranking/timeseries_groups method: get operationId: radar-get-ranking-domain-timeseries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/ranking/top method: get operationId: radar-get-ranking-top-domains x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/robots_txt/domains method: get operationId: radar-get-robots-txt-top-by-domain x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/robots_txt/top/{directive} method: get operationId: radar-get-robots-txt-top-by-directive x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/search/global method: get operationId: radar-get-search-global x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/tcp_resets_timeouts/summary method: get operationId: radar-get-tcp-resets-timeouts-summary x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/tcp_resets_timeouts/timeseries_groups method: get operationId: radar-get-tcp-resets-timeouts-timeseries-group x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/traffic_anomalies method: get operationId: radar-get-traffic-anomalies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/traffic_anomalies/locations method: get operationId: radar-get-traffic-anomalies-top x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/verified_bots/top/bots method: get operationId: radar-get-verified-bots-top-by-http-requests x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /radar/verified_bots/top/categories method: get operationId: radar-get-verified-bots-top-categories-by-http-requests x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user method: get operationId: user-user-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user method: patch operationId: user-edit-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/audit_logs method: get operationId: audit-logs-get-user-audit-logs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/billing/history method: get operationId: user-billing-history-(-deprecated)-billing-history-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/billing/profile method: get operationId: user-billing-profile-(-deprecated)-billing-profile-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/firewall/access_rules/rules method: get operationId: ip-access-rules-for-a-user-list-ip-access-rules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/firewall/access_rules/rules method: post operationId: ip-access-rules-for-a-user-create-an-ip-access-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/firewall/access_rules/rules/{identifier} method: delete operationId: ip-access-rules-for-a-user-delete-an-ip-access-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/firewall/access_rules/rules/{identifier} method: patch operationId: ip-access-rules-for-a-user-update-an-ip-access-rule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/invites method: get operationId: user'-s-invites-list-invitations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/invites/{invite_id} method: get operationId: user'-s-invites-invitation-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/invites/{invite_id} method: patch operationId: user'-s-invites-respond-to-invitation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/load_balancers/monitors method: get operationId: load-balancer-monitors-list-monitors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/load_balancers/monitors method: post operationId: load-balancer-monitors-create-monitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/load_balancers/monitors/{monitor_id} method: delete operationId: load-balancer-monitors-delete-monitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/load_balancers/monitors/{monitor_id} method: get operationId: load-balancer-monitors-monitor-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/load_balancers/monitors/{monitor_id} method: patch operationId: load-balancer-monitors-patch-monitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/load_balancers/monitors/{monitor_id} method: put operationId: load-balancer-monitors-update-monitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/load_balancers/monitors/{monitor_id}/preview method: post operationId: load-balancer-monitors-preview-monitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/load_balancers/monitors/{monitor_id}/references method: get operationId: load-balancer-monitors-list-monitor-references x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/load_balancers/pools method: get operationId: load-balancer-pools-list-pools x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/load_balancers/pools method: patch operationId: load-balancer-pools-patch-pools x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/load_balancers/pools method: post operationId: load-balancer-pools-create-pool x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/load_balancers/pools/{pool_id} method: delete operationId: load-balancer-pools-delete-pool x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/load_balancers/pools/{pool_id} method: get operationId: load-balancer-pools-pool-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/load_balancers/pools/{pool_id} method: patch operationId: load-balancer-pools-patch-pool x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/load_balancers/pools/{pool_id} method: put operationId: load-balancer-pools-update-pool x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/load_balancers/pools/{pool_id}/health method: get operationId: load-balancer-pools-pool-health-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/load_balancers/pools/{pool_id}/preview method: post operationId: load-balancer-pools-preview-pool x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/load_balancers/pools/{pool_id}/references method: get operationId: load-balancer-pools-list-pool-references x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/load_balancers/preview/{preview_id} method: get operationId: load-balancer-monitors-preview-result x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/load_balancing_analytics/events method: get operationId: load-balancer-healthcheck-events-list-healthcheck-events x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/organizations method: get operationId: user'-s-organizations-list-organizations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/organizations/{organization_id} method: delete operationId: user'-s-organizations-leave-organization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/organizations/{organization_id} method: get operationId: user'-s-organizations-organization-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/subscriptions method: get operationId: user-subscription-get-user-subscriptions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/subscriptions/{identifier} method: delete operationId: user-subscription-delete-user-subscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/subscriptions/{identifier} method: put operationId: user-subscription-update-user-subscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/tokens method: get operationId: user-api-tokens-list-tokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/tokens method: post operationId: user-api-tokens-create-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/tokens/{token_id} method: delete operationId: user-api-tokens-delete-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/tokens/{token_id} method: get operationId: user-api-tokens-token-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/tokens/{token_id} method: put operationId: user-api-tokens-update-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/tokens/{token_id}/value method: put operationId: user-api-tokens-roll-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/tokens/permission_groups method: get operationId: permission-groups-list-permission-groups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/tokens/verify method: get operationId: user-api-tokens-verify-token x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /zones method: get operationId: zones-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /zones method: post operationId: zones-post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{identifier}/subscription method: get operationId: zone-subscription-zone-subscription-details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /zones/{identifier}/subscription method: post operationId: zone-subscription-create-zone-subscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{identifier}/subscription method: put operationId: zone-subscription-update-zone-subscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{zone_id} method: delete operationId: zones-0-delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{zone_id} method: get operationId: zones-0-get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /zones/{zone_id} method: patch operationId: zones-0-patch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{zone_id}/access/apps method: get operationId: zone-level-access-applications-list-access-applications x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /zones/{zone_id}/access/apps method: post operationId: zone-level-access-applications-add-a-bookmark-application x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{zone_id}/access/apps/{app_id} method: delete operationId: zone-level-access-applications-delete-an-access-application x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{zone_id}/access/apps/{app_id} method: get operationId: zone-level-access-applications-get-an-access-application x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /zones/{zone_id}/access/apps/{app_id} method: put operationId: zone-level-access-applications-update-a-bookmark-application x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{zone_id}/access/apps/{app_id}/ca method: delete operationId: zone-level-access-short-lived-certificate-c-as-delete-a-short-lived-certificate-ca x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{zone_id}/access/apps/{app_id}/ca method: get operationId: zone-level-access-short-lived-certificate-c-as-get-a-short-lived-certificate-ca x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /zones/{zone_id}/access/apps/{app_id}/ca method: post operationId: zone-level-access-short-lived-certificate-c-as-create-a-short-lived-certificate-ca x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{zone_id}/access/apps/{app_id}/policies method: get operationId: zone-level-access-policies-list-access-policies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /zones/{zone_id}/access/apps/{app_id}/policies method: post operationId: zone-level-access-policies-create-an-access-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{zone_id}/access/apps/{app_id}/policies/{policy_id} method: delete operationId: zone-level-access-policies-delete-an-access-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{zone_id}/access/apps/{app_id}/policies/{policy_id} method: get operationId: zone-level-access-policies-get-an-access-policy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /zones/{zone_id}/access/apps/{app_id}/policies/{policy_id} method: put operationId: zone-level-access-policies-update-an-access-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zones/{zone_id}/access/apps/{app_id}/revoke_tokens method: post operationId: zone-level-access-applications-revoke-service-tokens x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /zones/{zone_id}/access/apps/{app_id}/user_policy_checks method: get operationId: zone-level-access-applications-test-access-policies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /zones/{zone_id}/access/apps/ca method: get operationId: zone-level-access-short-lived-certificate-c-as-list-short-lived-certificate-c-as x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /zones/{zone_id}/access/certificates method: get operationId: zone-level-access-mtls-authentication-list-mtls-certificates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /zones/{zone_id}/access/certificates method: post operationId: zone-level-access-mtls-authentication-add-an-mtls-certificate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: / method: get operationId: meta/root x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /admin/hooks method: get operationId: enterprise-admin/list-global-webhooks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /admin/hooks method: post operationId: enterprise-admin/create-global-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/hooks/{hook_id} method: get operationId: enterprise-admin/get-global-webhook x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /admin/hooks/{hook_id} method: patch operationId: enterprise-admin/update-global-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/hooks/{hook_id} method: delete operationId: enterprise-admin/delete-global-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/hooks/{hook_id}/pings method: post operationId: enterprise-admin/ping-global-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/keys method: get operationId: enterprise-admin/list-public-keys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /admin/keys/{key_ids} method: delete operationId: enterprise-admin/delete-public-key x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/ldap/teams/{team_id}/mapping method: patch operationId: enterprise-admin/update-ldap-mapping-for-team x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/ldap/teams/{team_id}/sync method: post operationId: enterprise-admin/sync-ldap-mapping-for-team x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/ldap/users/{username}/mapping method: patch operationId: enterprise-admin/update-ldap-mapping-for-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/ldap/users/{username}/sync method: post operationId: enterprise-admin/sync-ldap-mapping-for-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/organizations method: post operationId: enterprise-admin/create-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/organizations/{org} method: patch operationId: enterprise-admin/update-org-name x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/pre-receive-environments method: get operationId: enterprise-admin/list-pre-receive-environments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /admin/pre-receive-environments method: post operationId: enterprise-admin/create-pre-receive-environment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/pre-receive-environments/{pre_receive_environment_id} method: get operationId: enterprise-admin/get-pre-receive-environment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /admin/pre-receive-environments/{pre_receive_environment_id} method: patch operationId: enterprise-admin/update-pre-receive-environment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/pre-receive-environments/{pre_receive_environment_id} method: delete operationId: enterprise-admin/delete-pre-receive-environment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/pre-receive-environments/{pre_receive_environment_id}/downloads method: post operationId: enterprise-admin/start-pre-receive-environment-download x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/pre-receive-environments/{pre_receive_environment_id}/downloads/latest method: get operationId: enterprise-admin/get-download-status-for-pre-receive-environment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /admin/pre-receive-hooks method: get operationId: enterprise-admin/list-pre-receive-hooks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /admin/pre-receive-hooks method: post operationId: enterprise-admin/create-pre-receive-hook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/pre-receive-hooks/{pre_receive_hook_id} method: get operationId: enterprise-admin/get-pre-receive-hook x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /admin/pre-receive-hooks/{pre_receive_hook_id} method: patch operationId: enterprise-admin/update-pre-receive-hook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/pre-receive-hooks/{pre_receive_hook_id} method: delete operationId: enterprise-admin/delete-pre-receive-hook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/tokens method: get operationId: enterprise-admin/list-personal-access-tokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /admin/tokens/{token_id} method: delete operationId: enterprise-admin/delete-personal-access-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/users method: post operationId: enterprise-admin/create-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/users/{username} method: patch operationId: enterprise-admin/update-username-for-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/users/{username} method: delete operationId: enterprise-admin/delete-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/users/{username}/authorizations method: post operationId: enterprise-admin/create-impersonation-o-auth-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /admin/users/{username}/authorizations method: delete operationId: enterprise-admin/delete-impersonation-o-auth-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /app method: get operationId: apps/get-authenticated x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /app-manifests/{code}/conversions method: post operationId: apps/create-from-manifest x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /app/hook/config method: get operationId: apps/get-webhook-config-for-app x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /app/hook/config method: patch operationId: apps/update-webhook-config-for-app x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /app/hook/deliveries method: get operationId: apps/list-webhook-deliveries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /app/hook/deliveries/{delivery_id} method: get operationId: apps/get-webhook-delivery x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /app/hook/deliveries/{delivery_id}/attempts method: post operationId: apps/redeliver-webhook-delivery x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /app/installation-requests method: get operationId: apps/list-installation-requests-for-authenticated-app x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /app/installations method: get operationId: apps/list-installations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /app/installations/{installation_id} method: get operationId: apps/get-installation x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /app/installations/{installation_id} method: delete operationId: apps/delete-installation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /app/installations/{installation_id}/access_tokens method: post operationId: apps/create-installation-access-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /app/installations/{installation_id}/suspended method: put operationId: apps/suspend-installation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /app/installations/{installation_id}/suspended method: delete operationId: apps/unsuspend-installation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /applications/grants method: get operationId: oauth-authorizations/list-grants x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /applications/grants/{grant_id} method: get operationId: oauth-authorizations/get-grant x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /applications/grants/{grant_id} method: delete operationId: oauth-authorizations/delete-grant x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /applications/{client_id}/grant method: delete operationId: apps/delete-authorization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /applications/{client_id}/token method: post operationId: apps/check-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /applications/{client_id}/token method: patch operationId: apps/reset-token x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /applications/{client_id}/token method: delete operationId: apps/delete-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /applications/{client_id}/token/scoped method: post operationId: apps/scope-token x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apps/{app_slug} method: get operationId: apps/get-by-slug x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /authorizations method: get operationId: oauth-authorizations/list-authorizations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /authorizations method: post operationId: oauth-authorizations/create-authorization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /authorizations/clients/{client_id} method: put operationId: oauth-authorizations/get-or-create-authorization-for-app x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /authorizations/clients/{client_id}/{fingerprint} method: put operationId: oauth-authorizations/get-or-create-authorization-for-app-and-fingerprint x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /authorizations/{authorization_id} method: get operationId: oauth-authorizations/get-authorization x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /authorizations/{authorization_id} method: patch operationId: oauth-authorizations/update-authorization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /authorizations/{authorization_id} method: delete operationId: oauth-authorizations/delete-authorization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /codes_of_conduct method: get operationId: codes-of-conduct/get-all-codes-of-conduct x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /codes_of_conduct/{key} method: get operationId: codes-of-conduct/get-conduct-code x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /emojis method: get operationId: emojis/get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/announcement method: get operationId: enterprise-admin/get-announcement x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/announcement method: patch operationId: enterprise-admin/set-announcement x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprise/announcement method: delete operationId: enterprise-admin/remove-announcement x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprise/settings/license method: get operationId: enterprise-admin/get-license-information x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/stats/all method: get operationId: enterprise-admin/get-all-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/stats/comments method: get operationId: enterprise-admin/get-comment-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/stats/gists method: get operationId: enterprise-admin/get-gist-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/stats/hooks method: get operationId: enterprise-admin/get-hooks-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/stats/issues method: get operationId: enterprise-admin/get-issue-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/stats/milestones method: get operationId: enterprise-admin/get-milestone-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/stats/orgs method: get operationId: enterprise-admin/get-org-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/stats/pages method: get operationId: enterprise-admin/get-pages-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/stats/pulls method: get operationId: enterprise-admin/get-pull-request-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/stats/repos method: get operationId: enterprise-admin/get-repo-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprise/stats/users method: get operationId: enterprise-admin/get-user-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/cache/usage method: get operationId: actions/get-actions-cache-usage-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/cache/usage-policy method: get operationId: actions/get-actions-cache-usage-policy-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/cache/usage-policy method: patch operationId: actions/set-actions-cache-usage-policy-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/permissions method: get operationId: enterprise-admin/get-github-actions-permissions-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/permissions method: put operationId: enterprise-admin/set-github-actions-permissions-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/permissions/organizations method: get operationId: enterprise-admin/list-selected-organizations-enabled-github-actions-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/permissions/organizations method: put operationId: enterprise-admin/set-selected-organizations-enabled-github-actions-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/permissions/organizations/{org_id} method: put operationId: enterprise-admin/enable-selected-organization-github-actions-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/permissions/organizations/{org_id} method: delete operationId: enterprise-admin/disable-selected-organization-github-actions-enterprise x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /enterprises/{enterprise}/actions/permissions/selected-actions method: get operationId: enterprise-admin/get-allowed-actions-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/permissions/selected-actions method: put operationId: enterprise-admin/set-allowed-actions-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/permissions/workflow method: get operationId: actions/get-github-actions-default-workflow-permissions-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/permissions/workflow method: put operationId: actions/set-github-actions-default-workflow-permissions-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runner-groups method: get operationId: enterprise-admin/list-self-hosted-runner-groups-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/runner-groups method: post operationId: enterprise-admin/create-self-hosted-runner-group-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runner-groups/{runner_group_id} method: get operationId: enterprise-admin/get-self-hosted-runner-group-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/runner-groups/{runner_group_id} method: patch operationId: enterprise-admin/update-self-hosted-runner-group-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runner-groups/{runner_group_id} method: delete operationId: enterprise-admin/delete-self-hosted-runner-group-from-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runner-groups/{runner_group_id}/organizations method: get operationId: enterprise-admin/list-org-access-to-self-hosted-runner-group-in-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/runner-groups/{runner_group_id}/organizations method: put operationId: enterprise-admin/set-org-access-to-self-hosted-runner-group-in-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runner-groups/{runner_group_id}/organizations/{org_id} method: put operationId: enterprise-admin/add-org-access-to-self-hosted-runner-group-in-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runner-groups/{runner_group_id}/organizations/{org_id} method: delete operationId: enterprise-admin/remove-org-access-to-self-hosted-runner-group-in-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runner-groups/{runner_group_id}/runners method: get operationId: enterprise-admin/list-self-hosted-runners-in-group-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/runner-groups/{runner_group_id}/runners method: put operationId: enterprise-admin/set-self-hosted-runners-in-group-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runner-groups/{runner_group_id}/runners/{runner_id} method: put operationId: enterprise-admin/add-self-hosted-runner-to-group-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runner-groups/{runner_group_id}/runners/{runner_id} method: delete operationId: enterprise-admin/remove-self-hosted-runner-from-group-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runners method: get operationId: enterprise-admin/list-self-hosted-runners-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/runners/downloads method: get operationId: enterprise-admin/list-runner-applications-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/runners/registration-token method: post operationId: enterprise-admin/create-registration-token-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runners/remove-token method: post operationId: enterprise-admin/create-remove-token-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runners/{runner_id} method: get operationId: enterprise-admin/get-self-hosted-runner-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/runners/{runner_id} method: delete operationId: enterprise-admin/delete-self-hosted-runner-from-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runners/{runner_id}/labels method: get operationId: enterprise-admin/list-labels-for-self-hosted-runner-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/actions/runners/{runner_id}/labels method: post operationId: enterprise-admin/add-custom-labels-to-self-hosted-runner-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runners/{runner_id}/labels method: put operationId: enterprise-admin/set-custom-labels-for-self-hosted-runner-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runners/{runner_id}/labels method: delete operationId: enterprise-admin/remove-all-custom-labels-from-self-hosted-runner-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/actions/runners/{runner_id}/labels/{name} method: delete operationId: enterprise-admin/remove-custom-label-from-self-hosted-runner-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/audit-log method: get operationId: enterprise-admin/get-audit-log x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/code-scanning/alerts method: get operationId: code-scanning/list-alerts-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/code_security_and_analysis method: get operationId: secret-scanning/get-security-analysis-settings-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/code_security_and_analysis method: patch operationId: secret-scanning/patch-security-analysis-settings-for-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /enterprises/{enterprise}/dependabot/alerts method: get operationId: dependabot/list-alerts-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/secret-scanning/alerts method: get operationId: secret-scanning/list-alerts-for-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/settings/billing/advanced-security method: get operationId: billing/get-github-advanced-security-billing-ghe x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /enterprises/{enterprise}/{security_product}/{enablement} method: post operationId: secret-scanning/post-security-product-enablement-for-enterprise x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /events method: get operationId: activity/list-public-events x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /feeds method: get operationId: activity/get-feeds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /gists method: get operationId: gists/list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /gists method: post operationId: gists/create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /gists/public method: get operationId: gists/list-public x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /gists/starred method: get operationId: gists/list-starred x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /gists/{gist_id} method: get operationId: gists/get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /gists/{gist_id} method: patch operationId: gists/update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /gists/{gist_id} method: delete operationId: gists/delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /gists/{gist_id}/comments method: get operationId: gists/list-comments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /gists/{gist_id}/comments method: post operationId: gists/create-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /gists/{gist_id}/comments/{comment_id} method: get operationId: gists/get-comment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /gists/{gist_id}/comments/{comment_id} method: patch operationId: gists/update-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /gists/{gist_id}/comments/{comment_id} method: delete operationId: gists/delete-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /gists/{gist_id}/commits method: get operationId: gists/list-commits x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /gists/{gist_id}/forks method: get operationId: gists/list-forks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /gists/{gist_id}/forks method: post operationId: gists/fork x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /gists/{gist_id}/star method: get operationId: gists/check-is-starred x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /gists/{gist_id}/star method: put operationId: gists/star x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /gists/{gist_id}/star method: delete operationId: gists/unstar x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /gists/{gist_id}/{sha} method: get operationId: gists/get-revision x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /gitignore/templates method: get operationId: gitignore/get-all-templates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /gitignore/templates/{name} method: get operationId: gitignore/get-template x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /installation/repositories method: get operationId: apps/list-repos-accessible-to-installation x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /installation/token method: delete operationId: apps/revoke-installation-access-token x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /issues method: get operationId: issues/list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /licenses method: get operationId: licenses/get-all-commonly-used x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /licenses/{license} method: get operationId: licenses/get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /manage/v1/config/nodes method: get operationId: enterprise-admin/get-config-nodes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /manage/v1/replication/status method: get operationId: enterprise-admin/get-replication-status x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /manage/v1/version method: get operationId: enterprise-admin/get-version x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /markdown method: post operationId: markdown/render x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /markdown/raw method: post operationId: markdown/render-raw x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /meta method: get operationId: meta/get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /networks/{owner}/{repo}/events method: get operationId: activity/list-public-events-for-repo-network x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /notifications method: get operationId: activity/list-notifications-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /notifications method: put operationId: activity/mark-notifications-as-read x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /notifications/threads/{thread_id} method: get operationId: activity/get-thread x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /notifications/threads/{thread_id} method: patch operationId: activity/mark-thread-as-read x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /notifications/threads/{thread_id}/subscription method: get operationId: activity/get-thread-subscription-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /notifications/threads/{thread_id}/subscription method: put operationId: activity/set-thread-subscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /notifications/threads/{thread_id}/subscription method: delete operationId: activity/delete-thread-subscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /octocat method: get operationId: meta/get-octocat x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations method: get operationId: orgs/list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/{organization_id}/custom_roles method: get operationId: orgs/list-custom-roles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org} method: get operationId: orgs/get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org} method: patch operationId: orgs/update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org} method: delete operationId: orgs/delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/cache/usage method: get operationId: actions/get-actions-cache-usage-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/cache/usage-by-repository method: get operationId: actions/get-actions-cache-usage-by-repo-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/oidc/customization/sub method: get operationId: oidc/get-oidc-custom-sub-template-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/oidc/customization/sub method: put operationId: oidc/update-oidc-custom-sub-template-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/permissions method: get operationId: actions/get-github-actions-permissions-organization x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/permissions method: put operationId: actions/set-github-actions-permissions-organization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/permissions/repositories method: get operationId: actions/list-selected-repositories-enabled-github-actions-organization x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/permissions/repositories method: put operationId: actions/set-selected-repositories-enabled-github-actions-organization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/permissions/repositories/{repository_id} method: put operationId: actions/enable-selected-repository-github-actions-organization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/permissions/repositories/{repository_id} method: delete operationId: actions/disable-selected-repository-github-actions-organization x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /orgs/{org}/actions/permissions/selected-actions method: get operationId: actions/get-allowed-actions-organization x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/permissions/selected-actions method: put operationId: actions/set-allowed-actions-organization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/permissions/workflow method: get operationId: actions/get-github-actions-default-workflow-permissions-organization x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/permissions/workflow method: put operationId: actions/set-github-actions-default-workflow-permissions-organization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runner-groups method: get operationId: actions/list-self-hosted-runner-groups-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/runner-groups method: post operationId: actions/create-self-hosted-runner-group-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runner-groups/{runner_group_id} method: get operationId: actions/get-self-hosted-runner-group-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/runner-groups/{runner_group_id} method: patch operationId: actions/update-self-hosted-runner-group-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runner-groups/{runner_group_id} method: delete operationId: actions/delete-self-hosted-runner-group-from-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runner-groups/{runner_group_id}/repositories method: get operationId: actions/list-repo-access-to-self-hosted-runner-group-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/runner-groups/{runner_group_id}/repositories method: put operationId: actions/set-repo-access-to-self-hosted-runner-group-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runner-groups/{runner_group_id}/repositories/{repository_id} method: put operationId: actions/add-repo-access-to-self-hosted-runner-group-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runner-groups/{runner_group_id}/repositories/{repository_id} method: delete operationId: actions/remove-repo-access-to-self-hosted-runner-group-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runner-groups/{runner_group_id}/runners method: get operationId: actions/list-self-hosted-runners-in-group-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/runner-groups/{runner_group_id}/runners method: put operationId: actions/set-self-hosted-runners-in-group-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runner-groups/{runner_group_id}/runners/{runner_id} method: put operationId: actions/add-self-hosted-runner-to-group-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runner-groups/{runner_group_id}/runners/{runner_id} method: delete operationId: actions/remove-self-hosted-runner-from-group-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runners method: get operationId: actions/list-self-hosted-runners-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/runners/downloads method: get operationId: actions/list-runner-applications-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/runners/registration-token method: post operationId: actions/create-registration-token-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runners/remove-token method: post operationId: actions/create-remove-token-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runners/{runner_id} method: get operationId: actions/get-self-hosted-runner-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/runners/{runner_id} method: delete operationId: actions/delete-self-hosted-runner-from-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runners/{runner_id}/labels method: get operationId: actions/list-labels-for-self-hosted-runner-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/runners/{runner_id}/labels method: post operationId: actions/add-custom-labels-to-self-hosted-runner-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runners/{runner_id}/labels method: put operationId: actions/set-custom-labels-for-self-hosted-runner-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runners/{runner_id}/labels method: delete operationId: actions/remove-all-custom-labels-from-self-hosted-runner-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/runners/{runner_id}/labels/{name} method: delete operationId: actions/remove-custom-label-from-self-hosted-runner-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/secrets method: get operationId: actions/list-org-secrets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/secrets/public-key method: get operationId: actions/get-org-public-key x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/secrets/{secret_name} method: get operationId: actions/get-org-secret x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/secrets/{secret_name} method: put operationId: actions/create-or-update-org-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/secrets/{secret_name} method: delete operationId: actions/delete-org-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/secrets/{secret_name}/repositories method: get operationId: actions/list-selected-repos-for-org-secret x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/secrets/{secret_name}/repositories method: put operationId: actions/set-selected-repos-for-org-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/secrets/{secret_name}/repositories/{repository_id} method: put operationId: actions/add-selected-repo-to-org-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/secrets/{secret_name}/repositories/{repository_id} method: delete operationId: actions/remove-selected-repo-from-org-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/variables method: get operationId: actions/list-org-variables x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/variables method: post operationId: actions/create-org-variable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/variables/{name} method: get operationId: actions/get-org-variable x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/variables/{name} method: patch operationId: actions/update-org-variable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/variables/{name} method: delete operationId: actions/delete-org-variable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/variables/{name}/repositories method: get operationId: actions/list-selected-repos-for-org-variable x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/actions/variables/{name}/repositories method: put operationId: actions/set-selected-repos-for-org-variable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/variables/{name}/repositories/{repository_id} method: put operationId: actions/add-selected-repo-to-org-variable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/actions/variables/{name}/repositories/{repository_id} method: delete operationId: actions/remove-selected-repo-from-org-variable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/announcement method: get operationId: announcement-banners/get-announcement-banner-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/announcement method: patch operationId: announcement-banners/set-announcement-banner-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/announcement method: delete operationId: announcement-banners/remove-announcement-banner-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/audit-log method: get operationId: orgs/get-audit-log x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/code-scanning/alerts method: get operationId: code-scanning/list-alerts-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/custom-repository-roles method: get operationId: orgs/list-custom-repo-roles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/custom-repository-roles method: post operationId: orgs/create-custom-repo-role x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/custom-repository-roles/{role_id} method: get operationId: orgs/get-custom-repo-role x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/custom-repository-roles/{role_id} method: patch operationId: orgs/update-custom-repo-role x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/custom-repository-roles/{role_id} method: delete operationId: orgs/delete-custom-repo-role x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/dependabot/alerts method: get operationId: dependabot/list-alerts-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/dependabot/secrets method: get operationId: dependabot/list-org-secrets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/dependabot/secrets/public-key method: get operationId: dependabot/get-org-public-key x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/dependabot/secrets/{secret_name} method: get operationId: dependabot/get-org-secret x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/dependabot/secrets/{secret_name} method: put operationId: dependabot/create-or-update-org-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/dependabot/secrets/{secret_name} method: delete operationId: dependabot/delete-org-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/dependabot/secrets/{secret_name}/repositories method: get operationId: dependabot/list-selected-repos-for-org-secret x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/dependabot/secrets/{secret_name}/repositories method: put operationId: dependabot/set-selected-repos-for-org-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/dependabot/secrets/{secret_name}/repositories/{repository_id} method: put operationId: dependabot/add-selected-repo-to-org-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/dependabot/secrets/{secret_name}/repositories/{repository_id} method: delete operationId: dependabot/remove-selected-repo-from-org-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/docker/conflicts method: get operationId: packages/list-docker-migration-conflicting-packages-for-organization x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/events method: get operationId: activity/list-public-org-events x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/external-group/{group_id} method: get operationId: teams/external-idp-group-info-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/external-groups method: get operationId: teams/list-external-idp-groups-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/hooks method: get operationId: orgs/list-webhooks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/hooks method: post operationId: orgs/create-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/hooks/{hook_id} method: get operationId: orgs/get-webhook x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/hooks/{hook_id} method: patch operationId: orgs/update-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/hooks/{hook_id} method: delete operationId: orgs/delete-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/hooks/{hook_id}/config method: get operationId: orgs/get-webhook-config-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/hooks/{hook_id}/config method: patch operationId: orgs/update-webhook-config-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/hooks/{hook_id}/deliveries method: get operationId: orgs/list-webhook-deliveries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/hooks/{hook_id}/deliveries/{delivery_id} method: get operationId: orgs/get-webhook-delivery x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/hooks/{hook_id}/deliveries/{delivery_id}/attempts method: post operationId: orgs/redeliver-webhook-delivery x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/hooks/{hook_id}/pings method: post operationId: orgs/ping-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/installation method: get operationId: apps/get-org-installation x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/installations method: get operationId: orgs/list-app-installations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/issues method: get operationId: issues/list-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/members method: get operationId: orgs/list-members x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/members/{username} method: get operationId: orgs/check-membership-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/members/{username} method: delete operationId: orgs/remove-member x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/memberships/{username} method: get operationId: orgs/get-membership-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/memberships/{username} method: put operationId: orgs/set-membership-for-user x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/memberships/{username} method: delete operationId: orgs/remove-membership-for-user x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/migrations method: get operationId: migrations/list-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/migrations method: post operationId: migrations/start-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/migrations/{migration_id} method: get operationId: migrations/get-status-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/migrations/{migration_id}/archive method: get operationId: migrations/download-archive-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/migrations/{migration_id}/archive method: delete operationId: migrations/delete-archive-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/migrations/{migration_id}/repos/{repo_name}/lock method: delete operationId: migrations/unlock-repo-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/migrations/{migration_id}/repositories method: get operationId: migrations/list-repos-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/outside_collaborators method: get operationId: orgs/list-outside-collaborators x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/outside_collaborators/{username} method: put operationId: orgs/convert-member-to-outside-collaborator x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/outside_collaborators/{username} method: delete operationId: orgs/remove-outside-collaborator x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/packages method: get operationId: packages/list-packages-for-organization x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/packages/{package_type}/{package_name} method: get operationId: packages/get-package-for-organization x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/packages/{package_type}/{package_name} method: delete operationId: packages/delete-package-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/packages/{package_type}/{package_name}/restore method: post operationId: packages/restore-package-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/packages/{package_type}/{package_name}/versions method: get operationId: packages/get-all-package-versions-for-package-owned-by-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/packages/{package_type}/{package_name}/versions/{package_version_id} method: get operationId: packages/get-package-version-for-organization x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/packages/{package_type}/{package_name}/versions/{package_version_id} method: delete operationId: packages/delete-package-version-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/packages/{package_type}/{package_name}/versions/{package_version_id}/restore method: post operationId: packages/restore-package-version-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/pre-receive-hooks method: get operationId: enterprise-admin/list-pre-receive-hooks-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/pre-receive-hooks/{pre_receive_hook_id} method: get operationId: enterprise-admin/get-pre-receive-hook-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/pre-receive-hooks/{pre_receive_hook_id} method: patch operationId: enterprise-admin/update-pre-receive-hook-enforcement-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/pre-receive-hooks/{pre_receive_hook_id} method: delete operationId: enterprise-admin/remove-pre-receive-hook-enforcement-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/projects method: get operationId: projects/list-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/projects method: post operationId: projects/create-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/public_members method: get operationId: orgs/list-public-members x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/public_members/{username} method: get operationId: orgs/check-public-membership-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/public_members/{username} method: put operationId: orgs/set-public-membership-for-authenticated-user x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/public_members/{username} method: delete operationId: orgs/remove-public-membership-for-authenticated-user x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/repos method: get operationId: repos/list-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/repos method: post operationId: repos/create-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/repository-fine-grained-permissions method: get operationId: orgs/list-repo-fine-grained-permissions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/secret-scanning/alerts method: get operationId: secret-scanning/list-alerts-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/security-managers method: get operationId: orgs/list-security-manager-teams x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/security-managers/teams/{team_slug} method: put operationId: orgs/add-security-manager-team x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/security-managers/teams/{team_slug} method: delete operationId: orgs/remove-security-manager-team x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/settings/billing/advanced-security method: get operationId: billing/get-github-advanced-security-billing-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams method: get operationId: teams/list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams method: post operationId: teams/create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug} method: get operationId: teams/get-by-name x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug} method: patch operationId: teams/update-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug} method: delete operationId: teams/delete-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/discussions method: get operationId: teams/list-discussions-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/discussions method: post operationId: teams/create-discussion-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number} method: get operationId: teams/get-discussion-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number} method: patch operationId: teams/update-discussion-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number} method: delete operationId: teams/delete-discussion-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number}/comments method: get operationId: teams/list-discussion-comments-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number}/comments method: post operationId: teams/create-discussion-comment-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number}/comments/{comment_number} method: get operationId: teams/get-discussion-comment-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number}/comments/{comment_number} method: patch operationId: teams/update-discussion-comment-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number}/comments/{comment_number} method: delete operationId: teams/delete-discussion-comment-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number}/comments/{comment_number}/reactions method: get operationId: reactions/list-for-team-discussion-comment-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number}/comments/{comment_number}/reactions method: post operationId: reactions/create-for-team-discussion-comment-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number}/comments/{comment_number}/reactions/{reaction_id} method: delete operationId: reactions/delete-for-team-discussion-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number}/reactions method: get operationId: reactions/list-for-team-discussion-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number}/reactions method: post operationId: reactions/create-for-team-discussion-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/discussions/{discussion_number}/reactions/{reaction_id} method: delete operationId: reactions/delete-for-team-discussion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/external-groups method: get operationId: teams/list-linked-external-idp-groups-to-team-for-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/external-groups method: patch operationId: teams/link-external-idp-group-to-team-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/external-groups method: delete operationId: teams/unlink-external-idp-group-from-team-for-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/members method: get operationId: teams/list-members-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/memberships/{username} method: get operationId: teams/get-membership-for-user-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/memberships/{username} method: put operationId: teams/add-or-update-membership-for-user-in-org x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/memberships/{username} method: delete operationId: teams/remove-membership-for-user-in-org x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/projects method: get operationId: teams/list-projects-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/projects/{project_id} method: get operationId: teams/check-permissions-for-project-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/projects/{project_id} method: put operationId: teams/add-or-update-project-permissions-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/projects/{project_id} method: delete operationId: teams/remove-project-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/repos method: get operationId: teams/list-repos-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/repos/{owner}/{repo} method: get operationId: teams/check-permissions-for-repo-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/teams/{team_slug}/repos/{owner}/{repo} method: put operationId: teams/add-or-update-repo-permissions-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/repos/{owner}/{repo} method: delete operationId: teams/remove-repo-in-org x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgs/{org}/teams/{team_slug}/teams method: get operationId: teams/list-child-in-org x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgs/{org}/{security_product}/{enablement} method: post operationId: orgs/enable-or-disable-security-product-on-all-org-repos x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /projects/columns/cards/{card_id} method: get operationId: projects/get-card x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /projects/columns/cards/{card_id} method: patch operationId: projects/update-card x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/columns/cards/{card_id} method: delete operationId: projects/delete-card x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/columns/cards/{card_id}/moves method: post operationId: projects/move-card x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/columns/{column_id} method: get operationId: projects/get-column x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /projects/columns/{column_id} method: patch operationId: projects/update-column x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/columns/{column_id} method: delete operationId: projects/delete-column x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/columns/{column_id}/cards method: get operationId: projects/list-cards x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /projects/columns/{column_id}/cards method: post operationId: projects/create-card x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/columns/{column_id}/moves method: post operationId: projects/move-column x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{project_id} method: get operationId: projects/get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /projects/{project_id} method: patch operationId: projects/update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{project_id} method: delete operationId: projects/delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{project_id}/collaborators method: get operationId: projects/list-collaborators x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /projects/{project_id}/collaborators/{username} method: put operationId: projects/add-collaborator x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{project_id}/collaborators/{username} method: delete operationId: projects/remove-collaborator x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{project_id}/collaborators/{username}/permission method: get operationId: projects/get-permission-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /projects/{project_id}/columns method: get operationId: projects/list-columns x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /projects/{project_id}/columns method: post operationId: projects/create-column x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /rate_limit method: get operationId: rate-limit/get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo} method: get operationId: repos/get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo} method: patch operationId: repos/update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo} method: delete operationId: repos/delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/artifacts method: get operationId: actions/list-artifacts-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/artifacts/{artifact_id} method: get operationId: actions/get-artifact x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/artifacts/{artifact_id} method: delete operationId: actions/delete-artifact x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/artifacts/{artifact_id}/{archive_format} method: get operationId: actions/download-artifact x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/cache/usage method: get operationId: actions/get-actions-cache-usage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/cache/usage-policy method: get operationId: actions/get-actions-cache-usage-policy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/cache/usage-policy method: patch operationId: actions/set-actions-cache-usage-policy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/caches method: get operationId: actions/get-actions-cache-list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/caches method: delete operationId: actions/delete-actions-cache-by-key x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/caches/{cache_id} method: delete operationId: actions/delete-actions-cache-by-id x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/jobs/{job_id} method: get operationId: actions/get-job-for-workflow-run x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/jobs/{job_id}/logs method: get operationId: actions/download-job-logs-for-workflow-run x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/jobs/{job_id}/rerun method: post operationId: actions/re-run-job-for-workflow-run x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/oidc/customization/sub method: get operationId: actions/get-custom-oidc-sub-claim-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/oidc/customization/sub method: put operationId: actions/set-custom-oidc-sub-claim-for-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/organization-secrets method: get operationId: actions/list-repo-organization-secrets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/organization-variables method: get operationId: actions/list-repo-organization-variables x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/permissions method: get operationId: actions/get-github-actions-permissions-repository x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/permissions method: put operationId: actions/set-github-actions-permissions-repository x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/permissions/access method: get operationId: actions/get-workflow-access-to-repository x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/permissions/access method: put operationId: actions/set-workflow-access-to-repository x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/permissions/selected-actions method: get operationId: actions/get-allowed-actions-repository x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/permissions/selected-actions method: put operationId: actions/set-allowed-actions-repository x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/permissions/workflow method: get operationId: actions/get-github-actions-default-workflow-permissions-repository x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/permissions/workflow method: put operationId: actions/set-github-actions-default-workflow-permissions-repository x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runners method: get operationId: actions/list-self-hosted-runners-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runners/downloads method: get operationId: actions/list-runner-applications-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runners/registration-token method: post operationId: actions/create-registration-token-for-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runners/remove-token method: post operationId: actions/create-remove-token-for-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runners/{runner_id} method: get operationId: actions/get-self-hosted-runner-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runners/{runner_id} method: delete operationId: actions/delete-self-hosted-runner-from-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runners/{runner_id}/labels method: get operationId: actions/list-labels-for-self-hosted-runner-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runners/{runner_id}/labels method: post operationId: actions/add-custom-labels-to-self-hosted-runner-for-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runners/{runner_id}/labels method: put operationId: actions/set-custom-labels-for-self-hosted-runner-for-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runners/{runner_id}/labels method: delete operationId: actions/remove-all-custom-labels-from-self-hosted-runner-for-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runners/{runner_id}/labels/{name} method: delete operationId: actions/remove-custom-label-from-self-hosted-runner-for-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runs method: get operationId: actions/list-workflow-runs-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runs/{run_id} method: get operationId: actions/get-workflow-run x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runs/{run_id} method: delete operationId: actions/delete-workflow-run x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runs/{run_id}/approvals method: get operationId: actions/get-reviews-for-run x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runs/{run_id}/artifacts method: get operationId: actions/list-workflow-run-artifacts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runs/{run_id}/attempts/{attempt_number} method: get operationId: actions/get-workflow-run-attempt x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runs/{run_id}/attempts/{attempt_number}/jobs method: get operationId: actions/list-jobs-for-workflow-run-attempt x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runs/{run_id}/attempts/{attempt_number}/logs method: get operationId: actions/download-workflow-run-attempt-logs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runs/{run_id}/cancel method: post operationId: actions/cancel-workflow-run x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runs/{run_id}/jobs method: get operationId: actions/list-jobs-for-workflow-run x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runs/{run_id}/logs method: get operationId: actions/download-workflow-run-logs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runs/{run_id}/logs method: delete operationId: actions/delete-workflow-run-logs x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runs/{run_id}/pending_deployments method: get operationId: actions/get-pending-deployments-for-run x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/runs/{run_id}/pending_deployments method: post operationId: actions/review-pending-deployments-for-run x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runs/{run_id}/rerun method: post operationId: actions/re-run-workflow x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/runs/{run_id}/rerun-failed-jobs method: post operationId: actions/re-run-workflow-failed-jobs x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/secrets method: get operationId: actions/list-repo-secrets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/secrets/public-key method: get operationId: actions/get-repo-public-key x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/secrets/{secret_name} method: get operationId: actions/get-repo-secret x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/secrets/{secret_name} method: put operationId: actions/create-or-update-repo-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/secrets/{secret_name} method: delete operationId: actions/delete-repo-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/variables method: get operationId: actions/list-repo-variables x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/variables method: post operationId: actions/create-repo-variable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/variables/{name} method: get operationId: actions/get-repo-variable x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/variables/{name} method: patch operationId: actions/update-repo-variable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/variables/{name} method: delete operationId: actions/delete-repo-variable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/workflows method: get operationId: actions/list-repo-workflows x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/workflows/{workflow_id} method: get operationId: actions/get-workflow x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/actions/workflows/{workflow_id}/disable method: put operationId: actions/disable-workflow x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /repos/{owner}/{repo}/actions/workflows/{workflow_id}/dispatches method: post operationId: actions/create-workflow-dispatch x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /repos/{owner}/{repo}/actions/workflows/{workflow_id}/enable method: put operationId: actions/enable-workflow x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs method: get operationId: actions/list-workflow-runs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/assignees method: get operationId: issues/list-assignees x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/assignees/{assignee} method: get operationId: issues/check-user-can-be-assigned x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/autolinks method: get operationId: repos/list-autolinks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/autolinks method: post operationId: repos/create-autolink x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/autolinks/{autolink_id} method: get operationId: repos/get-autolink x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/autolinks/{autolink_id} method: delete operationId: repos/delete-autolink x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches method: get operationId: repos/list-branches x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/branches/{branch} method: get operationId: repos/get-branch x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/branches/{branch}/protection method: get operationId: repos/get-branch-protection x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/branches/{branch}/protection method: put operationId: repos/update-branch-protection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection method: delete operationId: repos/delete-branch-protection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/enforce_admins method: get operationId: repos/get-admin-branch-protection x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/branches/{branch}/protection/enforce_admins method: post operationId: repos/set-admin-branch-protection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/enforce_admins method: delete operationId: repos/delete-admin-branch-protection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_pull_request_reviews method: get operationId: repos/get-pull-request-review-protection x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_pull_request_reviews method: patch operationId: repos/update-pull-request-review-protection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_pull_request_reviews method: delete operationId: repos/delete-pull-request-review-protection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_signatures method: get operationId: repos/get-commit-signature-protection x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_signatures method: post operationId: repos/create-commit-signature-protection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_signatures method: delete operationId: repos/delete-commit-signature-protection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_status_checks method: get operationId: repos/get-status-checks-protection x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_status_checks method: patch operationId: repos/update-status-check-protection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_status_checks method: delete operationId: repos/remove-status-check-protection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_status_checks/contexts method: get operationId: repos/get-all-status-check-contexts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_status_checks/contexts method: post operationId: repos/add-status-check-contexts x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_status_checks/contexts method: put operationId: repos/set-status-check-contexts x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/required_status_checks/contexts method: delete operationId: repos/remove-status-check-contexts x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions method: get operationId: repos/get-access-restrictions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions method: delete operationId: repos/delete-access-restrictions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/apps method: get operationId: repos/get-apps-with-access-to-protected-branch x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/apps method: post operationId: repos/add-app-access-restrictions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/apps method: put operationId: repos/set-app-access-restrictions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/apps method: delete operationId: repos/remove-app-access-restrictions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/teams method: get operationId: repos/get-teams-with-access-to-protected-branch x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/teams method: post operationId: repos/add-team-access-restrictions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/teams method: put operationId: repos/set-team-access-restrictions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/teams method: delete operationId: repos/remove-team-access-restrictions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/users method: get operationId: repos/get-users-with-access-to-protected-branch x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/users method: post operationId: repos/add-user-access-restrictions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/users method: put operationId: repos/set-user-access-restrictions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/protection/restrictions/users method: delete operationId: repos/remove-user-access-restrictions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/branches/{branch}/rename method: post operationId: repos/rename-branch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/check-runs method: post operationId: checks/create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/check-runs/{check_run_id} method: get operationId: checks/get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/check-runs/{check_run_id} method: patch operationId: checks/update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/check-runs/{check_run_id}/annotations method: get operationId: checks/list-annotations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/check-runs/{check_run_id}/rerequest method: post operationId: checks/rerequest-run x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/check-suites method: post operationId: checks/create-suite x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/check-suites/preferences method: patch operationId: checks/set-suites-preferences x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/check-suites/{check_suite_id} method: get operationId: checks/get-suite x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/check-suites/{check_suite_id}/check-runs method: get operationId: checks/list-for-suite x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/check-suites/{check_suite_id}/rerequest method: post operationId: checks/rerequest-suite x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/code-scanning/alerts method: get operationId: code-scanning/list-alerts-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/code-scanning/alerts/{alert_number} method: get operationId: code-scanning/get-alert x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/code-scanning/alerts/{alert_number} method: patch operationId: code-scanning/update-alert x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/code-scanning/alerts/{alert_number}/instances method: get operationId: code-scanning/list-alert-instances x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/code-scanning/analyses method: get operationId: code-scanning/list-recent-analyses x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/code-scanning/analyses/{analysis_id} method: get operationId: code-scanning/get-analysis x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/code-scanning/analyses/{analysis_id} method: delete operationId: code-scanning/delete-analysis x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/code-scanning/default-setup method: get operationId: code-scanning/get-default-setup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/code-scanning/default-setup method: patch operationId: code-scanning/update-default-setup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/code-scanning/sarifs method: post operationId: code-scanning/upload-sarif x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/code-scanning/sarifs/{sarif_id} method: get operationId: code-scanning/get-sarif x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/codeowners/errors method: get operationId: repos/codeowners-errors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/collaborators method: get operationId: repos/list-collaborators x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/collaborators/{username} method: get operationId: repos/check-collaborator x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/collaborators/{username} method: put operationId: repos/add-collaborator x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/collaborators/{username} method: delete operationId: repos/remove-collaborator x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/collaborators/{username}/permission method: get operationId: repos/get-collaborator-permission-level x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/comments method: get operationId: repos/list-commit-comments-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/comments/{comment_id} method: get operationId: repos/get-commit-comment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/comments/{comment_id} method: patch operationId: repos/update-commit-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/comments/{comment_id} method: delete operationId: repos/delete-commit-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/comments/{comment_id}/reactions method: get operationId: reactions/list-for-commit-comment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/comments/{comment_id}/reactions method: post operationId: reactions/create-for-commit-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/comments/{comment_id}/reactions/{reaction_id} method: delete operationId: reactions/delete-for-commit-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/commits method: get operationId: repos/list-commits x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/commits/{commit_sha}/branches-where-head method: get operationId: repos/list-branches-for-head-commit x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/commits/{commit_sha}/comments method: get operationId: repos/list-comments-for-commit x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/commits/{commit_sha}/comments method: post operationId: repos/create-commit-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/commits/{commit_sha}/pulls method: get operationId: repos/list-pull-requests-associated-with-commit x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/commits/{ref} method: get operationId: repos/get-commit x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/commits/{ref}/check-runs method: get operationId: checks/list-for-ref x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/commits/{ref}/check-suites method: get operationId: checks/list-suites-for-ref x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/commits/{ref}/status method: get operationId: repos/get-combined-status-for-ref x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/commits/{ref}/statuses method: get operationId: repos/list-commit-statuses-for-ref x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/compare/{basehead} method: get operationId: repos/compare-commits x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/contents/{path} method: get operationId: repos/get-content x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/contents/{path} method: put operationId: repos/create-or-update-file-contents x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/contents/{path} method: delete operationId: repos/delete-file x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/contributors method: get operationId: repos/list-contributors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/dependabot/alerts method: get operationId: dependabot/list-alerts-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/dependabot/alerts/{alert_number} method: get operationId: dependabot/get-alert x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/dependabot/alerts/{alert_number} method: patch operationId: dependabot/update-alert x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/dependabot/secrets method: get operationId: dependabot/list-repo-secrets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/dependabot/secrets/public-key method: get operationId: dependabot/get-repo-public-key x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/dependabot/secrets/{secret_name} method: get operationId: dependabot/get-repo-secret x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/dependabot/secrets/{secret_name} method: put operationId: dependabot/create-or-update-repo-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/dependabot/secrets/{secret_name} method: delete operationId: dependabot/delete-repo-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/dependency-graph/compare/{basehead} method: get operationId: dependency-graph/diff-range x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/dependency-graph/sbom method: get operationId: dependency-graph/export-sbom x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/dependency-graph/snapshots method: post operationId: dependency-graph/create-repository-snapshot x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/deployments method: get operationId: repos/list-deployments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/deployments method: post operationId: repos/create-deployment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/deployments/{deployment_id} method: get operationId: repos/get-deployment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/deployments/{deployment_id} method: delete operationId: repos/delete-deployment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/deployments/{deployment_id}/statuses method: get operationId: repos/list-deployment-statuses x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/deployments/{deployment_id}/statuses method: post operationId: repos/create-deployment-status x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/deployments/{deployment_id}/statuses/{status_id} method: get operationId: repos/get-deployment-status x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/dispatches method: post operationId: repos/create-dispatch-event x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /repos/{owner}/{repo}/environments method: get operationId: repos/get-all-environments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/environments/{environment_name} method: get operationId: repos/get-environment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/environments/{environment_name} method: put operationId: repos/create-or-update-environment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/environments/{environment_name} method: delete operationId: repos/delete-an-environment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/environments/{environment_name}/deployment-branch-policies method: get operationId: repos/list-deployment-branch-policies x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/environments/{environment_name}/deployment-branch-policies method: post operationId: repos/create-deployment-branch-policy x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/environments/{environment_name}/deployment-branch-policies/{branch_policy_id} method: get operationId: repos/get-deployment-branch-policy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/environments/{environment_name}/deployment-branch-policies/{branch_policy_id} method: put operationId: repos/update-deployment-branch-policy x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/environments/{environment_name}/deployment-branch-policies/{branch_policy_id} method: delete operationId: repos/delete-deployment-branch-policy x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/environments/{environment_name}/secrets method: get operationId: actions/list-environment-secrets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/environments/{environment_name}/secrets/public-key method: get operationId: actions/get-environment-public-key x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/environments/{environment_name}/secrets/{secret_name} method: get operationId: actions/get-environment-secret x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/environments/{environment_name}/secrets/{secret_name} method: put operationId: actions/create-or-update-environment-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/environments/{environment_name}/secrets/{secret_name} method: delete operationId: actions/delete-environment-secret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/environments/{environment_name}/variables method: get operationId: actions/list-environment-variables x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/environments/{environment_name}/variables method: post operationId: actions/create-environment-variable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/environments/{environment_name}/variables/{name} method: get operationId: actions/get-environment-variable x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/environments/{environment_name}/variables/{name} method: patch operationId: actions/update-environment-variable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/environments/{environment_name}/variables/{name} method: delete operationId: actions/delete-environment-variable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/events method: get operationId: activity/list-repo-events x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/forks method: get operationId: repos/list-forks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/forks method: post operationId: repos/create-fork x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/git/blobs method: post operationId: git/create-blob x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/git/blobs/{file_sha} method: get operationId: git/get-blob x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/git/commits method: post operationId: git/create-commit x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/git/commits/{commit_sha} method: get operationId: git/get-commit x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/git/matching-refs/{ref} method: get operationId: git/list-matching-refs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/git/ref/{ref} method: get operationId: git/get-ref x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/git/refs method: post operationId: git/create-ref x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/git/refs/{ref} method: patch operationId: git/update-ref x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/git/refs/{ref} method: delete operationId: git/delete-ref x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/git/tags method: post operationId: git/create-tag x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/git/tags/{tag_sha} method: get operationId: git/get-tag x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/git/trees method: post operationId: git/create-tree x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/git/trees/{tree_sha} method: get operationId: git/get-tree x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/hooks method: get operationId: repos/list-webhooks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/hooks method: post operationId: repos/create-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/hooks/{hook_id} method: get operationId: repos/get-webhook x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/hooks/{hook_id} method: patch operationId: repos/update-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/hooks/{hook_id} method: delete operationId: repos/delete-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/hooks/{hook_id}/config method: get operationId: repos/get-webhook-config-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/hooks/{hook_id}/config method: patch operationId: repos/update-webhook-config-for-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/hooks/{hook_id}/deliveries method: get operationId: repos/list-webhook-deliveries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/hooks/{hook_id}/deliveries/{delivery_id} method: get operationId: repos/get-webhook-delivery x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/hooks/{hook_id}/deliveries/{delivery_id}/attempts method: post operationId: repos/redeliver-webhook-delivery x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/hooks/{hook_id}/pings method: post operationId: repos/ping-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/hooks/{hook_id}/tests method: post operationId: repos/test-push-webhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/installation method: get operationId: apps/get-repo-installation x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/invitations method: get operationId: repos/list-invitations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/invitations/{invitation_id} method: patch operationId: repos/update-invitation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/invitations/{invitation_id} method: delete operationId: repos/delete-invitation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues method: get operationId: issues/list-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/issues method: post operationId: issues/create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/comments method: get operationId: issues/list-comments-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/issues/comments/{comment_id} method: get operationId: issues/get-comment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/issues/comments/{comment_id} method: patch operationId: issues/update-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/comments/{comment_id} method: delete operationId: issues/delete-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/comments/{comment_id}/reactions method: get operationId: reactions/list-for-issue-comment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/issues/comments/{comment_id}/reactions method: post operationId: reactions/create-for-issue-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/comments/{comment_id}/reactions/{reaction_id} method: delete operationId: reactions/delete-for-issue-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/events method: get operationId: issues/list-events-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/issues/events/{event_id} method: get operationId: issues/get-event x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/issues/{issue_number} method: get operationId: issues/get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/issues/{issue_number} method: patch operationId: issues/update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/{issue_number}/assignees method: post operationId: issues/add-assignees x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/{issue_number}/assignees method: delete operationId: issues/remove-assignees x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/{issue_number}/assignees/{assignee} method: get operationId: issues/check-user-can-be-assigned-to-issue x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/issues/{issue_number}/comments method: get operationId: issues/list-comments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/issues/{issue_number}/comments method: post operationId: issues/create-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/{issue_number}/events method: get operationId: issues/list-events x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/issues/{issue_number}/labels method: get operationId: issues/list-labels-on-issue x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/issues/{issue_number}/labels method: post operationId: issues/add-labels x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/{issue_number}/labels method: put operationId: issues/set-labels x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/{issue_number}/labels method: delete operationId: issues/remove-all-labels x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/{issue_number}/labels/{name} method: delete operationId: issues/remove-label x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/{issue_number}/lock method: put operationId: issues/lock x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/{issue_number}/lock method: delete operationId: issues/unlock x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/{issue_number}/reactions method: get operationId: reactions/list-for-issue x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/issues/{issue_number}/reactions method: post operationId: reactions/create-for-issue x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/{issue_number}/reactions/{reaction_id} method: delete operationId: reactions/delete-for-issue x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/issues/{issue_number}/timeline method: get operationId: issues/list-events-for-timeline x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/keys method: get operationId: repos/list-deploy-keys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/keys method: post operationId: repos/create-deploy-key x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/keys/{key_id} method: get operationId: repos/get-deploy-key x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/keys/{key_id} method: delete operationId: repos/delete-deploy-key x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/labels method: get operationId: issues/list-labels-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/labels method: post operationId: issues/create-label x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/labels/{name} method: get operationId: issues/get-label x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/labels/{name} method: patch operationId: issues/update-label x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/labels/{name} method: delete operationId: issues/delete-label x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/languages method: get operationId: repos/list-languages x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/lfs method: put operationId: repos/enable-lfs-for-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/lfs method: delete operationId: repos/disable-lfs-for-repo x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /repos/{owner}/{repo}/license method: get operationId: licenses/get-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/merge-upstream method: post operationId: repos/merge-upstream x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/merges method: post operationId: repos/merge x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/milestones method: get operationId: issues/list-milestones x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/milestones method: post operationId: issues/create-milestone x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/milestones/{milestone_number} method: get operationId: issues/get-milestone x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/milestones/{milestone_number} method: patch operationId: issues/update-milestone x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/milestones/{milestone_number} method: delete operationId: issues/delete-milestone x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/milestones/{milestone_number}/labels method: get operationId: issues/list-labels-for-milestone x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/notifications method: get operationId: activity/list-repo-notifications-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/notifications method: put operationId: activity/mark-repo-notifications-as-read x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pages method: get operationId: repos/get-pages x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pages method: post operationId: repos/create-pages-site x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pages method: put operationId: repos/update-information-about-pages-site x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pages method: delete operationId: repos/delete-pages-site x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pages/builds method: get operationId: repos/list-pages-builds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pages/builds method: post operationId: repos/request-pages-build x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pages/builds/latest method: get operationId: repos/get-latest-pages-build x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pages/builds/{build_id} method: get operationId: repos/get-pages-build x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pages/deployments method: post operationId: repos/create-pages-deployment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pre-receive-hooks method: get operationId: enterprise-admin/list-pre-receive-hooks-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pre-receive-hooks/{pre_receive_hook_id} method: get operationId: enterprise-admin/get-pre-receive-hook-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pre-receive-hooks/{pre_receive_hook_id} method: patch operationId: enterprise-admin/update-pre-receive-hook-enforcement-for-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pre-receive-hooks/{pre_receive_hook_id} method: delete operationId: enterprise-admin/remove-pre-receive-hook-enforcement-for-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/projects method: get operationId: projects/list-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/projects method: post operationId: projects/create-for-repo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls method: get operationId: pulls/list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls method: post operationId: pulls/create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/comments method: get operationId: pulls/list-review-comments-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls/comments/{comment_id} method: get operationId: pulls/get-review-comment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls/comments/{comment_id} method: patch operationId: pulls/update-review-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/comments/{comment_id} method: delete operationId: pulls/delete-review-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/comments/{comment_id}/reactions method: get operationId: reactions/list-for-pull-request-review-comment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls/comments/{comment_id}/reactions method: post operationId: reactions/create-for-pull-request-review-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/comments/{comment_id}/reactions/{reaction_id} method: delete operationId: reactions/delete-for-pull-request-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/{pull_number} method: get operationId: pulls/get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls/{pull_number} method: patch operationId: pulls/update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/{pull_number}/comments method: get operationId: pulls/list-review-comments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls/{pull_number}/comments method: post operationId: pulls/create-review-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/{pull_number}/comments/{comment_id}/replies method: post operationId: pulls/create-reply-for-review-comment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/{pull_number}/commits method: get operationId: pulls/list-commits x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls/{pull_number}/files method: get operationId: pulls/list-files x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls/{pull_number}/merge method: get operationId: pulls/check-if-merged x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls/{pull_number}/merge method: put operationId: pulls/merge x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/{pull_number}/requested_reviewers method: get operationId: pulls/list-requested-reviewers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls/{pull_number}/requested_reviewers method: post operationId: pulls/request-reviewers x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/{pull_number}/requested_reviewers method: delete operationId: pulls/remove-requested-reviewers x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/{pull_number}/reviews method: get operationId: pulls/list-reviews x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls/{pull_number}/reviews method: post operationId: pulls/create-review x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/{pull_number}/reviews/{review_id} method: get operationId: pulls/get-review x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls/{pull_number}/reviews/{review_id} method: put operationId: pulls/update-review x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/{pull_number}/reviews/{review_id} method: delete operationId: pulls/delete-pending-review x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/{pull_number}/reviews/{review_id}/comments method: get operationId: pulls/list-comments-for-review x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/pulls/{pull_number}/reviews/{review_id}/dismissals method: put operationId: pulls/dismiss-review x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/{pull_number}/reviews/{review_id}/events method: post operationId: pulls/submit-review x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/pulls/{pull_number}/update-branch method: put operationId: pulls/update-branch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/readme method: get operationId: repos/get-readme x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/readme/{dir} method: get operationId: repos/get-readme-in-directory x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/releases method: get operationId: repos/list-releases x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/releases method: post operationId: repos/create-release x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/releases/assets/{asset_id} method: get operationId: repos/get-release-asset x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/releases/assets/{asset_id} method: patch operationId: repos/update-release-asset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/releases/assets/{asset_id} method: delete operationId: repos/delete-release-asset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/releases/generate-notes method: post operationId: repos/generate-release-notes x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/releases/latest method: get operationId: repos/get-latest-release x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/releases/tags/{tag} method: get operationId: repos/get-release-by-tag x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/releases/{release_id} method: get operationId: repos/get-release x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/releases/{release_id} method: patch operationId: repos/update-release x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/releases/{release_id} method: delete operationId: repos/delete-release x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/releases/{release_id}/assets method: get operationId: repos/list-release-assets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/releases/{release_id}/assets method: post operationId: repos/upload-release-asset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/releases/{release_id}/reactions method: get operationId: reactions/list-for-release x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/releases/{release_id}/reactions method: post operationId: reactions/create-for-release x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/releases/{release_id}/reactions/{reaction_id} method: delete operationId: reactions/delete-for-release x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/replicas/caches method: get operationId: repos/list-cache-info x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/secret-scanning/alerts method: get operationId: secret-scanning/list-alerts-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/secret-scanning/alerts/{alert_number} method: get operationId: secret-scanning/get-alert x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/secret-scanning/alerts/{alert_number} method: patch operationId: secret-scanning/update-alert x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/secret-scanning/alerts/{alert_number}/locations method: get operationId: secret-scanning/list-locations-for-alert x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/stargazers method: get operationId: activity/list-stargazers-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/stats/code_frequency method: get operationId: repos/get-code-frequency-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/stats/commit_activity method: get operationId: repos/get-commit-activity-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/stats/contributors method: get operationId: repos/get-contributors-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/stats/participation method: get operationId: repos/get-participation-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/stats/punch_card method: get operationId: repos/get-punch-card-stats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/statuses/{sha} method: post operationId: repos/create-commit-status x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/subscribers method: get operationId: activity/list-watchers-for-repo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/subscription method: get operationId: activity/get-repo-subscription x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/subscription method: put operationId: activity/set-repo-subscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/subscription method: delete operationId: activity/delete-repo-subscription x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/tags method: get operationId: repos/list-tags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/tags/protection method: get operationId: repos/list-tag-protection x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/tags/protection method: post operationId: repos/create-tag-protection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/tags/protection/{tag_protection_id} method: delete operationId: repos/delete-tag-protection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/tarball/{ref} method: get operationId: repos/download-tarball-archive x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/teams method: get operationId: repos/list-teams x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/topics method: get operationId: repos/get-all-topics x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/topics method: put operationId: repos/replace-all-topics x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/transfer method: post operationId: repos/transfer x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/vulnerability-alerts method: get operationId: repos/check-vulnerability-alerts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{owner}/{repo}/vulnerability-alerts method: put operationId: repos/enable-vulnerability-alerts x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repos/{owner}/{repo}/vulnerability-alerts method: delete operationId: repos/disable-vulnerability-alerts x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /repos/{owner}/{repo}/zipball/{ref} method: get operationId: repos/download-zipball-archive x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /repos/{template_owner}/{template_repo}/generate method: post operationId: repos/create-using-template x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /repositories method: get operationId: repos/list-public x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scim/v2/enterprises/{enterprise}/Groups method: get operationId: enterprise-admin/list-provisioned-groups-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scim/v2/enterprises/{enterprise}/Groups method: post operationId: enterprise-admin/provision-enterprise-group x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scim/v2/enterprises/{enterprise}/Groups/{scim_group_id} method: get operationId: enterprise-admin/get-provisioning-information-for-enterprise-group x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scim/v2/enterprises/{enterprise}/Groups/{scim_group_id} method: put operationId: enterprise-admin/set-information-for-provisioned-enterprise-group x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scim/v2/enterprises/{enterprise}/Groups/{scim_group_id} method: patch operationId: enterprise-admin/update-attribute-for-enterprise-group x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scim/v2/enterprises/{enterprise}/Groups/{scim_group_id} method: delete operationId: enterprise-admin/delete-scim-group-from-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scim/v2/enterprises/{enterprise}/Users method: get operationId: enterprise-admin/list-provisioned-identities-enterprise x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scim/v2/enterprises/{enterprise}/Users method: post operationId: enterprise-admin/provision-enterprise-user x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scim/v2/enterprises/{enterprise}/Users/{scim_user_id} method: get operationId: enterprise-admin/get-provisioning-information-for-enterprise-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scim/v2/enterprises/{enterprise}/Users/{scim_user_id} method: put operationId: enterprise-admin/set-information-for-provisioned-enterprise-user x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scim/v2/enterprises/{enterprise}/Users/{scim_user_id} method: patch operationId: enterprise-admin/update-attribute-for-enterprise-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scim/v2/enterprises/{enterprise}/Users/{scim_user_id} method: delete operationId: enterprise-admin/delete-user-from-enterprise x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /search/code method: get operationId: search/code x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /search/commits method: get operationId: search/commits x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /search/issues method: get operationId: search/issues-and-pull-requests x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /search/labels method: get operationId: search/labels x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /search/repositories method: get operationId: search/repos x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /search/topics method: get operationId: search/topics x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /search/users method: get operationId: search/users x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /setup/api/configcheck method: get operationId: enterprise-admin/get-configuration-status x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /setup/api/configure method: post operationId: enterprise-admin/start-configuration-process x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /setup/api/maintenance method: get operationId: enterprise-admin/get-maintenance-status x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /setup/api/maintenance method: post operationId: enterprise-admin/enable-or-disable-maintenance-mode x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /setup/api/settings method: get operationId: enterprise-admin/get-settings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /setup/api/settings method: put operationId: enterprise-admin/set-settings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /setup/api/settings/authorized-keys method: get operationId: enterprise-admin/get-all-authorized-ssh-keys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /setup/api/settings/authorized-keys method: post operationId: enterprise-admin/add-authorized-ssh-key x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /setup/api/settings/authorized-keys method: delete operationId: enterprise-admin/remove-authorized-ssh-key x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /setup/api/start method: post operationId: enterprise-admin/create-enterprise-server-license x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /setup/api/upgrade method: post operationId: enterprise-admin/upgrade-license x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id} method: get operationId: teams/get-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id} method: patch operationId: teams/update-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id} method: delete operationId: teams/delete-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/discussions method: get operationId: teams/list-discussions-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/discussions method: post operationId: teams/create-discussion-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/discussions/{discussion_number} method: get operationId: teams/get-discussion-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/discussions/{discussion_number} method: patch operationId: teams/update-discussion-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/discussions/{discussion_number} method: delete operationId: teams/delete-discussion-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/discussions/{discussion_number}/comments method: get operationId: teams/list-discussion-comments-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/discussions/{discussion_number}/comments method: post operationId: teams/create-discussion-comment-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/discussions/{discussion_number}/comments/{comment_number} method: get operationId: teams/get-discussion-comment-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/discussions/{discussion_number}/comments/{comment_number} method: patch operationId: teams/update-discussion-comment-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/discussions/{discussion_number}/comments/{comment_number} method: delete operationId: teams/delete-discussion-comment-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/discussions/{discussion_number}/comments/{comment_number}/reactions method: get operationId: reactions/list-for-team-discussion-comment-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/discussions/{discussion_number}/comments/{comment_number}/reactions method: post operationId: reactions/create-for-team-discussion-comment-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/discussions/{discussion_number}/reactions method: get operationId: reactions/list-for-team-discussion-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/discussions/{discussion_number}/reactions method: post operationId: reactions/create-for-team-discussion-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/members method: get operationId: teams/list-members-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/members/{username} method: get operationId: teams/get-member-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/members/{username} method: put operationId: teams/add-member-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/members/{username} method: delete operationId: teams/remove-member-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/memberships/{username} method: get operationId: teams/get-membership-for-user-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/memberships/{username} method: put operationId: teams/add-or-update-membership-for-user-legacy x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/memberships/{username} method: delete operationId: teams/remove-membership-for-user-legacy x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/projects method: get operationId: teams/list-projects-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/projects/{project_id} method: get operationId: teams/check-permissions-for-project-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/projects/{project_id} method: put operationId: teams/add-or-update-project-permissions-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/projects/{project_id} method: delete operationId: teams/remove-project-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/repos method: get operationId: teams/list-repos-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/repos/{owner}/{repo} method: get operationId: teams/check-permissions-for-repo-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /teams/{team_id}/repos/{owner}/{repo} method: put operationId: teams/add-or-update-repo-permissions-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/repos/{owner}/{repo} method: delete operationId: teams/remove-repo-legacy x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{team_id}/teams method: get operationId: teams/list-child-legacy x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user method: get operationId: users/get-authenticated x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user method: patch operationId: users/update-authenticated x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/docker/conflicts method: get operationId: packages/list-docker-migration-conflicting-packages-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/emails method: get operationId: users/list-emails-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/emails method: post operationId: users/add-email-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/emails method: delete operationId: users/delete-email-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/followers method: get operationId: users/list-followers-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/following method: get operationId: users/list-followed-by-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/following/{username} method: get operationId: users/check-person-is-followed-by-authenticated x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/following/{username} method: put operationId: users/follow x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/following/{username} method: delete operationId: users/unfollow x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/gpg_keys method: get operationId: users/list-gpg-keys-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/gpg_keys method: post operationId: users/create-gpg-key-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/gpg_keys/{gpg_key_id} method: get operationId: users/get-gpg-key-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/gpg_keys/{gpg_key_id} method: delete operationId: users/delete-gpg-key-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/installations method: get operationId: apps/list-installations-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/installations/{installation_id}/repositories method: get operationId: apps/list-installation-repos-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/installations/{installation_id}/repositories/{repository_id} method: put operationId: apps/add-repo-to-installation-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/installations/{installation_id}/repositories/{repository_id} method: delete operationId: apps/remove-repo-from-installation-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/issues method: get operationId: issues/list-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/keys method: get operationId: users/list-public-ssh-keys-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/keys method: post operationId: users/create-public-ssh-key-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/keys/{key_id} method: get operationId: users/get-public-ssh-key-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/keys/{key_id} method: delete operationId: users/delete-public-ssh-key-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/memberships/orgs method: get operationId: orgs/list-memberships-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/memberships/orgs/{org} method: get operationId: orgs/get-membership-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/memberships/orgs/{org} method: patch operationId: orgs/update-membership-for-authenticated-user x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/migrations method: get operationId: migrations/list-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/migrations method: post operationId: migrations/start-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/migrations/{migration_id}/archive method: get operationId: migrations/get-archive-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/migrations/{migration_id}/repositories method: get operationId: migrations/list-repos-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/orgs method: get operationId: orgs/list-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/packages method: get operationId: packages/list-packages-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/packages/{package_type}/{package_name} method: get operationId: packages/get-package-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/packages/{package_type}/{package_name} method: delete operationId: packages/delete-package-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/packages/{package_type}/{package_name}/restore method: post operationId: packages/restore-package-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/packages/{package_type}/{package_name}/versions method: get operationId: packages/get-all-package-versions-for-package-owned-by-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/packages/{package_type}/{package_name}/versions/{package_version_id} method: get operationId: packages/get-package-version-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/packages/{package_type}/{package_name}/versions/{package_version_id} method: delete operationId: packages/delete-package-version-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/packages/{package_type}/{package_name}/versions/{package_version_id}/restore method: post operationId: packages/restore-package-version-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/projects method: post operationId: projects/create-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/public_emails method: get operationId: users/list-public-emails-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/repos method: get operationId: repos/list-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/repos method: post operationId: repos/create-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/repository_invitations method: get operationId: repos/list-invitations-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/repository_invitations/{invitation_id} method: patch operationId: repos/accept-invitation-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/repository_invitations/{invitation_id} method: delete operationId: repos/decline-invitation-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/social_accounts method: get operationId: users/list-social-accounts-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/social_accounts method: post operationId: users/add-social-account-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/social_accounts method: delete operationId: users/delete-social-account-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/ssh_signing_keys method: get operationId: users/list-ssh-signing-keys-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/ssh_signing_keys method: post operationId: users/create-ssh-signing-key-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/ssh_signing_keys/{ssh_signing_key_id} method: get operationId: users/get-ssh-signing-key-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/ssh_signing_keys/{ssh_signing_key_id} method: delete operationId: users/delete-ssh-signing-key-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/starred method: get operationId: activity/list-repos-starred-by-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/starred/{owner}/{repo} method: get operationId: activity/check-repo-is-starred-by-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/starred/{owner}/{repo} method: put operationId: activity/star-repo-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/starred/{owner}/{repo} method: delete operationId: activity/unstar-repo-for-authenticated-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /user/subscriptions method: get operationId: activity/list-watched-repos-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/teams method: get operationId: teams/list-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /user/{account_id} method: get operationId: users/get-by-id x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users method: get operationId: users/list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username} method: get operationId: users/get-by-username x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/docker/conflicts method: get operationId: packages/list-docker-migration-conflicting-packages-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/events method: get operationId: activity/list-events-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/events/orgs/{org} method: get operationId: activity/list-org-events-for-authenticated-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/events/public method: get operationId: activity/list-public-events-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/followers method: get operationId: users/list-followers-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/following method: get operationId: users/list-following-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/following/{target_user} method: get operationId: users/check-following-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/gists method: get operationId: gists/list-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/gpg_keys method: get operationId: users/list-gpg-keys-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/hovercard method: get operationId: users/get-context-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/installation method: get operationId: apps/get-user-installation x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/keys method: get operationId: users/list-public-keys-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/orgs method: get operationId: orgs/list-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/packages method: get operationId: packages/list-packages-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/packages/{package_type}/{package_name} method: get operationId: packages/get-package-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/packages/{package_type}/{package_name} method: delete operationId: packages/delete-package-for-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{username}/packages/{package_type}/{package_name}/restore method: post operationId: packages/restore-package-for-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{username}/packages/{package_type}/{package_name}/versions method: get operationId: packages/get-all-package-versions-for-package-owned-by-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/packages/{package_type}/{package_name}/versions/{package_version_id} method: get operationId: packages/get-package-version-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/packages/{package_type}/{package_name}/versions/{package_version_id} method: delete operationId: packages/delete-package-version-for-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{username}/packages/{package_type}/{package_name}/versions/{package_version_id}/restore method: post operationId: packages/restore-package-version-for-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{username}/projects method: get operationId: projects/list-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/received_events method: get operationId: activity/list-received-events-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/received_events/public method: get operationId: activity/list-received-public-events-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/repos method: get operationId: repos/list-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/site_admin method: put operationId: enterprise-admin/promote-user-to-be-site-administrator x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{username}/site_admin method: delete operationId: enterprise-admin/demote-site-administrator x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{username}/social_accounts method: get operationId: users/list-social-accounts-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/ssh_signing_keys method: get operationId: users/list-ssh-signing-keys-for-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/starred method: get operationId: activity/list-repos-starred-by-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/subscriptions method: get operationId: activity/list-repos-watched-by-user x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users/{username}/suspended method: put operationId: enterprise-admin/suspend-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{username}/suspended method: delete operationId: enterprise-admin/unsuspend-user x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /zen method: get operationId: meta/get-zen x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /news method: get operationId: News_Category x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /news/search method: get operationId: News_Search x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /news/trendingtopics method: get operationId: News_Trending x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /videos/details method: get operationId: Videos_Details x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /videos/search method: get operationId: Videos_Search x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /videos/trending method: get operationId: Videos_Trending x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /search method: get operationId: Web_Search x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts method: get operationId: getAccounts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/invoices method: get operationId: getAccountInvoices x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apis method: get operationId: getApis x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apis method: post operationId: createApi x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId} method: get operationId: getApi x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apis/{apiId} method: put operationId: updateApi x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId} method: delete operationId: deleteApi x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId}/collections method: post operationId: addApiCollection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId}/collections/{collectionId} method: get operationId: getApiCollection x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apis/{apiId}/collections/{collectionId}/sync-with-schema-tasks method: put operationId: syncCollectionWithSchema x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId}/comments method: get operationId: getApiComments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apis/{apiId}/comments method: post operationId: createApiComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId}/comments/{commentId} method: put operationId: updateApiComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId}/comments/{commentId} method: delete operationId: deleteApiComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId}/schemas method: post operationId: createApiSchema x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId}/schemas/{schemaId} method: get operationId: getApiSchema x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apis/{apiId}/schemas/{schemaId}/files method: get operationId: getApiSchemaFiles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apis/{apiId}/schemas/{schemaId}/files/{file-path} method: get operationId: getApiSchemaFileContents x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apis/{apiId}/schemas/{schemaId}/files/{file-path} method: put operationId: createUpdateApiSchemaFile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId}/schemas/{schemaId}/files/{file-path} method: delete operationId: deleteApiSchemaFile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId}/tags method: get operationId: getApiTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apis/{apiId}/tags method: put operationId: updateApiTags x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId}/tasks/{taskId} method: get operationId: getStatusOfAnAsyncTask x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apis/{apiId}/versions method: get operationId: getApiVersions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apis/{apiId}/versions method: post operationId: createApiVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId}/versions/{versionId} method: get operationId: getApiVersion x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /apis/{apiId}/versions/{versionId} method: put operationId: updateApiVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /apis/{apiId}/versions/{versionId} method: delete operationId: deleteApiVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /audit/logs method: get operationId: getAuditLogs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collection-access-keys method: get operationId: getCollectionAccessKeys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collection-access-keys/{keyId} method: delete operationId: deleteCollectionAccessKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections method: get operationId: getCollections x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections method: post operationId: createCollection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/fork/{collectionId} method: post operationId: createCollectionFork x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/merge method: post operationId: mergeCollectionFork x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId} method: get operationId: getCollection x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId} method: put operationId: putCollection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId} method: patch operationId: patchCollection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId} method: delete operationId: deleteCollection x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/collection-forks method: get operationId: getCollectionsForkedByUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/comments method: get operationId: getCollectionComments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/comments method: post operationId: createCollectionComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/comments/{commentId} method: put operationId: updateCollectionComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/comments/{commentId} method: delete operationId: deleteCollectionComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/folders method: post operationId: createCollectionFolder x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/folders/{folderId}/comments method: get operationId: getFolderComments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/folders/{folderId}/comments method: post operationId: createFolderComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/folders/{folderId}/comments/{commentId} method: put operationId: updateFolderComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/folders/{folderId}/comments/{commentId} method: delete operationId: deleteFolderComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/forks method: get operationId: getCollectionForks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/pulls method: put operationId: pullCollectionChanges x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/pull-requests method: get operationId: getCollectionPullRequests x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/pull-requests method: post operationId: createCollectionPullRequest x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/requests method: post operationId: createCollectionRequest x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/requests/{requestId}/comments method: get operationId: getRequestComments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/requests/{requestId}/comments method: post operationId: createRequestComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/requests/{requestId}/comments/{commentId} method: put operationId: updateRequestComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/requests/{requestId}/comments/{commentId} method: delete operationId: deleteRequestComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/responses method: post operationId: createCollectionResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/responses/{responseId}/comments method: get operationId: getResponseComments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/responses/{responseId}/comments method: post operationId: createResponseComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/responses/{responseId}/comments/{commentId} method: put operationId: updateResponseComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/responses/{responseId}/comments/{commentId} method: delete operationId: deleteResponseComment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/roles method: get operationId: getCollectionRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/roles method: patch operationId: updateCollectionRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/source-status method: get operationId: getSourceCollectionStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/folders/{folderId} method: get operationId: getCollectionFolder x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/folders/{folderId} method: put operationId: updateCollectionFolder x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/folders/{folderId} method: delete operationId: deleteCollectionFolder x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/requests/{requestId} method: get operationId: getCollectionRequest x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/requests/{requestId} method: put operationId: updateCollectionRequest x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/requests/{requestId} method: delete operationId: deleteCollectionRequest x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/responses/{responseId} method: get operationId: getCollectionResponse x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/responses/{responseId} method: put operationId: updateCollectionResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/responses/{responseId} method: delete operationId: deleteCollectionResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/tags method: get operationId: getCollectionTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collections/{collectionId}/tags method: put operationId: updateCollectionTags x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collections/{collectionId}/transformations method: get operationId: transformCollectionToOpenAPI x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /collection-folders-transfers method: post operationId: transferCollectionFolders x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collection-requests-transfers method: post operationId: transferCollectionRequests x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /collection-responses-transfers method: post operationId: transferCollectionResponses x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /comments-resolutions/{threadId} method: post operationId: resolveCommentThread x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /detected-secrets-queries method: post operationId: detectedSecretsQueries x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /detected-secrets/{secretId} method: put operationId: updateDetectedSecretResolutions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /detected-secrets/{secretId}/locations method: get operationId: getDetectedSecretsLocations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments method: get operationId: getEnvironments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments method: post operationId: createEnvironment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentId} method: get operationId: getEnvironment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentId} method: put operationId: updateEnvironment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentId} method: delete operationId: deleteEnvironment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentId}/forks method: post operationId: forkEnvironment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentId}/forks method: get operationId: getEnvironmentForks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentId}/merges method: post operationId: mergeEnvironmentFork x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentId}/pulls method: post operationId: pullEnvironment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /import/openapi method: post operationId: importOpenApiDefinition x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /me method: get operationId: getAuthenticatedUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /mocks method: get operationId: getMocks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /mocks method: post operationId: createMock x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /mocks/{mockId} method: get operationId: getMock x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /mocks/{mockId} method: put operationId: updateMock x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /mocks/{mockId} method: delete operationId: deleteMock x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /mocks/{mockId}/call-logs method: get operationId: getMockCallLogs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /mocks/{mockId}/publish method: post operationId: publishMock x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /mocks/{mockId}/unpublish method: delete operationId: unpublishMock x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /mocks/{mockId}/server-responses method: get operationId: getMockServerResponses x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /mocks/{mockId}/server-responses method: post operationId: createMockServerResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /mocks/{mockId}/server-responses/{serverResponseId} method: get operationId: getMockServerResponse x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /mocks/{mockId}/server-responses/{serverResponseId} method: put operationId: updateMockServerResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /mocks/{mockId}/server-responses/{serverResponseId} method: delete operationId: deleteMockServerResponse x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /monitors method: get operationId: getMonitors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /monitors method: post operationId: createMonitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /monitors/{monitorId} method: get operationId: getMonitor x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /monitors/{monitorId} method: put operationId: updateMonitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /monitors/{monitorId} method: delete operationId: deleteMonitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /monitors/{monitorId}/run method: post operationId: runMonitor x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /network/private method: get operationId: getAllElementsAndFolders x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /network/private method: post operationId: postPanElementOrFolder x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /network/private/{elementType}/{elementId} method: put operationId: updatePanElementOrFolder x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /network/private/{elementType}/{elementId} method: delete operationId: deletePanElementOrFolder x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /network/private/network-entity/request/all method: get operationId: getAllPanAddElementRequests x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /network/private/network-entity/request/{requestId} method: put operationId: respondPanElementAddRequest x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /pull-requests/{pullRequestId} method: get operationId: getPullRequest x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /pull-requests/{pullRequestId} method: put operationId: updatePullRequest x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /pull-requests/{pullRequestId}/tasks method: post operationId: reviewPullRequest x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /secret-types method: get operationId: getSecretTypes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /security/api-validation method: post operationId: schemaSecurityValidation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tags/{slug}/entities method: get operationId: getTaggedEntities x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scim/v2/Groups method: get operationId: getScimGroupResources x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scim/v2/Groups method: post operationId: createScimGroup x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scim/v2/Groups/{groupId} method: get operationId: getScimGroupResource x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scim/v2/Groups/{groupId} method: patch operationId: scimUpdateGroup x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scim/v2/Groups/{groupId} method: delete operationId: deleteScimGroup x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scim/v2/ResourceTypes method: get operationId: getScimResourceTypes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scim/v2/ServiceProviderConfig method: get operationId: getScimServiceProviderConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scim/v2/Users method: get operationId: getScimUserResources x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scim/v2/Users method: post operationId: createScimUser x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scim/v2/Users/{userId} method: get operationId: getScimUserResource x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /scim/v2/Users/{userId} method: put operationId: updateScimUser x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /scim/v2/Users/{userId} method: patch operationId: updateScimUserState x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /webhooks method: post operationId: createWebhook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workspaces method: get operationId: getWorkspaces x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /workspaces method: post operationId: createWorkspace x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workspaces-roles method: get operationId: getAllWorkspaceRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /workspaces/{workspaceId} method: get operationId: getWorkspace x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /workspaces/{workspaceId} method: put operationId: updateWorkspace x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workspaces/{workspaceId} method: delete operationId: deleteWorkspace x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workspaces/{workspaceId}/global-variables method: get operationId: getWorkspaceGlobalVariables x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /workspaces/{workspaceId}/global-variables method: put operationId: updateWorkspaceGlobalVariables x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workspaces/{workspaceId}/roles method: patch operationId: updateWorkspaceRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workspaces/{workspaceId}/roles method: get operationId: getWorkspaceRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /workspaces/{workspaceId}/tags method: get operationId: getWorkspaceTags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /workspaces/{workspaceId}/tags method: put operationId: updateWorkspaceTags x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required