openapi: 3.1.0 info: contact: email: support@konghq.com name: Kong Inc url: https://konghq.com description: 'OpenAPI 3.0 spec for Kong Gateway''s Admin API. You can learn more about Kong Gateway at [developer.konghq.com](https://developer.konghq.com). Give Kong a star at the [Kong/kong](https://github.com/kong/kong) repository.' license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html title: Kong Enterprise Admin ACLs Plugins API version: 3.14.0 servers: - description: Default Admin API URL url: '{protocol}://{hostname}:{port}{path}' variables: hostname: default: localhost description: Hostname for Kong's Admin API path: default: / description: Base path for Kong's Admin API port: default: '8001' description: Port for Kong's Admin API protocol: default: http description: Protocol for requests to Kong's Admin API enum: - http - https security: - adminToken: [] tags: - description: 'A plugin entity represents a plugin configuration that will be executed during the HTTP request/response lifecycle. Plugins let you add functionality to services that run behind a Kong Gateway instance, like authentication or rate limiting. You can find more information about available plugins and which values each plugin accepts at the [Plugin Hub](https://developer.konghq.com/plugins/).

When adding a plugin configuration to a service, the plugin will run on every request made by a client to that service. If a plugin needs to be tuned to different values for some specific consumers, you can do so by creating a separate plugin instance that specifies both the service and the consumer, through the service and consumer fields.' name: Plugins paths: /{workspace}/plugins: get: operationId: list-plugin summary: List all Plugins description: List all Plugins parameters: - $ref: '#/components/parameters/PaginationSize' - $ref: '#/components/parameters/PaginationOffset' - $ref: '#/components/parameters/PaginationTagsFilter' - $ref: '#/components/parameters/Workspace' responses: '200': description: A successful response listing Plugins content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/Plugin' next: $ref: '#/components/schemas/PaginationNextResponse' offset: $ref: '#/components/schemas/PaginationOffsetResponse' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins x-keep-sdk: true post: operationId: create-plugin summary: Create a new Plugin description: Create a new Plugin parameters: - $ref: '#/components/parameters/Workspace' requestBody: description: Description of the new Plugin for creation required: true content: application/json: schema: $ref: '#/components/schemas/Plugin' responses: '201': description: Successfully created Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins x-keep-sdk: true /{workspace}/plugins#ACL: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginACL#create operationId: create-acl-plugin summary: Create a ACL plugin description: Create a ACL plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ACLPlugin' responses: '201': description: Created ACL plugin content: application/json: schema: $ref: '#/components/schemas/ACLPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Ace: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAce#create operationId: create-ace-plugin summary: Create a Ace plugin description: Create a Ace plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AcePlugin' responses: '201': description: Created Ace plugin content: application/json: schema: $ref: '#/components/schemas/AcePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Acme: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAcme#create operationId: create-acme-plugin summary: Create a Acme plugin description: Create a Acme plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AcmePlugin' responses: '201': description: Created Acme plugin content: application/json: schema: $ref: '#/components/schemas/AcmePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiA2aProxy: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiA2aProxy#create operationId: create-aia2aproxy-plugin summary: Create a AiA2aProxy plugin description: Create a AiA2aProxy plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiA2aProxyPlugin' responses: '201': description: Created AiA2aProxy plugin content: application/json: schema: $ref: '#/components/schemas/AiA2aProxyPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiAwsGuardrails: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiAwsGuardrails#create operationId: create-aiawsguardrails-plugin summary: Create a AiAwsGuardrails plugin description: Create a AiAwsGuardrails plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiAwsGuardrailsPlugin' responses: '201': description: Created AiAwsGuardrails plugin content: application/json: schema: $ref: '#/components/schemas/AiAwsGuardrailsPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiAzureContentSafety: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiAzureContentSafety#create operationId: create-aiazurecontentsafety-plugin summary: Create a AiAzureContentSafety plugin description: Create a AiAzureContentSafety plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiAzureContentSafetyPlugin' responses: '201': description: Created AiAzureContentSafety plugin content: application/json: schema: $ref: '#/components/schemas/AiAzureContentSafetyPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiCustomGuardrail: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiCustomGuardrail#create operationId: create-aicustomguardrail-plugin summary: Create a AiCustomGuardrail plugin description: Create a AiCustomGuardrail plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiCustomGuardrailPlugin' responses: '201': description: Created AiCustomGuardrail plugin content: application/json: schema: $ref: '#/components/schemas/AiCustomGuardrailPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiGcpModelArmor: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiGcpModelArmor#create operationId: create-aigcpmodelarmor-plugin summary: Create a AiGcpModelArmor plugin description: Create a AiGcpModelArmor plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiGcpModelArmorPlugin' responses: '201': description: Created AiGcpModelArmor plugin content: application/json: schema: $ref: '#/components/schemas/AiGcpModelArmorPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiLakeraGuard: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiLakeraGuard#create operationId: create-ailakeraguard-plugin summary: Create a AiLakeraGuard plugin description: Create a AiLakeraGuard plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiLakeraGuardPlugin' responses: '201': description: Created AiLakeraGuard plugin content: application/json: schema: $ref: '#/components/schemas/AiLakeraGuardPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiLlmAsJudge: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiLlmAsJudge#create operationId: create-aillmasjudge-plugin summary: Create a AiLlmAsJudge plugin description: Create a AiLlmAsJudge plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiLlmAsJudgePlugin' responses: '201': description: Created AiLlmAsJudge plugin content: application/json: schema: $ref: '#/components/schemas/AiLlmAsJudgePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiMcpOauth2: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiMcpOauth2#create operationId: create-aimcpoauth2-plugin summary: Create a AiMcpOauth2 plugin description: Create a AiMcpOauth2 plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiMcpOauth2Plugin' responses: '201': description: Created AiMcpOauth2 plugin content: application/json: schema: $ref: '#/components/schemas/AiMcpOauth2Plugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiMcpProxy: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiMcpProxy#create operationId: create-aimcpproxy-plugin summary: Create a AiMcpProxy plugin description: Create a AiMcpProxy plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiMcpProxyPlugin' responses: '201': description: Created AiMcpProxy plugin content: application/json: schema: $ref: '#/components/schemas/AiMcpProxyPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiPromptCompressor: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptCompressor#create operationId: create-aipromptcompressor-plugin summary: Create a AiPromptCompressor plugin description: Create a AiPromptCompressor plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiPromptCompressorPlugin' responses: '201': description: Created AiPromptCompressor plugin content: application/json: schema: $ref: '#/components/schemas/AiPromptCompressorPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiPromptDecorator: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptDecorator#create operationId: create-aipromptdecorator-plugin summary: Create a AiPromptDecorator plugin description: Create a AiPromptDecorator plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiPromptDecoratorPlugin' responses: '201': description: Created AiPromptDecorator plugin content: application/json: schema: $ref: '#/components/schemas/AiPromptDecoratorPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiPromptGuard: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptGuard#create operationId: create-aipromptguard-plugin summary: Create a AiPromptGuard plugin description: Create a AiPromptGuard plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiPromptGuardPlugin' responses: '201': description: Created AiPromptGuard plugin content: application/json: schema: $ref: '#/components/schemas/AiPromptGuardPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiPromptTemplate: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptTemplate#create operationId: create-aiprompttemplate-plugin summary: Create a AiPromptTemplate plugin description: Create a AiPromptTemplate plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiPromptTemplatePlugin' responses: '201': description: Created AiPromptTemplate plugin content: application/json: schema: $ref: '#/components/schemas/AiPromptTemplatePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiProxy: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiProxy#create operationId: create-aiproxy-plugin summary: Create a AiProxy plugin description: Create a AiProxy plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiProxyPlugin' responses: '201': description: Created AiProxy plugin content: application/json: schema: $ref: '#/components/schemas/AiProxyPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiProxyAdvanced: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiProxyAdvanced#create operationId: create-aiproxyadvanced-plugin summary: Create a AiProxyAdvanced plugin description: Create a AiProxyAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiProxyAdvancedPlugin' responses: '201': description: Created AiProxyAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/AiProxyAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiRagInjector: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiRagInjector#create operationId: create-airaginjector-plugin summary: Create a AiRagInjector plugin description: Create a AiRagInjector plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiRagInjectorPlugin' responses: '201': description: Created AiRagInjector plugin content: application/json: schema: $ref: '#/components/schemas/AiRagInjectorPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiRateLimitingAdvanced: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiRateLimitingAdvanced#create operationId: create-airatelimitingadvanced-plugin summary: Create a AiRateLimitingAdvanced plugin description: Create a AiRateLimitingAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiRateLimitingAdvancedPlugin' responses: '201': description: Created AiRateLimitingAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/AiRateLimitingAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiRequestTransformer: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiRequestTransformer#create operationId: create-airequesttransformer-plugin summary: Create a AiRequestTransformer plugin description: Create a AiRequestTransformer plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiRequestTransformerPlugin' responses: '201': description: Created AiRequestTransformer plugin content: application/json: schema: $ref: '#/components/schemas/AiRequestTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiResponseTransformer: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiResponseTransformer#create operationId: create-airesponsetransformer-plugin summary: Create a AiResponseTransformer plugin description: Create a AiResponseTransformer plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiResponseTransformerPlugin' responses: '201': description: Created AiResponseTransformer plugin content: application/json: schema: $ref: '#/components/schemas/AiResponseTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiSanitizer: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSanitizer#create operationId: create-aisanitizer-plugin summary: Create a AiSanitizer plugin description: Create a AiSanitizer plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiSanitizerPlugin' responses: '201': description: Created AiSanitizer plugin content: application/json: schema: $ref: '#/components/schemas/AiSanitizerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiSemanticCache: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSemanticCache#create operationId: create-aisemanticcache-plugin summary: Create a AiSemanticCache plugin description: Create a AiSemanticCache plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiSemanticCachePlugin' responses: '201': description: Created AiSemanticCache plugin content: application/json: schema: $ref: '#/components/schemas/AiSemanticCachePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiSemanticPromptGuard: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSemanticPromptGuard#create operationId: create-aisemanticpromptguard-plugin summary: Create a AiSemanticPromptGuard plugin description: Create a AiSemanticPromptGuard plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiSemanticPromptGuardPlugin' responses: '201': description: Created AiSemanticPromptGuard plugin content: application/json: schema: $ref: '#/components/schemas/AiSemanticPromptGuardPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AiSemanticResponseGuard: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSemanticResponseGuard#create operationId: create-aisemanticresponseguard-plugin summary: Create a AiSemanticResponseGuard plugin description: Create a AiSemanticResponseGuard plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiSemanticResponseGuardPlugin' responses: '201': description: Created AiSemanticResponseGuard plugin content: application/json: schema: $ref: '#/components/schemas/AiSemanticResponseGuardPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AppDynamics: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAppDynamics#create operationId: create-appdynamics-plugin summary: Create a AppDynamics plugin description: Create a AppDynamics plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AppDynamicsPlugin' responses: '201': description: Created AppDynamics plugin content: application/json: schema: $ref: '#/components/schemas/AppDynamicsPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AwsLambda: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAwsLambda#create operationId: create-awslambda-plugin summary: Create a AwsLambda plugin description: Create a AwsLambda plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AwsLambdaPlugin' responses: '201': description: Created AwsLambda plugin content: application/json: schema: $ref: '#/components/schemas/AwsLambdaPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#AzureFunctions: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAzureFunctions#create operationId: create-azurefunctions-plugin summary: Create a AzureFunctions plugin description: Create a AzureFunctions plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AzureFunctionsPlugin' responses: '201': description: Created AzureFunctions plugin content: application/json: schema: $ref: '#/components/schemas/AzureFunctionsPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#BasicAuth: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginBasicAuth#create operationId: create-basicauth-plugin summary: Create a BasicAuth plugin description: Create a BasicAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/BasicAuthPlugin' responses: '201': description: Created BasicAuth plugin content: application/json: schema: $ref: '#/components/schemas/BasicAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#BotDetection: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginBotDetection#create operationId: create-botdetection-plugin summary: Create a BotDetection plugin description: Create a BotDetection plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/BotDetectionPlugin' responses: '201': description: Created BotDetection plugin content: application/json: schema: $ref: '#/components/schemas/BotDetectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Canary: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginCanary#create operationId: create-canary-plugin summary: Create a Canary plugin description: Create a Canary plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CanaryPlugin' responses: '201': description: Created Canary plugin content: application/json: schema: $ref: '#/components/schemas/CanaryPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Confluent: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginConfluent#create operationId: create-confluent-plugin summary: Create a Confluent plugin description: Create a Confluent plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ConfluentPlugin' responses: '201': description: Created Confluent plugin content: application/json: schema: $ref: '#/components/schemas/ConfluentPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#ConfluentConsume: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginConfluentConsume#create operationId: create-confluentconsume-plugin summary: Create a ConfluentConsume plugin description: Create a ConfluentConsume plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ConfluentConsumePlugin' responses: '201': description: Created ConfluentConsume plugin content: application/json: schema: $ref: '#/components/schemas/ConfluentConsumePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#CorrelationId: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginCorrelationId#create operationId: create-correlationid-plugin summary: Create a CorrelationId plugin description: Create a CorrelationId plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CorrelationIdPlugin' responses: '201': description: Created CorrelationId plugin content: application/json: schema: $ref: '#/components/schemas/CorrelationIdPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Cors: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginCors#create operationId: create-cors-plugin summary: Create a Cors plugin description: Create a Cors plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CorsPlugin' responses: '201': description: Created Cors plugin content: application/json: schema: $ref: '#/components/schemas/CorsPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Datadog: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginDatadog#create operationId: create-datadog-plugin summary: Create a Datadog plugin description: Create a Datadog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/DatadogPlugin' responses: '201': description: Created Datadog plugin content: application/json: schema: $ref: '#/components/schemas/DatadogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Datakit: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginDatakit#create operationId: create-datakit-plugin summary: Create a Datakit plugin description: Create a Datakit plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/DatakitPlugin' responses: '201': description: Created Datakit plugin content: application/json: schema: $ref: '#/components/schemas/DatakitPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Degraphql: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginDegraphql#create operationId: create-degraphql-plugin summary: Create a Degraphql plugin description: Create a Degraphql plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/DegraphqlPlugin' responses: '201': description: Created Degraphql plugin content: application/json: schema: $ref: '#/components/schemas/DegraphqlPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#ExitTransformer: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginExitTransformer#create operationId: create-exittransformer-plugin summary: Create a ExitTransformer plugin description: Create a ExitTransformer plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ExitTransformerPlugin' responses: '201': description: Created ExitTransformer plugin content: application/json: schema: $ref: '#/components/schemas/ExitTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#FileLog: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginFileLog#create operationId: create-filelog-plugin summary: Create a FileLog plugin description: Create a FileLog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/FileLogPlugin' responses: '201': description: Created FileLog plugin content: application/json: schema: $ref: '#/components/schemas/FileLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#ForwardProxy: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginForwardProxy#create operationId: create-forwardproxy-plugin summary: Create a ForwardProxy plugin description: Create a ForwardProxy plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ForwardProxyPlugin' responses: '201': description: Created ForwardProxy plugin content: application/json: schema: $ref: '#/components/schemas/ForwardProxyPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#GraphqlProxyCacheAdvanced: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGraphqlProxyCacheAdvanced#create operationId: create-graphqlproxycacheadvanced-plugin summary: Create a GraphqlProxyCacheAdvanced plugin description: Create a GraphqlProxyCacheAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GraphqlProxyCacheAdvancedPlugin' responses: '201': description: Created GraphqlProxyCacheAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/GraphqlProxyCacheAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#GraphqlRateLimitingAdvanced: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGraphqlRateLimitingAdvanced#create operationId: create-graphqlratelimitingadvanced-plugin summary: Create a GraphqlRateLimitingAdvanced plugin description: Create a GraphqlRateLimitingAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GraphqlRateLimitingAdvancedPlugin' responses: '201': description: Created GraphqlRateLimitingAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/GraphqlRateLimitingAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#GrpcGateway: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGrpcGateway#create operationId: create-grpcgateway-plugin summary: Create a GrpcGateway plugin description: Create a GrpcGateway plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GrpcGatewayPlugin' responses: '201': description: Created GrpcGateway plugin content: application/json: schema: $ref: '#/components/schemas/GrpcGatewayPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#GrpcWeb: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGrpcWeb#create operationId: create-grpcweb-plugin summary: Create a GrpcWeb plugin description: Create a GrpcWeb plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GrpcWebPlugin' responses: '201': description: Created GrpcWeb plugin content: application/json: schema: $ref: '#/components/schemas/GrpcWebPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#HeaderCertAuth: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginHeaderCertAuth#create operationId: create-headercertauth-plugin summary: Create a HeaderCertAuth plugin description: Create a HeaderCertAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/HeaderCertAuthPlugin' responses: '201': description: Created HeaderCertAuth plugin content: application/json: schema: $ref: '#/components/schemas/HeaderCertAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#HmacAuth: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginHmacAuth#create operationId: create-hmacauth-plugin summary: Create a HmacAuth plugin description: Create a HmacAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/HmacAuthPlugin' responses: '201': description: Created HmacAuth plugin content: application/json: schema: $ref: '#/components/schemas/HmacAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#HttpLog: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginHttpLog#create operationId: create-httplog-plugin summary: Create a HttpLog plugin description: Create a HttpLog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/HttpLogPlugin' responses: '201': description: Created HttpLog plugin content: application/json: schema: $ref: '#/components/schemas/HttpLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#InjectionProtection: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginInjectionProtection#create operationId: create-injectionprotection-plugin summary: Create a InjectionProtection plugin description: Create a InjectionProtection plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/InjectionProtectionPlugin' responses: '201': description: Created InjectionProtection plugin content: application/json: schema: $ref: '#/components/schemas/InjectionProtectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#IpRestriction: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginIpRestriction#create operationId: create-iprestriction-plugin summary: Create a IpRestriction plugin description: Create a IpRestriction plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/IpRestrictionPlugin' responses: '201': description: Created IpRestriction plugin content: application/json: schema: $ref: '#/components/schemas/IpRestrictionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Jq: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJq#create operationId: create-jq-plugin summary: Create a Jq plugin description: Create a Jq plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/JqPlugin' responses: '201': description: Created Jq plugin content: application/json: schema: $ref: '#/components/schemas/JqPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#JsonThreatProtection: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJsonThreatProtection#create operationId: create-jsonthreatprotection-plugin summary: Create a JsonThreatProtection plugin description: Create a JsonThreatProtection plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/JsonThreatProtectionPlugin' responses: '201': description: Created JsonThreatProtection plugin content: application/json: schema: $ref: '#/components/schemas/JsonThreatProtectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#JweDecrypt: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJweDecrypt#create operationId: create-jwedecrypt-plugin summary: Create a JweDecrypt plugin description: Create a JweDecrypt plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/JweDecryptPlugin' responses: '201': description: Created JweDecrypt plugin content: application/json: schema: $ref: '#/components/schemas/JweDecryptPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Jwt: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJwt#create operationId: create-jwt-plugin summary: Create a Jwt plugin description: Create a Jwt plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/JwtPlugin' responses: '201': description: Created Jwt plugin content: application/json: schema: $ref: '#/components/schemas/JwtPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#JwtSigner: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJwtSigner#create operationId: create-jwtsigner-plugin summary: Create a JwtSigner plugin description: Create a JwtSigner plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/JwtSignerPlugin' responses: '201': description: Created JwtSigner plugin content: application/json: schema: $ref: '#/components/schemas/JwtSignerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#KafkaConsume: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKafkaConsume#create operationId: create-kafkaconsume-plugin summary: Create a KafkaConsume plugin description: Create a KafkaConsume plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/KafkaConsumePlugin' responses: '201': description: Created KafkaConsume plugin content: application/json: schema: $ref: '#/components/schemas/KafkaConsumePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#KafkaLog: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKafkaLog#create operationId: create-kafkalog-plugin summary: Create a KafkaLog plugin description: Create a KafkaLog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/KafkaLogPlugin' responses: '201': description: Created KafkaLog plugin content: application/json: schema: $ref: '#/components/schemas/KafkaLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#KafkaUpstream: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKafkaUpstream#create operationId: create-kafkaupstream-plugin summary: Create a KafkaUpstream plugin description: Create a KafkaUpstream plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/KafkaUpstreamPlugin' responses: '201': description: Created KafkaUpstream plugin content: application/json: schema: $ref: '#/components/schemas/KafkaUpstreamPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#KeyAuth: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKeyAuth#create operationId: create-keyauth-plugin summary: Create a KeyAuth plugin description: Create a KeyAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/KeyAuthPlugin' responses: '201': description: Created KeyAuth plugin content: application/json: schema: $ref: '#/components/schemas/KeyAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#KeyAuthEnc: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKeyAuthEnc#create operationId: create-keyauthenc-plugin summary: Create a KeyAuthEnc plugin description: Create a KeyAuthEnc plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/KeyAuthEncPlugin' responses: '201': description: Created KeyAuthEnc plugin content: application/json: schema: $ref: '#/components/schemas/KeyAuthEncPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#LdapAuth: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginLdapAuth#create operationId: create-ldapauth-plugin summary: Create a LdapAuth plugin description: Create a LdapAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/LdapAuthPlugin' responses: '201': description: Created LdapAuth plugin content: application/json: schema: $ref: '#/components/schemas/LdapAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#LdapAuthAdvanced: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginLdapAuthAdvanced#create operationId: create-ldapauthadvanced-plugin summary: Create a LdapAuthAdvanced plugin description: Create a LdapAuthAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/LdapAuthAdvancedPlugin' responses: '201': description: Created LdapAuthAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/LdapAuthAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Loggly: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginLoggly#create operationId: create-loggly-plugin summary: Create a Loggly plugin description: Create a Loggly plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/LogglyPlugin' responses: '201': description: Created Loggly plugin content: application/json: schema: $ref: '#/components/schemas/LogglyPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#MeteringAndBilling: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginMeteringAndBilling#create operationId: create-meteringandbilling-plugin summary: Create a MeteringAndBilling plugin description: Create a MeteringAndBilling plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/MeteringAndBillingPlugin' responses: '201': description: Created MeteringAndBilling plugin content: application/json: schema: $ref: '#/components/schemas/MeteringAndBillingPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Mocking: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginMocking#create operationId: create-mocking-plugin summary: Create a Mocking plugin description: Create a Mocking plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/MockingPlugin' responses: '201': description: Created Mocking plugin content: application/json: schema: $ref: '#/components/schemas/MockingPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#MtlsAuth: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginMtlsAuth#create operationId: create-mtlsauth-plugin summary: Create a MtlsAuth plugin description: Create a MtlsAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/MtlsAuthPlugin' responses: '201': description: Created MtlsAuth plugin content: application/json: schema: $ref: '#/components/schemas/MtlsAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#OasValidation: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOasValidation#create operationId: create-oasvalidation-plugin summary: Create a OasValidation plugin description: Create a OasValidation plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/OasValidationPlugin' responses: '201': description: Created OasValidation plugin content: application/json: schema: $ref: '#/components/schemas/OasValidationPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Oauth2: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOauth2#create operationId: create-oauth2-plugin summary: Create a Oauth2 plugin description: Create a Oauth2 plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Oauth2Plugin' responses: '201': description: Created Oauth2 plugin content: application/json: schema: $ref: '#/components/schemas/Oauth2Plugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Oauth2Introspection: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOauth2Introspection#create operationId: create-oauth2introspection-plugin summary: Create a Oauth2Introspection plugin description: Create a Oauth2Introspection plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Oauth2IntrospectionPlugin' responses: '201': description: Created Oauth2Introspection plugin content: application/json: schema: $ref: '#/components/schemas/Oauth2IntrospectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Opa: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOpa#create operationId: create-opa-plugin summary: Create a Opa plugin description: Create a Opa plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/OpaPlugin' responses: '201': description: Created Opa plugin content: application/json: schema: $ref: '#/components/schemas/OpaPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#OpenidConnect: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOpenidConnect#create operationId: create-openidconnect-plugin summary: Create a OpenidConnect plugin description: Create a OpenidConnect plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/OpenidConnectPlugin' responses: '201': description: Created OpenidConnect plugin content: application/json: schema: $ref: '#/components/schemas/OpenidConnectPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Opentelemetry: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOpentelemetry#create operationId: create-opentelemetry-plugin summary: Create a Opentelemetry plugin description: Create a Opentelemetry plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/OpentelemetryPlugin' responses: '201': description: Created Opentelemetry plugin content: application/json: schema: $ref: '#/components/schemas/OpentelemetryPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#PostFunction: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginPostFunction#create operationId: create-postfunction-plugin summary: Create a PostFunction plugin description: Create a PostFunction plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PostFunctionPlugin' responses: '201': description: Created PostFunction plugin content: application/json: schema: $ref: '#/components/schemas/PostFunctionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#PreFunction: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginPreFunction#create operationId: create-prefunction-plugin summary: Create a PreFunction plugin description: Create a PreFunction plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PreFunctionPlugin' responses: '201': description: Created PreFunction plugin content: application/json: schema: $ref: '#/components/schemas/PreFunctionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Prometheus: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginPrometheus#create operationId: create-prometheus-plugin summary: Create a Prometheus plugin description: Create a Prometheus plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrometheusPlugin' responses: '201': description: Created Prometheus plugin content: application/json: schema: $ref: '#/components/schemas/PrometheusPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#ProxyCache: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginProxyCache#create operationId: create-proxycache-plugin summary: Create a ProxyCache plugin description: Create a ProxyCache plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ProxyCachePlugin' responses: '201': description: Created ProxyCache plugin content: application/json: schema: $ref: '#/components/schemas/ProxyCachePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#ProxyCacheAdvanced: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginProxyCacheAdvanced#create operationId: create-proxycacheadvanced-plugin summary: Create a ProxyCacheAdvanced plugin description: Create a ProxyCacheAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ProxyCacheAdvancedPlugin' responses: '201': description: Created ProxyCacheAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/ProxyCacheAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#RateLimiting: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRateLimiting#create operationId: create-ratelimiting-plugin summary: Create a RateLimiting plugin description: Create a RateLimiting plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RateLimitingPlugin' responses: '201': description: Created RateLimiting plugin content: application/json: schema: $ref: '#/components/schemas/RateLimitingPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#RateLimitingAdvanced: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRateLimitingAdvanced#create operationId: create-ratelimitingadvanced-plugin summary: Create a RateLimitingAdvanced plugin description: Create a RateLimitingAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RateLimitingAdvancedPlugin' responses: '201': description: Created RateLimitingAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/RateLimitingAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Redirect: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRedirect#create operationId: create-redirect-plugin summary: Create a Redirect plugin description: Create a Redirect plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RedirectPlugin' responses: '201': description: Created Redirect plugin content: application/json: schema: $ref: '#/components/schemas/RedirectPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#RequestCallout: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestCallout#create operationId: create-requestcallout-plugin summary: Create a RequestCallout plugin description: Create a RequestCallout plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestCalloutPlugin' responses: '201': description: Created RequestCallout plugin content: application/json: schema: $ref: '#/components/schemas/RequestCalloutPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#RequestSizeLimiting: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestSizeLimiting#create operationId: create-requestsizelimiting-plugin summary: Create a RequestSizeLimiting plugin description: Create a RequestSizeLimiting plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestSizeLimitingPlugin' responses: '201': description: Created RequestSizeLimiting plugin content: application/json: schema: $ref: '#/components/schemas/RequestSizeLimitingPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#RequestTermination: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestTermination#create operationId: create-requesttermination-plugin summary: Create a RequestTermination plugin description: Create a RequestTermination plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestTerminationPlugin' responses: '201': description: Created RequestTermination plugin content: application/json: schema: $ref: '#/components/schemas/RequestTerminationPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#RequestTransformer: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestTransformer#create operationId: create-requesttransformer-plugin summary: Create a RequestTransformer plugin description: Create a RequestTransformer plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestTransformerPlugin' responses: '201': description: Created RequestTransformer plugin content: application/json: schema: $ref: '#/components/schemas/RequestTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#RequestTransformerAdvanced: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestTransformerAdvanced#create operationId: create-requesttransformeradvanced-plugin summary: Create a RequestTransformerAdvanced plugin description: Create a RequestTransformerAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestTransformerAdvancedPlugin' responses: '201': description: Created RequestTransformerAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/RequestTransformerAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#RequestValidator: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestValidator#create operationId: create-requestvalidator-plugin summary: Create a RequestValidator plugin description: Create a RequestValidator plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestValidatorPlugin' responses: '201': description: Created RequestValidator plugin content: application/json: schema: $ref: '#/components/schemas/RequestValidatorPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#ResponseRatelimiting: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginResponseRatelimiting#create operationId: create-responseratelimiting-plugin summary: Create a ResponseRatelimiting plugin description: Create a ResponseRatelimiting plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ResponseRatelimitingPlugin' responses: '201': description: Created ResponseRatelimiting plugin content: application/json: schema: $ref: '#/components/schemas/ResponseRatelimitingPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#ResponseTransformer: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginResponseTransformer#create operationId: create-responsetransformer-plugin summary: Create a ResponseTransformer plugin description: Create a ResponseTransformer plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ResponseTransformerPlugin' responses: '201': description: Created ResponseTransformer plugin content: application/json: schema: $ref: '#/components/schemas/ResponseTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#ResponseTransformerAdvanced: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginResponseTransformerAdvanced#create operationId: create-responsetransformeradvanced-plugin summary: Create a ResponseTransformerAdvanced plugin description: Create a ResponseTransformerAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ResponseTransformerAdvancedPlugin' responses: '201': description: Created ResponseTransformerAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/ResponseTransformerAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#RouteByHeader: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRouteByHeader#create operationId: create-routebyheader-plugin summary: Create a RouteByHeader plugin description: Create a RouteByHeader plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RouteByHeaderPlugin' responses: '201': description: Created RouteByHeader plugin content: application/json: schema: $ref: '#/components/schemas/RouteByHeaderPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#RouteTransformerAdvanced: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRouteTransformerAdvanced#create operationId: create-routetransformeradvanced-plugin summary: Create a RouteTransformerAdvanced plugin description: Create a RouteTransformerAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RouteTransformerAdvancedPlugin' responses: '201': description: Created RouteTransformerAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/RouteTransformerAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Saml: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSaml#create operationId: create-saml-plugin summary: Create a Saml plugin description: Create a Saml plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SamlPlugin' responses: '201': description: Created Saml plugin content: application/json: schema: $ref: '#/components/schemas/SamlPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#ServiceProtection: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginServiceProtection#create operationId: create-serviceprotection-plugin summary: Create a ServiceProtection plugin description: Create a ServiceProtection plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ServiceProtectionPlugin' responses: '201': description: Created ServiceProtection plugin content: application/json: schema: $ref: '#/components/schemas/ServiceProtectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Session: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSession#create operationId: create-session-plugin summary: Create a Session plugin description: Create a Session plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SessionPlugin' responses: '201': description: Created Session plugin content: application/json: schema: $ref: '#/components/schemas/SessionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#SolaceConsume: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSolaceConsume#create operationId: create-solaceconsume-plugin summary: Create a SolaceConsume plugin description: Create a SolaceConsume plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SolaceConsumePlugin' responses: '201': description: Created SolaceConsume plugin content: application/json: schema: $ref: '#/components/schemas/SolaceConsumePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#SolaceLog: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSolaceLog#create operationId: create-solacelog-plugin summary: Create a SolaceLog plugin description: Create a SolaceLog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SolaceLogPlugin' responses: '201': description: Created SolaceLog plugin content: application/json: schema: $ref: '#/components/schemas/SolaceLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#SolaceUpstream: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSolaceUpstream#create operationId: create-solaceupstream-plugin summary: Create a SolaceUpstream plugin description: Create a SolaceUpstream plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SolaceUpstreamPlugin' responses: '201': description: Created SolaceUpstream plugin content: application/json: schema: $ref: '#/components/schemas/SolaceUpstreamPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#StandardWebhooks: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginStandardWebhooks#create operationId: create-standardwebhooks-plugin summary: Create a StandardWebhooks plugin description: Create a StandardWebhooks plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/StandardWebhooksPlugin' responses: '201': description: Created StandardWebhooks plugin content: application/json: schema: $ref: '#/components/schemas/StandardWebhooksPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Statsd: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginStatsd#create operationId: create-statsd-plugin summary: Create a Statsd plugin description: Create a Statsd plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/StatsdPlugin' responses: '201': description: Created Statsd plugin content: application/json: schema: $ref: '#/components/schemas/StatsdPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#StatsdAdvanced: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginStatsdAdvanced#create operationId: create-statsdadvanced-plugin summary: Create a StatsdAdvanced plugin description: Create a StatsdAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/StatsdAdvancedPlugin' responses: '201': description: Created StatsdAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/StatsdAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Syslog: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSyslog#create operationId: create-syslog-plugin summary: Create a Syslog plugin description: Create a Syslog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SyslogPlugin' responses: '201': description: Created Syslog plugin content: application/json: schema: $ref: '#/components/schemas/SyslogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#TcpLog: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginTcpLog#create operationId: create-tcplog-plugin summary: Create a TcpLog plugin description: Create a TcpLog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TcpLogPlugin' responses: '201': description: Created TcpLog plugin content: application/json: schema: $ref: '#/components/schemas/TcpLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#TlsHandshakeModifier: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginTlsHandshakeModifier#create operationId: create-tlshandshakemodifier-plugin summary: Create a TlsHandshakeModifier plugin description: Create a TlsHandshakeModifier plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TlsHandshakeModifierPlugin' responses: '201': description: Created TlsHandshakeModifier plugin content: application/json: schema: $ref: '#/components/schemas/TlsHandshakeModifierPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#TlsMetadataHeaders: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginTlsMetadataHeaders#create operationId: create-tlsmetadataheaders-plugin summary: Create a TlsMetadataHeaders plugin description: Create a TlsMetadataHeaders plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TlsMetadataHeadersPlugin' responses: '201': description: Created TlsMetadataHeaders plugin content: application/json: schema: $ref: '#/components/schemas/TlsMetadataHeadersPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#UdpLog: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginUdpLog#create operationId: create-udplog-plugin summary: Create a UdpLog plugin description: Create a UdpLog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UdpLogPlugin' responses: '201': description: Created UdpLog plugin content: application/json: schema: $ref: '#/components/schemas/UdpLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#UpstreamOauth: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginUpstreamOauth#create operationId: create-upstreamoauth-plugin summary: Create a UpstreamOauth plugin description: Create a UpstreamOauth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpstreamOauthPlugin' responses: '201': description: Created UpstreamOauth plugin content: application/json: schema: $ref: '#/components/schemas/UpstreamOauthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#UpstreamTimeout: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginUpstreamTimeout#create operationId: create-upstreamtimeout-plugin summary: Create a UpstreamTimeout plugin description: Create a UpstreamTimeout plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpstreamTimeoutPlugin' responses: '201': description: Created UpstreamTimeout plugin content: application/json: schema: $ref: '#/components/schemas/UpstreamTimeoutPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#VaultAuth: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginVaultAuth#create operationId: create-vaultauth-plugin summary: Create a VaultAuth plugin description: Create a VaultAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/VaultAuthPlugin' responses: '201': description: Created VaultAuth plugin content: application/json: schema: $ref: '#/components/schemas/VaultAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#WebsocketSizeLimit: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginWebsocketSizeLimit#create operationId: create-websocketsizelimit-plugin summary: Create a WebsocketSizeLimit plugin description: Create a WebsocketSizeLimit plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/WebsocketSizeLimitPlugin' responses: '201': description: Created WebsocketSizeLimit plugin content: application/json: schema: $ref: '#/components/schemas/WebsocketSizeLimitPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#WebsocketValidator: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginWebsocketValidator#create operationId: create-websocketvalidator-plugin summary: Create a WebsocketValidator plugin description: Create a WebsocketValidator plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/WebsocketValidatorPlugin' responses: '201': description: Created WebsocketValidator plugin content: application/json: schema: $ref: '#/components/schemas/WebsocketValidatorPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#XmlThreatProtection: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginXmlThreatProtection#create operationId: create-xmlthreatprotection-plugin summary: Create a XmlThreatProtection plugin description: Create a XmlThreatProtection plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/XmlThreatProtectionPlugin' responses: '201': description: Created XmlThreatProtection plugin content: application/json: schema: $ref: '#/components/schemas/XmlThreatProtectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins#Zipkin: parameters: - $ref: '#/components/parameters/Workspace' post: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginZipkin#create operationId: create-zipkin-plugin summary: Create a Zipkin plugin description: Create a Zipkin plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ZipkinPlugin' responses: '201': description: Created Zipkin plugin content: application/json: schema: $ref: '#/components/schemas/ZipkinPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}: parameters: - $ref: '#/components/parameters/PluginId' delete: operationId: delete-plugin summary: Delete a Plugin description: Delete a Plugin parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins x-keep-sdk: true get: operationId: get-plugin summary: Get a Plugin description: Get a Plugin using ID. parameters: - $ref: '#/components/parameters/Workspace' responses: '200': description: Successfully fetched Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins x-keep-sdk: true patch: operationId: update-plugin summary: Update a Plugin description: Update a Plugin parameters: - $ref: '#/components/parameters/Workspace' requestBody: description: Fields of the Plugin that need to be updated required: true content: application/json: schema: $ref: '#/components/schemas/Plugin' responses: '200': description: Successfully updated Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins x-keep-sdk: true put: operationId: upsert-plugin summary: Upsert a Plugin description: Create or Update Plugin using ID. parameters: - $ref: '#/components/parameters/Workspace' requestBody: description: Description of the Plugin required: true content: application/json: schema: $ref: '#/components/schemas/Plugin' responses: '200': description: Successfully upserted Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins x-keep-sdk: true /{workspace}/plugins/{PluginId}#ACL: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginACL#delete operationId: delete-acl-plugin summary: Delete a ACL plugin description: Delete a ACL plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginACL#read operationId: get-acl-plugin summary: Get a ACL plugin description: Get a ACL plugin responses: '200': description: ACL plugin content: application/json: schema: $ref: '#/components/schemas/ACLPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginACL#update operationId: update-acl-plugin summary: Update a ACL plugin description: Update a ACL plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ACLPlugin' responses: '200': description: ACL plugin content: application/json: schema: $ref: '#/components/schemas/ACLPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Ace: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAce#delete operationId: delete-ace-plugin summary: Delete a Ace plugin description: Delete a Ace plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAce#read operationId: get-ace-plugin summary: Get a Ace plugin description: Get a Ace plugin responses: '200': description: Ace plugin content: application/json: schema: $ref: '#/components/schemas/AcePlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAce#update operationId: update-ace-plugin summary: Update a Ace plugin description: Update a Ace plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AcePlugin' responses: '200': description: Ace plugin content: application/json: schema: $ref: '#/components/schemas/AcePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Acme: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAcme#delete operationId: delete-acme-plugin summary: Delete a Acme plugin description: Delete a Acme plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAcme#read operationId: get-acme-plugin summary: Get a Acme plugin description: Get a Acme plugin responses: '200': description: Acme plugin content: application/json: schema: $ref: '#/components/schemas/AcmePlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAcme#update operationId: update-acme-plugin summary: Update a Acme plugin description: Update a Acme plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AcmePlugin' responses: '200': description: Acme plugin content: application/json: schema: $ref: '#/components/schemas/AcmePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiA2aProxy: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiA2aProxy#delete operationId: delete-aia2aproxy-plugin summary: Delete a AiA2aProxy plugin description: Delete a AiA2aProxy plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiA2aProxy#read operationId: get-aia2aproxy-plugin summary: Get a AiA2aProxy plugin description: Get a AiA2aProxy plugin responses: '200': description: AiA2aProxy plugin content: application/json: schema: $ref: '#/components/schemas/AiA2aProxyPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiA2aProxy#update operationId: update-aia2aproxy-plugin summary: Update a AiA2aProxy plugin description: Update a AiA2aProxy plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiA2aProxyPlugin' responses: '200': description: AiA2aProxy plugin content: application/json: schema: $ref: '#/components/schemas/AiA2aProxyPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiAwsGuardrails: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiAwsGuardrails#delete operationId: delete-aiawsguardrails-plugin summary: Delete a AiAwsGuardrails plugin description: Delete a AiAwsGuardrails plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiAwsGuardrails#read operationId: get-aiawsguardrails-plugin summary: Get a AiAwsGuardrails plugin description: Get a AiAwsGuardrails plugin responses: '200': description: AiAwsGuardrails plugin content: application/json: schema: $ref: '#/components/schemas/AiAwsGuardrailsPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiAwsGuardrails#update operationId: update-aiawsguardrails-plugin summary: Update a AiAwsGuardrails plugin description: Update a AiAwsGuardrails plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiAwsGuardrailsPlugin' responses: '200': description: AiAwsGuardrails plugin content: application/json: schema: $ref: '#/components/schemas/AiAwsGuardrailsPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiAzureContentSafety: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiAzureContentSafety#delete operationId: delete-aiazurecontentsafety-plugin summary: Delete a AiAzureContentSafety plugin description: Delete a AiAzureContentSafety plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiAzureContentSafety#read operationId: get-aiazurecontentsafety-plugin summary: Get a AiAzureContentSafety plugin description: Get a AiAzureContentSafety plugin responses: '200': description: AiAzureContentSafety plugin content: application/json: schema: $ref: '#/components/schemas/AiAzureContentSafetyPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiAzureContentSafety#update operationId: update-aiazurecontentsafety-plugin summary: Update a AiAzureContentSafety plugin description: Update a AiAzureContentSafety plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiAzureContentSafetyPlugin' responses: '200': description: AiAzureContentSafety plugin content: application/json: schema: $ref: '#/components/schemas/AiAzureContentSafetyPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiCustomGuardrail: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiCustomGuardrail#delete operationId: delete-aicustomguardrail-plugin summary: Delete a AiCustomGuardrail plugin description: Delete a AiCustomGuardrail plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiCustomGuardrail#read operationId: get-aicustomguardrail-plugin summary: Get a AiCustomGuardrail plugin description: Get a AiCustomGuardrail plugin responses: '200': description: AiCustomGuardrail plugin content: application/json: schema: $ref: '#/components/schemas/AiCustomGuardrailPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiCustomGuardrail#update operationId: update-aicustomguardrail-plugin summary: Update a AiCustomGuardrail plugin description: Update a AiCustomGuardrail plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiCustomGuardrailPlugin' responses: '200': description: AiCustomGuardrail plugin content: application/json: schema: $ref: '#/components/schemas/AiCustomGuardrailPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiGcpModelArmor: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiGcpModelArmor#delete operationId: delete-aigcpmodelarmor-plugin summary: Delete a AiGcpModelArmor plugin description: Delete a AiGcpModelArmor plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiGcpModelArmor#read operationId: get-aigcpmodelarmor-plugin summary: Get a AiGcpModelArmor plugin description: Get a AiGcpModelArmor plugin responses: '200': description: AiGcpModelArmor plugin content: application/json: schema: $ref: '#/components/schemas/AiGcpModelArmorPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiGcpModelArmor#update operationId: update-aigcpmodelarmor-plugin summary: Update a AiGcpModelArmor plugin description: Update a AiGcpModelArmor plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiGcpModelArmorPlugin' responses: '200': description: AiGcpModelArmor plugin content: application/json: schema: $ref: '#/components/schemas/AiGcpModelArmorPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiLakeraGuard: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiLakeraGuard#delete operationId: delete-ailakeraguard-plugin summary: Delete a AiLakeraGuard plugin description: Delete a AiLakeraGuard plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiLakeraGuard#read operationId: get-ailakeraguard-plugin summary: Get a AiLakeraGuard plugin description: Get a AiLakeraGuard plugin responses: '200': description: AiLakeraGuard plugin content: application/json: schema: $ref: '#/components/schemas/AiLakeraGuardPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiLakeraGuard#update operationId: update-ailakeraguard-plugin summary: Update a AiLakeraGuard plugin description: Update a AiLakeraGuard plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiLakeraGuardPlugin' responses: '200': description: AiLakeraGuard plugin content: application/json: schema: $ref: '#/components/schemas/AiLakeraGuardPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiLlmAsJudge: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiLlmAsJudge#delete operationId: delete-aillmasjudge-plugin summary: Delete a AiLlmAsJudge plugin description: Delete a AiLlmAsJudge plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiLlmAsJudge#read operationId: get-aillmasjudge-plugin summary: Get a AiLlmAsJudge plugin description: Get a AiLlmAsJudge plugin responses: '200': description: AiLlmAsJudge plugin content: application/json: schema: $ref: '#/components/schemas/AiLlmAsJudgePlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiLlmAsJudge#update operationId: update-aillmasjudge-plugin summary: Update a AiLlmAsJudge plugin description: Update a AiLlmAsJudge plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiLlmAsJudgePlugin' responses: '200': description: AiLlmAsJudge plugin content: application/json: schema: $ref: '#/components/schemas/AiLlmAsJudgePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiMcpOauth2: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiMcpOauth2#delete operationId: delete-aimcpoauth2-plugin summary: Delete a AiMcpOauth2 plugin description: Delete a AiMcpOauth2 plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiMcpOauth2#read operationId: get-aimcpoauth2-plugin summary: Get a AiMcpOauth2 plugin description: Get a AiMcpOauth2 plugin responses: '200': description: AiMcpOauth2 plugin content: application/json: schema: $ref: '#/components/schemas/AiMcpOauth2Plugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiMcpOauth2#update operationId: update-aimcpoauth2-plugin summary: Update a AiMcpOauth2 plugin description: Update a AiMcpOauth2 plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiMcpOauth2Plugin' responses: '200': description: AiMcpOauth2 plugin content: application/json: schema: $ref: '#/components/schemas/AiMcpOauth2Plugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiMcpProxy: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiMcpProxy#delete operationId: delete-aimcpproxy-plugin summary: Delete a AiMcpProxy plugin description: Delete a AiMcpProxy plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiMcpProxy#read operationId: get-aimcpproxy-plugin summary: Get a AiMcpProxy plugin description: Get a AiMcpProxy plugin responses: '200': description: AiMcpProxy plugin content: application/json: schema: $ref: '#/components/schemas/AiMcpProxyPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiMcpProxy#update operationId: update-aimcpproxy-plugin summary: Update a AiMcpProxy plugin description: Update a AiMcpProxy plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiMcpProxyPlugin' responses: '200': description: AiMcpProxy plugin content: application/json: schema: $ref: '#/components/schemas/AiMcpProxyPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiPromptCompressor: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptCompressor#delete operationId: delete-aipromptcompressor-plugin summary: Delete a AiPromptCompressor plugin description: Delete a AiPromptCompressor plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptCompressor#read operationId: get-aipromptcompressor-plugin summary: Get a AiPromptCompressor plugin description: Get a AiPromptCompressor plugin responses: '200': description: AiPromptCompressor plugin content: application/json: schema: $ref: '#/components/schemas/AiPromptCompressorPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptCompressor#update operationId: update-aipromptcompressor-plugin summary: Update a AiPromptCompressor plugin description: Update a AiPromptCompressor plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiPromptCompressorPlugin' responses: '200': description: AiPromptCompressor plugin content: application/json: schema: $ref: '#/components/schemas/AiPromptCompressorPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiPromptDecorator: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptDecorator#delete operationId: delete-aipromptdecorator-plugin summary: Delete a AiPromptDecorator plugin description: Delete a AiPromptDecorator plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptDecorator#read operationId: get-aipromptdecorator-plugin summary: Get a AiPromptDecorator plugin description: Get a AiPromptDecorator plugin responses: '200': description: AiPromptDecorator plugin content: application/json: schema: $ref: '#/components/schemas/AiPromptDecoratorPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptDecorator#update operationId: update-aipromptdecorator-plugin summary: Update a AiPromptDecorator plugin description: Update a AiPromptDecorator plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiPromptDecoratorPlugin' responses: '200': description: AiPromptDecorator plugin content: application/json: schema: $ref: '#/components/schemas/AiPromptDecoratorPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiPromptGuard: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptGuard#delete operationId: delete-aipromptguard-plugin summary: Delete a AiPromptGuard plugin description: Delete a AiPromptGuard plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptGuard#read operationId: get-aipromptguard-plugin summary: Get a AiPromptGuard plugin description: Get a AiPromptGuard plugin responses: '200': description: AiPromptGuard plugin content: application/json: schema: $ref: '#/components/schemas/AiPromptGuardPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptGuard#update operationId: update-aipromptguard-plugin summary: Update a AiPromptGuard plugin description: Update a AiPromptGuard plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiPromptGuardPlugin' responses: '200': description: AiPromptGuard plugin content: application/json: schema: $ref: '#/components/schemas/AiPromptGuardPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiPromptTemplate: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptTemplate#delete operationId: delete-aiprompttemplate-plugin summary: Delete a AiPromptTemplate plugin description: Delete a AiPromptTemplate plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptTemplate#read operationId: get-aiprompttemplate-plugin summary: Get a AiPromptTemplate plugin description: Get a AiPromptTemplate plugin responses: '200': description: AiPromptTemplate plugin content: application/json: schema: $ref: '#/components/schemas/AiPromptTemplatePlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiPromptTemplate#update operationId: update-aiprompttemplate-plugin summary: Update a AiPromptTemplate plugin description: Update a AiPromptTemplate plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiPromptTemplatePlugin' responses: '200': description: AiPromptTemplate plugin content: application/json: schema: $ref: '#/components/schemas/AiPromptTemplatePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiProxy: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiProxy#delete operationId: delete-aiproxy-plugin summary: Delete a AiProxy plugin description: Delete a AiProxy plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiProxy#read operationId: get-aiproxy-plugin summary: Get a AiProxy plugin description: Get a AiProxy plugin responses: '200': description: AiProxy plugin content: application/json: schema: $ref: '#/components/schemas/AiProxyPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiProxy#update operationId: update-aiproxy-plugin summary: Update a AiProxy plugin description: Update a AiProxy plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiProxyPlugin' responses: '200': description: AiProxy plugin content: application/json: schema: $ref: '#/components/schemas/AiProxyPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiProxyAdvanced: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiProxyAdvanced#delete operationId: delete-aiproxyadvanced-plugin summary: Delete a AiProxyAdvanced plugin description: Delete a AiProxyAdvanced plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiProxyAdvanced#read operationId: get-aiproxyadvanced-plugin summary: Get a AiProxyAdvanced plugin description: Get a AiProxyAdvanced plugin responses: '200': description: AiProxyAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/AiProxyAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiProxyAdvanced#update operationId: update-aiproxyadvanced-plugin summary: Update a AiProxyAdvanced plugin description: Update a AiProxyAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiProxyAdvancedPlugin' responses: '200': description: AiProxyAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/AiProxyAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiRagInjector: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiRagInjector#delete operationId: delete-airaginjector-plugin summary: Delete a AiRagInjector plugin description: Delete a AiRagInjector plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiRagInjector#read operationId: get-airaginjector-plugin summary: Get a AiRagInjector plugin description: Get a AiRagInjector plugin responses: '200': description: AiRagInjector plugin content: application/json: schema: $ref: '#/components/schemas/AiRagInjectorPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiRagInjector#update operationId: update-airaginjector-plugin summary: Update a AiRagInjector plugin description: Update a AiRagInjector plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiRagInjectorPlugin' responses: '200': description: AiRagInjector plugin content: application/json: schema: $ref: '#/components/schemas/AiRagInjectorPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiRateLimitingAdvanced: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiRateLimitingAdvanced#delete operationId: delete-airatelimitingadvanced-plugin summary: Delete a AiRateLimitingAdvanced plugin description: Delete a AiRateLimitingAdvanced plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiRateLimitingAdvanced#read operationId: get-airatelimitingadvanced-plugin summary: Get a AiRateLimitingAdvanced plugin description: Get a AiRateLimitingAdvanced plugin responses: '200': description: AiRateLimitingAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/AiRateLimitingAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiRateLimitingAdvanced#update operationId: update-airatelimitingadvanced-plugin summary: Update a AiRateLimitingAdvanced plugin description: Update a AiRateLimitingAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiRateLimitingAdvancedPlugin' responses: '200': description: AiRateLimitingAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/AiRateLimitingAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiRequestTransformer: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiRequestTransformer#delete operationId: delete-airequesttransformer-plugin summary: Delete a AiRequestTransformer plugin description: Delete a AiRequestTransformer plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiRequestTransformer#read operationId: get-airequesttransformer-plugin summary: Get a AiRequestTransformer plugin description: Get a AiRequestTransformer plugin responses: '200': description: AiRequestTransformer plugin content: application/json: schema: $ref: '#/components/schemas/AiRequestTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiRequestTransformer#update operationId: update-airequesttransformer-plugin summary: Update a AiRequestTransformer plugin description: Update a AiRequestTransformer plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiRequestTransformerPlugin' responses: '200': description: AiRequestTransformer plugin content: application/json: schema: $ref: '#/components/schemas/AiRequestTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiResponseTransformer: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiResponseTransformer#delete operationId: delete-airesponsetransformer-plugin summary: Delete a AiResponseTransformer plugin description: Delete a AiResponseTransformer plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiResponseTransformer#read operationId: get-airesponsetransformer-plugin summary: Get a AiResponseTransformer plugin description: Get a AiResponseTransformer plugin responses: '200': description: AiResponseTransformer plugin content: application/json: schema: $ref: '#/components/schemas/AiResponseTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiResponseTransformer#update operationId: update-airesponsetransformer-plugin summary: Update a AiResponseTransformer plugin description: Update a AiResponseTransformer plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiResponseTransformerPlugin' responses: '200': description: AiResponseTransformer plugin content: application/json: schema: $ref: '#/components/schemas/AiResponseTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiSanitizer: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSanitizer#delete operationId: delete-aisanitizer-plugin summary: Delete a AiSanitizer plugin description: Delete a AiSanitizer plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSanitizer#read operationId: get-aisanitizer-plugin summary: Get a AiSanitizer plugin description: Get a AiSanitizer plugin responses: '200': description: AiSanitizer plugin content: application/json: schema: $ref: '#/components/schemas/AiSanitizerPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSanitizer#update operationId: update-aisanitizer-plugin summary: Update a AiSanitizer plugin description: Update a AiSanitizer plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiSanitizerPlugin' responses: '200': description: AiSanitizer plugin content: application/json: schema: $ref: '#/components/schemas/AiSanitizerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiSemanticCache: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSemanticCache#delete operationId: delete-aisemanticcache-plugin summary: Delete a AiSemanticCache plugin description: Delete a AiSemanticCache plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSemanticCache#read operationId: get-aisemanticcache-plugin summary: Get a AiSemanticCache plugin description: Get a AiSemanticCache plugin responses: '200': description: AiSemanticCache plugin content: application/json: schema: $ref: '#/components/schemas/AiSemanticCachePlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSemanticCache#update operationId: update-aisemanticcache-plugin summary: Update a AiSemanticCache plugin description: Update a AiSemanticCache plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiSemanticCachePlugin' responses: '200': description: AiSemanticCache plugin content: application/json: schema: $ref: '#/components/schemas/AiSemanticCachePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiSemanticPromptGuard: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSemanticPromptGuard#delete operationId: delete-aisemanticpromptguard-plugin summary: Delete a AiSemanticPromptGuard plugin description: Delete a AiSemanticPromptGuard plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSemanticPromptGuard#read operationId: get-aisemanticpromptguard-plugin summary: Get a AiSemanticPromptGuard plugin description: Get a AiSemanticPromptGuard plugin responses: '200': description: AiSemanticPromptGuard plugin content: application/json: schema: $ref: '#/components/schemas/AiSemanticPromptGuardPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSemanticPromptGuard#update operationId: update-aisemanticpromptguard-plugin summary: Update a AiSemanticPromptGuard plugin description: Update a AiSemanticPromptGuard plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiSemanticPromptGuardPlugin' responses: '200': description: AiSemanticPromptGuard plugin content: application/json: schema: $ref: '#/components/schemas/AiSemanticPromptGuardPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AiSemanticResponseGuard: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSemanticResponseGuard#delete operationId: delete-aisemanticresponseguard-plugin summary: Delete a AiSemanticResponseGuard plugin description: Delete a AiSemanticResponseGuard plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSemanticResponseGuard#read operationId: get-aisemanticresponseguard-plugin summary: Get a AiSemanticResponseGuard plugin description: Get a AiSemanticResponseGuard plugin responses: '200': description: AiSemanticResponseGuard plugin content: application/json: schema: $ref: '#/components/schemas/AiSemanticResponseGuardPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAiSemanticResponseGuard#update operationId: update-aisemanticresponseguard-plugin summary: Update a AiSemanticResponseGuard plugin description: Update a AiSemanticResponseGuard plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AiSemanticResponseGuardPlugin' responses: '200': description: AiSemanticResponseGuard plugin content: application/json: schema: $ref: '#/components/schemas/AiSemanticResponseGuardPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AppDynamics: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAppDynamics#delete operationId: delete-appdynamics-plugin summary: Delete a AppDynamics plugin description: Delete a AppDynamics plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAppDynamics#read operationId: get-appdynamics-plugin summary: Get a AppDynamics plugin description: Get a AppDynamics plugin responses: '200': description: AppDynamics plugin content: application/json: schema: $ref: '#/components/schemas/AppDynamicsPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAppDynamics#update operationId: update-appdynamics-plugin summary: Update a AppDynamics plugin description: Update a AppDynamics plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AppDynamicsPlugin' responses: '200': description: AppDynamics plugin content: application/json: schema: $ref: '#/components/schemas/AppDynamicsPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AwsLambda: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAwsLambda#delete operationId: delete-awslambda-plugin summary: Delete a AwsLambda plugin description: Delete a AwsLambda plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAwsLambda#read operationId: get-awslambda-plugin summary: Get a AwsLambda plugin description: Get a AwsLambda plugin responses: '200': description: AwsLambda plugin content: application/json: schema: $ref: '#/components/schemas/AwsLambdaPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAwsLambda#update operationId: update-awslambda-plugin summary: Update a AwsLambda plugin description: Update a AwsLambda plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AwsLambdaPlugin' responses: '200': description: AwsLambda plugin content: application/json: schema: $ref: '#/components/schemas/AwsLambdaPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#AzureFunctions: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAzureFunctions#delete operationId: delete-azurefunctions-plugin summary: Delete a AzureFunctions plugin description: Delete a AzureFunctions plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAzureFunctions#read operationId: get-azurefunctions-plugin summary: Get a AzureFunctions plugin description: Get a AzureFunctions plugin responses: '200': description: AzureFunctions plugin content: application/json: schema: $ref: '#/components/schemas/AzureFunctionsPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginAzureFunctions#update operationId: update-azurefunctions-plugin summary: Update a AzureFunctions plugin description: Update a AzureFunctions plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AzureFunctionsPlugin' responses: '200': description: AzureFunctions plugin content: application/json: schema: $ref: '#/components/schemas/AzureFunctionsPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#BasicAuth: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginBasicAuth#delete operationId: delete-basicauth-plugin summary: Delete a BasicAuth plugin description: Delete a BasicAuth plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginBasicAuth#read operationId: get-basicauth-plugin summary: Get a BasicAuth plugin description: Get a BasicAuth plugin responses: '200': description: BasicAuth plugin content: application/json: schema: $ref: '#/components/schemas/BasicAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginBasicAuth#update operationId: update-basicauth-plugin summary: Update a BasicAuth plugin description: Update a BasicAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/BasicAuthPlugin' responses: '200': description: BasicAuth plugin content: application/json: schema: $ref: '#/components/schemas/BasicAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#BotDetection: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginBotDetection#delete operationId: delete-botdetection-plugin summary: Delete a BotDetection plugin description: Delete a BotDetection plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginBotDetection#read operationId: get-botdetection-plugin summary: Get a BotDetection plugin description: Get a BotDetection plugin responses: '200': description: BotDetection plugin content: application/json: schema: $ref: '#/components/schemas/BotDetectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginBotDetection#update operationId: update-botdetection-plugin summary: Update a BotDetection plugin description: Update a BotDetection plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/BotDetectionPlugin' responses: '200': description: BotDetection plugin content: application/json: schema: $ref: '#/components/schemas/BotDetectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Canary: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginCanary#delete operationId: delete-canary-plugin summary: Delete a Canary plugin description: Delete a Canary plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginCanary#read operationId: get-canary-plugin summary: Get a Canary plugin description: Get a Canary plugin responses: '200': description: Canary plugin content: application/json: schema: $ref: '#/components/schemas/CanaryPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginCanary#update operationId: update-canary-plugin summary: Update a Canary plugin description: Update a Canary plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CanaryPlugin' responses: '200': description: Canary plugin content: application/json: schema: $ref: '#/components/schemas/CanaryPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Confluent: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginConfluent#delete operationId: delete-confluent-plugin summary: Delete a Confluent plugin description: Delete a Confluent plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginConfluent#read operationId: get-confluent-plugin summary: Get a Confluent plugin description: Get a Confluent plugin responses: '200': description: Confluent plugin content: application/json: schema: $ref: '#/components/schemas/ConfluentPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginConfluent#update operationId: update-confluent-plugin summary: Update a Confluent plugin description: Update a Confluent plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ConfluentPlugin' responses: '200': description: Confluent plugin content: application/json: schema: $ref: '#/components/schemas/ConfluentPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#ConfluentConsume: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginConfluentConsume#delete operationId: delete-confluentconsume-plugin summary: Delete a ConfluentConsume plugin description: Delete a ConfluentConsume plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginConfluentConsume#read operationId: get-confluentconsume-plugin summary: Get a ConfluentConsume plugin description: Get a ConfluentConsume plugin responses: '200': description: ConfluentConsume plugin content: application/json: schema: $ref: '#/components/schemas/ConfluentConsumePlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginConfluentConsume#update operationId: update-confluentconsume-plugin summary: Update a ConfluentConsume plugin description: Update a ConfluentConsume plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ConfluentConsumePlugin' responses: '200': description: ConfluentConsume plugin content: application/json: schema: $ref: '#/components/schemas/ConfluentConsumePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#CorrelationId: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginCorrelationId#delete operationId: delete-correlationid-plugin summary: Delete a CorrelationId plugin description: Delete a CorrelationId plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginCorrelationId#read operationId: get-correlationid-plugin summary: Get a CorrelationId plugin description: Get a CorrelationId plugin responses: '200': description: CorrelationId plugin content: application/json: schema: $ref: '#/components/schemas/CorrelationIdPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginCorrelationId#update operationId: update-correlationid-plugin summary: Update a CorrelationId plugin description: Update a CorrelationId plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CorrelationIdPlugin' responses: '200': description: CorrelationId plugin content: application/json: schema: $ref: '#/components/schemas/CorrelationIdPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Cors: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginCors#delete operationId: delete-cors-plugin summary: Delete a Cors plugin description: Delete a Cors plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginCors#read operationId: get-cors-plugin summary: Get a Cors plugin description: Get a Cors plugin responses: '200': description: Cors plugin content: application/json: schema: $ref: '#/components/schemas/CorsPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginCors#update operationId: update-cors-plugin summary: Update a Cors plugin description: Update a Cors plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CorsPlugin' responses: '200': description: Cors plugin content: application/json: schema: $ref: '#/components/schemas/CorsPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Datadog: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginDatadog#delete operationId: delete-datadog-plugin summary: Delete a Datadog plugin description: Delete a Datadog plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginDatadog#read operationId: get-datadog-plugin summary: Get a Datadog plugin description: Get a Datadog plugin responses: '200': description: Datadog plugin content: application/json: schema: $ref: '#/components/schemas/DatadogPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginDatadog#update operationId: update-datadog-plugin summary: Update a Datadog plugin description: Update a Datadog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/DatadogPlugin' responses: '200': description: Datadog plugin content: application/json: schema: $ref: '#/components/schemas/DatadogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Datakit: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginDatakit#delete operationId: delete-datakit-plugin summary: Delete a Datakit plugin description: Delete a Datakit plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginDatakit#read operationId: get-datakit-plugin summary: Get a Datakit plugin description: Get a Datakit plugin responses: '200': description: Datakit plugin content: application/json: schema: $ref: '#/components/schemas/DatakitPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginDatakit#update operationId: update-datakit-plugin summary: Update a Datakit plugin description: Update a Datakit plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/DatakitPlugin' responses: '200': description: Datakit plugin content: application/json: schema: $ref: '#/components/schemas/DatakitPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Degraphql: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginDegraphql#delete operationId: delete-degraphql-plugin summary: Delete a Degraphql plugin description: Delete a Degraphql plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginDegraphql#read operationId: get-degraphql-plugin summary: Get a Degraphql plugin description: Get a Degraphql plugin responses: '200': description: Degraphql plugin content: application/json: schema: $ref: '#/components/schemas/DegraphqlPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginDegraphql#update operationId: update-degraphql-plugin summary: Update a Degraphql plugin description: Update a Degraphql plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/DegraphqlPlugin' responses: '200': description: Degraphql plugin content: application/json: schema: $ref: '#/components/schemas/DegraphqlPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#ExitTransformer: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginExitTransformer#delete operationId: delete-exittransformer-plugin summary: Delete a ExitTransformer plugin description: Delete a ExitTransformer plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginExitTransformer#read operationId: get-exittransformer-plugin summary: Get a ExitTransformer plugin description: Get a ExitTransformer plugin responses: '200': description: ExitTransformer plugin content: application/json: schema: $ref: '#/components/schemas/ExitTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginExitTransformer#update operationId: update-exittransformer-plugin summary: Update a ExitTransformer plugin description: Update a ExitTransformer plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ExitTransformerPlugin' responses: '200': description: ExitTransformer plugin content: application/json: schema: $ref: '#/components/schemas/ExitTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#FileLog: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginFileLog#delete operationId: delete-filelog-plugin summary: Delete a FileLog plugin description: Delete a FileLog plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginFileLog#read operationId: get-filelog-plugin summary: Get a FileLog plugin description: Get a FileLog plugin responses: '200': description: FileLog plugin content: application/json: schema: $ref: '#/components/schemas/FileLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginFileLog#update operationId: update-filelog-plugin summary: Update a FileLog plugin description: Update a FileLog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/FileLogPlugin' responses: '200': description: FileLog plugin content: application/json: schema: $ref: '#/components/schemas/FileLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#ForwardProxy: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginForwardProxy#delete operationId: delete-forwardproxy-plugin summary: Delete a ForwardProxy plugin description: Delete a ForwardProxy plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginForwardProxy#read operationId: get-forwardproxy-plugin summary: Get a ForwardProxy plugin description: Get a ForwardProxy plugin responses: '200': description: ForwardProxy plugin content: application/json: schema: $ref: '#/components/schemas/ForwardProxyPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginForwardProxy#update operationId: update-forwardproxy-plugin summary: Update a ForwardProxy plugin description: Update a ForwardProxy plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ForwardProxyPlugin' responses: '200': description: ForwardProxy plugin content: application/json: schema: $ref: '#/components/schemas/ForwardProxyPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#GraphqlProxyCacheAdvanced: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGraphqlProxyCacheAdvanced#delete operationId: delete-graphqlproxycacheadvanced-plugin summary: Delete a GraphqlProxyCacheAdvanced plugin description: Delete a GraphqlProxyCacheAdvanced plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGraphqlProxyCacheAdvanced#read operationId: get-graphqlproxycacheadvanced-plugin summary: Get a GraphqlProxyCacheAdvanced plugin description: Get a GraphqlProxyCacheAdvanced plugin responses: '200': description: GraphqlProxyCacheAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/GraphqlProxyCacheAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGraphqlProxyCacheAdvanced#update operationId: update-graphqlproxycacheadvanced-plugin summary: Update a GraphqlProxyCacheAdvanced plugin description: Update a GraphqlProxyCacheAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GraphqlProxyCacheAdvancedPlugin' responses: '200': description: GraphqlProxyCacheAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/GraphqlProxyCacheAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#GraphqlRateLimitingAdvanced: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGraphqlRateLimitingAdvanced#delete operationId: delete-graphqlratelimitingadvanced-plugin summary: Delete a GraphqlRateLimitingAdvanced plugin description: Delete a GraphqlRateLimitingAdvanced plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGraphqlRateLimitingAdvanced#read operationId: get-graphqlratelimitingadvanced-plugin summary: Get a GraphqlRateLimitingAdvanced plugin description: Get a GraphqlRateLimitingAdvanced plugin responses: '200': description: GraphqlRateLimitingAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/GraphqlRateLimitingAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGraphqlRateLimitingAdvanced#update operationId: update-graphqlratelimitingadvanced-plugin summary: Update a GraphqlRateLimitingAdvanced plugin description: Update a GraphqlRateLimitingAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GraphqlRateLimitingAdvancedPlugin' responses: '200': description: GraphqlRateLimitingAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/GraphqlRateLimitingAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#GrpcGateway: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGrpcGateway#delete operationId: delete-grpcgateway-plugin summary: Delete a GrpcGateway plugin description: Delete a GrpcGateway plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGrpcGateway#read operationId: get-grpcgateway-plugin summary: Get a GrpcGateway plugin description: Get a GrpcGateway plugin responses: '200': description: GrpcGateway plugin content: application/json: schema: $ref: '#/components/schemas/GrpcGatewayPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGrpcGateway#update operationId: update-grpcgateway-plugin summary: Update a GrpcGateway plugin description: Update a GrpcGateway plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GrpcGatewayPlugin' responses: '200': description: GrpcGateway plugin content: application/json: schema: $ref: '#/components/schemas/GrpcGatewayPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#GrpcWeb: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGrpcWeb#delete operationId: delete-grpcweb-plugin summary: Delete a GrpcWeb plugin description: Delete a GrpcWeb plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGrpcWeb#read operationId: get-grpcweb-plugin summary: Get a GrpcWeb plugin description: Get a GrpcWeb plugin responses: '200': description: GrpcWeb plugin content: application/json: schema: $ref: '#/components/schemas/GrpcWebPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginGrpcWeb#update operationId: update-grpcweb-plugin summary: Update a GrpcWeb plugin description: Update a GrpcWeb plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/GrpcWebPlugin' responses: '200': description: GrpcWeb plugin content: application/json: schema: $ref: '#/components/schemas/GrpcWebPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#HeaderCertAuth: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginHeaderCertAuth#delete operationId: delete-headercertauth-plugin summary: Delete a HeaderCertAuth plugin description: Delete a HeaderCertAuth plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginHeaderCertAuth#read operationId: get-headercertauth-plugin summary: Get a HeaderCertAuth plugin description: Get a HeaderCertAuth plugin responses: '200': description: HeaderCertAuth plugin content: application/json: schema: $ref: '#/components/schemas/HeaderCertAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginHeaderCertAuth#update operationId: update-headercertauth-plugin summary: Update a HeaderCertAuth plugin description: Update a HeaderCertAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/HeaderCertAuthPlugin' responses: '200': description: HeaderCertAuth plugin content: application/json: schema: $ref: '#/components/schemas/HeaderCertAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#HmacAuth: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginHmacAuth#delete operationId: delete-hmacauth-plugin summary: Delete a HmacAuth plugin description: Delete a HmacAuth plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginHmacAuth#read operationId: get-hmacauth-plugin summary: Get a HmacAuth plugin description: Get a HmacAuth plugin responses: '200': description: HmacAuth plugin content: application/json: schema: $ref: '#/components/schemas/HmacAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginHmacAuth#update operationId: update-hmacauth-plugin summary: Update a HmacAuth plugin description: Update a HmacAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/HmacAuthPlugin' responses: '200': description: HmacAuth plugin content: application/json: schema: $ref: '#/components/schemas/HmacAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#HttpLog: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginHttpLog#delete operationId: delete-httplog-plugin summary: Delete a HttpLog plugin description: Delete a HttpLog plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginHttpLog#read operationId: get-httplog-plugin summary: Get a HttpLog plugin description: Get a HttpLog plugin responses: '200': description: HttpLog plugin content: application/json: schema: $ref: '#/components/schemas/HttpLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginHttpLog#update operationId: update-httplog-plugin summary: Update a HttpLog plugin description: Update a HttpLog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/HttpLogPlugin' responses: '200': description: HttpLog plugin content: application/json: schema: $ref: '#/components/schemas/HttpLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#InjectionProtection: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginInjectionProtection#delete operationId: delete-injectionprotection-plugin summary: Delete a InjectionProtection plugin description: Delete a InjectionProtection plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginInjectionProtection#read operationId: get-injectionprotection-plugin summary: Get a InjectionProtection plugin description: Get a InjectionProtection plugin responses: '200': description: InjectionProtection plugin content: application/json: schema: $ref: '#/components/schemas/InjectionProtectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginInjectionProtection#update operationId: update-injectionprotection-plugin summary: Update a InjectionProtection plugin description: Update a InjectionProtection plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/InjectionProtectionPlugin' responses: '200': description: InjectionProtection plugin content: application/json: schema: $ref: '#/components/schemas/InjectionProtectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#IpRestriction: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginIpRestriction#delete operationId: delete-iprestriction-plugin summary: Delete a IpRestriction plugin description: Delete a IpRestriction plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginIpRestriction#read operationId: get-iprestriction-plugin summary: Get a IpRestriction plugin description: Get a IpRestriction plugin responses: '200': description: IpRestriction plugin content: application/json: schema: $ref: '#/components/schemas/IpRestrictionPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginIpRestriction#update operationId: update-iprestriction-plugin summary: Update a IpRestriction plugin description: Update a IpRestriction plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/IpRestrictionPlugin' responses: '200': description: IpRestriction plugin content: application/json: schema: $ref: '#/components/schemas/IpRestrictionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Jq: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJq#delete operationId: delete-jq-plugin summary: Delete a Jq plugin description: Delete a Jq plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJq#read operationId: get-jq-plugin summary: Get a Jq plugin description: Get a Jq plugin responses: '200': description: Jq plugin content: application/json: schema: $ref: '#/components/schemas/JqPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJq#update operationId: update-jq-plugin summary: Update a Jq plugin description: Update a Jq plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/JqPlugin' responses: '200': description: Jq plugin content: application/json: schema: $ref: '#/components/schemas/JqPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#JsonThreatProtection: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJsonThreatProtection#delete operationId: delete-jsonthreatprotection-plugin summary: Delete a JsonThreatProtection plugin description: Delete a JsonThreatProtection plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJsonThreatProtection#read operationId: get-jsonthreatprotection-plugin summary: Get a JsonThreatProtection plugin description: Get a JsonThreatProtection plugin responses: '200': description: JsonThreatProtection plugin content: application/json: schema: $ref: '#/components/schemas/JsonThreatProtectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJsonThreatProtection#update operationId: update-jsonthreatprotection-plugin summary: Update a JsonThreatProtection plugin description: Update a JsonThreatProtection plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/JsonThreatProtectionPlugin' responses: '200': description: JsonThreatProtection plugin content: application/json: schema: $ref: '#/components/schemas/JsonThreatProtectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#JweDecrypt: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJweDecrypt#delete operationId: delete-jwedecrypt-plugin summary: Delete a JweDecrypt plugin description: Delete a JweDecrypt plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJweDecrypt#read operationId: get-jwedecrypt-plugin summary: Get a JweDecrypt plugin description: Get a JweDecrypt plugin responses: '200': description: JweDecrypt plugin content: application/json: schema: $ref: '#/components/schemas/JweDecryptPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJweDecrypt#update operationId: update-jwedecrypt-plugin summary: Update a JweDecrypt plugin description: Update a JweDecrypt plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/JweDecryptPlugin' responses: '200': description: JweDecrypt plugin content: application/json: schema: $ref: '#/components/schemas/JweDecryptPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Jwt: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJwt#delete operationId: delete-jwt-plugin summary: Delete a Jwt plugin description: Delete a Jwt plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJwt#read operationId: get-jwt-plugin summary: Get a Jwt plugin description: Get a Jwt plugin responses: '200': description: Jwt plugin content: application/json: schema: $ref: '#/components/schemas/JwtPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJwt#update operationId: update-jwt-plugin summary: Update a Jwt plugin description: Update a Jwt plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/JwtPlugin' responses: '200': description: Jwt plugin content: application/json: schema: $ref: '#/components/schemas/JwtPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#JwtSigner: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJwtSigner#delete operationId: delete-jwtsigner-plugin summary: Delete a JwtSigner plugin description: Delete a JwtSigner plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJwtSigner#read operationId: get-jwtsigner-plugin summary: Get a JwtSigner plugin description: Get a JwtSigner plugin responses: '200': description: JwtSigner plugin content: application/json: schema: $ref: '#/components/schemas/JwtSignerPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginJwtSigner#update operationId: update-jwtsigner-plugin summary: Update a JwtSigner plugin description: Update a JwtSigner plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/JwtSignerPlugin' responses: '200': description: JwtSigner plugin content: application/json: schema: $ref: '#/components/schemas/JwtSignerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#KafkaConsume: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKafkaConsume#delete operationId: delete-kafkaconsume-plugin summary: Delete a KafkaConsume plugin description: Delete a KafkaConsume plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKafkaConsume#read operationId: get-kafkaconsume-plugin summary: Get a KafkaConsume plugin description: Get a KafkaConsume plugin responses: '200': description: KafkaConsume plugin content: application/json: schema: $ref: '#/components/schemas/KafkaConsumePlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKafkaConsume#update operationId: update-kafkaconsume-plugin summary: Update a KafkaConsume plugin description: Update a KafkaConsume plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/KafkaConsumePlugin' responses: '200': description: KafkaConsume plugin content: application/json: schema: $ref: '#/components/schemas/KafkaConsumePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#KafkaLog: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKafkaLog#delete operationId: delete-kafkalog-plugin summary: Delete a KafkaLog plugin description: Delete a KafkaLog plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKafkaLog#read operationId: get-kafkalog-plugin summary: Get a KafkaLog plugin description: Get a KafkaLog plugin responses: '200': description: KafkaLog plugin content: application/json: schema: $ref: '#/components/schemas/KafkaLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKafkaLog#update operationId: update-kafkalog-plugin summary: Update a KafkaLog plugin description: Update a KafkaLog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/KafkaLogPlugin' responses: '200': description: KafkaLog plugin content: application/json: schema: $ref: '#/components/schemas/KafkaLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#KafkaUpstream: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKafkaUpstream#delete operationId: delete-kafkaupstream-plugin summary: Delete a KafkaUpstream plugin description: Delete a KafkaUpstream plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKafkaUpstream#read operationId: get-kafkaupstream-plugin summary: Get a KafkaUpstream plugin description: Get a KafkaUpstream plugin responses: '200': description: KafkaUpstream plugin content: application/json: schema: $ref: '#/components/schemas/KafkaUpstreamPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKafkaUpstream#update operationId: update-kafkaupstream-plugin summary: Update a KafkaUpstream plugin description: Update a KafkaUpstream plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/KafkaUpstreamPlugin' responses: '200': description: KafkaUpstream plugin content: application/json: schema: $ref: '#/components/schemas/KafkaUpstreamPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#KeyAuth: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKeyAuth#delete operationId: delete-keyauth-plugin summary: Delete a KeyAuth plugin description: Delete a KeyAuth plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKeyAuth#read operationId: get-keyauth-plugin summary: Get a KeyAuth plugin description: Get a KeyAuth plugin responses: '200': description: KeyAuth plugin content: application/json: schema: $ref: '#/components/schemas/KeyAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKeyAuth#update operationId: update-keyauth-plugin summary: Update a KeyAuth plugin description: Update a KeyAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/KeyAuthPlugin' responses: '200': description: KeyAuth plugin content: application/json: schema: $ref: '#/components/schemas/KeyAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#KeyAuthEnc: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKeyAuthEnc#delete operationId: delete-keyauthenc-plugin summary: Delete a KeyAuthEnc plugin description: Delete a KeyAuthEnc plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKeyAuthEnc#read operationId: get-keyauthenc-plugin summary: Get a KeyAuthEnc plugin description: Get a KeyAuthEnc plugin responses: '200': description: KeyAuthEnc plugin content: application/json: schema: $ref: '#/components/schemas/KeyAuthEncPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginKeyAuthEnc#update operationId: update-keyauthenc-plugin summary: Update a KeyAuthEnc plugin description: Update a KeyAuthEnc plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/KeyAuthEncPlugin' responses: '200': description: KeyAuthEnc plugin content: application/json: schema: $ref: '#/components/schemas/KeyAuthEncPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#LdapAuth: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginLdapAuth#delete operationId: delete-ldapauth-plugin summary: Delete a LdapAuth plugin description: Delete a LdapAuth plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginLdapAuth#read operationId: get-ldapauth-plugin summary: Get a LdapAuth plugin description: Get a LdapAuth plugin responses: '200': description: LdapAuth plugin content: application/json: schema: $ref: '#/components/schemas/LdapAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginLdapAuth#update operationId: update-ldapauth-plugin summary: Update a LdapAuth plugin description: Update a LdapAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/LdapAuthPlugin' responses: '200': description: LdapAuth plugin content: application/json: schema: $ref: '#/components/schemas/LdapAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#LdapAuthAdvanced: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginLdapAuthAdvanced#delete operationId: delete-ldapauthadvanced-plugin summary: Delete a LdapAuthAdvanced plugin description: Delete a LdapAuthAdvanced plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginLdapAuthAdvanced#read operationId: get-ldapauthadvanced-plugin summary: Get a LdapAuthAdvanced plugin description: Get a LdapAuthAdvanced plugin responses: '200': description: LdapAuthAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/LdapAuthAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginLdapAuthAdvanced#update operationId: update-ldapauthadvanced-plugin summary: Update a LdapAuthAdvanced plugin description: Update a LdapAuthAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/LdapAuthAdvancedPlugin' responses: '200': description: LdapAuthAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/LdapAuthAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Loggly: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginLoggly#delete operationId: delete-loggly-plugin summary: Delete a Loggly plugin description: Delete a Loggly plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginLoggly#read operationId: get-loggly-plugin summary: Get a Loggly plugin description: Get a Loggly plugin responses: '200': description: Loggly plugin content: application/json: schema: $ref: '#/components/schemas/LogglyPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginLoggly#update operationId: update-loggly-plugin summary: Update a Loggly plugin description: Update a Loggly plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/LogglyPlugin' responses: '200': description: Loggly plugin content: application/json: schema: $ref: '#/components/schemas/LogglyPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#MeteringAndBilling: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginMeteringAndBilling#delete operationId: delete-meteringandbilling-plugin summary: Delete a MeteringAndBilling plugin description: Delete a MeteringAndBilling plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginMeteringAndBilling#read operationId: get-meteringandbilling-plugin summary: Get a MeteringAndBilling plugin description: Get a MeteringAndBilling plugin responses: '200': description: MeteringAndBilling plugin content: application/json: schema: $ref: '#/components/schemas/MeteringAndBillingPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginMeteringAndBilling#update operationId: update-meteringandbilling-plugin summary: Update a MeteringAndBilling plugin description: Update a MeteringAndBilling plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/MeteringAndBillingPlugin' responses: '200': description: MeteringAndBilling plugin content: application/json: schema: $ref: '#/components/schemas/MeteringAndBillingPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Mocking: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginMocking#delete operationId: delete-mocking-plugin summary: Delete a Mocking plugin description: Delete a Mocking plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginMocking#read operationId: get-mocking-plugin summary: Get a Mocking plugin description: Get a Mocking plugin responses: '200': description: Mocking plugin content: application/json: schema: $ref: '#/components/schemas/MockingPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginMocking#update operationId: update-mocking-plugin summary: Update a Mocking plugin description: Update a Mocking plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/MockingPlugin' responses: '200': description: Mocking plugin content: application/json: schema: $ref: '#/components/schemas/MockingPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#MtlsAuth: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginMtlsAuth#delete operationId: delete-mtlsauth-plugin summary: Delete a MtlsAuth plugin description: Delete a MtlsAuth plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginMtlsAuth#read operationId: get-mtlsauth-plugin summary: Get a MtlsAuth plugin description: Get a MtlsAuth plugin responses: '200': description: MtlsAuth plugin content: application/json: schema: $ref: '#/components/schemas/MtlsAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginMtlsAuth#update operationId: update-mtlsauth-plugin summary: Update a MtlsAuth plugin description: Update a MtlsAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/MtlsAuthPlugin' responses: '200': description: MtlsAuth plugin content: application/json: schema: $ref: '#/components/schemas/MtlsAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#OasValidation: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOasValidation#delete operationId: delete-oasvalidation-plugin summary: Delete a OasValidation plugin description: Delete a OasValidation plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOasValidation#read operationId: get-oasvalidation-plugin summary: Get a OasValidation plugin description: Get a OasValidation plugin responses: '200': description: OasValidation plugin content: application/json: schema: $ref: '#/components/schemas/OasValidationPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOasValidation#update operationId: update-oasvalidation-plugin summary: Update a OasValidation plugin description: Update a OasValidation plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/OasValidationPlugin' responses: '200': description: OasValidation plugin content: application/json: schema: $ref: '#/components/schemas/OasValidationPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Oauth2: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOauth2#delete operationId: delete-oauth2-plugin summary: Delete a Oauth2 plugin description: Delete a Oauth2 plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOauth2#read operationId: get-oauth2-plugin summary: Get a Oauth2 plugin description: Get a Oauth2 plugin responses: '200': description: Oauth2 plugin content: application/json: schema: $ref: '#/components/schemas/Oauth2Plugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOauth2#update operationId: update-oauth2-plugin summary: Update a Oauth2 plugin description: Update a Oauth2 plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Oauth2Plugin' responses: '200': description: Oauth2 plugin content: application/json: schema: $ref: '#/components/schemas/Oauth2Plugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Oauth2Introspection: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOauth2Introspection#delete operationId: delete-oauth2introspection-plugin summary: Delete a Oauth2Introspection plugin description: Delete a Oauth2Introspection plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOauth2Introspection#read operationId: get-oauth2introspection-plugin summary: Get a Oauth2Introspection plugin description: Get a Oauth2Introspection plugin responses: '200': description: Oauth2Introspection plugin content: application/json: schema: $ref: '#/components/schemas/Oauth2IntrospectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOauth2Introspection#update operationId: update-oauth2introspection-plugin summary: Update a Oauth2Introspection plugin description: Update a Oauth2Introspection plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Oauth2IntrospectionPlugin' responses: '200': description: Oauth2Introspection plugin content: application/json: schema: $ref: '#/components/schemas/Oauth2IntrospectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Opa: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOpa#delete operationId: delete-opa-plugin summary: Delete a Opa plugin description: Delete a Opa plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOpa#read operationId: get-opa-plugin summary: Get a Opa plugin description: Get a Opa plugin responses: '200': description: Opa plugin content: application/json: schema: $ref: '#/components/schemas/OpaPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOpa#update operationId: update-opa-plugin summary: Update a Opa plugin description: Update a Opa plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/OpaPlugin' responses: '200': description: Opa plugin content: application/json: schema: $ref: '#/components/schemas/OpaPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#OpenidConnect: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOpenidConnect#delete operationId: delete-openidconnect-plugin summary: Delete a OpenidConnect plugin description: Delete a OpenidConnect plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOpenidConnect#read operationId: get-openidconnect-plugin summary: Get a OpenidConnect plugin description: Get a OpenidConnect plugin responses: '200': description: OpenidConnect plugin content: application/json: schema: $ref: '#/components/schemas/OpenidConnectPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOpenidConnect#update operationId: update-openidconnect-plugin summary: Update a OpenidConnect plugin description: Update a OpenidConnect plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/OpenidConnectPlugin' responses: '200': description: OpenidConnect plugin content: application/json: schema: $ref: '#/components/schemas/OpenidConnectPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Opentelemetry: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOpentelemetry#delete operationId: delete-opentelemetry-plugin summary: Delete a Opentelemetry plugin description: Delete a Opentelemetry plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOpentelemetry#read operationId: get-opentelemetry-plugin summary: Get a Opentelemetry plugin description: Get a Opentelemetry plugin responses: '200': description: Opentelemetry plugin content: application/json: schema: $ref: '#/components/schemas/OpentelemetryPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginOpentelemetry#update operationId: update-opentelemetry-plugin summary: Update a Opentelemetry plugin description: Update a Opentelemetry plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/OpentelemetryPlugin' responses: '200': description: Opentelemetry plugin content: application/json: schema: $ref: '#/components/schemas/OpentelemetryPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#PostFunction: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginPostFunction#delete operationId: delete-postfunction-plugin summary: Delete a PostFunction plugin description: Delete a PostFunction plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginPostFunction#read operationId: get-postfunction-plugin summary: Get a PostFunction plugin description: Get a PostFunction plugin responses: '200': description: PostFunction plugin content: application/json: schema: $ref: '#/components/schemas/PostFunctionPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginPostFunction#update operationId: update-postfunction-plugin summary: Update a PostFunction plugin description: Update a PostFunction plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PostFunctionPlugin' responses: '200': description: PostFunction plugin content: application/json: schema: $ref: '#/components/schemas/PostFunctionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#PreFunction: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginPreFunction#delete operationId: delete-prefunction-plugin summary: Delete a PreFunction plugin description: Delete a PreFunction plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginPreFunction#read operationId: get-prefunction-plugin summary: Get a PreFunction plugin description: Get a PreFunction plugin responses: '200': description: PreFunction plugin content: application/json: schema: $ref: '#/components/schemas/PreFunctionPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginPreFunction#update operationId: update-prefunction-plugin summary: Update a PreFunction plugin description: Update a PreFunction plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PreFunctionPlugin' responses: '200': description: PreFunction plugin content: application/json: schema: $ref: '#/components/schemas/PreFunctionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Prometheus: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginPrometheus#delete operationId: delete-prometheus-plugin summary: Delete a Prometheus plugin description: Delete a Prometheus plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginPrometheus#read operationId: get-prometheus-plugin summary: Get a Prometheus plugin description: Get a Prometheus plugin responses: '200': description: Prometheus plugin content: application/json: schema: $ref: '#/components/schemas/PrometheusPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginPrometheus#update operationId: update-prometheus-plugin summary: Update a Prometheus plugin description: Update a Prometheus plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PrometheusPlugin' responses: '200': description: Prometheus plugin content: application/json: schema: $ref: '#/components/schemas/PrometheusPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#ProxyCache: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginProxyCache#delete operationId: delete-proxycache-plugin summary: Delete a ProxyCache plugin description: Delete a ProxyCache plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginProxyCache#read operationId: get-proxycache-plugin summary: Get a ProxyCache plugin description: Get a ProxyCache plugin responses: '200': description: ProxyCache plugin content: application/json: schema: $ref: '#/components/schemas/ProxyCachePlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginProxyCache#update operationId: update-proxycache-plugin summary: Update a ProxyCache plugin description: Update a ProxyCache plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ProxyCachePlugin' responses: '200': description: ProxyCache plugin content: application/json: schema: $ref: '#/components/schemas/ProxyCachePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#ProxyCacheAdvanced: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginProxyCacheAdvanced#delete operationId: delete-proxycacheadvanced-plugin summary: Delete a ProxyCacheAdvanced plugin description: Delete a ProxyCacheAdvanced plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginProxyCacheAdvanced#read operationId: get-proxycacheadvanced-plugin summary: Get a ProxyCacheAdvanced plugin description: Get a ProxyCacheAdvanced plugin responses: '200': description: ProxyCacheAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/ProxyCacheAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginProxyCacheAdvanced#update operationId: update-proxycacheadvanced-plugin summary: Update a ProxyCacheAdvanced plugin description: Update a ProxyCacheAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ProxyCacheAdvancedPlugin' responses: '200': description: ProxyCacheAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/ProxyCacheAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#RateLimiting: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRateLimiting#delete operationId: delete-ratelimiting-plugin summary: Delete a RateLimiting plugin description: Delete a RateLimiting plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRateLimiting#read operationId: get-ratelimiting-plugin summary: Get a RateLimiting plugin description: Get a RateLimiting plugin responses: '200': description: RateLimiting plugin content: application/json: schema: $ref: '#/components/schemas/RateLimitingPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRateLimiting#update operationId: update-ratelimiting-plugin summary: Update a RateLimiting plugin description: Update a RateLimiting plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RateLimitingPlugin' responses: '200': description: RateLimiting plugin content: application/json: schema: $ref: '#/components/schemas/RateLimitingPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#RateLimitingAdvanced: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRateLimitingAdvanced#delete operationId: delete-ratelimitingadvanced-plugin summary: Delete a RateLimitingAdvanced plugin description: Delete a RateLimitingAdvanced plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRateLimitingAdvanced#read operationId: get-ratelimitingadvanced-plugin summary: Get a RateLimitingAdvanced plugin description: Get a RateLimitingAdvanced plugin responses: '200': description: RateLimitingAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/RateLimitingAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRateLimitingAdvanced#update operationId: update-ratelimitingadvanced-plugin summary: Update a RateLimitingAdvanced plugin description: Update a RateLimitingAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RateLimitingAdvancedPlugin' responses: '200': description: RateLimitingAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/RateLimitingAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Redirect: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRedirect#delete operationId: delete-redirect-plugin summary: Delete a Redirect plugin description: Delete a Redirect plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRedirect#read operationId: get-redirect-plugin summary: Get a Redirect plugin description: Get a Redirect plugin responses: '200': description: Redirect plugin content: application/json: schema: $ref: '#/components/schemas/RedirectPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRedirect#update operationId: update-redirect-plugin summary: Update a Redirect plugin description: Update a Redirect plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RedirectPlugin' responses: '200': description: Redirect plugin content: application/json: schema: $ref: '#/components/schemas/RedirectPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#RequestCallout: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestCallout#delete operationId: delete-requestcallout-plugin summary: Delete a RequestCallout plugin description: Delete a RequestCallout plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestCallout#read operationId: get-requestcallout-plugin summary: Get a RequestCallout plugin description: Get a RequestCallout plugin responses: '200': description: RequestCallout plugin content: application/json: schema: $ref: '#/components/schemas/RequestCalloutPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestCallout#update operationId: update-requestcallout-plugin summary: Update a RequestCallout plugin description: Update a RequestCallout plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestCalloutPlugin' responses: '200': description: RequestCallout plugin content: application/json: schema: $ref: '#/components/schemas/RequestCalloutPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#RequestSizeLimiting: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestSizeLimiting#delete operationId: delete-requestsizelimiting-plugin summary: Delete a RequestSizeLimiting plugin description: Delete a RequestSizeLimiting plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestSizeLimiting#read operationId: get-requestsizelimiting-plugin summary: Get a RequestSizeLimiting plugin description: Get a RequestSizeLimiting plugin responses: '200': description: RequestSizeLimiting plugin content: application/json: schema: $ref: '#/components/schemas/RequestSizeLimitingPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestSizeLimiting#update operationId: update-requestsizelimiting-plugin summary: Update a RequestSizeLimiting plugin description: Update a RequestSizeLimiting plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestSizeLimitingPlugin' responses: '200': description: RequestSizeLimiting plugin content: application/json: schema: $ref: '#/components/schemas/RequestSizeLimitingPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#RequestTermination: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestTermination#delete operationId: delete-requesttermination-plugin summary: Delete a RequestTermination plugin description: Delete a RequestTermination plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestTermination#read operationId: get-requesttermination-plugin summary: Get a RequestTermination plugin description: Get a RequestTermination plugin responses: '200': description: RequestTermination plugin content: application/json: schema: $ref: '#/components/schemas/RequestTerminationPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestTermination#update operationId: update-requesttermination-plugin summary: Update a RequestTermination plugin description: Update a RequestTermination plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestTerminationPlugin' responses: '200': description: RequestTermination plugin content: application/json: schema: $ref: '#/components/schemas/RequestTerminationPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#RequestTransformer: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestTransformer#delete operationId: delete-requesttransformer-plugin summary: Delete a RequestTransformer plugin description: Delete a RequestTransformer plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestTransformer#read operationId: get-requesttransformer-plugin summary: Get a RequestTransformer plugin description: Get a RequestTransformer plugin responses: '200': description: RequestTransformer plugin content: application/json: schema: $ref: '#/components/schemas/RequestTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestTransformer#update operationId: update-requesttransformer-plugin summary: Update a RequestTransformer plugin description: Update a RequestTransformer plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestTransformerPlugin' responses: '200': description: RequestTransformer plugin content: application/json: schema: $ref: '#/components/schemas/RequestTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#RequestTransformerAdvanced: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestTransformerAdvanced#delete operationId: delete-requesttransformeradvanced-plugin summary: Delete a RequestTransformerAdvanced plugin description: Delete a RequestTransformerAdvanced plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestTransformerAdvanced#read operationId: get-requesttransformeradvanced-plugin summary: Get a RequestTransformerAdvanced plugin description: Get a RequestTransformerAdvanced plugin responses: '200': description: RequestTransformerAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/RequestTransformerAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestTransformerAdvanced#update operationId: update-requesttransformeradvanced-plugin summary: Update a RequestTransformerAdvanced plugin description: Update a RequestTransformerAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestTransformerAdvancedPlugin' responses: '200': description: RequestTransformerAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/RequestTransformerAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#RequestValidator: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestValidator#delete operationId: delete-requestvalidator-plugin summary: Delete a RequestValidator plugin description: Delete a RequestValidator plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestValidator#read operationId: get-requestvalidator-plugin summary: Get a RequestValidator plugin description: Get a RequestValidator plugin responses: '200': description: RequestValidator plugin content: application/json: schema: $ref: '#/components/schemas/RequestValidatorPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRequestValidator#update operationId: update-requestvalidator-plugin summary: Update a RequestValidator plugin description: Update a RequestValidator plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RequestValidatorPlugin' responses: '200': description: RequestValidator plugin content: application/json: schema: $ref: '#/components/schemas/RequestValidatorPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#ResponseRatelimiting: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginResponseRatelimiting#delete operationId: delete-responseratelimiting-plugin summary: Delete a ResponseRatelimiting plugin description: Delete a ResponseRatelimiting plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginResponseRatelimiting#read operationId: get-responseratelimiting-plugin summary: Get a ResponseRatelimiting plugin description: Get a ResponseRatelimiting plugin responses: '200': description: ResponseRatelimiting plugin content: application/json: schema: $ref: '#/components/schemas/ResponseRatelimitingPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginResponseRatelimiting#update operationId: update-responseratelimiting-plugin summary: Update a ResponseRatelimiting plugin description: Update a ResponseRatelimiting plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ResponseRatelimitingPlugin' responses: '200': description: ResponseRatelimiting plugin content: application/json: schema: $ref: '#/components/schemas/ResponseRatelimitingPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#ResponseTransformer: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginResponseTransformer#delete operationId: delete-responsetransformer-plugin summary: Delete a ResponseTransformer plugin description: Delete a ResponseTransformer plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginResponseTransformer#read operationId: get-responsetransformer-plugin summary: Get a ResponseTransformer plugin description: Get a ResponseTransformer plugin responses: '200': description: ResponseTransformer plugin content: application/json: schema: $ref: '#/components/schemas/ResponseTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginResponseTransformer#update operationId: update-responsetransformer-plugin summary: Update a ResponseTransformer plugin description: Update a ResponseTransformer plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ResponseTransformerPlugin' responses: '200': description: ResponseTransformer plugin content: application/json: schema: $ref: '#/components/schemas/ResponseTransformerPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#ResponseTransformerAdvanced: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginResponseTransformerAdvanced#delete operationId: delete-responsetransformeradvanced-plugin summary: Delete a ResponseTransformerAdvanced plugin description: Delete a ResponseTransformerAdvanced plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginResponseTransformerAdvanced#read operationId: get-responsetransformeradvanced-plugin summary: Get a ResponseTransformerAdvanced plugin description: Get a ResponseTransformerAdvanced plugin responses: '200': description: ResponseTransformerAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/ResponseTransformerAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginResponseTransformerAdvanced#update operationId: update-responsetransformeradvanced-plugin summary: Update a ResponseTransformerAdvanced plugin description: Update a ResponseTransformerAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ResponseTransformerAdvancedPlugin' responses: '200': description: ResponseTransformerAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/ResponseTransformerAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#RouteByHeader: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRouteByHeader#delete operationId: delete-routebyheader-plugin summary: Delete a RouteByHeader plugin description: Delete a RouteByHeader plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRouteByHeader#read operationId: get-routebyheader-plugin summary: Get a RouteByHeader plugin description: Get a RouteByHeader plugin responses: '200': description: RouteByHeader plugin content: application/json: schema: $ref: '#/components/schemas/RouteByHeaderPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRouteByHeader#update operationId: update-routebyheader-plugin summary: Update a RouteByHeader plugin description: Update a RouteByHeader plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RouteByHeaderPlugin' responses: '200': description: RouteByHeader plugin content: application/json: schema: $ref: '#/components/schemas/RouteByHeaderPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#RouteTransformerAdvanced: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRouteTransformerAdvanced#delete operationId: delete-routetransformeradvanced-plugin summary: Delete a RouteTransformerAdvanced plugin description: Delete a RouteTransformerAdvanced plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRouteTransformerAdvanced#read operationId: get-routetransformeradvanced-plugin summary: Get a RouteTransformerAdvanced plugin description: Get a RouteTransformerAdvanced plugin responses: '200': description: RouteTransformerAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/RouteTransformerAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginRouteTransformerAdvanced#update operationId: update-routetransformeradvanced-plugin summary: Update a RouteTransformerAdvanced plugin description: Update a RouteTransformerAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/RouteTransformerAdvancedPlugin' responses: '200': description: RouteTransformerAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/RouteTransformerAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Saml: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSaml#delete operationId: delete-saml-plugin summary: Delete a Saml plugin description: Delete a Saml plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSaml#read operationId: get-saml-plugin summary: Get a Saml plugin description: Get a Saml plugin responses: '200': description: Saml plugin content: application/json: schema: $ref: '#/components/schemas/SamlPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSaml#update operationId: update-saml-plugin summary: Update a Saml plugin description: Update a Saml plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SamlPlugin' responses: '200': description: Saml plugin content: application/json: schema: $ref: '#/components/schemas/SamlPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#ServiceProtection: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginServiceProtection#delete operationId: delete-serviceprotection-plugin summary: Delete a ServiceProtection plugin description: Delete a ServiceProtection plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginServiceProtection#read operationId: get-serviceprotection-plugin summary: Get a ServiceProtection plugin description: Get a ServiceProtection plugin responses: '200': description: ServiceProtection plugin content: application/json: schema: $ref: '#/components/schemas/ServiceProtectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginServiceProtection#update operationId: update-serviceprotection-plugin summary: Update a ServiceProtection plugin description: Update a ServiceProtection plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ServiceProtectionPlugin' responses: '200': description: ServiceProtection plugin content: application/json: schema: $ref: '#/components/schemas/ServiceProtectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Session: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSession#delete operationId: delete-session-plugin summary: Delete a Session plugin description: Delete a Session plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSession#read operationId: get-session-plugin summary: Get a Session plugin description: Get a Session plugin responses: '200': description: Session plugin content: application/json: schema: $ref: '#/components/schemas/SessionPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSession#update operationId: update-session-plugin summary: Update a Session plugin description: Update a Session plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SessionPlugin' responses: '200': description: Session plugin content: application/json: schema: $ref: '#/components/schemas/SessionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#SolaceConsume: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSolaceConsume#delete operationId: delete-solaceconsume-plugin summary: Delete a SolaceConsume plugin description: Delete a SolaceConsume plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSolaceConsume#read operationId: get-solaceconsume-plugin summary: Get a SolaceConsume plugin description: Get a SolaceConsume plugin responses: '200': description: SolaceConsume plugin content: application/json: schema: $ref: '#/components/schemas/SolaceConsumePlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSolaceConsume#update operationId: update-solaceconsume-plugin summary: Update a SolaceConsume plugin description: Update a SolaceConsume plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SolaceConsumePlugin' responses: '200': description: SolaceConsume plugin content: application/json: schema: $ref: '#/components/schemas/SolaceConsumePlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#SolaceLog: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSolaceLog#delete operationId: delete-solacelog-plugin summary: Delete a SolaceLog plugin description: Delete a SolaceLog plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSolaceLog#read operationId: get-solacelog-plugin summary: Get a SolaceLog plugin description: Get a SolaceLog plugin responses: '200': description: SolaceLog plugin content: application/json: schema: $ref: '#/components/schemas/SolaceLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSolaceLog#update operationId: update-solacelog-plugin summary: Update a SolaceLog plugin description: Update a SolaceLog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SolaceLogPlugin' responses: '200': description: SolaceLog plugin content: application/json: schema: $ref: '#/components/schemas/SolaceLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#SolaceUpstream: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSolaceUpstream#delete operationId: delete-solaceupstream-plugin summary: Delete a SolaceUpstream plugin description: Delete a SolaceUpstream plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSolaceUpstream#read operationId: get-solaceupstream-plugin summary: Get a SolaceUpstream plugin description: Get a SolaceUpstream plugin responses: '200': description: SolaceUpstream plugin content: application/json: schema: $ref: '#/components/schemas/SolaceUpstreamPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSolaceUpstream#update operationId: update-solaceupstream-plugin summary: Update a SolaceUpstream plugin description: Update a SolaceUpstream plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SolaceUpstreamPlugin' responses: '200': description: SolaceUpstream plugin content: application/json: schema: $ref: '#/components/schemas/SolaceUpstreamPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#StandardWebhooks: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginStandardWebhooks#delete operationId: delete-standardwebhooks-plugin summary: Delete a StandardWebhooks plugin description: Delete a StandardWebhooks plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginStandardWebhooks#read operationId: get-standardwebhooks-plugin summary: Get a StandardWebhooks plugin description: Get a StandardWebhooks plugin responses: '200': description: StandardWebhooks plugin content: application/json: schema: $ref: '#/components/schemas/StandardWebhooksPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginStandardWebhooks#update operationId: update-standardwebhooks-plugin summary: Update a StandardWebhooks plugin description: Update a StandardWebhooks plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/StandardWebhooksPlugin' responses: '200': description: StandardWebhooks plugin content: application/json: schema: $ref: '#/components/schemas/StandardWebhooksPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Statsd: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginStatsd#delete operationId: delete-statsd-plugin summary: Delete a Statsd plugin description: Delete a Statsd plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginStatsd#read operationId: get-statsd-plugin summary: Get a Statsd plugin description: Get a Statsd plugin responses: '200': description: Statsd plugin content: application/json: schema: $ref: '#/components/schemas/StatsdPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginStatsd#update operationId: update-statsd-plugin summary: Update a Statsd plugin description: Update a Statsd plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/StatsdPlugin' responses: '200': description: Statsd plugin content: application/json: schema: $ref: '#/components/schemas/StatsdPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#StatsdAdvanced: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginStatsdAdvanced#delete operationId: delete-statsdadvanced-plugin summary: Delete a StatsdAdvanced plugin description: Delete a StatsdAdvanced plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginStatsdAdvanced#read operationId: get-statsdadvanced-plugin summary: Get a StatsdAdvanced plugin description: Get a StatsdAdvanced plugin responses: '200': description: StatsdAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/StatsdAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginStatsdAdvanced#update operationId: update-statsdadvanced-plugin summary: Update a StatsdAdvanced plugin description: Update a StatsdAdvanced plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/StatsdAdvancedPlugin' responses: '200': description: StatsdAdvanced plugin content: application/json: schema: $ref: '#/components/schemas/StatsdAdvancedPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Syslog: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSyslog#delete operationId: delete-syslog-plugin summary: Delete a Syslog plugin description: Delete a Syslog plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSyslog#read operationId: get-syslog-plugin summary: Get a Syslog plugin description: Get a Syslog plugin responses: '200': description: Syslog plugin content: application/json: schema: $ref: '#/components/schemas/SyslogPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginSyslog#update operationId: update-syslog-plugin summary: Update a Syslog plugin description: Update a Syslog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SyslogPlugin' responses: '200': description: Syslog plugin content: application/json: schema: $ref: '#/components/schemas/SyslogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#TcpLog: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginTcpLog#delete operationId: delete-tcplog-plugin summary: Delete a TcpLog plugin description: Delete a TcpLog plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginTcpLog#read operationId: get-tcplog-plugin summary: Get a TcpLog plugin description: Get a TcpLog plugin responses: '200': description: TcpLog plugin content: application/json: schema: $ref: '#/components/schemas/TcpLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginTcpLog#update operationId: update-tcplog-plugin summary: Update a TcpLog plugin description: Update a TcpLog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TcpLogPlugin' responses: '200': description: TcpLog plugin content: application/json: schema: $ref: '#/components/schemas/TcpLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#TlsHandshakeModifier: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginTlsHandshakeModifier#delete operationId: delete-tlshandshakemodifier-plugin summary: Delete a TlsHandshakeModifier plugin description: Delete a TlsHandshakeModifier plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginTlsHandshakeModifier#read operationId: get-tlshandshakemodifier-plugin summary: Get a TlsHandshakeModifier plugin description: Get a TlsHandshakeModifier plugin responses: '200': description: TlsHandshakeModifier plugin content: application/json: schema: $ref: '#/components/schemas/TlsHandshakeModifierPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginTlsHandshakeModifier#update operationId: update-tlshandshakemodifier-plugin summary: Update a TlsHandshakeModifier plugin description: Update a TlsHandshakeModifier plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TlsHandshakeModifierPlugin' responses: '200': description: TlsHandshakeModifier plugin content: application/json: schema: $ref: '#/components/schemas/TlsHandshakeModifierPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#TlsMetadataHeaders: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginTlsMetadataHeaders#delete operationId: delete-tlsmetadataheaders-plugin summary: Delete a TlsMetadataHeaders plugin description: Delete a TlsMetadataHeaders plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginTlsMetadataHeaders#read operationId: get-tlsmetadataheaders-plugin summary: Get a TlsMetadataHeaders plugin description: Get a TlsMetadataHeaders plugin responses: '200': description: TlsMetadataHeaders plugin content: application/json: schema: $ref: '#/components/schemas/TlsMetadataHeadersPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginTlsMetadataHeaders#update operationId: update-tlsmetadataheaders-plugin summary: Update a TlsMetadataHeaders plugin description: Update a TlsMetadataHeaders plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/TlsMetadataHeadersPlugin' responses: '200': description: TlsMetadataHeaders plugin content: application/json: schema: $ref: '#/components/schemas/TlsMetadataHeadersPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#UdpLog: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginUdpLog#delete operationId: delete-udplog-plugin summary: Delete a UdpLog plugin description: Delete a UdpLog plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginUdpLog#read operationId: get-udplog-plugin summary: Get a UdpLog plugin description: Get a UdpLog plugin responses: '200': description: UdpLog plugin content: application/json: schema: $ref: '#/components/schemas/UdpLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginUdpLog#update operationId: update-udplog-plugin summary: Update a UdpLog plugin description: Update a UdpLog plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UdpLogPlugin' responses: '200': description: UdpLog plugin content: application/json: schema: $ref: '#/components/schemas/UdpLogPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#UpstreamOauth: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginUpstreamOauth#delete operationId: delete-upstreamoauth-plugin summary: Delete a UpstreamOauth plugin description: Delete a UpstreamOauth plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginUpstreamOauth#read operationId: get-upstreamoauth-plugin summary: Get a UpstreamOauth plugin description: Get a UpstreamOauth plugin responses: '200': description: UpstreamOauth plugin content: application/json: schema: $ref: '#/components/schemas/UpstreamOauthPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginUpstreamOauth#update operationId: update-upstreamoauth-plugin summary: Update a UpstreamOauth plugin description: Update a UpstreamOauth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpstreamOauthPlugin' responses: '200': description: UpstreamOauth plugin content: application/json: schema: $ref: '#/components/schemas/UpstreamOauthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#UpstreamTimeout: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginUpstreamTimeout#delete operationId: delete-upstreamtimeout-plugin summary: Delete a UpstreamTimeout plugin description: Delete a UpstreamTimeout plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginUpstreamTimeout#read operationId: get-upstreamtimeout-plugin summary: Get a UpstreamTimeout plugin description: Get a UpstreamTimeout plugin responses: '200': description: UpstreamTimeout plugin content: application/json: schema: $ref: '#/components/schemas/UpstreamTimeoutPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginUpstreamTimeout#update operationId: update-upstreamtimeout-plugin summary: Update a UpstreamTimeout plugin description: Update a UpstreamTimeout plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpstreamTimeoutPlugin' responses: '200': description: UpstreamTimeout plugin content: application/json: schema: $ref: '#/components/schemas/UpstreamTimeoutPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#VaultAuth: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginVaultAuth#delete operationId: delete-vaultauth-plugin summary: Delete a VaultAuth plugin description: Delete a VaultAuth plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginVaultAuth#read operationId: get-vaultauth-plugin summary: Get a VaultAuth plugin description: Get a VaultAuth plugin responses: '200': description: VaultAuth plugin content: application/json: schema: $ref: '#/components/schemas/VaultAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginVaultAuth#update operationId: update-vaultauth-plugin summary: Update a VaultAuth plugin description: Update a VaultAuth plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/VaultAuthPlugin' responses: '200': description: VaultAuth plugin content: application/json: schema: $ref: '#/components/schemas/VaultAuthPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#WebsocketSizeLimit: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginWebsocketSizeLimit#delete operationId: delete-websocketsizelimit-plugin summary: Delete a WebsocketSizeLimit plugin description: Delete a WebsocketSizeLimit plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginWebsocketSizeLimit#read operationId: get-websocketsizelimit-plugin summary: Get a WebsocketSizeLimit plugin description: Get a WebsocketSizeLimit plugin responses: '200': description: WebsocketSizeLimit plugin content: application/json: schema: $ref: '#/components/schemas/WebsocketSizeLimitPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginWebsocketSizeLimit#update operationId: update-websocketsizelimit-plugin summary: Update a WebsocketSizeLimit plugin description: Update a WebsocketSizeLimit plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/WebsocketSizeLimitPlugin' responses: '200': description: WebsocketSizeLimit plugin content: application/json: schema: $ref: '#/components/schemas/WebsocketSizeLimitPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#WebsocketValidator: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginWebsocketValidator#delete operationId: delete-websocketvalidator-plugin summary: Delete a WebsocketValidator plugin description: Delete a WebsocketValidator plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginWebsocketValidator#read operationId: get-websocketvalidator-plugin summary: Get a WebsocketValidator plugin description: Get a WebsocketValidator plugin responses: '200': description: WebsocketValidator plugin content: application/json: schema: $ref: '#/components/schemas/WebsocketValidatorPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginWebsocketValidator#update operationId: update-websocketvalidator-plugin summary: Update a WebsocketValidator plugin description: Update a WebsocketValidator plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/WebsocketValidatorPlugin' responses: '200': description: WebsocketValidator plugin content: application/json: schema: $ref: '#/components/schemas/WebsocketValidatorPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#XmlThreatProtection: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginXmlThreatProtection#delete operationId: delete-xmlthreatprotection-plugin summary: Delete a XmlThreatProtection plugin description: Delete a XmlThreatProtection plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginXmlThreatProtection#read operationId: get-xmlthreatprotection-plugin summary: Get a XmlThreatProtection plugin description: Get a XmlThreatProtection plugin responses: '200': description: XmlThreatProtection plugin content: application/json: schema: $ref: '#/components/schemas/XmlThreatProtectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginXmlThreatProtection#update operationId: update-xmlthreatprotection-plugin summary: Update a XmlThreatProtection plugin description: Update a XmlThreatProtection plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/XmlThreatProtectionPlugin' responses: '200': description: XmlThreatProtection plugin content: application/json: schema: $ref: '#/components/schemas/XmlThreatProtectionPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /{workspace}/plugins/{PluginId}#Zipkin: parameters: - $ref: '#/components/parameters/PluginId' - $ref: '#/components/parameters/Workspace' delete: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginZipkin#delete operationId: delete-zipkin-plugin summary: Delete a Zipkin plugin description: Delete a Zipkin plugin responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins get: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginZipkin#read operationId: get-zipkin-plugin summary: Get a Zipkin plugin description: Get a Zipkin plugin responses: '200': description: Zipkin plugin content: application/json: schema: $ref: '#/components/schemas/ZipkinPlugin' '401': $ref: '#/components/responses/HTTP401Error' '404': description: Resource does not exist tags: - Plugins put: x-speakeasy-entity-operation: terraform-datasource: null terraform-resource: PluginZipkin#update operationId: update-zipkin-plugin summary: Update a Zipkin plugin description: Update a Zipkin plugin requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ZipkinPlugin' responses: '200': description: Zipkin plugin content: application/json: schema: $ref: '#/components/schemas/ZipkinPlugin' '401': $ref: '#/components/responses/HTTP401Error' tags: - Plugins /schemas/plugins/{pluginName}: parameters: - name: pluginName in: path description: The name of the plugin required: true schema: type: string get: operationId: fetch-plugin-schema summary: Get plugin schema description: Get the schema for a plugin responses: '200': $ref: '#/components/responses/GetPluginSchemaResponse' tags: - Plugins x-keep-sdk: true /v2/control-planes/{controlPlaneId}/core-entities/consumer_groups/{ConsumerGroupId}/plugins: parameters: - $ref: '#/components/parameters/controlPlaneId' get: operationId: list-plugin-with-consumer_group summary: List all Plugins associated with a Consumer Group description: List all Plugins associated with a Consumer Group parameters: - $ref: '#/components/parameters/ConsumerGroupId' - $ref: '#/components/parameters/PaginationSize' - $ref: '#/components/parameters/PaginationOffset' - $ref: '#/components/parameters/PaginationTagsFilter' responses: '200': description: A successful response listing Plugins content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/Plugin_2' next: $ref: '#/components/schemas/PaginationNextResponse' offset: $ref: '#/components/schemas/PaginationOffsetResponse' tags: - Plugins post: operationId: create-plugin-with-consumer_group summary: Create a new Plugin associated with a Consumer Group description: Create a new Plugin associated with a Consumer Group parameters: - $ref: '#/components/parameters/ConsumerGroupId' requestBody: description: Description of new Plugin for creation required: true content: application/json: schema: $ref: '#/components/schemas/PluginWithoutParents' responses: '201': description: Successfully created Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' tags: - Plugins /v2/control-planes/{controlPlaneId}/core-entities/consumer_groups/{ConsumerGroupId}/plugins/{PluginId}: parameters: - $ref: '#/components/parameters/controlPlaneId' delete: operationId: delete-plugin-with-consumer_group summary: Delete a a Plugin associated with a Consumer Group description: Delete a a Plugin associated with a Consumer Group using ID. parameters: - $ref: '#/components/parameters/ConsumerGroupId' - $ref: '#/components/parameters/PluginId_2' responses: '204': description: Successfully deleted Plugin or the resource didn't exist tags: - Plugins get: operationId: get-plugin-with-consumer_group summary: Get a Plugin associated with a Consumer Group description: Get a Plugin associated with a Consumer Group using ID. parameters: - $ref: '#/components/parameters/ConsumerGroupId' - $ref: '#/components/parameters/PluginId_2' - $ref: '#/components/parameters/ExpandPartials' responses: '200': description: Successfully fetched Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' '404': description: Resource does not exist tags: - Plugins put: operationId: upsert-plugin-with-consumer_group summary: Upsert a Plugin associated with a Consumer Group description: Create or Update a Plugin associated with a Consumer Group using ID. parameters: - $ref: '#/components/parameters/ConsumerGroupId' - $ref: '#/components/parameters/PluginId_2' requestBody: description: Description of the Plugin required: true content: application/json: schema: $ref: '#/components/schemas/PluginWithoutParents' responses: '200': description: Successfully upserted Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' tags: - Plugins /v2/control-planes/{controlPlaneId}/core-entities/consumers/{ConsumerIdForNestedEntities}/plugins: parameters: - $ref: '#/components/parameters/controlPlaneId' get: operationId: list-plugin-with-consumer summary: List all Plugins associated with a Consumer description: List all Plugins associated with a Consumer parameters: - $ref: '#/components/parameters/ConsumerIdForNestedEntities' - $ref: '#/components/parameters/PaginationSize' - $ref: '#/components/parameters/PaginationOffset' - $ref: '#/components/parameters/PaginationTagsFilter' responses: '200': description: A successful response listing Plugins content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/Plugin_2' next: $ref: '#/components/schemas/PaginationNextResponse' offset: $ref: '#/components/schemas/PaginationOffsetResponse' tags: - Plugins post: operationId: create-plugin-with-consumer summary: Create a new Plugin associated with a Consumer description: Create a new Plugin associated with a Consumer parameters: - $ref: '#/components/parameters/ConsumerIdForNestedEntities' requestBody: description: Description of new Plugin for creation required: true content: application/json: schema: $ref: '#/components/schemas/PluginWithoutParents' responses: '201': description: Successfully created Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' tags: - Plugins /v2/control-planes/{controlPlaneId}/core-entities/consumers/{ConsumerIdForNestedEntities}/plugins/{PluginId}: parameters: - $ref: '#/components/parameters/controlPlaneId' delete: operationId: delete-plugin-with-consumer summary: Delete a a Plugin associated with a Consumer description: Delete a a Plugin associated with a Consumer using ID. parameters: - $ref: '#/components/parameters/ConsumerIdForNestedEntities' - $ref: '#/components/parameters/PluginId_2' responses: '204': description: Successfully deleted Plugin or the resource didn't exist tags: - Plugins get: operationId: get-plugin-with-consumer summary: Get a Plugin associated with a Consumer description: Get a Plugin associated with a Consumer using ID. parameters: - $ref: '#/components/parameters/ConsumerIdForNestedEntities' - $ref: '#/components/parameters/PluginId_2' - $ref: '#/components/parameters/ExpandPartials' responses: '200': description: Successfully fetched Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' '404': description: Resource does not exist tags: - Plugins put: operationId: upsert-plugin-with-consumer summary: Upsert a Plugin associated with a Consumer description: Create or Update a Plugin associated with a Consumer using ID. parameters: - $ref: '#/components/parameters/ConsumerIdForNestedEntities' - $ref: '#/components/parameters/PluginId_2' requestBody: description: Description of the Plugin required: true content: application/json: schema: $ref: '#/components/schemas/PluginWithoutParents' responses: '200': description: Successfully upserted Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' tags: - Plugins /v2/control-planes/{controlPlaneId}/core-entities/plugins: parameters: - $ref: '#/components/parameters/controlPlaneId' get: operationId: list-plugin summary: List all Plugins description: List all Plugins parameters: - $ref: '#/components/parameters/PaginationSize' - $ref: '#/components/parameters/PaginationOffset' - $ref: '#/components/parameters/PaginationTagsFilter' - $ref: '#/components/parameters/NameContainsFilter' - $ref: '#/components/parameters/NameEqualsFilter' responses: '200': description: A successful response listing Plugins content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/Plugin_2' next: $ref: '#/components/schemas/PaginationNextResponse' offset: $ref: '#/components/schemas/PaginationOffsetResponse' '401': $ref: '#/components/responses/HTTP401Error_2' tags: - Plugins post: operationId: create-plugin summary: Create a new Plugin description: Create a new Plugin requestBody: description: Description of the new Plugin for creation required: true content: application/json: schema: $ref: '#/components/schemas/Plugin_2' responses: '201': description: Successfully created Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' '401': $ref: '#/components/responses/HTTP401Error_2' tags: - Plugins /v2/control-planes/{controlPlaneId}/core-entities/plugins/{PluginId}: parameters: - $ref: '#/components/parameters/PluginId_2' - $ref: '#/components/parameters/controlPlaneId' delete: operationId: delete-plugin summary: Delete a Plugin description: Delete a Plugin parameters: - $ref: '#/components/parameters/PluginId_2' responses: '204': description: Successfully deleted Plugin or the resource didn't exist '401': $ref: '#/components/responses/HTTP401Error_2' tags: - Plugins get: operationId: get-plugin summary: Get a Plugin description: Get a Plugin using ID. parameters: - $ref: '#/components/parameters/ExpandPartials' responses: '200': description: Successfully fetched Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' '401': $ref: '#/components/responses/HTTP401Error_2' '404': description: Resource does not exist tags: - Plugins put: operationId: upsert-plugin summary: Upsert a Plugin description: Create or Update Plugin using ID. requestBody: description: Description of the Plugin required: true content: application/json: schema: $ref: '#/components/schemas/Plugin_2' responses: '200': description: Successfully upserted Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' '401': $ref: '#/components/responses/HTTP401Error_2' tags: - Plugins /v2/control-planes/{controlPlaneId}/core-entities/routes/{RouteId}/plugins: parameters: - $ref: '#/components/parameters/controlPlaneId' get: operationId: list-plugin-with-route summary: List all Plugins associated with a Route description: List all Plugins associated with a Route parameters: - $ref: '#/components/parameters/RouteId' - $ref: '#/components/parameters/PaginationSize' - $ref: '#/components/parameters/PaginationOffset' - $ref: '#/components/parameters/PaginationTagsFilter' responses: '200': description: A successful response listing Plugins content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/Plugin_2' next: $ref: '#/components/schemas/PaginationNextResponse' offset: $ref: '#/components/schemas/PaginationOffsetResponse' tags: - Plugins post: operationId: create-plugin-with-route summary: Create a new Plugin associated with a Route description: Create a new Plugin associated with a Route parameters: - $ref: '#/components/parameters/RouteId' requestBody: description: Description of new Plugin for creation required: true content: application/json: schema: $ref: '#/components/schemas/PluginWithoutParents' responses: '201': description: Successfully created Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' tags: - Plugins /v2/control-planes/{controlPlaneId}/core-entities/routes/{RouteId}/plugins/{PluginId}: parameters: - $ref: '#/components/parameters/controlPlaneId' delete: operationId: delete-plugin-with-route summary: Delete a a Plugin associated with a Route description: Delete a a Plugin associated with a Route using ID. parameters: - $ref: '#/components/parameters/RouteId' - $ref: '#/components/parameters/PluginId_2' responses: '204': description: Successfully deleted Plugin or the resource didn't exist tags: - Plugins get: operationId: get-plugin-with-route summary: Get a Plugin associated with a Route description: Get a Plugin associated with a Route using ID. parameters: - $ref: '#/components/parameters/RouteId' - $ref: '#/components/parameters/PluginId_2' - $ref: '#/components/parameters/ExpandPartials' responses: '200': description: Successfully fetched Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' '404': description: Resource does not exist tags: - Plugins put: operationId: upsert-plugin-with-route summary: Upsert a Plugin associated with a Route description: Create or Update a Plugin associated with a Route using ID. parameters: - $ref: '#/components/parameters/RouteId' - $ref: '#/components/parameters/PluginId_2' requestBody: description: Description of the Plugin required: true content: application/json: schema: $ref: '#/components/schemas/PluginWithoutParents' responses: '200': description: Successfully upserted Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' tags: - Plugins /v2/control-planes/{controlPlaneId}/core-entities/schemas/plugins/{pluginName}: parameters: - name: pluginName in: path description: The name of the plugin required: true schema: type: string - $ref: '#/components/parameters/controlPlaneId' get: operationId: fetch-plugin-schema summary: Get plugin schema description: Get the schema for a plugin responses: '200': $ref: '#/components/responses/GetPluginSchemaResponse' tags: - Plugins x-keep-sdk: true /v2/control-planes/{controlPlaneId}/core-entities/services/{ServiceId}/plugins: parameters: - $ref: '#/components/parameters/controlPlaneId' get: operationId: list-plugin-with-service summary: List all Plugins associated with a Service description: List all Plugins associated with a Service parameters: - $ref: '#/components/parameters/ServiceId' - $ref: '#/components/parameters/PaginationSize' - $ref: '#/components/parameters/PaginationOffset' - $ref: '#/components/parameters/PaginationTagsFilter' responses: '200': description: A successful response listing Plugins content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/Plugin_2' next: $ref: '#/components/schemas/PaginationNextResponse' offset: $ref: '#/components/schemas/PaginationOffsetResponse' tags: - Plugins post: operationId: create-plugin-with-service summary: Create a new Plugin associated with a Service description: Create a new Plugin associated with a Service parameters: - $ref: '#/components/parameters/ServiceId' requestBody: description: Description of new Plugin for creation required: true content: application/json: schema: $ref: '#/components/schemas/PluginWithoutParents' responses: '201': description: Successfully created Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' tags: - Plugins /v2/control-planes/{controlPlaneId}/core-entities/services/{ServiceId}/plugins/{PluginId}: parameters: - $ref: '#/components/parameters/controlPlaneId' delete: operationId: delete-plugin-with-service summary: Delete a a Plugin associated with a Service description: Delete a a Plugin associated with a Service using ID. parameters: - $ref: '#/components/parameters/ServiceId' - $ref: '#/components/parameters/PluginId_2' responses: '204': description: Successfully deleted Plugin or the resource didn't exist tags: - Plugins get: operationId: get-plugin-with-service summary: Get a Plugin associated with a Service description: Get a Plugin associated with a Service using ID. parameters: - $ref: '#/components/parameters/ServiceId' - $ref: '#/components/parameters/PluginId_2' - $ref: '#/components/parameters/ExpandPartials' responses: '200': description: Successfully fetched Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' '404': description: Resource does not exist tags: - Plugins put: operationId: upsert-plugin-with-service summary: Upsert a Plugin associated with a Service description: Create or Update a Plugin associated with a Service using ID. parameters: - $ref: '#/components/parameters/ServiceId' - $ref: '#/components/parameters/PluginId_2' requestBody: description: Description of the Plugin required: true content: application/json: schema: $ref: '#/components/schemas/PluginWithoutParents' responses: '200': description: Successfully upserted Plugin content: application/json: schema: $ref: '#/components/schemas/Plugin_2' tags: - Plugins components: schemas: ResponseRatelimitingPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/ResponseRatelimitingPluginConfig' InjectionProtectionPluginConfig: x-speakeasy-entity: PluginInjectionProtection properties: config: type: object properties: custom_injections: description: Custom regexes to check for. type: array items: properties: name: description: A unique name for this injection. type: string regex: description: The regex to match against. type: string required: - name - regex type: object enforcement_mode: description: Enforcement mode of the security policy. type: string default: block enum: - block - log_only error_message: description: The response message when validation fails type: string default: Bad Request error_status_code: description: The response status code when validation fails. type: integer default: 400 maximum: 499 minimum: 400 injection_types: description: The type of injections to check for. type: array items: enum: - java_exception - js - sql - sql_low_sensitivity - ssi - xpath_abbreviated - xpath_extended type: string default: - sql locations: description: The locations to check for injection. type: array items: enum: - body - headers - path - path_and_query - query type: string default: - path_and_query name: const: injection-protection protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AiProxyPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiProxyPluginConfig' AcmePlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AcmePluginConfig' KafkaLogPluginConfig: x-speakeasy-entity: PluginKafkaLog properties: config: type: object properties: authentication: type: object properties: mechanism: description: 'The SASL authentication mechanism. Supported options: `PLAIN`, `SCRAM-SHA-256` or `SCRAM-SHA-512`.' type: string enum: - PLAIN - SCRAM-SHA-256 - SCRAM-SHA-512 password: description: Password for SASL authentication. type: string x-encrypted: true x-referenceable: true strategy: description: The authentication strategy for the plugin, the only option for the value is `sasl`. type: string enum: - sasl tokenauth: description: Enable this to indicate `DelegationToken` authentication type: boolean user: description: Username for SASL authentication. type: string x-encrypted: true x-referenceable: true bootstrap_servers: description: 'Set of bootstrap brokers in a `{host: host, port: port}` list format.' type: array items: properties: host: description: A string representing a host name, such as example.com. type: string port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 required: - host - port type: object cluster_name: description: An identifier for the Kafka cluster. By default, this field generates a random string. You can also set your own custom cluster identifier. If more than one Kafka plugin is configured without a `cluster_name` (that is, if the default autogenerated value is removed), these plugins will use the same producer, and by extension, the same cluster. Logs will be sent to the leader of the cluster. type: string custom_fields_by_lua: description: Lua code as a key-value map type: object additionalProperties: type: string keepalive: type: integer default: 60000 keepalive_enabled: type: boolean default: false key_query_arg: description: The request query parameter name that contains the Kafka message key. If specified, messages with the same key will be sent to the same Kafka partition, ensuring consistent ordering. type: string producer_async: description: Flag to enable asynchronous mode. type: boolean default: true producer_async_buffering_limits_messages_in_memory: description: Maximum number of messages that can be buffered in memory in asynchronous mode. type: integer default: 50000 producer_async_flush_timeout: description: Maximum time interval in milliseconds between buffer flushes in asynchronous mode. type: integer default: 1000 producer_request_acks: description: 'The number of acknowledgments the producer requires the leader to have received before considering a request complete. Allowed values: 0 for no acknowledgments; 1 for only the leader; and -1 for the full ISR (In-Sync Replica set).' type: integer default: 1 enum: - -1 - 0 - 1 producer_request_limits_bytes_per_request: description: Maximum size of a Produce request in bytes. type: integer default: 1048576 producer_request_limits_messages_per_request: description: Maximum number of messages to include into a single Produce request. type: integer default: 200 producer_request_retries_backoff_timeout: description: Backoff interval between retry attempts in milliseconds. type: integer default: 100 producer_request_retries_max_attempts: description: Maximum number of retry attempts per single Produce request. type: integer default: 10 producer_request_timeout: description: Time to wait for a Produce response in milliseconds type: integer default: 2000 schema_registry: description: The plugin-global schema registry configuration. This can be overwritten by the topic configuration. type: object properties: confluent: type: object properties: authentication: type: object properties: basic: type: object properties: password: type: string x-encrypted: true x-referenceable: true username: type: string x-encrypted: true x-referenceable: true required: - password - username mode: description: Authentication mode to use with the schema registry. type: string default: none enum: - basic - none - oauth2 oauth2: type: object properties: audience: description: List of audiences passed to the IdP when obtaining a new token. type: array items: type: string default: [] client_id: description: The client ID for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true client_secret: description: The client secret for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true grant_type: description: The OAuth grant type to be used. type: string default: client_credentials enum: - client_credentials - password password: description: The password to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true scopes: description: List of scopes to request from the IdP when obtaining a new token. type: array items: type: string default: - openid token_endpoint: description: The token endpoint URI. type: string token_headers: description: Extra headers to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true token_post_args: description: Extra post arguments to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true username: description: The username to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true required: - token_endpoint oauth2_client: type: object properties: auth_method: description: 'The authentication method used in client requests to the IdP. Supported values are: `client_secret_basic` to send `client_id` and `client_secret` in the `Authorization: Basic` header, `client_secret_post` to send `client_id` and `client_secret` as part of the request body, or `client_secret_jwt` to send a JWT signed with the `client_secret` using the client assertion as part of the body.' type: string default: client_secret_post enum: - client_secret_basic - client_secret_jwt - client_secret_post - none client_secret_jwt_alg: description: The algorithm to use with JWT when using `client_secret_jwt` authentication. type: string default: HS512 enum: - HS256 - HS512 http_proxy: description: The proxy to use when making HTTP requests to the IdP. type: string http_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `http_proxy`. type: string http_version: description: 'The HTTP version used for requests made by this plugin. Supported values: `1.1` for HTTP 1.1 and `1.0` for HTTP 1.0.' type: number default: 1.1 https_proxy: description: The proxy to use when making HTTPS requests to the IdP. type: string https_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `https_proxy`. type: string keep_alive: description: Whether to use keepalive connections to the IdP. type: boolean default: true no_proxy: description: A comma-separated list of hosts that should not be proxied. type: string ssl_verify: description: Whether to verify the certificate presented by the IdP when using HTTPS. type: boolean default: true timeout: description: Network I/O timeout for requests to the IdP in milliseconds. type: integer default: 10000 maximum: 2147483646 minimum: 0 key_schema: type: object properties: schema_version: description: The schema version to use for serialization/deserialization. Use 'latest' to always fetch the most recent version. type: string subject_name: description: The name of the subject type: string ssl_verify: description: Set to false to disable SSL certificate verification when connecting to the schema registry. type: boolean default: true ttl: description: The TTL in seconds for the schema registry cache. type: number maximum: 3600 minimum: 0 url: description: The URL of the schema registry. type: string value_schema: type: object properties: schema_version: description: The schema version to use for serialization/deserialization. Use 'latest' to always fetch the most recent version. type: string subject_name: description: The name of the subject type: string security: type: object properties: certificate_id: description: UUID of certificate entity for mTLS authentication. type: string ssl: description: Enables TLS. type: boolean ssl_verify: description: When using TLS, this option enables verification of the certificate presented by the server. type: boolean default: true timeout: description: Socket timeout in milliseconds. type: integer default: 10000 topic: description: The Kafka topic to publish to. type: string required: - topic consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: kafka-log protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config IpRestrictionPluginConfig: x-speakeasy-entity: PluginIpRestriction properties: config: type: object properties: allow: description: List of IPs or CIDR ranges to allow. One of `config.allow` or `config.deny` must be specified. type: array items: description: A string representing an IP address or CIDR block, such as 192.168.1.1 or 192.168.0.0/16. type: string deny: description: List of IPs or CIDR ranges to deny. One of `config.allow` or `config.deny` must be specified. type: array items: description: A string representing an IP address or CIDR block, such as 192.168.1.1 or 192.168.0.0/16. type: string message: description: The message to send as a response body to rejected requests. type: string status: description: The HTTP status of the requests that will be rejected by the plugin. type: number consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ip-restriction protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https - tcp - tls route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AppDynamicsPluginConfig: x-speakeasy-entity: PluginAppDynamics properties: config: type: object additionalProperties: true consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: app-dynamics protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AiResponseTransformerPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiResponseTransformerPluginConfig' AiAwsGuardrailsPluginConfig: x-speakeasy-entity: PluginAiAwsGuardrails properties: config: type: object properties: allow_masking: description: Allow to masking the request/response instead of blocking it. Streaming will be disabled if this is enabled. type: boolean default: false aws_access_key_id: description: The AWS access key ID to use for authentication type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The target AWS IAM role ARN used to access the guardrails service type: string aws_region: description: The AWS region to use for the Bedrock API type: string aws_role_session_name: description: The identifier of the assumed role session type: string aws_secret_access_key: description: The AWS secret access key to use for authentication type: string x-encrypted: true x-referenceable: true aws_sts_endpoint_url: description: Override the STS endpoint URL when assuming a different role type: string guarding_mode: description: The guardrail mode to use for the request type: string default: INPUT enum: - BOTH - INPUT - OUTPUT guardrails_id: description: The guardrail identifier used in the request to apply the guardrail. type: string guardrails_version: description: The guardrail version used in the request to apply the guardrail. Note that the value of this field must match the pattern `(([1-9][0-9]{0,7})|(DRAFT))` according to the AWS documentation https://docs.aws.amazon.com/bedrock/latest/APIReference/API_runtime_ApplyGuardrail.html#API_runtime_ApplyGuardrail_RequestSyntax. type: string log_blocked_content: description: Whether to log prompts and responses that are blocked by the guardrail. type: boolean default: false response_buffer_size: description: The amount of bytes receiving from upstream to be buffered before sending to the guardrails service. This only applies to the response content guard. type: number default: 100 ssl_verify: description: Verify TLS certificate when connecting to the bedrock service. type: boolean default: true stop_on_error: description: Stop processing if an error occurs type: boolean default: true text_source: description: Select where to pick the 'text' for the Content Guard Services request. type: string default: concatenate_all_content enum: - concatenate_all_content - concatenate_user_content timeout: description: Connection timeout with the bedrock service type: number default: 10000 required: - aws_region - guardrails_id - guardrails_version consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-aws-guardrails protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config AiSemanticCachePluginConfig: x-speakeasy-entity: PluginAiSemanticCache properties: config: type: object properties: cache_control: description: When enabled, respect the Cache-Control behaviors defined in RFC7234. type: boolean default: false cache_ttl: description: TTL in seconds of cache entities. Must be a value greater than 0. type: integer default: 300 embeddings: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true model: type: object properties: name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: azure: type: object properties: api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' deployment_id: description: Deployment ID for Azure OpenAI instances. type: string instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean upstream_url: description: upstream url for the embeddings type: string provider: description: AI provider format to use for embeddings API type: string enum: - azure - bedrock - gemini - huggingface - mistral - ollama - openai required: - name - provider required: - model exact_caching: description: When enabled, a first check for exact query will be done. It will impact DB size type: boolean default: false ignore_assistant_prompts: description: Ignore and discard any assistant prompts when Vectorizing the request type: boolean default: false ignore_system_prompts: description: Ignore and discard any system prompts when Vectorizing the request type: boolean default: false ignore_tool_prompts: description: Ignore and discard any tool prompts when Vectorizing the request type: boolean default: false llm_format: description: LLM input and output format and schema to use type: string default: openai enum: - anthropic - bedrock - cohere - gemini - huggingface - openai message_countback: description: Number of messages in the chat history to Vectorize/Cache type: number default: 1 maximum: 1000 minimum: 1 stop_on_failure: description: Halt the LLM request process in case of a caching system failure type: boolean default: false vectordb: type: object properties: dimensions: description: the desired dimensionality for the vectors type: integer distance_metric: description: the distance metric to use for vector searches type: string enum: - cosine - euclidean pgvector: type: object properties: database: description: the database of the pgvector database type: string default: kong-pgvector host: description: the host of the pgvector database type: string default: 127.0.0.1 password: description: the password of the pgvector database type: string x-encrypted: true x-referenceable: true port: description: the port of the pgvector database type: integer default: 5432 ssl: description: whether to use ssl for the pgvector database type: boolean default: false ssl_cert: description: the path of ssl cert to use for the pgvector database type: string ssl_cert_key: description: the path of ssl cert key to use for the pgvector database type: string ssl_required: description: whether ssl is required for the pgvector database type: boolean default: false ssl_verify: description: whether to verify ssl for the pgvector database type: boolean default: true ssl_version: description: the ssl version to use for the pgvector database type: string default: tlsv1_2 enum: - any - tlsv1_2 - tlsv1_3 timeout: description: the timeout of the pgvector database type: number default: 5000 user: description: the user of the pgvector database type: string default: postgres x-referenceable: true redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true strategy: description: which vector database driver to use type: string enum: - pgvector - redis threshold: description: the default similarity threshold for accepting semantic search results (float). Higher threshold means more results are considered similar. type: number required: - dimensions - distance_metric - strategy required: - embeddings - vectordb consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-semantic-cache protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config JqPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/JqPluginConfig' TlsMetadataHeadersPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/TlsMetadataHeadersPluginConfig' TcpLogPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/TcpLogPluginConfig' AiGcpModelArmorPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiGcpModelArmorPluginConfig' TlsHandshakeModifierPluginConfig: x-speakeasy-entity: PluginTlsHandshakeModifier properties: config: type: object properties: tls_client_certificate: description: TLS Client Certificate type: string default: REQUEST enum: - REQUEST name: const: tls-handshake-modifier protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpcs - https - tls type: string format: set default: - grpcs - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string OpaPluginConfig: x-speakeasy-entity: PluginOpa properties: config: type: object properties: include_body_in_opa_input: type: boolean default: false include_consumer_in_opa_input: description: If set to true, the Kong Gateway Consumer object in use for the current request (if any) is included as input to OPA. type: boolean default: false include_parsed_json_body_in_opa_input: description: If set to true and the `Content-Type` header of the current request is `application/json`, the request body will be JSON decoded and the decoded struct is included as input to OPA. type: boolean default: false include_route_in_opa_input: description: If set to true, the Kong Gateway Route object in use for the current request is included as input to OPA. type: boolean default: false include_service_in_opa_input: description: If set to true, the Kong Gateway Service object in use for the current request is included as input to OPA. type: boolean default: false include_uri_captures_in_opa_input: description: If set to true, the regex capture groups captured on the Kong Gateway Route's path field in the current request (if any) are included as input to OPA. type: boolean default: false opa_host: description: A string representing a host name, such as example.com. type: string default: localhost opa_path: description: A string representing a URL path, such as /path/to/resource. Must start with a forward slash (/) and must not contain empty segments (i.e., two consecutive forward slashes). type: string opa_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 8181 maximum: 65535 minimum: 0 opa_protocol: description: The protocol to use when talking to Open Policy Agent (OPA) server. Allowed protocols are `http` and `https`. type: string default: http enum: - http - https ssl_verify: description: If set to true, the OPA certificate will be verified according to the CA certificates specified in lua_ssl_trusted_certificate. type: boolean default: true required: - opa_path name: const: opa protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config WebsocketSizeLimitPluginConfig: x-speakeasy-entity: PluginWebsocketSizeLimit properties: config: type: object properties: client_max_payload: type: integer maximum: 33554432 minimum: 1 upstream_max_payload: type: integer maximum: 33554432 minimum: 1 consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: websocket-size-limit protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - ws - wss type: string format: set default: - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string PreFunctionPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/PreFunctionPluginConfig' GraphqlProxyCacheAdvancedPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/GraphqlProxyCacheAdvancedPluginConfig' BotDetectionPluginConfig: x-speakeasy-entity: PluginBotDetection properties: config: type: object properties: allow: description: An array of regular expressions that should be allowed. The regular expressions will be checked against the `User-Agent` header. type: array items: type: string default: [] deny: description: An array of regular expressions that should be denied. The regular expressions will be checked against the `User-Agent` header. type: array items: type: string default: [] name: const: bot-detection protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AiMcpOauth2PluginConfig: x-speakeasy-entity: PluginAiMcpOauth2 properties: config: description: The configuration for MCP authorization in OAuth2. If this is enabled, make sure the configured metadata_endpoint is also covered by the same route so the authorization can be applied correctly. type: object properties: args: description: Additional arguments to send in the POST body. type: object additionalProperties: type: string authorization_servers: type: array items: description: The authorization server identifier. type: string minLength: 1 cache_introspection: description: If enabled, the plugin will cache the introspection response for the access token. This can improve performance by reducing the number of introspection requests to the authorization server. type: boolean default: true claim_to_header: description: Map top-level token claims to upstream headers. Mutually exclusive with upstream_headers. type: array items: properties: claim: description: The claim name to be used in the access token. type: string header: description: The HTTP header name to be used for forwarding the claim value to the upstream. type: string required: - claim - header type: object minLength: 1 client_alg: description: The client JWT signing algorithm. type: string enum: - ES256 - ES384 - ES512 - EdDSA - HS256 - HS384 - HS512 - PS256 - PS384 - PS512 - RS256 - RS384 - RS512 client_auth: description: The client authentication method. type: string enum: - client_secret_basic - client_secret_jwt - client_secret_post - none - private_key_jwt - self_signed_tls_client_auth - tls_client_auth client_id: description: The client ID for authentication. type: string x-referenceable: true client_jwk: description: The client JWK for private_key_jwt authentication. type: string x-encrypted: true x-referenceable: true client_secret: description: The client secret for authentication. type: string x-encrypted: true x-referenceable: true consumer_by: description: 'Consumer fields used for mapping: - `id`: try to find the matching Consumer by `id` - `username`: try to find the matching Consumer by `username` - `custom_id`: try to find the matching Consumer by `custom_id`.' type: array items: enum: - custom_id - id - username type: string default: - custom_id - username minLength: 1 consumer_claim: description: The claim used for consumer mapping. If multiple values are set, it means the claim is inside a nested object of the token payload. type: array items: type: string minLength: 1 consumer_groups_claim: description: The claim used for consumer groups mapping. If multiple values are set, it means the claim is inside a nested object of the token payload. type: array items: type: string minLength: 1 consumer_groups_optional: description: Do not terminate the request if consumer groups mapping fails. type: boolean default: false consumer_optional: description: Do not terminate the request if consumer mapping fails. type: boolean default: false credential_claim: description: The claim used to derive virtual credentials (e.g. to be consumed by the rate-limiting plugin), in case the consumer mapping is not used. If multiple values are set, it means the claim is inside a nested object of the token payload. type: array items: type: string default: - sub headers: description: Additional headers for the introspection request. type: object additionalProperties: type: string http_proxy: description: HTTP proxy to use. type: string http_proxy_authorization: description: HTTP proxy authorization header. type: string http_version: description: The HTTP version used for requests. type: number default: 1.1 https_proxy: description: HTTPS proxy to use. type: string https_proxy_authorization: description: HTTPS proxy authorization header. type: string insecure_relaxed_audience_validation: description: If enabled, the plugin will not validate the audience of the access token. Disable it if the authorization server does not correctly set the audience claim according to RFC 8707 and MCP specification. type: boolean default: false introspection_endpoint: description: The Token Introspection Endpoint. If not provided, the plugin will attempt to use JWKS to verify the token. If the token is opaque, this field must be provided. type: string introspection_format: description: Controls introspection response format. type: string enum: - base64 - base64url - string jwks_cache_ttl: description: The cache TTL in seconds for JWKS. type: integer default: 3600 jwks_endpoint: description: The JWKS endpoint URL for fetching the authorization server's public keys. If not provided, the plugin will attempt to discover it from the authorization server metadata. type: string jwt_claims_leeway: description: The leeway in seconds for JWT claims validation (exp, nbf). This allows tokens that are slightly expired or not yet valid due to clock skew. type: integer default: 0 keepalive: description: Enable HTTP keepalive for requests. type: boolean default: true max_request_body_size: description: max allowed body size allowed to be handled as MCP request. 0 means unlimited, but the size of this body will still be limited by Nginx's client_max_body_size. type: integer default: 1048576 metadata_cache_ttl: description: The cache TTL in seconds for discovered authorization server metadata. type: integer default: 3600 metadata_discovery_endpoint: description: Custom OAuth 2.0 authorization server metadata discovery URL. If provided, the plugin will use this URL directly instead of trying standard well-known discovery paths. The custom endpoint URL should end with either '/.well-known/openid-configuration' or '/.well-known/oauth-authorization-server'. type: string metadata_discovery_retry: description: The number of retry attempts for metadata discovery requests per URL. type: integer default: 3 metadata_endpoint: description: The path for OAuth 2.0 Protected Resource Metadata. Default to $resource/.well-known/oauth-protected-resource. For example, if the configured resource is https://api.example.com/mcp, the metadata endpoint is /mcp/.well-known/oauth-protected-resource. type: string mtls_introspection_endpoint: description: The mTLS alias for the introspection endpoint. type: string no_proxy: description: Comma-separated list of hosts to exclude from proxy. type: string passthrough_credentials: description: Keep the credentials used for authentication in the request. If multiple credentials are sent with the same request, the plugin will keep those that were used for successful authentication. type: boolean default: false resource: description: The resource identifier. type: string scopes_supported: type: array items: description: Recommended scopes that are used in authorization requests to request access to this protected resource. type: string minLength: 1 ssl_verify: description: Verify the SSL certificate. type: boolean default: true timeout: description: Network I/O timeout in milliseconds. type: number default: 10000 tls_client_auth_cert: description: PEM-encoded client certificate for mTLS. type: string tls_client_auth_key: description: PEM-encoded private key for mTLS. type: string tls_client_auth_ssl_verify: description: Verify server certificate in mTLS. type: boolean default: true token_exchange: description: Configuration details about token exchange that should happen before reaching upstream MCP server type: object properties: cache: type: object properties: enabled: description: Whether to cache exchanged token type: boolean default: true ttl: description: The default cache TTL to store exchanged token. If the exchange endpoint does not provide 'expires_in' data when token is exchanged this TTL value will be used to cache it. type: integer default: 3600 client_auth: description: The type of authentication method to use with the exchange endpoint. Use 'inherit' to use the same client_id, and secret as in introspection_endpoint. type: string default: client_secret_basic enum: - client_secret_basic - client_secret_post - inherit - none client_id: description: The client ID for authentication. type: string x-referenceable: true client_secret: description: The client secret for authentication. type: string x-encrypted: true x-referenceable: true enabled: description: Whether Token Exchange should be enabled type: boolean default: false request: type: object properties: actor_token: description: Static actor token value (when source is config). type: string actor_token_header: description: Header name containing actor token (when source is header). type: string actor_token_source: description: Where to obtain actor token. type: string default: none enum: - config - header - none actor_token_type: description: The token type identifier of actor token. type: string default: urn:ietf:params:oauth:token-type:access_token audience: description: Audiences used in the token exchange request. type: array items: type: string minLength: 1 requested_token_type: description: The desired output token type. type: string default: urn:ietf:params:oauth:token-type:access_token resource: description: The absolute URI of target MCP service where token will be used. type: string scopes: description: Scopes used in the token exchange request. type: array items: type: string minLength: 1 subject_token_type: description: The type of token to be exchanged. type: string default: urn:ietf:params:oauth:token-type:access_token token_endpoint: description: The token exchange endopint. type: string required: - token_endpoint upstream_headers: description: Map token claims to upstream headers using path-based access. Each entry specifies a header name and a path (array of strings) to traverse the token claims. Mutually exclusive with claim_to_header. type: array items: properties: header: description: The name of the header. type: string path: description: The path of the header value. type: array items: type: string minLength: 1 required: - header - path type: object required: - authorization_servers - resource name: const: ai-mcp-oauth2 protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config ResponseTransformerPluginConfig: x-speakeasy-entity: PluginResponseTransformer properties: config: type: object properties: add: type: object properties: headers: type: array items: type: string default: [] json: type: array items: type: string default: [] json_types: description: 'List of JSON type names. Specify the types of the JSON values returned when appending JSON properties. Each string element can be one of: boolean, number, or string.' type: array items: enum: - boolean - number - string type: string default: [] append: type: object properties: headers: type: array items: type: string default: [] json: type: array items: type: string default: [] json_types: description: 'List of JSON type names. Specify the types of the JSON values returned when appending JSON properties. Each string element can be one of: boolean, number, or string.' type: array items: enum: - boolean - number - string type: string default: [] remove: type: object properties: headers: type: array items: type: string default: [] json: type: array items: type: string default: [] rename: type: object properties: headers: type: array items: type: string default: [] json: type: array items: type: string default: [] replace: type: object properties: headers: type: array items: type: string default: [] json: type: array items: type: string default: [] json_types: description: 'List of JSON type names. Specify the types of the JSON values returned when appending JSON properties. Each string element can be one of: boolean, number, or string.' type: array items: enum: - boolean - number - string type: string default: [] consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: response-transformer protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string KafkaConsumePluginConfig: x-speakeasy-entity: PluginKafkaConsume properties: config: type: object properties: authentication: type: object properties: mechanism: description: 'The SASL authentication mechanism. Supported options: `PLAIN` or `SCRAM-SHA-256`.' type: string enum: - PLAIN - SCRAM-SHA-256 - SCRAM-SHA-512 password: description: Password for SASL authentication. type: string x-encrypted: true x-referenceable: true strategy: description: The authentication strategy for the plugin, the only option for the value is `sasl`. type: string enum: - sasl tokenauth: description: Enable this to indicate `DelegationToken` authentication type: boolean user: description: Username for SASL authentication. type: string x-encrypted: true x-referenceable: true auto_offset_reset: description: The offset to start from when there is no initial offset in the consumer group. type: string default: latest enum: - earliest - latest bootstrap_servers: description: 'Set of bootstrap brokers in a `{host: host, port: port}` list format.' type: array items: properties: host: description: A string representing a host name, such as example.com. type: string port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 required: - host - port type: object cluster_name: description: An identifier for the Kafka cluster. type: string commit_strategy: description: The strategy to use for committing offsets. type: string default: auto enum: - auto - 'off' dlq_topic: description: The topic to use for the Dead Letter Queue. type: string enable_dlq: description: Enables Dead Letter Queue. When enabled, if the message doesn't conform to the schema (from Schema Registry) or there's an error in the `message_by_lua_functions`, it will be forwarded to `dlq_topic` that can be processed later. type: boolean enforce_latest_offset_reset: description: When true, 'latest' offset reset behaves correctly (starts from end). When false (default), maintains backwards compatibility where 'latest' acts like 'earliest'. type: boolean default: false message_by_lua_functions: description: The Lua functions that manipulates the message being sent to the client. type: array items: type: string message_deserializer: description: The deserializer to use for the consumed messages. type: string default: noop enum: - json - noop mode: description: The mode of operation for the plugin. type: string default: http-get enum: - http-get - server-sent-events - websocket schema_registry: description: The plugin-global schema registry configuration. type: object properties: confluent: type: object properties: authentication: type: object properties: basic: type: object properties: password: type: string x-encrypted: true x-referenceable: true username: type: string x-encrypted: true x-referenceable: true required: - password - username mode: description: Authentication mode to use with the schema registry. type: string default: none enum: - basic - none - oauth2 oauth2: type: object properties: audience: description: List of audiences passed to the IdP when obtaining a new token. type: array items: type: string default: [] client_id: description: The client ID for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true client_secret: description: The client secret for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true grant_type: description: The OAuth grant type to be used. type: string default: client_credentials enum: - client_credentials - password password: description: The password to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true scopes: description: List of scopes to request from the IdP when obtaining a new token. type: array items: type: string default: - openid token_endpoint: description: The token endpoint URI. type: string token_headers: description: Extra headers to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true token_post_args: description: Extra post arguments to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true username: description: The username to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true required: - token_endpoint oauth2_client: type: object properties: auth_method: description: 'The authentication method used in client requests to the IdP. Supported values are: `client_secret_basic` to send `client_id` and `client_secret` in the `Authorization: Basic` header, `client_secret_post` to send `client_id` and `client_secret` as part of the request body, or `client_secret_jwt` to send a JWT signed with the `client_secret` using the client assertion as part of the body.' type: string default: client_secret_post enum: - client_secret_basic - client_secret_jwt - client_secret_post - none client_secret_jwt_alg: description: The algorithm to use with JWT when using `client_secret_jwt` authentication. type: string default: HS512 enum: - HS256 - HS512 http_proxy: description: The proxy to use when making HTTP requests to the IdP. type: string http_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `http_proxy`. type: string http_version: description: 'The HTTP version used for requests made by this plugin. Supported values: `1.1` for HTTP 1.1 and `1.0` for HTTP 1.0.' type: number default: 1.1 https_proxy: description: The proxy to use when making HTTPS requests to the IdP. type: string https_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `https_proxy`. type: string keep_alive: description: Whether to use keepalive connections to the IdP. type: boolean default: true no_proxy: description: A comma-separated list of hosts that should not be proxied. type: string ssl_verify: description: Whether to verify the certificate presented by the IdP when using HTTPS. type: boolean default: true timeout: description: Network I/O timeout for requests to the IdP in milliseconds. type: integer default: 10000 maximum: 2147483646 minimum: 0 ssl_verify: description: Set to false to disable SSL certificate verification when connecting to the schema registry. type: boolean default: true ttl: description: The TTL in seconds for the schema registry cache. type: number maximum: 3600 minimum: 0 url: description: The URL of the schema registry. type: string security: type: object properties: certificate_id: description: UUID of certificate entity for mTLS authentication. type: string ssl: description: Enables TLS. type: boolean ssl_verify: description: When using TLS, this option enables verification of the certificate presented by the server. type: boolean default: true topics: description: The Kafka topics and their configuration you want to consume from. type: array items: properties: name: type: string schema_registry: description: The plugin-global schema registry configuration. type: object properties: confluent: type: object properties: authentication: type: object properties: basic: type: object properties: password: type: string x-encrypted: true x-referenceable: true username: type: string x-encrypted: true x-referenceable: true required: - password - username mode: description: Authentication mode to use with the schema registry. type: string default: none enum: - basic - none - oauth2 oauth2: type: object properties: audience: description: List of audiences passed to the IdP when obtaining a new token. type: array items: type: string default: [] client_id: description: The client ID for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true client_secret: description: The client secret for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true grant_type: description: The OAuth grant type to be used. type: string default: client_credentials enum: - client_credentials - password password: description: The password to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true scopes: description: List of scopes to request from the IdP when obtaining a new token. type: array items: type: string default: - openid token_endpoint: description: The token endpoint URI. type: string token_headers: description: Extra headers to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true token_post_args: description: Extra post arguments to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true username: description: The username to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true required: - token_endpoint oauth2_client: type: object properties: auth_method: description: 'The authentication method used in client requests to the IdP. Supported values are: `client_secret_basic` to send `client_id` and `client_secret` in the `Authorization: Basic` header, `client_secret_post` to send `client_id` and `client_secret` as part of the request body, or `client_secret_jwt` to send a JWT signed with the `client_secret` using the client assertion as part of the body.' type: string default: client_secret_post enum: - client_secret_basic - client_secret_jwt - client_secret_post - none client_secret_jwt_alg: description: The algorithm to use with JWT when using `client_secret_jwt` authentication. type: string default: HS512 enum: - HS256 - HS512 http_proxy: description: The proxy to use when making HTTP requests to the IdP. type: string http_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `http_proxy`. type: string http_version: description: 'The HTTP version used for requests made by this plugin. Supported values: `1.1` for HTTP 1.1 and `1.0` for HTTP 1.0.' type: number default: 1.1 https_proxy: description: The proxy to use when making HTTPS requests to the IdP. type: string https_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `https_proxy`. type: string keep_alive: description: Whether to use keepalive connections to the IdP. type: boolean default: true no_proxy: description: A comma-separated list of hosts that should not be proxied. type: string ssl_verify: description: Whether to verify the certificate presented by the IdP when using HTTPS. type: boolean default: true timeout: description: Network I/O timeout for requests to the IdP in milliseconds. type: integer default: 10000 maximum: 2147483646 minimum: 0 ssl_verify: description: Set to false to disable SSL certificate verification when connecting to the schema registry. type: boolean default: true ttl: description: The TTL in seconds for the schema registry cache. type: number maximum: 3600 minimum: 0 url: description: The URL of the schema registry. type: string required: - name type: object minLength: 1 required: - bootstrap_servers - topics consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: kafka-consume protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string required: - config ResponseTransformerPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/ResponseTransformerPluginConfig' XmlThreatProtectionPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/XmlThreatProtectionPluginConfig' HttpLogPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/HttpLogPluginConfig' SolaceUpstreamPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/SolaceUpstreamPluginConfig' Plugin: description: A Plugin entity represents a plugin configuration that will be executed during the HTTP request/response lifecycle. It is how you can add functionalities to Services that run behind Kong, like Authentication or Rate Limiting for example. You can find more information about how to install and what values each plugin takes by visiting the [Kong Hub](https://docs.konghq.com/hub/). When adding a Plugin Configuration to a Service, every request made by a client to that Service will run said Plugin. If a Plugin needs to be tuned to different values for some specific Consumers, you can do so by creating a separate plugin instance that specifies both the Service and the Consumer, through the `service` and `consumer` fields. type: object properties: condition: description: An expression used for conditional control over plugin execution. If the expression evaluates to `true` during the request flow, the plugin is executed; otherwise, it is skipped. type: string maxLength: 1024 nullable: true config: description: The configuration properties for the Plugin which can be found on the plugins documentation page in the [Kong Hub](https://docs.konghq.com/hub/). type: object additionalProperties: true nullable: true consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object nullable: true properties: id: type: string x-foreign: true consumer_group: description: If set, the plugin will activate only for requests where the specified group has been authenticated type: object nullable: true properties: id: type: string x-foreign: true created_at: description: Unix epoch when the resource was created. type: integer nullable: true enabled: description: Whether the plugin is applied. type: boolean default: true nullable: true id: description: A string representing a UUID (universally unique identifier). type: string minLength: 1 nullable: true instance_name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true name: description: The name of the Plugin that's going to be added. Currently, the Plugin must be installed in every Kong instance separately. type: string minLength: 1 ordering: type: object nullable: true properties: after: type: object properties: access: type: array items: type: string before: type: object properties: access: type: array items: type: string partials: description: A list of partials to be used by the plugin. type: array items: properties: id: description: A string representing a UUID (universally unique identifier). type: string minLength: 1 name: description: A unique string representing a UTF-8 encoded name. type: string path: type: string type: object nullable: true protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support `"tcp"` and `"tls"`. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string default: - grpc - grpcs - http - https nullable: true route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the Route being used. type: object nullable: true properties: id: type: string x-foreign: true service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object nullable: true properties: id: type: string x-foreign: true tags: description: An optional set of strings associated with the Plugin for grouping and filtering. type: array items: description: A string representing a tag. type: string nullable: true updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: anonymous: null hide_credentials: false key_in_body: false key_in_header: true key_in_query: true key_names: - apikey run_on_preflight: true enabled: true id: 3fd1eea1-885a-4011-b986-289943ff8177 name: key-auth partials: - id: cff1230a-00f7-4ae8-b376-c370f0eb4dae name: foo-partial path: config.redis - id: 129ee345-cba8-4e55-9d6d-93c223ff91ae name: bar-partial path: config.redis protocols: - grpc - grpcs - http - https additionalProperties: false required: - name LdapAuthAdvancedPluginConfig: x-speakeasy-entity: PluginLdapAuthAdvanced properties: config: type: object properties: anonymous: description: An optional string (consumer UUID or username) value to use as an “anonymous” consumer if authentication fails. If empty (default null), the request will fail with an authentication failure `4xx`. Note that this value must refer to the consumer `id` or `username` attribute, and **not** its `custom_id`. type: string default: '' attribute: description: Attribute to be used to search the user; e.g., "cn". type: string base_dn: description: Base DN as the starting point for the search; e.g., 'dc=example,dc=com'. type: string bind_dn: description: The DN to bind to. Used to perform LDAP search of user. This `bind_dn` should have permissions to search for the user being authenticated. type: string x-referenceable: true cache_ttl: description: Cache expiry time in seconds. type: number default: 60 consumer_by: description: Whether to authenticate consumers based on `username`, `custom_id`, or both. type: array items: enum: - custom_id - username type: string default: - custom_id - username consumer_optional: description: Whether consumer mapping is optional. If `consumer_optional=true`, the plugin will not attempt to associate a consumer with the LDAP authenticated user. type: boolean default: false group_base_dn: description: Sets a distinguished name (DN) for the entry where LDAP searches for groups begin. This field is case-insensitive.',dc=com'. type: string group_member_attribute: description: Sets the attribute holding the members of the LDAP group. This field is case-sensitive. type: string default: memberOf group_name_attribute: description: Sets the attribute holding the name of a group, typically called `name` (in Active Directory) or `cn` (in OpenLDAP). This field is case-insensitive. type: string groups_required: description: The groups required to be present in the LDAP search result for successful authorization. This config parameter works in both **AND** / **OR** cases. - When `["group1 group2"]` are in the same array indices, both `group1` AND `group2` need to be present in the LDAP search result. - When `["group1", "group2"]` are in different array indices, either `group1` OR `group2` need to be present in the LDAP search result. type: array items: type: string header_type: description: 'An optional string to use as part of the Authorization header. By default, a valid Authorization header looks like this: `Authorization: ldap base64(username:password)`. If `header_type` is set to "basic", then the Authorization header would be `Authorization: basic base64(username:password)`. Note that `header_type` can take any string, not just `''ldap''` and `''basic''`.' type: string default: ldap hide_credentials: description: An optional boolean value telling the plugin to hide the credential to the upstream server. It will be removed by Kong before proxying the request. type: boolean default: true keepalive: description: An optional value in milliseconds that defines how long an idle connection to LDAP server will live before being closed. type: number default: 60000 ldap_host: description: Host on which the LDAP server is running. type: string ldap_password: description: The password to the LDAP server. type: string x-encrypted: true x-referenceable: true ldap_port: description: TCP port where the LDAP server is listening. 389 is the default port for non-SSL LDAP and AD. 636 is the port required for SSL LDAP and AD. If `ldaps` is configured, you must use port 636. type: number default: 389 ldaps: description: Set it to `true` to use `ldaps`, a secure protocol (that can be configured to TLS) to connect to the LDAP server. When `ldaps` is configured, you must use port 636. If the `ldap` setting is enabled, ensure the `start_tls` setting is disabled. type: boolean default: false log_search_results: description: Displays all the LDAP search results received from the LDAP server for debugging purposes. Not recommended to be enabled in a production environment. type: boolean default: false realm: description: When authentication fails the plugin sends `WWW-Authenticate` header with `realm` attribute value. type: string start_tls: description: Set it to `true` to issue StartTLS (Transport Layer Security) extended operation over `ldap` connection. If the `start_tls` setting is enabled, ensure the `ldaps` setting is disabled. type: boolean default: false timeout: description: An optional timeout in milliseconds when waiting for connection with LDAP server. type: number default: 10000 verify_ldap_host: description: Set to `true` to authenticate LDAP server. The server certificate will be verified according to the CA certificates specified by the `lua_ssl_trusted_certificate` directive. type: boolean default: true required: - attribute - base_dn - ldap_host name: const: ldap-auth-advanced protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config AiSemanticResponseGuardPluginConfig: x-speakeasy-entity: PluginAiSemanticResponseGuard properties: config: type: object properties: embeddings: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true model: type: object properties: name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: azure: type: object properties: api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' deployment_id: description: Deployment ID for Azure OpenAI instances. type: string instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean upstream_url: description: upstream url for the embeddings type: string provider: description: AI provider format to use for embeddings API type: string enum: - azure - bedrock - gemini - huggingface - mistral - ollama - openai required: - name - provider required: - model genai_category: description: Generative AI category of the request type: string default: text/generation enum: - audio/speech - audio/transcription - image/generation - realtime/generation - text/embeddings - text/generation - video/generation llm_format: description: LLM input and output format and schema to use type: string default: openai enum: - anthropic - bedrock - cohere - gemini - huggingface - openai rules: type: object properties: allow_responses: description: List of responses to allow. type: array items: maxLength: 500 minLength: 1 type: string maxLength: 100 deny_responses: description: List of responses to deny. type: array items: maxLength: 500 minLength: 1 type: string maxLength: 100 max_response_body_size: description: Max allowed body size allowed to be introspected. 0 means unlimited, but the size of this body will still be limited by Nginx's client_max_body_size. type: integer default: 8192 search: type: object properties: threshold: description: Threshold for the similarity score to be considered a match. type: number default: 0.5 vectordb: type: object properties: dimensions: description: the desired dimensionality for the vectors type: integer distance_metric: description: the distance metric to use for vector searches type: string enum: - cosine - euclidean pgvector: type: object properties: database: description: the database of the pgvector database type: string default: kong-pgvector host: description: the host of the pgvector database type: string default: 127.0.0.1 password: description: the password of the pgvector database type: string x-encrypted: true x-referenceable: true port: description: the port of the pgvector database type: integer default: 5432 ssl: description: whether to use ssl for the pgvector database type: boolean default: false ssl_cert: description: the path of ssl cert to use for the pgvector database type: string ssl_cert_key: description: the path of ssl cert key to use for the pgvector database type: string ssl_required: description: whether ssl is required for the pgvector database type: boolean default: false ssl_verify: description: whether to verify ssl for the pgvector database type: boolean default: true ssl_version: description: the ssl version to use for the pgvector database type: string default: tlsv1_2 enum: - any - tlsv1_2 - tlsv1_3 timeout: description: the timeout of the pgvector database type: number default: 5000 user: description: the user of the pgvector database type: string default: postgres x-referenceable: true redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true strategy: description: which vector database driver to use type: string enum: - pgvector - redis threshold: description: the default similarity threshold for accepting semantic search results (float). Higher threshold means more results are considered similar. type: number required: - dimensions - distance_metric - strategy required: - embeddings - vectordb consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-semantic-response-guard protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config CanaryPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/CanaryPluginConfig' AiMcpOauth2Plugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiMcpOauth2PluginConfig' KeyAuthEncPluginConfig: x-speakeasy-entity: PluginKeyAuthEnc properties: config: type: object properties: anonymous: description: An optional string (consumer UUID or username) value to use as an “anonymous” consumer if authentication fails. If empty (default null), the request will fail with an authentication failure `4xx`. Note that this value must refer to the consumer `id` or `username` attribute, and **not** its `custom_id`. type: string hide_credentials: description: An optional boolean value telling the plugin to show or hide the credential from the upstream service. If `true`, the plugin strips the credential from the request (i.e., the header, query string, or request body containing the key) before proxying it. type: boolean default: true key_in_body: description: 'If enabled, the plugin reads the request body (if said request has one and its MIME type is supported) and tries to find the key in it. Supported MIME types: `application/www-form-urlencoded`, `application/json`, and `multipart/form-data`.' type: boolean default: false key_in_header: description: If enabled (default), the plugin reads the request header and tries to find the key in it. type: boolean default: true key_in_query: description: If enabled (default), the plugin reads the query parameter in the request and tries to find the key in it. type: boolean default: true key_names: description: Describes an array of parameter names where the plugin will look for a key. The client must send the authentication key in one of those key names, and the plugin will try to read the credential from a header, request body, or query string parameter with the same name. Key names may only contain [a-z], [A-Z], [0-9], [_] underscore, and [-] hyphen. type: array items: description: A string representing an HTTP header name. type: string default: - apikey realm: description: When authentication fails the plugin sends `WWW-Authenticate` header with `realm` attribute value. type: string run_on_preflight: description: A boolean value that indicates whether the plugin should run (and try to authenticate) on `OPTIONS` preflight requests. If set to `false`, then `OPTIONS` requests are always allowed. type: boolean default: true name: const: key-auth-enc protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string HmacAuthPluginConfig: x-speakeasy-entity: PluginHmacAuth properties: config: type: object properties: algorithms: description: A list of HMAC digest algorithms that the user wants to support. Allowed values are `hmac-sha224`, `hmac-sha256`, `hmac-sha384`, `hmac-sha512`, and `hmac-sha1` (disabled by default, and not available in FIPS mode) type: array items: enum: - hmac-sha1 - hmac-sha224 - hmac-sha256 - hmac-sha384 - hmac-sha512 type: string default: - hmac-sha224 - hmac-sha256 - hmac-sha384 - hmac-sha512 anonymous: description: An optional string (Consumer UUID or username) value to use as an “anonymous” consumer if authentication fails. type: string clock_skew: description: Clock skew in seconds to prevent replay attacks. type: number default: 300 enforce_headers: description: A list of headers that the client should at least use for HTTP signature creation. type: array items: type: string default: [] hide_credentials: description: An optional boolean value telling the plugin to show or hide the credential from the upstream service. type: boolean default: true realm: description: When authentication fails the plugin sends `WWW-Authenticate` header with `realm` attribute value. type: string validate_request_body: description: A boolean value telling the plugin to enable body validation. type: boolean default: false name: const: hmac-auth protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AwsLambdaPluginConfig: x-speakeasy-entity: PluginAwsLambda properties: config: type: object properties: aws_assume_role_arn: description: The target AWS IAM role ARN used to invoke the Lambda function. type: string x-encrypted: true x-referenceable: true aws_imds_protocol_version: description: 'Identifier to select the IMDS protocol version to use: `v1` or `v2`.' type: string default: v1 enum: - v1 - v2 aws_key: description: The AWS key credential to be used when invoking the function. type: string x-encrypted: true x-referenceable: true aws_region: description: A string representing a host name, such as example.com. type: string aws_role_session_name: description: The identifier of the assumed role session. type: string default: kong aws_secret: description: 'The AWS secret credential to be used when invoking the function. ' type: string x-encrypted: true x-referenceable: true aws_sts_endpoint_url: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string awsgateway_compatible: description: An optional value that defines whether the plugin should wrap requests into the Amazon API gateway. type: boolean default: false awsgateway_compatible_payload_version: description: An optional value that defines which version will be used to generate the AWS API Gateway compatible payload. The default will be `1.0`. type: string default: '1.0' enum: - '1.0' - '2.0' base64_encode_body: description: An optional value that Base64-encodes the request body. type: boolean default: true disable_https: type: boolean default: false empty_arrays_mode: description: An optional value that defines whether Kong should send empty arrays (returned by Lambda function) as `[]` arrays or `{}` objects in JSON responses. The value `legacy` means Kong will send empty arrays as `{}` objects in response type: string default: legacy enum: - correct - legacy forward_request_body: description: 'An optional value that defines whether the request body is sent in the request_body field of the JSON-encoded request. If the body arguments can be parsed, they are sent in the separate request_body_args field of the request. ' type: boolean default: false forward_request_headers: description: An optional value that defines whether the original HTTP request headers are sent as a map in the request_headers field of the JSON-encoded request. type: boolean default: false forward_request_method: description: An optional value that defines whether the original HTTP request method verb is sent in the request_method field of the JSON-encoded request. type: boolean default: false forward_request_uri: description: An optional value that defines whether the original HTTP request URI is sent in the request_uri field of the JSON-encoded request. type: boolean default: false function_name: description: The AWS Lambda function to invoke. Both function name and function ARN (including partial) are supported. type: string host: description: A string representing a host name, such as example.com. type: string invocation_type: description: The InvocationType to use when invoking the function. Available types are RequestResponse, Event, DryRun. type: string default: RequestResponse enum: - DryRun - Event - RequestResponse is_proxy_integration: description: An optional value that defines whether the response format to receive from the Lambda to this format. type: boolean default: false keepalive: description: An optional value in milliseconds that defines how long an idle connection lives before being closed. type: number default: 60000 log_type: description: The LogType to use when invoking the function. By default, None and Tail are supported. type: string default: Tail enum: - None - Tail port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 443 maximum: 65535 minimum: 0 proxy_url: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string qualifier: description: The qualifier to use when invoking the function. type: string skip_large_bodies: description: An optional value that defines whether Kong should send large bodies that are buffered to disk type: boolean default: true ssl_verify: description: Set to `true` to verify the TLS certificate when connecting to AWS services. type: boolean default: true timeout: description: An optional timeout in milliseconds when invoking the function. type: number default: 60000 unhandled_status: description: The response status code to use (instead of the default 200, 202, or 204) in the case of an Unhandled Function Error. type: integer maximum: 999 minimum: 100 consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: aws-lambda protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string StatsdPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/StatsdPluginConfig' IpRestrictionPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/IpRestrictionPluginConfig' AiAzureContentSafetyPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiAzureContentSafetyPluginConfig' WebsocketValidatorPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/WebsocketValidatorPluginConfig' AiPromptGuardPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiPromptGuardPluginConfig' AiRagInjectorPluginConfig: x-speakeasy-entity: PluginAiRagInjector properties: config: type: object properties: collection_acl_config: description: Per-collection ACL overrides type: object additionalProperties: properties: allow: description: Consumer identifiers allowed access to this collection type: array items: type: string default: [] deny: description: Consumer identifiers denied access to this collection type: array items: type: string default: [] type: object consumer_identifier: description: The type of consumer identifier used for ACL checks type: string default: consumer_group enum: - consumer_group - consumer_id - custom_id - username embeddings: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true model: type: object properties: name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: azure: type: object properties: api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' deployment_id: description: Deployment ID for Azure OpenAI instances. type: string instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean upstream_url: description: upstream url for the embeddings type: string provider: description: AI provider format to use for embeddings API type: string enum: - azure - bedrock - gemini - huggingface - mistral - ollama - openai required: - name - provider required: - model fetch_chunks_count: description: The maximum number of chunks to fetch from vectordb type: number default: 5 filter_mode: description: Defines how the plugin behaves when a filter is invalid. Set to `compatible` to ignore invalid filters, or `strict` to raise an error. This can be overridden per request. type: string default: compatible enum: - compatible - strict global_acl_config: description: Global ACL configuration for all RAG operations type: object properties: allow: description: Consumer identifiers allowed access (groups, IDs, usernames, or custom IDs based on consumer_identifier setting) type: array items: type: string default: [] deny: description: Consumer identifiers denied access (groups, IDs, usernames, or custom IDs based on consumer_identifier setting) type: array items: type: string default: [] inject_as_role: type: string default: user enum: - assistant - system - user inject_template: type: string default: ' ' max_filter_clauses: description: Maximum number of filter clauses allowed type: integer default: 100 maximum: 1000 minimum: 1 stop_on_failure: description: Halt the LLM request process in case of a vectordb or embeddings service failure type: boolean default: false stop_on_filter_error: description: Default behavior when filter parsing fails (can be overridden per-request) type: boolean default: false vectordb: type: object properties: dimensions: description: the desired dimensionality for the vectors type: integer distance_metric: description: the distance metric to use for vector searches type: string enum: - cosine - euclidean pgvector: type: object properties: database: description: the database of the pgvector database type: string default: kong-pgvector host: description: the host of the pgvector database type: string default: 127.0.0.1 password: description: the password of the pgvector database type: string x-encrypted: true x-referenceable: true port: description: the port of the pgvector database type: integer default: 5432 ssl: description: whether to use ssl for the pgvector database type: boolean default: false ssl_cert: description: the path of ssl cert to use for the pgvector database type: string ssl_cert_key: description: the path of ssl cert key to use for the pgvector database type: string ssl_required: description: whether ssl is required for the pgvector database type: boolean default: false ssl_verify: description: whether to verify ssl for the pgvector database type: boolean default: true ssl_version: description: the ssl version to use for the pgvector database type: string default: tlsv1_2 enum: - any - tlsv1_2 - tlsv1_3 timeout: description: the timeout of the pgvector database type: number default: 5000 user: description: the user of the pgvector database type: string default: postgres x-referenceable: true redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true strategy: description: which vector database driver to use type: string enum: - pgvector - redis threshold: description: the default similarity threshold for accepting semantic search results (float). Higher threshold means more results are considered similar. type: number required: - dimensions - distance_metric - strategy vectordb_namespace: description: The namespace of the vectordb to use for embeddings lookup type: string default: kong_rag_injector required: - embeddings - vectordb consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-rag-injector protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config AiSanitizerPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiSanitizerPluginConfig' RouteByHeaderPluginConfig: x-speakeasy-entity: PluginRouteByHeader properties: config: type: object properties: rules: description: Route by header rules. type: array items: properties: condition: type: object additionalProperties: type: string minLength: 1 upstream_name: type: string required: - upstream_name type: object default: [] consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: route-by-header protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AiLakeraGuardPluginConfig: x-speakeasy-entity: PluginAiLakeraGuard properties: config: type: object properties: api_key: description: API key for the Lakera Guard subscription. type: string x-encrypted: true x-referenceable: true guarding_mode: description: The guardrail mode to use for the request type: string default: INPUT enum: - BOTH - INPUT - OUTPUT lakera_service_url: description: The guard-operation URL of the Lakera Guard service. Defaults to the SaaS /v2/guard endpoint. It can be set to a locally hosted instance of Lakera Guard. type: string default: https://api.lakera.ai/v2/guard x-referenceable: true log_blocked_content: description: Whether to log prompts and responses that are blocked by the guardrail. type: boolean default: false project_id: description: Project ID to apply filters from. If null, it will use the subscription's default project. type: string x-referenceable: true request_failure_message: description: The message to return when a failure occurs on the request phase. type: string default: Request was filtered by Lakera Guard response_buffer_size: description: The amount of bytes receiving from upstream to be buffered before sending to the Lakera Guard service. This only applies to the response content guard. type: number default: 100 response_failure_message: description: The message to return when a failure occurs on the response phase. type: string default: Response was filtered by Lakera Guard reveal_failure_categories: description: Whether to reveal failure categories in the response to the caller. They will always be written to the gateway logs, even if set to false. type: boolean default: false stop_on_error: description: Stop processing if an error occurs. type: boolean default: true text_source: description: Select where to pick the 'text' for the Lakera Guard request (when text/generation is selected). type: string default: concatenate_all_content enum: - concatenate_all_content - concatenate_user_content - last_message timeout: description: Connection timeout with the Lakera Guard service type: number default: 10000 verify_ssl: description: Whether to verify the SSL certificate of the configured Lakera Guard endpoint. type: boolean default: true consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-lakera-guard protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string RequestCalloutPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/RequestCalloutPluginConfig' DatadogPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/DatadogPluginConfig' DegraphqlPluginConfig: x-speakeasy-entity: PluginDegraphql properties: config: type: object properties: graphql_server_path: description: The GraphQL endpoint serve path type: string default: /graphql name: const: degraphql protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string SolaceLogPluginConfig: x-speakeasy-entity: PluginSolaceLog properties: config: type: object properties: message: description: The log message related configuration. type: object properties: ack_timeout: description: When using a non-DIRECT guaranteed delivery mode, this property sets the log message acknowledgement timeout (waiting time). type: integer default: 2000 maximum: 100000 minimum: 1 custom_fields_by_lua: description: A key-value map that dynamically modifies log fields using Lua code. type: object additionalProperties: type: string delivery_mode: description: Sets the log message delivery mode. type: string default: DIRECT enum: - DIRECT - PERSISTENT destinations: description: The log message destinations. type: array items: properties: name: description: The name of the destination. You can use `$(uri_captures[''])` in this field to capture the name from a regex request URI (replace `` with a real value; for example `$(uri_captures['queue'])` when the matched route has a path `~/(?[a-z]+)`). type: string type: description: The type of the destination. type: string default: QUEUE enum: - QUEUE - TOPIC required: - name type: object minLength: 1 dmq_eligible: description: Sets the dead message queue (DMQ) eligible property on the log message. type: boolean default: false priority: description: Sets the log message priority. type: integer default: 4 maximum: 255 minimum: 0 sender_id: description: Allows the application to set the sender identifier. type: string tracing: description: Enable or disable the tracing propagation. This is primarily used for distributed tracing and message correlation, especially in debugging or tracking message flows across multiple systems. type: boolean default: false tracing_sampled: description: Forcibly turn on the tracing on all the messages for distributed tracing (tracing needs to be enabled as well). type: boolean default: false ttl: description: Sets the time to live (TTL) in milliseconds for the log message. Setting the time to live to zero disables the TTL for the log message. type: integer default: 0 required: - destinations session: description: Session related configuration. type: object properties: authentication: description: Session authentication related configuration. type: object properties: access_token: description: The OAuth2 access token used with `OAUTH2` authentication scheme when connecting to an event broker. type: string x-encrypted: true x-referenceable: true access_token_header: description: Specifies the header that contains access token for the `OAUTH2` authentication scheme when connecting to an event broker. This header takes precedence over the `access_token` field. type: string basic_auth_header: description: Specifies the header that contains Basic Authentication credentials for the `BASIC` authentication scheme when connecting to an event broker. This header takes precedence over the `username` and `password` fields. type: string id_token: description: The OpenID Connect ID token used with `OAUTH2` authentication scheme when connecting to an event broker. type: string x-encrypted: true x-referenceable: true id_token_header: description: Specifies the header that contains id token for the `OAUTH2` authentication scheme when connecting to an event broker. This header takes precedence over the `id_token` field. type: string password: description: The password used with `BASIC` authentication scheme when connecting to an event broker. type: string maxLength: 128 x-encrypted: true x-referenceable: true scheme: description: The client authentication scheme used when connection to an event broker. type: string default: BASIC enum: - BASIC - NONE - OAUTH2 username: description: The username used with `BASIC` authentication scheme when connecting to an event broker. type: string maxLength: 189 x-encrypted: true x-referenceable: true calculate_message_expiry: description: If this property is true and time-to-live has a positive value in a message, the expiration time is calculated when the message is sent or received type: boolean default: true connect_timeout: description: The timeout period (in milliseconds) for a connect operation to a given host (per host). type: integer default: 3000 maximum: 100000 minimum: 100 generate_rcv_timestamps: description: When enabled, a receive timestamp is recorded for each message. type: boolean default: true generate_send_timestamps: description: When enabled, a send timestamp is automatically included (if not already present) in the Solace-defined fields for each message sent. type: boolean default: true generate_sender_id: description: When enabled, a sender id is automatically included (if not already present) in the Solace-defined fields for each message sent. type: boolean default: true generate_sequence_number: description: When enabled, a sequence number is automatically included (if not already present) in the Solace-defined fields for each message sent. type: boolean default: true host: description: 'The IPv4 or IPv6 address or host name to connect to (see: https://docs.solace.com/API-Developer-Online-Ref-Documentation/c/index.html#host-entry).' type: string x-referenceable: true properties: description: Additional Solace session properties (each setting needs to have `SESSION_` prefix). type: object additionalProperties: type: string x-lua-required: true x-referenceable: true ssl_validate_certificate: description: Indicates whether the API should validate server certificates with the trusted certificates. type: boolean default: true vpn_name: description: The name of the Message VPN to attempt to join when connecting to an event broker. type: string maxLength: 32 required: - host required: - message - session name: const: solace-log protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config ConfluentConsumePluginConfig: x-speakeasy-entity: PluginConfluentConsume properties: config: type: object properties: auto_offset_reset: description: The offset to start from when there is no initial offset in the consumer group. type: string default: earliest enum: - earliest - latest bootstrap_servers: description: 'Set of bootstrap brokers in a `{host: host, port: port}` list format.' type: array items: properties: host: description: A string representing a host name, such as example.com. type: string port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 required: - host - port type: object cluster_api_key: description: Username/Apikey for SASL authentication. type: string x-encrypted: true x-referenceable: true cluster_api_secret: description: Password/ApiSecret for SASL authentication. type: string x-encrypted: true x-referenceable: true cluster_name: description: An identifier for the Kafka cluster. By default, this field generates a random string. You can also set your own custom cluster identifier. If more than one Kafka plugin is configured without a `cluster_name` (that is, if the default autogenerated value is removed), these plugins will use the same producer, and by extension, the same cluster. Logs will be sent to the leader of the cluster. type: string commit_strategy: description: The strategy to use for committing offsets. type: string default: auto enum: - auto - 'off' confluent_cloud_api_key: description: Apikey for authentication with Confluent Cloud. This allows for management tasks such as creating topics, ACLs, etc. type: string x-encrypted: true x-referenceable: true confluent_cloud_api_secret: description: The corresponding secret for the Confluent Cloud API key. type: string x-encrypted: true x-referenceable: true dlq_topic: description: The topic to use for the Dead Letter Queue. type: string enable_dlq: description: Enables Dead Letter Queue. When enabled, if the message doesn't conform to the schema (from Schema Registry) or there's an error in the `message_by_lua_functions`, it will be forwarded to `dlq_topic` that can be processed later. type: boolean enforce_latest_offset_reset: description: When true, 'latest' offset reset behaves correctly (starts from end). When false (default), maintains backwards compatibility where 'latest' acts like 'earliest'. type: boolean default: false keepalive: description: Keepalive timeout in milliseconds. type: integer default: 60000 keepalive_enabled: type: boolean default: false message_by_lua_functions: description: The Lua functions that manipulates the message being sent to the client. type: array items: type: string message_deserializer: description: The deserializer to use for the consumed messages. type: string default: noop enum: - json - noop mode: description: The mode of operation for the plugin. type: string default: http-get enum: - http-get - server-sent-events - websocket schema_registry: description: The plugin-global schema registry configuration. type: object properties: confluent: type: object properties: authentication: type: object properties: basic: type: object properties: password: type: string x-encrypted: true x-referenceable: true username: type: string x-encrypted: true x-referenceable: true required: - password - username mode: description: Authentication mode to use with the schema registry. type: string default: none enum: - basic - none - oauth2 oauth2: type: object properties: audience: description: List of audiences passed to the IdP when obtaining a new token. type: array items: type: string default: [] client_id: description: The client ID for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true client_secret: description: The client secret for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true grant_type: description: The OAuth grant type to be used. type: string default: client_credentials enum: - client_credentials - password password: description: The password to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true scopes: description: List of scopes to request from the IdP when obtaining a new token. type: array items: type: string default: - openid token_endpoint: description: The token endpoint URI. type: string token_headers: description: Extra headers to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true token_post_args: description: Extra post arguments to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true username: description: The username to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true required: - token_endpoint oauth2_client: type: object properties: auth_method: description: 'The authentication method used in client requests to the IdP. Supported values are: `client_secret_basic` to send `client_id` and `client_secret` in the `Authorization: Basic` header, `client_secret_post` to send `client_id` and `client_secret` as part of the request body, or `client_secret_jwt` to send a JWT signed with the `client_secret` using the client assertion as part of the body.' type: string default: client_secret_post enum: - client_secret_basic - client_secret_jwt - client_secret_post - none client_secret_jwt_alg: description: The algorithm to use with JWT when using `client_secret_jwt` authentication. type: string default: HS512 enum: - HS256 - HS512 http_proxy: description: The proxy to use when making HTTP requests to the IdP. type: string http_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `http_proxy`. type: string http_version: description: 'The HTTP version used for requests made by this plugin. Supported values: `1.1` for HTTP 1.1 and `1.0` for HTTP 1.0.' type: number default: 1.1 https_proxy: description: The proxy to use when making HTTPS requests to the IdP. type: string https_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `https_proxy`. type: string keep_alive: description: Whether to use keepalive connections to the IdP. type: boolean default: true no_proxy: description: A comma-separated list of hosts that should not be proxied. type: string ssl_verify: description: Whether to verify the certificate presented by the IdP when using HTTPS. type: boolean default: true timeout: description: Network I/O timeout for requests to the IdP in milliseconds. type: integer default: 10000 maximum: 2147483646 minimum: 0 ssl_verify: description: Set to false to disable SSL certificate verification when connecting to the schema registry. type: boolean default: true ttl: description: The TTL in seconds for the schema registry cache. type: number maximum: 3600 minimum: 0 url: description: The URL of the schema registry. type: string security: type: object properties: ssl_verify: description: Enables verification of the certificate presented by the server. type: boolean default: true timeout: description: Socket timeout in milliseconds. type: integer default: 10000 topics: description: The Kafka topics and their configuration you want to consume from. type: array items: properties: name: type: string schema_registry: description: The plugin-global schema registry configuration. type: object properties: confluent: type: object properties: authentication: type: object properties: basic: type: object properties: password: type: string x-encrypted: true x-referenceable: true username: type: string x-encrypted: true x-referenceable: true required: - password - username mode: description: Authentication mode to use with the schema registry. type: string default: none enum: - basic - none - oauth2 oauth2: type: object properties: audience: description: List of audiences passed to the IdP when obtaining a new token. type: array items: type: string default: [] client_id: description: The client ID for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true client_secret: description: The client secret for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true grant_type: description: The OAuth grant type to be used. type: string default: client_credentials enum: - client_credentials - password password: description: The password to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true scopes: description: List of scopes to request from the IdP when obtaining a new token. type: array items: type: string default: - openid token_endpoint: description: The token endpoint URI. type: string token_headers: description: Extra headers to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true token_post_args: description: Extra post arguments to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true username: description: The username to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true required: - token_endpoint oauth2_client: type: object properties: auth_method: description: 'The authentication method used in client requests to the IdP. Supported values are: `client_secret_basic` to send `client_id` and `client_secret` in the `Authorization: Basic` header, `client_secret_post` to send `client_id` and `client_secret` as part of the request body, or `client_secret_jwt` to send a JWT signed with the `client_secret` using the client assertion as part of the body.' type: string default: client_secret_post enum: - client_secret_basic - client_secret_jwt - client_secret_post - none client_secret_jwt_alg: description: The algorithm to use with JWT when using `client_secret_jwt` authentication. type: string default: HS512 enum: - HS256 - HS512 http_proxy: description: The proxy to use when making HTTP requests to the IdP. type: string http_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `http_proxy`. type: string http_version: description: 'The HTTP version used for requests made by this plugin. Supported values: `1.1` for HTTP 1.1 and `1.0` for HTTP 1.0.' type: number default: 1.1 https_proxy: description: The proxy to use when making HTTPS requests to the IdP. type: string https_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `https_proxy`. type: string keep_alive: description: Whether to use keepalive connections to the IdP. type: boolean default: true no_proxy: description: A comma-separated list of hosts that should not be proxied. type: string ssl_verify: description: Whether to verify the certificate presented by the IdP when using HTTPS. type: boolean default: true timeout: description: Network I/O timeout for requests to the IdP in milliseconds. type: integer default: 10000 maximum: 2147483646 minimum: 0 ssl_verify: description: Set to false to disable SSL certificate verification when connecting to the schema registry. type: boolean default: true ttl: description: The TTL in seconds for the schema registry cache. type: number maximum: 3600 minimum: 0 url: description: The URL of the schema registry. type: string required: - name type: object minLength: 1 required: - cluster_api_key - cluster_api_secret - topics consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: confluent-consume protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config AiMcpProxyPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiMcpProxyPluginConfig' GrpcWebPluginConfig: x-speakeasy-entity: PluginGrpcWeb properties: config: type: object properties: allow_origin_header: description: The value of the `Access-Control-Allow-Origin` header in the response to the gRPC-Web client. type: string default: '*' pass_stripped_path: description: If set to `true` causes the plugin to pass the stripped request path to the upstream gRPC service. type: boolean proto: description: If present, describes the gRPC types and methods. Required to support payload transcoding. When absent, the web client must use application/grpw-web+proto content. type: string consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: grpc-web protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string ProxyCacheAdvancedPluginConfig: x-speakeasy-entity: PluginProxyCacheAdvanced properties: config: type: object properties: bypass_on_err: description: Unhandled errors while trying to retrieve a cache entry (such as redis down) are resolved with `Bypass`, with the request going upstream. type: boolean default: false cache_control: description: When enabled, respect the Cache-Control behaviors defined in RFC7234. type: boolean default: false cache_ttl: description: TTL in seconds of cache entities. type: integer default: 300 content_type: description: Upstream response content types considered cacheable. The plugin performs an **exact match** against each specified value; for example, if the upstream is expected to respond with a `application/json; charset=utf-8` content-type, the plugin configuration must contain said value or a `Bypass` cache status is returned. type: array items: type: string default: - application/json - text/plain ignore_uri_case: description: Determines whether to treat URIs as case sensitive. By default, case sensitivity is enabled. If set to true, requests are cached while ignoring case sensitivity in the URI. type: boolean default: false memory: type: object properties: dictionary_name: description: The name of the shared dictionary in which to hold cache entities when the memory strategy is selected. Note that this dictionary currently must be defined manually in the Kong Nginx template. type: string default: kong_db_cache redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true request_method: description: 'Downstream request methods considered cacheable. Available options: `HEAD`, `GET`, `POST`, `PATCH`, `PUT`.' type: array items: enum: - GET - HEAD - PATCH - POST - PUT type: string default: - GET - HEAD response_code: description: Upstream response status code considered cacheable. The integers must be a value between 100 and 900. type: array items: maximum: 900 minimum: 100 type: integer default: - 200 - 301 - 404 minLength: 1 response_headers: description: Caching related diagnostic headers that should be included in cached responses type: object properties: X-Cache-Key: type: boolean default: true X-Cache-Status: type: boolean default: true age: type: boolean default: true storage_ttl: description: Number of seconds to keep resources in the storage backend. This value is independent of `cache_ttl` or resource TTLs defined by Cache-Control behaviors. type: integer strategy: description: 'The backing data store in which to hold cache entities. Accepted values are: `memory` and `redis`.' type: string enum: - memory - redis vary_headers: description: Relevant headers considered for the cache key. If undefined, none of the headers are taken into consideration. type: array items: type: string vary_query_params: description: Relevant query parameters considered for the cache key. If undefined, all params are taken into consideration. By default, the max number of params accepted is 100. You can change this value via the `lua_max_post_args` in `kong.conf`. type: array items: type: string required: - strategy consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: proxy-cache-advanced protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config SessionPluginConfig: x-speakeasy-entity: PluginSession properties: config: type: object properties: absolute_timeout: description: The session cookie absolute timeout, in seconds. Specifies how long the session can be used until it is no longer valid. type: number default: 86400 audience: description: The session audience, which is the intended target application. For example `"my-application"`. type: string default: default bind: description: Bind the session to data acquired from the HTTP request or connection. type: array items: enum: - ip - scheme - user-agent type: string cookie_domain: description: The domain with which the cookie is intended to be exchanged. type: string cookie_http_only: description: Applies the `HttpOnly` tag so that the cookie is sent only to a server. type: boolean default: true cookie_name: description: The name of the cookie. type: string default: session cookie_path: description: The resource in the host where the cookie is available. type: string default: / cookie_same_site: description: Determines whether and how a cookie may be sent with cross-site requests. type: string default: Strict enum: - Default - Lax - None - Strict cookie_secure: description: Applies the Secure directive so that the cookie may be sent to the server only with an encrypted request over the HTTPS protocol. type: boolean default: true hash_subject: description: Whether to hash or not the subject when store_metadata is enabled. type: boolean default: false idling_timeout: description: The session cookie idle time, in seconds. type: number default: 900 logout_methods: description: A set of HTTP methods that the plugin will respond to. type: array items: enum: - DELETE - GET - POST type: string default: - DELETE - POST logout_post_arg: description: The POST argument passed to logout requests. Do not change this property. type: string default: session_logout logout_query_arg: description: The query argument passed to logout requests. type: string default: session_logout read_body_for_logout: type: boolean default: false remember: description: Enables or disables persistent sessions. type: boolean default: false remember_absolute_timeout: description: The persistent session absolute timeout limit, in seconds. type: number default: 2592000 remember_cookie_name: description: Persistent session cookie name. Use with the `remember` configuration parameter. type: string default: remember remember_rolling_timeout: description: The persistent session rolling timeout window, in seconds. type: number default: 604800 request_headers: description: List of information to include, as headers, in the response to the downstream. type: array items: enum: - absolute-timeout - audience - id - idling-timeout - rolling-timeout - subject - timeout type: string response_headers: description: List of information to include, as headers, in the response to the downstream. type: array items: enum: - absolute-timeout - audience - id - idling-timeout - rolling-timeout - subject - timeout type: string rolling_timeout: description: The session cookie rolling timeout, in seconds. Specifies how long the session can be used until it needs to be renewed. type: number default: 3600 secret: description: The secret that is used in keyed HMAC generation. type: string x-encrypted: true x-referenceable: true stale_ttl: description: The duration, in seconds, after which an old cookie is discarded, starting from the moment when the session becomes outdated and is replaced by a new one. type: number default: 10 storage: description: 'Determines where the session data is stored. `kong`: Stores encrypted session data into Kong''s current database strategy; the cookie will not contain any session data. `cookie`: Stores encrypted session data within the cookie itself.' type: string default: cookie enum: - cookie - kong store_metadata: description: Whether to also store metadata of sessions, such as collecting data of sessions for a specific audience belonging to a specific subject. type: boolean default: false name: const: session protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AiPromptTemplatePlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiPromptTemplatePluginConfig' SolaceConsumePluginConfig: x-speakeasy-entity: PluginSolaceConsume properties: config: type: object properties: flow: description: The flow related configuration. type: object properties: ack_mode: description: Controls how acknowledgments are generated for received Guaranteed messages. When set to `AUTO`, the messages are positively acknowledged upon receiving them. When set to 'CLIENT', the messages are positively or negatively acknowledged by Kong regarding to client delivery status. type: string default: CLIENT enum: - AUTO - CLIENT binds: type: array items: properties: name: description: The name of the Queue that is the target of the bind. You can use $(uri_captures['']) in this field (replace `` with a real value, for example `$uri_captures['queue']` when the matched route has a path `~/(?[a-z]+)`) type: string type: description: The type of object to which this Flow is bound. type: string default: QUEUE enum: - QUEUE required: - name type: object minLength: 1 functions: description: The Lua functions that manipulates the message being received from Solace. The `message` variable can be used to access the current message content, and the function can return a new content. type: array items: type: string max_unacked_messages: description: This property controls the maximum number of messages that may be unacknowledged on the Flow. type: integer default: -1 properties: description: Additional Solace flow properties (each setting needs to have `FLOW_` prefix). type: object additionalProperties: type: string x-lua-required: true x-referenceable: true selector: description: The selector when binding to an endpoint. type: string wait_timeout: description: Specifies in milliseconds how long to wait for messages to appear on each poll before giving up or retrying. type: integer default: 50 maximum: 5000 minimum: 1 window_size: description: The Guaranteed message window size for the Flow. type: integer default: 255 maximum: 255 minimum: 1 required: - binds mode: description: The mode of operation for the plugin. The `AUTO` determines the mode automatically from the client request. type: string default: POLLING enum: - AUTO - POLLING - SERVER-SENT-EVENTS - WEBSOCKET polling: description: The `POLLING` mode related configuration settings. type: object properties: timeout: description: Polling timeout in milliseconds. When set to `0`, the polling works like short-polling and waits at maximum the Flow `wait_timeout` amount of time for the new messages (short-polling). When set to larger than `0`, the connection is kept open and only closed after the timeout or in case messages appear earlier (long-polling). type: integer default: 0 maximum: 300000 minimum: 0 session: description: Session related configuration. type: object properties: authentication: description: Session authentication related configuration. type: object properties: access_token: description: The OAuth2 access token used with `OAUTH2` authentication scheme when connecting to an event broker. type: string x-encrypted: true x-referenceable: true access_token_header: description: Specifies the header that contains access token for the `OAUTH2` authentication scheme when connecting to an event broker. This header takes precedence over the `access_token` field. type: string basic_auth_header: description: Specifies the header that contains Basic Authentication credentials for the `BASIC` authentication scheme when connecting to an event broker. This header takes precedence over the `username` and `password` fields. type: string id_token: description: The OpenID Connect ID token used with `OAUTH2` authentication scheme when connecting to an event broker. type: string x-encrypted: true x-referenceable: true id_token_header: description: Specifies the header that contains id token for the `OAUTH2` authentication scheme when connecting to an event broker. This header takes precedence over the `id_token` field. type: string password: description: The password used with `BASIC` authentication scheme when connecting to an event broker. type: string maxLength: 128 x-encrypted: true x-referenceable: true scheme: description: The client authentication scheme used when connection to an event broker. type: string default: BASIC enum: - BASIC - NONE - OAUTH2 username: description: The username used with `BASIC` authentication scheme when connecting to an event broker. type: string maxLength: 189 x-encrypted: true x-referenceable: true calculate_message_expiry: description: If this property is true and time-to-live has a positive value in a message, the expiration time is calculated when the message is sent or received type: boolean default: true connect_timeout: description: The timeout period (in milliseconds) for a connect operation to a given host (per host). type: integer default: 3000 maximum: 100000 minimum: 100 generate_rcv_timestamps: description: When enabled, a receive timestamp is recorded for each message. type: boolean default: true generate_send_timestamps: description: When enabled, a send timestamp is automatically included (if not already present) in the Solace-defined fields for each message sent. type: boolean default: true generate_sender_id: description: When enabled, a sender id is automatically included (if not already present) in the Solace-defined fields for each message sent. type: boolean default: true generate_sequence_number: description: When enabled, a sequence number is automatically included (if not already present) in the Solace-defined fields for each message sent. type: boolean default: true host: description: 'The IPv4 or IPv6 address or host name to connect to (see: https://docs.solace.com/API-Developer-Online-Ref-Documentation/c/index.html#host-entry).' type: string x-referenceable: true properties: description: Additional Solace session properties (each setting needs to have `SESSION_` prefix). type: object additionalProperties: type: string x-lua-required: true x-referenceable: true ssl_validate_certificate: description: Indicates whether the API should validate server certificates with the trusted certificates. type: boolean default: true vpn_name: description: The name of the Message VPN to attempt to join when connecting to an event broker. type: string maxLength: 32 required: - host websocket: description: The `WEBSOCKET` mode related configuration settings. type: object properties: max_recv_len: description: Specifies the maximal length of payload allowed when receiving WebSocket frames. type: integer default: 65536 max_send_len: description: Specifies the maximal length of payload allowed when sending WebSocket frames. type: integer default: 65536 timeout: description: Specifies the network timeout threshold in milliseconds. type: integer default: 1000 maximum: 60000 minimum: 1 required: - flow - session name: const: solace-consume protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config ForwardProxyPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/ForwardProxyPluginConfig' AiPromptTemplatePluginConfig: x-speakeasy-entity: PluginAiPromptTemplate properties: config: type: object properties: allow_untemplated_requests: description: Set true to allow requests that don't call or match any template. type: boolean default: true log_original_request: description: Set true to add the original request to the Kong log plugin(s) output. type: boolean default: false max_request_body_size: description: max allowed body size allowed to be introspected. 0 means unlimited, but the size of this body will still be limited by Nginx's client_max_body_size. type: integer default: 1048576 templates: description: Array of templates available to the request context. type: array items: properties: name: description: Unique name for the template, can be called with `{template://NAME}` type: string template: description: Template string for this request, supports mustache-style `{{placeholders}}` type: string required: - name - template type: object required: - templates consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-prompt-template protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config ExitTransformerPluginConfig: x-speakeasy-entity: PluginExitTransformer properties: config: type: object properties: functions: type: array items: type: string handle_unexpected: description: Determines whether to handle unexpected errors by transforming their responses. type: boolean default: false handle_unknown: description: Determines whether to handle unknown status codes by transforming their responses. type: boolean default: false required: - functions consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: exit-transformer protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config HttpLogPluginConfig: x-speakeasy-entity: PluginHttpLog properties: config: type: object properties: content_type: description: Indicates the type of data sent. The only available option is `application/json`. type: string default: application/json enum: - application/json - application/json; charset=utf-8 custom_fields_by_lua: description: Lua code as a key-value map type: object additionalProperties: type: string flush_timeout: description: Optional time in seconds. If `queue_size` > 1, this is the max idle time before sending a log with less than `queue_size` records. type: number headers: description: An optional table of headers included in the HTTP message to the upstream server. Values are indexed by header name, and each header name accepts a single string. type: object additionalProperties: type: string http_endpoint: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string x-encrypted: true x-referenceable: true keepalive: description: An optional value in milliseconds that defines how long an idle connection will live before being closed. type: number default: 60000 method: description: An optional method used to send data to the HTTP server. Supported values are `POST` (default), `PUT`, and `PATCH`. type: string default: POST enum: - PATCH - POST - PUT queue: type: object properties: concurrency_limit: description: The number of of queue delivery timers. -1 indicates unlimited. type: integer default: 1 enum: - -1 - 1 initial_retry_delay: description: Time in seconds before the initial retry is made for a failing batch. type: number default: 0.01 maximum: 1000000 minimum: 0.001 max_batch_size: description: Maximum number of entries that can be processed at a time. type: integer default: 1 maximum: 1000000 minimum: 1 max_bytes: description: Maximum number of bytes that can be waiting on a queue, requires string content. type: integer max_coalescing_delay: description: Maximum number of (fractional) seconds to elapse after the first entry was queued before the queue starts calling the handler. type: number default: 1 maximum: 3600 minimum: 0 max_entries: description: Maximum number of entries that can be waiting on the queue. type: integer default: 10000 maximum: 1000000 minimum: 1 max_retry_delay: description: Maximum time in seconds between retries, caps exponential backoff. type: number default: 60 maximum: 1000000 minimum: 0.001 max_retry_time: description: Time in seconds before the queue gives up calling a failed handler for a batch. type: number default: 60 queue_size: description: Maximum number of log entries to be sent on each message to the upstream server. type: integer retry_count: description: Number of times to retry when sending data to the upstream server. type: integer ssl_verify: description: When using TLS, this option enables verification of the certificate presented by the server. type: boolean default: true timeout: description: An optional timeout in milliseconds when sending data to the upstream server. type: number default: 10000 required: - http_endpoint consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: http-log protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config CorrelationIdPluginConfig: x-speakeasy-entity: PluginCorrelationId properties: config: type: object properties: echo_downstream: description: Whether to echo the header back to downstream (the client). type: boolean default: false generator: description: The generator to use for the correlation ID. Accepted values are `uuid`, `uuid#counter`, and `tracker`. See [Generators](#generators). type: string default: uuid#counter enum: - tracker - uuid - uuid#counter header_name: description: The HTTP header name to use for the correlation ID. type: string default: Kong-Request-ID consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: correlation-id protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string UpstreamOauthPluginConfig: x-speakeasy-entity: PluginUpstreamOauth properties: config: type: object properties: behavior: type: object properties: idp_error_response_body_template: description: The template to use to create the body of the response to return to the consumer if Kong fails to obtain a token from the IdP. type: string default: '{ "code": "{{status}}", "message": "{{message}}" }' idp_error_response_content_type: description: The Content-Type of the response to return to the consumer if Kong fails to obtain a token from the IdP. type: string default: application/json; charset=utf-8 idp_error_response_message: description: The message to embed in the body of the response to return to the consumer if Kong fails to obtain a token from the IdP. type: string default: Failed to authenticate request to upstream idp_error_response_status_code: description: The response code to return to the consumer if Kong fails to obtain a token from the IdP. type: integer default: 502 maximum: 599 minimum: 500 purge_token_on_upstream_status_codes: description: An array of status codes which will force an access token to be purged when returned by the upstream. An empty array will disable this functionality. type: array items: maximum: 599 minimum: 100 type: integer default: - 401 upstream_access_token_header_name: description: The name of the header used to send the access token (obtained from the IdP) to the upstream service. type: string default: Authorization cache: type: object properties: default_ttl: description: The lifetime of a token without an explicit `expires_in` value. type: number default: 3600 eagerly_expire: description: The number of seconds to eagerly expire a cached token. By default, a cached token expires 5 seconds before its lifetime as defined in `expires_in`. type: integer default: 5 memory: type: object properties: dictionary_name: description: The shared dictionary used by the plugin to cache tokens if `config.cache.strategy` is set to `memory`. type: string default: kong_db_cache redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true strategy: description: The method Kong should use to cache tokens issued by the IdP. type: string default: memory enum: - memory - redis client: type: object properties: auth_method: description: 'The authentication method used in client requests to the IdP. Supported values are: `client_secret_basic` to send `client_id` and `client_secret` in the `Authorization: Basic` header, `client_secret_post` to send `client_id` and `client_secret` as part of the request body, or `client_secret_jwt` to send a JWT signed with the `client_secret` using the client assertion as part of the body.' type: string default: client_secret_post enum: - client_secret_basic - client_secret_jwt - client_secret_post - none client_secret_jwt_alg: description: The algorithm to use with JWT when using `client_secret_jwt` authentication. type: string default: HS512 enum: - HS256 - HS512 http_proxy: description: The proxy to use when making HTTP requests to the IdP. type: string http_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `http_proxy`. type: string http_version: description: 'The HTTP version used for requests made by this plugin. Supported values: `1.1` for HTTP 1.1 and `1.0` for HTTP 1.0.' type: number default: 1.1 https_proxy: description: The proxy to use when making HTTPS requests to the IdP. type: string https_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `https_proxy`. type: string keep_alive: description: Whether to use keepalive connections to the IdP. type: boolean default: true no_proxy: description: A comma-separated list of hosts that should not be proxied. type: string ssl_verify: description: Whether to verify the certificate presented by the IdP when using HTTPS. type: boolean default: true timeout: description: Network I/O timeout for requests to the IdP in milliseconds. type: integer default: 10000 maximum: 2147483646 minimum: 0 oauth: type: object properties: audience: description: List of audiences passed to the IdP when obtaining a new token. type: array items: type: string default: [] client_id: description: The client ID for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true client_secret: description: The client secret for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true grant_type: description: The OAuth grant type to be used. type: string default: client_credentials enum: - client_credentials - password password: description: The password to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true scopes: description: List of scopes to request from the IdP when obtaining a new token. type: array items: type: string default: - openid token_endpoint: description: The token endpoint URI. type: string token_headers: description: Extra headers to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true token_post_args: description: Extra post arguments to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true username: description: The username to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true required: - token_endpoint required: - oauth consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: upstream-oauth protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config TlsMetadataHeadersPluginConfig: x-speakeasy-entity: PluginTlsMetadataHeaders properties: config: type: object properties: client_cert_fingerprint_header_name: description: Define the HTTP header name used for the SHA1 fingerprint of the client certificate. type: string default: X-Client-Cert-Fingerprint client_cert_header_name: description: Define the HTTP header name used for the PEM format URL encoded client certificate. type: string default: X-Client-Cert client_cert_issuer_dn_header_name: description: Define the HTTP header name used for the issuer DN of the client certificate. type: string default: X-Client-Cert-Issuer-DN client_cert_subject_dn_header_name: description: Define the HTTP header name used for the subject DN of the client certificate. type: string default: X-Client-Cert-Subject-DN client_serial_header_name: description: Define the HTTP header name used for the serial number of the client certificate. type: string default: X-Client-Cert-Serial inject_client_cert_details: description: Enables TLS client certificate metadata values to be injected into HTTP headers. type: boolean default: false name: const: tls-metadata-headers protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpcs - https - tls type: string format: set default: - grpcs - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AiProxyPluginConfig: x-speakeasy-entity: PluginAiProxy properties: config: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true genai_category: description: Generative AI category of the request type: string default: text/generation enum: - audio/speech - audio/transcription - image/generation - text/embeddings - text/generation - video/generation llm_format: description: LLM input and output format and schema to use type: string default: openai enum: - anthropic - bedrock - cohere - gemini - huggingface - openai logging: type: object properties: log_payloads: description: If enabled, will log the request and response body into the Kong log plugin(s) output.Furthermore if Opentelemetry instrumentation is enabled the traces will contain this data as well. type: boolean default: false log_statistics: description: If enabled and supported by the driver, will add model usage and token metrics into the Kong log plugin(s) output. type: boolean default: false max_request_body_size: description: max allowed body size allowed to be introspected. 0 means unlimited, but the size of this body will still be limited by Nginx's client_max_body_size. type: integer default: 1048576 model: type: object properties: model_alias: description: The model name parameter from the request that this model should map to. type: string name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: anthropic_version: description: Defines the schema/API version, if using Anthropic provider. type: string azure_api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' azure_deployment_id: description: Deployment ID for Azure OpenAI instances. type: string azure_instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string cohere: type: object properties: embedding_input_type: description: The purpose of the input text to calculate embedding vectors. type: string default: classification enum: - classification - clustering - image - search_document - search_query wait_for_model: description: Wait for the model if it is not ready type: boolean dashscope: type: object properties: international: description: 'Two Dashscope endpoints are available, and the international endpoint will be used when this is set to `true`. It is recommended to set this to `true` when using international version of dashscope. ' type: boolean default: true databricks: type: object properties: workspace_instance_id: description: Workspace Instance ID ('dbc-xxx-yyy') for Databricks model serving. type: string embeddings_dimensions: description: If using embeddings models, set the number of dimensions to generate. type: integer gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string endpoint_id: description: If running Gemini on Vertex Model Garden, specify the endpoint ID. type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean input_cost: description: Defines the cost per 1M tokens in your prompt. type: number llama2_format: description: If using llama2 provider, select the upstream message format. type: string enum: - ollama - openai - raw max_tokens: description: Defines the max_tokens, if using chat or completion models. type: integer mistral_format: description: If using mistral provider, select the upstream message format. type: string enum: - ollama - openai output_cost: description: Defines the cost per 1M tokens in the output of the AI. type: number temperature: description: Defines the matching temperature, if using chat or completion models. type: number maximum: 5 minimum: 0 top_k: description: Defines the top-k most likely tokens, if supported. type: integer maximum: 500 minimum: 0 top_p: description: Defines the top-p probability mass, if supported. type: number maximum: 1 minimum: 0 upstream_path: description: Manually specify or override the AI operation path, used when e.g. using the 'preserve' route_type. type: string upstream_url: description: Manually specify or override the full URL to the AI operation endpoints, when calling (self-)hosted models, or for running via a private endpoint. type: string provider: description: AI provider request format - Kong translates requests to and from the specified backend compatible formats. type: string enum: - anthropic - azure - bedrock - cerebras - cohere - dashscope - databricks - deepseek - gemini - huggingface - llama2 - mistral - ollama - openai - vllm - xai required: - provider model_name_header: description: Display the model name selected in the X-Kong-LLM-Model response header type: boolean default: true response_streaming: description: Whether to 'optionally allow', 'deny', or 'always' (force) the streaming of answers via server sent events. type: string default: allow enum: - allow - always - deny route_type: description: 'The model''s operation implementation, for this provider. ' type: string enum: - audio/v1/audio/speech - audio/v1/audio/transcriptions - audio/v1/audio/translations - image/v1/images/edits - image/v1/images/generations - llm/v1/assistants - llm/v1/batches - llm/v1/chat - llm/v1/completions - llm/v1/embeddings - llm/v1/files - llm/v1/responses - preserve - realtime/v1/realtime - video/v1/videos/generations required: - model - route_type consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-proxy protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config RequestTransformerAdvancedPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/RequestTransformerAdvancedPluginConfig' InjectionProtectionPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/InjectionProtectionPluginConfig' ProxyCacheAdvancedPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/ProxyCacheAdvancedPluginConfig' RequestTerminationPluginConfig: x-speakeasy-entity: PluginRequestTermination properties: config: type: object properties: body: description: The raw response body to send. This is mutually exclusive with the `config.message` field. type: string content_type: description: Content type of the raw response configured with `config.body`. type: string echo: description: When set, the plugin will echo a copy of the request back to the client. The main usecase for this is debugging. It can be combined with `trigger` in order to debug requests on live systems without disturbing real traffic. type: boolean default: false message: description: The message to send, if using the default response generator. type: string status_code: description: The response code to send. Must be an integer between 100 and 599. type: integer default: 503 maximum: 599 minimum: 100 trigger: description: A string representing an HTTP header name. type: string consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: request-termination protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string RateLimitingAdvancedPluginConfig: x-speakeasy-entity: PluginRateLimitingAdvanced properties: config: type: object properties: compound_identifier: description: Similar to `identifer`, but supports combining multiple items. The priority of `compound_identifier` is higher than `identifier`, which means if `compound_identifer` is set, it will be used, otherwise `identifier` will be used. type: array items: enum: - consumer - consumer-group - credential - header - ip - path - route - service type: string consumer_groups: description: List of consumer groups allowed to override the rate limiting settings for the given Route or Service. Required if `enforce_consumer_groups` is set to `true`. type: array items: type: string dictionary_name: description: The shared dictionary where counters are stored. When the plugin is configured to synchronize counter data externally (that is `config.strategy` is `cluster` or `redis` and `config.sync_rate` isn't `-1`), this dictionary serves as a buffer to populate counters in the data store on each synchronization cycle. type: string default: kong_rate_limiting_counters disable_penalty: description: If set to `true`, this doesn't count denied requests (status = `429`). If set to `false`, all requests, including denied ones, are counted. This parameter only affects the `sliding` window_type. type: boolean default: false enforce_consumer_groups: description: Determines if consumer groups are allowed to override the rate limiting settings for the given Route or Service. Flipping `enforce_consumer_groups` from `true` to `false` disables the group override, but does not clear the list of consumer groups. You can then flip `enforce_consumer_groups` to `true` to re-enforce the groups. type: boolean default: false error_code: description: Set a custom error code to return when the rate limit is exceeded. type: number default: 429 error_message: description: Set a custom error message to return when the rate limit is exceeded. type: string default: API rate limit exceeded header_name: description: A string representing an HTTP header name. type: string hide_client_headers: description: Optionally hide informative response headers that would otherwise provide information about the current status of limits and counters. type: boolean default: false identifier: description: The type of identifier used to generate the rate limit key. Defines the scope used to increment the rate limiting counters. Note if `identifier` is `consumer-group`, the plugin must be applied on a consumer group entity. Because a consumer may belong to multiple consumer groups, the plugin needs to know explicitly which consumer group to limit the rate. type: string default: consumer enum: - consumer - consumer-group - credential - header - ip - path - route - service limit: description: One or more requests-per-window limits to apply. There must be a matching number of window limits and sizes specified. type: array items: type: number lock_dictionary_name: description: The shared dictionary where concurrency control locks are stored. The default shared dictionary is `kong_locks`. The shared dictionary should be declare in nginx-kong.conf. type: string default: kong_locks namespace: description: Specifies the rate-limiting namespace for this plugin instance. A namespace acts as a logical grouping for configuration and counter data used by the rate-limiting algorithm. Namespaces define how and where counter data is stored and synchronized. When multiple plugin instances share the same namespace, they also share the same rate-limiting counters and synchronization configuration. Conversely, using different namespaces ensures that each plugin instance maintains its own independent counters. type: string path: description: A string representing a URL path, such as /path/to/resource. Must start with a forward slash (/) and must not contain empty segments (i.e., two consecutive forward slashes). type: string redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 redis_proxy_type: description: If the `connection_is_proxied` is enabled, this field indicates the proxy type and version you are using. For example, you can enable this optioin when you want authentication between Kong and Envoy proxy. type: string enum: - envoy_v1.31 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true retry_after_jitter_max: description: The upper bound of a jitter (random delay) in seconds to be added to the `Retry-After` header of denied requests (status = `429`) in order to prevent all the clients from coming back at the same time. The lower bound of the jitter is `0`; in this case, the `Retry-After` header is equal to the `RateLimit-Reset` header. type: number default: 0 strategy: description: 'The rate-limiting strategy to use for retrieving and incrementing the limits. Available values are: `local`, `redis` and `cluster`.' type: string default: local enum: - cluster - local - redis sync_rate: description: How often to sync counter data to the central data store. A value of 0 results in synchronous behavior; a value of -1 ignores sync behavior entirely and only stores counters in node memory. A value greater than 0 will sync the counters in the specified number of seconds. The minimum allowed interval is 0.02 seconds (20ms). type: number throttling: type: object properties: enabled: description: Determines if the throttling feature is enabled or not type: boolean default: false interval: description: The period between two successive retries for an individual request (in seconds) type: number default: 5 maximum: 1000000 minimum: 1 queue_limit: description: The maximum number of requests allowed for throttling type: number default: 5 maximum: 1000000 minimum: 1 retry_times: description: The maximum number of retries for an individual request type: number default: 3 maximum: 1000000 minimum: 1 window_size: description: One or more window sizes to apply a limit to (defined in seconds). There must be a matching number of window limits and sizes specified. type: array items: type: number window_type: description: Sets the time window type to either `sliding` (default) or `fixed`. Sliding windows apply the rate limiting logic while taking into account previous hit rates (from the window that immediately precedes the current) using a dynamic weight. Fixed windows consist of buckets that are statically assigned to a definitive time range, each request is mapped to only one fixed window based on its timestamp and will affect only that window's counters. type: string default: sliding enum: - fixed - sliding required: - limit - window_size consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: rate-limiting-advanced protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config Plugin_2: description: A Plugin entity represents a plugin configuration that will be executed during the HTTP request/response lifecycle. It is how you can add functionalities to Services that run behind Kong, like Authentication or Rate Limiting for example. You can find more information about how to install and what values each plugin takes by visiting the [Kong Hub](https://docs.konghq.com/hub/). When adding a Plugin Configuration to a Service, every request made by a client to that Service will run said Plugin. If a Plugin needs to be tuned to different values for some specific Consumers, you can do so by creating a separate plugin instance that specifies both the Service and the Consumer, through the `service` and `consumer` fields. type: object properties: condition: description: An expression used for conditional control over plugin execution. If the expression evaluates to `true` during the request flow, the plugin is executed; otherwise, it is skipped. type: string maxLength: 1024 nullable: true config: description: The configuration properties for the Plugin which can be found on the plugins documentation page in the [Kong Hub](https://docs.konghq.com/hub/). type: object additionalProperties: true nullable: true consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object nullable: true properties: id: type: string x-foreign: true consumer_group: description: If set, the plugin will activate only for requests where the specified group has been authenticated type: object nullable: true properties: id: type: string x-foreign: true created_at: description: Unix epoch when the resource was created. type: integer nullable: true enabled: description: Whether the plugin is applied. type: boolean default: true nullable: true id: description: A string representing a UUID (universally unique identifier). type: string minLength: 1 nullable: true instance_name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true name: description: The name of the Plugin that's going to be added. Currently, the Plugin must be installed in every Kong instance separately. type: string minLength: 1 ordering: type: object nullable: true properties: after: type: object properties: access: type: array items: type: string before: type: object properties: access: type: array items: type: string partials: description: A list of partials to be used by the plugin. type: array items: properties: id: description: A string representing a UUID (universally unique identifier). type: string minLength: 1 name: description: A unique string representing a UTF-8 encoded name. type: string path: type: string type: object nullable: true protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support `"tcp"` and `"tls"`. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string x-speakeasy-unknown-values: allow default: - grpc - grpcs - http - https nullable: true route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the Route being used. type: object nullable: true properties: id: type: string x-foreign: true service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object nullable: true properties: id: type: string x-foreign: true tags: description: An optional set of strings associated with the Plugin for grouping and filtering. type: array items: description: A string representing a tag. type: string nullable: true updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: anonymous: null hide_credentials: false key_in_body: false key_in_header: true key_in_query: true key_names: - apikey run_on_preflight: true enabled: true id: 3fd1eea1-885a-4011-b986-289943ff8177 name: key-auth partials: - id: cff1230a-00f7-4ae8-b376-c370f0eb4dae name: foo-partial path: config.redis - id: 129ee345-cba8-4e55-9d6d-93c223ff91ae name: bar-partial path: config.redis protocols: - grpc - grpcs - http - https additionalProperties: false required: - name RedirectPluginConfig: x-speakeasy-entity: PluginRedirect properties: config: type: object properties: keep_incoming_path: description: Use the incoming request's path and query string in the redirect URL type: boolean default: false location: description: The URL to redirect to type: string status_code: description: The response code to send. Must be an integer between 100 and 599. type: integer default: 301 maximum: 599 minimum: 100 required: - location consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: redirect protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config JwtPluginConfig: x-speakeasy-entity: PluginJwt properties: config: type: object properties: anonymous: description: An optional string (consumer UUID or username) value to use as an “anonymous” consumer if authentication fails. type: string claims_to_verify: description: 'A list of registered claims (according to RFC 7519) that Kong can verify as well. Accepted values: one of exp or nbf.' type: array items: enum: - exp - nbf type: string cookie_names: description: A list of cookie names that Kong will inspect to retrieve JWTs. type: array items: type: string default: [] header_names: description: A list of HTTP header names that Kong will inspect to retrieve JWTs. type: array items: type: string default: - authorization key_claim_name: description: The name of the claim in which the key identifying the secret must be passed. The plugin will attempt to read this claim from the JWT payload and the header, in that order. type: string default: iss maximum_expiration: description: A value between 0 and 31536000 (365 days) limiting the lifetime of the JWT to maximum_expiration seconds in the future. type: number default: 0 maximum: 31536000 minimum: 0 realm: description: When authentication fails the plugin sends `WWW-Authenticate` header with `realm` attribute value. type: string run_on_preflight: description: A boolean value that indicates whether the plugin should run (and try to authenticate) on OPTIONS preflight requests. If set to false, then OPTIONS requests will always be allowed. type: boolean default: true secret_is_base64: description: If true, the plugin assumes the credential’s secret to be base64 encoded. You will need to create a base64-encoded secret for your Consumer, and sign your JWT with the original secret. type: boolean default: false uri_param_names: description: A list of querystring parameters that Kong will inspect to retrieve JWTs. type: array items: type: string default: - jwt name: const: jwt protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string RequestTransformerAdvancedPluginConfig: x-speakeasy-entity: PluginRequestTransformerAdvanced properties: config: type: object properties: add: type: object properties: body: type: array items: type: string x-referenceable: true default: [] headers: type: array items: type: string x-referenceable: true default: [] json_types: type: array items: enum: - boolean - number - string type: string default: [] querystring: type: array items: type: string x-referenceable: true default: [] allow: type: object properties: body: type: array items: type: string append: type: object properties: body: type: array items: type: string x-referenceable: true default: [] headers: type: array items: type: string x-referenceable: true default: [] json_types: type: array items: enum: - boolean - number - string type: string default: [] querystring: type: array items: type: string x-referenceable: true default: [] dots_in_keys: description: Specify whether dots (for example, `customers.info.phone`) should be treated as part of a property name or used to descend into nested JSON objects. type: boolean default: true http_method: description: A string representing an HTTP method, such as GET, POST, PUT, or DELETE. The string must contain only uppercase letters. type: string remove: type: object properties: body: type: array items: type: string default: [] headers: type: array items: type: string default: [] querystring: type: array items: type: string default: [] rename: type: object properties: body: type: array items: type: string x-referenceable: true default: [] headers: type: array items: type: string x-referenceable: true default: [] querystring: type: array items: type: string x-referenceable: true default: [] replace: type: object properties: body: type: array items: type: string x-referenceable: true default: [] headers: type: array items: type: string x-referenceable: true default: [] json_types: type: array items: enum: - boolean - number - string type: string default: [] querystring: type: array items: type: string x-referenceable: true default: [] uri: type: string consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: request-transformer-advanced protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string PrometheusPluginConfig: x-speakeasy-entity: PluginPrometheus properties: config: type: object properties: ai_metrics: description: A boolean value that determines if ai metrics should be collected. If enabled, the `ai_llm_requests_total`, `ai_llm_cost_total` and `ai_llm_tokens_total` metrics will be exported. type: boolean default: false bandwidth_metrics: description: A boolean value that determines if bandwidth metrics should be collected. If enabled, `bandwidth_bytes` and `stream_sessions_total` metrics will be exported. type: boolean default: false latency_metrics: description: A boolean value that determines if latency metrics should be collected. If enabled, `kong_latency_ms`, `upstream_latency_ms` and `request_latency_ms` metrics will be exported. type: boolean default: false per_consumer: description: A boolean value that determines if per-consumer metrics should be collected. If enabled, the `kong_http_requests_total` and `kong_bandwidth_bytes` metrics fill in the consumer label when available. type: boolean default: false status_code_metrics: description: A boolean value that determines if status code metrics should be collected. If enabled, `http_requests_total`, `stream_sessions_total` metrics will be exported. type: boolean default: false upstream_health_metrics: description: A boolean value that determines if upstream metrics should be collected. If enabled, `upstream_target_health` metric will be exported. type: boolean default: false wasm_metrics: type: boolean consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: prometheus protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string WebsocketSizeLimitPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/WebsocketSizeLimitPluginConfig' RequestValidatorPluginConfig: x-speakeasy-entity: PluginRequestValidator properties: config: type: object properties: allowed_content_types: description: List of allowed content types. The value can be configured with the `charset` parameter. For example, `application/json; charset=UTF-8`. type: array items: type: string default: - application/json body_schema: description: The request body schema specification. One of `body_schema` or `parameter_schema` must be specified. type: string content_type_parameter_validation: description: Determines whether to enable parameters validation of request content-type. type: boolean default: true parameter_schema: description: Array of parameter validator specification. One of `body_schema` or `parameter_schema` must be specified. type: array items: properties: explode: description: Required when `schema` and `style` are set. When `explode` is `true`, parameter values of type `array` or `object` generate separate parameters for each value of the array or key-value pair of the map. For other types of parameters, this property has no effect. type: boolean in: description: The location of the parameter. type: string enum: - header - path - query name: description: The name of the parameter. Parameter names are case-sensitive, and correspond to the parameter name used by the `in` property. If `in` is `path`, the `name` field MUST correspond to the named capture group from the configured `route`. type: string required: description: Determines whether this parameter is mandatory. type: boolean schema: description: Required when `style` and `explode` are set. This is the schema defining the type used for the parameter. It is validated using `draft4` for JSON Schema draft 4 compliant validator. In addition to being a valid JSON Schema, the parameter schema MUST have a top-level `type` property to enable proper deserialization before validating. type: string style: description: Required when `schema` and `explode` are set. Describes how the parameter value will be deserialized depending on the type of the parameter value. type: string enum: - deepObject - form - label - matrix - pipeDelimited - simple - spaceDelimited required: - in - name - required type: object verbose_response: description: If enabled, the plugin returns more verbose and detailed validation errors. type: boolean default: false version: description: Which validator to use. Supported values are `kong` (default) for using Kong's own schema validator, or `draft4`, `draft7`, `draft201909`, and `draft202012` for using their respective JSON Schema Draft compliant validators. type: string default: kong enum: - draft201909 - draft202012 - draft4 - draft6 - draft7 - kong consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: request-validator protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string CanaryPluginConfig: x-speakeasy-entity: PluginCanary properties: config: type: object properties: canary_by_header_name: description: A string representing an HTTP header name. type: string duration: description: The duration of the canary release in seconds. type: number default: 3600 groups: description: The groups allowed to access the canary release. type: array items: type: string hash: description: 'Hash algorithm to be used for canary release. * `consumer`: The hash will be based on the consumer. * `ip`: The hash will be based on the client IP address. * `none`: No hash will be applied. * `allow`: Allows the specified groups to access the canary release. * `deny`: Denies the specified groups from accessing the canary release. * `header`: The hash will be based on the specified header value.' type: string default: consumer enum: - allow - consumer - deny - header - ip - none hash_header: description: A string representing an HTTP header name. type: string percentage: description: The percentage of traffic to be routed to the canary release. type: number maximum: 100 minimum: 0 start: description: Future time in seconds since epoch, when the canary release will start. Ignored when `percentage` is set, or when using `allow` or `deny` in `hash`. type: number steps: description: The number of steps for the canary release. type: number default: 1000 minimum: 1 upstream_fallback: description: Specifies whether to fallback to the upstream server if the canary release fails. type: boolean default: false upstream_host: description: A string representing a host name, such as example.com. type: string upstream_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 upstream_uri: description: The URI of the upstream server to be used for the canary release. type: string minLength: 1 name: const: canary protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AiRagInjectorPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiRagInjectorPluginConfig' Oauth2IntrospectionPluginConfig: x-speakeasy-entity: PluginOauth2Introspection properties: config: type: object properties: anonymous: description: An optional string (consumer UUID or username) value to use as an “anonymous” consumer if authentication fails. If empty (default null), the request fails with an authentication failure `4xx`. Note that this value must refer to the consumer `id` or `username` attribute, and **not** its `custom_id`. type: string default: '' authorization_value: description: The value to set as the `Authorization` header when querying the introspection endpoint. This depends on the OAuth 2.0 server, but usually is the `client_id` and `client_secret` as a Base64-encoded Basic Auth string (`Basic MG9hNWl...`). type: string x-encrypted: true x-referenceable: true consumer_by: description: A string indicating whether to associate OAuth2 `username` or `client_id` with the consumer's username. OAuth2 `username` is mapped to a consumer's `username` field, while an OAuth2 `client_id` maps to a consumer's `custom_id`. type: string default: username enum: - client_id - username custom_claims_forward: description: A list of custom claims to be forwarded from the introspection response to the upstream request. Claims are forwarded in headers with prefix `X-Credential-{claim-name}`. type: array items: type: string default: [] custom_introspection_headers: description: A list of custom headers to be added in the introspection request. type: object default: {} additionalProperties: type: string hide_credentials: description: An optional boolean value telling the plugin to hide the credential to the upstream API server. It will be removed by Kong before proxying the request. type: boolean default: true introspect_request: description: A boolean indicating whether to forward information about the current downstream request to the introspect endpoint. If true, headers `X-Request-Path` and `X-Request-Http-Method` will be inserted into the introspect request. type: boolean default: false introspection_url: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string keepalive: description: An optional value in milliseconds that defines how long an idle connection lives before being closed. type: integer default: 60000 run_on_preflight: description: A boolean value that indicates whether the plugin should run (and try to authenticate) on `OPTIONS` preflight requests. If set to `false`, then `OPTIONS` requests will always be allowed. type: boolean default: true timeout: description: An optional timeout in milliseconds when sending data to the upstream server. type: integer default: 10000 token_type_hint: description: The `token_type_hint` value to associate to introspection requests. type: string ttl: description: The TTL in seconds for the introspection response. Set to 0 to disable the expiration. type: number default: 30 required: - authorization_value - introspection_url name: const: oauth2-introspection protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config ServiceProtectionPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/ServiceProtectionPluginConfig' LogglyPluginConfig: x-speakeasy-entity: PluginLoggly properties: config: type: object properties: client_errors_severity: type: string default: info enum: - alert - crit - debug - emerg - err - info - notice - warning custom_fields_by_lua: description: Lua code as a key-value map type: object additionalProperties: type: string host: description: A string representing a host name, such as example.com. type: string default: logs-01.loggly.com key: type: string x-encrypted: true x-referenceable: true log_level: type: string default: info enum: - alert - crit - debug - emerg - err - info - notice - warning port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 514 maximum: 65535 minimum: 0 server_errors_severity: type: string default: info enum: - alert - crit - debug - emerg - err - info - notice - warning successful_severity: type: string default: info enum: - alert - crit - debug - emerg - err - info - notice - warning tags: type: array items: type: string default: - kong timeout: type: number default: 10000 required: - key consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: loggly protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config SolaceUpstreamPluginConfig: x-speakeasy-entity: PluginSolaceUpstream properties: config: type: object properties: message: description: The message related configuration. type: object properties: ack_timeout: description: When using a non-DIRECT guaranteed delivery mode, this property sets the message acknowledgement timeout in milliseconds (waiting time). type: integer default: 2000 maximum: 100000 minimum: 1 content_encoding: description: Sets the HTTP Content-Encoding applied to the Solace message payload (for example, gzip). If unset, the request Content-Encoding header is used when available. type: string content_type: description: Sets the HTTP Content-Type applied to the Solace message payload. If unset, the request Content-Type header is used when available. type: string default_content: description: When not using `forward_method`, `forward_uri`, `forward_headers`, `forward_body` or `forward_body_raw_only`, this sets the message content. type: string delivery_mode: description: Sets the message delivery mode. type: string default: DIRECT enum: - DIRECT - PERSISTENT destinations: description: The message destinations. type: array items: properties: name: description: The name of the destination. You can use $(uri_captures['']) in this field (replace `` with a real value, for example `$uri_captures[’queue’]` when the matched route has a path `~/(?[a-z]+)`). type: string type: description: The type of the destination. type: string default: QUEUE enum: - QUEUE - TOPIC required: - name type: object minLength: 1 dmq_eligible: description: Sets the dead message queue (DMQ) eligible property on the message. type: boolean default: false forward_body: description: Include the request body and the body arguments in the message. type: boolean default: false forward_body_raw_only: description: Forward only the raw request body without wrapping it in a JSON payload or adding extra fields. type: boolean default: false forward_headers: description: Include the request headers in the message. type: boolean default: false forward_method: description: Include the request method in the message. type: boolean default: false forward_uri: description: Include the request URI and the URI arguments (as in, query arguments) in the message. type: boolean default: false functions: description: The Lua functions that manipulates (or generates) the message being sent to Solace. The `message` variable can be used to access the current message content, and the function can return a new content. type: array items: type: string priority: description: Sets the message priority. type: integer default: 4 maximum: 255 minimum: 0 sender_id: description: Allows the application to set the content of the sender identifier. type: string tracing: description: Enable or disable the tracing propagation. This is primarily used for distributed tracing and message correlation, especially in debugging or tracking message flows across multiple systems. type: boolean default: false tracing_sampled: description: Forcibly turn on the tracing on all the messages for distributed tracing (tracing needs to be enabled as well). type: boolean default: false ttl: description: Sets the time to live (TTL) in milliseconds for the message. Setting the time to live to zero disables the TTL for the message. type: integer default: 0 user_properties: description: User defined properties to be included in the message. Separate static properties from header mappings. type: object properties: headers: description: Header settings for user properties (mapping, inclusion and exclusion). type: object properties: exclude_headers: description: Headers that must not be forwarded into user properties. This is used to exclude sensitive headers such as authorization from being forwarded as user properties, or to avoid duplication when a header is mapped to a user property but you don't want the original header to be included as well. type: array items: type: string include_headers: description: Headers to include as user properties even without explicit mapping. type: array items: type: string mappings: description: Header-to-user_property mapping (key = HTTP header name, value = target user property name). type: object additionalProperties: type: string x-lua-required: true predefined_properties: description: Predefined user properties to set on every message (key = property name, value = property value). type: object additionalProperties: type: string x-lua-required: true required: - destinations session: description: Session related configuration. type: object properties: authentication: description: Session authentication related configuration. type: object properties: access_token: description: The OAuth2 access token used with `OAUTH2` authentication scheme when connecting to an event broker. type: string x-encrypted: true x-referenceable: true access_token_header: description: Specifies the header that contains access token for the `OAUTH2` authentication scheme when connecting to an event broker. This header takes precedence over the `access_token` field. type: string basic_auth_header: description: Specifies the header that contains Basic Authentication credentials for the `BASIC` authentication scheme when connecting to an event broker. This header takes precedence over the `username` and `password` fields. type: string id_token: description: The OpenID Connect ID token used with `OAUTH2` authentication scheme when connecting to an event broker. type: string x-encrypted: true x-referenceable: true id_token_header: description: Specifies the header that contains id token for the `OAUTH2` authentication scheme when connecting to an event broker. This header takes precedence over the `id_token` field. type: string password: description: The password used with `BASIC` authentication scheme when connecting to an event broker. type: string maxLength: 128 x-encrypted: true x-referenceable: true scheme: description: The client authentication scheme used when connection to an event broker. type: string default: BASIC enum: - BASIC - NONE - OAUTH2 username: description: The username used with `BASIC` authentication scheme when connecting to an event broker. type: string maxLength: 189 x-encrypted: true x-referenceable: true calculate_message_expiry: description: If this property is true and time-to-live has a positive value in a message, the expiration time is calculated when the message is sent or received type: boolean default: true connect_timeout: description: The timeout period (in milliseconds) for a connect operation to a given host (per host). type: integer default: 3000 maximum: 100000 minimum: 100 generate_rcv_timestamps: description: When enabled, a receive timestamp is recorded for each message. type: boolean default: true generate_send_timestamps: description: When enabled, a send timestamp is automatically included (if not already present) in the Solace-defined fields for each message sent. type: boolean default: true generate_sender_id: description: When enabled, a sender id is automatically included (if not already present) in the Solace-defined fields for each message sent. type: boolean default: true generate_sequence_number: description: When enabled, a sequence number is automatically included (if not already present) in the Solace-defined fields for each message sent. type: boolean default: true host: description: 'The IPv4 or IPv6 address or host name to connect to (see: https://docs.solace.com/API-Developer-Online-Ref-Documentation/c/index.html#host-entry).' type: string x-referenceable: true properties: description: Additional Solace session properties (each setting needs to have `SESSION_` prefix). type: object additionalProperties: type: string x-lua-required: true x-referenceable: true ssl_validate_certificate: description: Indicates whether the API should validate server certificates with the trusted certificates. type: boolean default: true vpn_name: description: The name of the Message VPN to attempt to join when connecting to an event broker. type: string maxLength: 32 required: - host required: - message - session name: const: solace-upstream protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config KeyAuthPluginConfig: x-speakeasy-entity: PluginKeyAuth properties: config: type: object properties: anonymous: description: An optional string (consumer UUID or username) value to use as an “anonymous” consumer if authentication fails. If empty (default null), the request will fail with an authentication failure `4xx`. type: string hide_credentials: description: An optional boolean value telling the plugin to show or hide the credential from the upstream service. If `true`, the plugin strips the credential from the request. type: boolean default: true identity_realms: description: A configuration of Konnect Identity Realms that indicate where to source a consumer from. type: array items: properties: id: description: A string representing a UUID (universally unique identifier). type: string region: type: string scope: type: string enum: - cp - realm type: object key_in_body: description: 'If enabled, the plugin reads the request body. Supported MIME types: `application/www-form-urlencoded`, `application/json`, and `multipart/form-data`.' type: boolean default: false key_in_header: description: If enabled (default), the plugin reads the request header and tries to find the key in it. type: boolean default: true key_in_query: description: If enabled (default), the plugin reads the query parameter in the request and tries to find the key in it. type: boolean default: true key_names: description: Describes an array of parameter names where the plugin will look for a key. The key names may only contain [a-z], [A-Z], [0-9], [_] underscore, and [-] hyphen. type: array items: description: A string representing an HTTP header name. type: string default: - apikey realm: description: When authentication fails the plugin sends `WWW-Authenticate` header with `realm` attribute value. type: string run_on_preflight: description: A boolean value that indicates whether the plugin should run (and try to authenticate) on `OPTIONS` preflight requests. If set to `false`, then `OPTIONS` requests are always allowed. type: boolean default: true name: const: key-auth protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string SyslogPluginConfig: x-speakeasy-entity: PluginSyslog properties: config: type: object properties: client_errors_severity: type: string default: info enum: - alert - crit - debug - emerg - err - info - notice - warning custom_fields_by_lua: description: Lua code as a key-value map type: object additionalProperties: type: string facility: description: The facility is used by the operating system to decide how to handle each log message. type: string default: user enum: - auth - authpriv - cron - daemon - ftp - kern - local0 - local1 - local2 - local3 - local4 - local5 - local6 - local7 - lpr - mail - news - syslog - user - uucp log_level: type: string default: info enum: - alert - crit - debug - emerg - err - info - notice - warning server_errors_severity: type: string default: info enum: - alert - crit - debug - emerg - err - info - notice - warning successful_severity: type: string default: info enum: - alert - crit - debug - emerg - err - info - notice - warning consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: syslog protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AiSemanticCachePlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiSemanticCachePluginConfig' TlsHandshakeModifierPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/TlsHandshakeModifierPluginConfig' MtlsAuthPluginConfig: x-speakeasy-entity: PluginMtlsAuth properties: config: type: object properties: allow_partial_chain: description: Allow certificate verification with only an intermediate certificate. When this is enabled, you don't need to upload the full chain to Kong Certificates. type: boolean default: false anonymous: description: An optional string (consumer UUID or username) value to use as an “anonymous” consumer if authentication fails. If empty (default null), the request fails with an authentication failure `4xx`. Note that this value must refer to the consumer `id` or `username` attribute, and **not** its `custom_id`. type: string authenticated_group_by: description: Certificate property to use as the authenticated group. Valid values are `CN` (Common Name) or `DN` (Distinguished Name). Once `skip_consumer_lookup` is applied, any client with a valid certificate can access the Service/API. To restrict usage to only some of the authenticated users, also add the ACL plugin (not covered here) and create allowed or denied groups of users. type: string default: CN enum: - CN - DN ca_certificates: description: List of CA Certificates strings to use as Certificate Authorities (CA) when validating a client certificate. At least one is required but you can specify as many as needed. The value of this array is comprised of primary keys (`id`). type: array items: type: string cache_ttl: description: Cache expiry time in seconds. type: number default: 60 cert_cache_ttl: description: The length of time in seconds between refreshes of the revocation check status cache. type: number default: 60000 consumer_by: description: Whether to match the subject name of the client-supplied certificate against consumer's `username` and/or `custom_id` attribute. If set to `[]` (the empty array), then auto-matching is disabled. type: array items: enum: - custom_id - username type: string default: - custom_id - username default_consumer: description: The UUID or username of the consumer to use when a trusted client certificate is presented but no consumer matches. Note that this value must refer to the consumer `id` or `username` attribute, and **not** its `custom_id`. type: string http_proxy_host: description: A string representing a host name, such as example.com. type: string http_proxy_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 http_timeout: description: HTTP timeout threshold in milliseconds when communicating with the OCSP server or downloading CRL. type: number default: 30000 https_proxy_host: description: A string representing a host name, such as example.com. type: string https_proxy_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 revocation_check_mode: description: Controls client certificate revocation check behavior. If set to `SKIP`, no revocation check is performed. If set to `IGNORE_CA_ERROR`, the plugin respects the revocation status when either OCSP or CRL URL is set, and doesn't fail on network issues. If set to `STRICT`, the plugin only treats the certificate as valid when it's able to verify the revocation status. type: string default: IGNORE_CA_ERROR enum: - IGNORE_CA_ERROR - SKIP - STRICT san_dirname_matcher: description: 'Specifies a list of Subject Alternative Name (SAN) DirectoryName attributes to use for consumer lookup. Applicable only when `skip_consumer_lookup` is false. Supported formats: OID, Long Name, or Short Name. Examples: `commonName` (Long Name), `CN` (Short Name), `2.5.4.3` (OID). If left empty (default), all attributes present in the SAN DirectoryName extension are used. The matcher is case sensitive.' type: array items: type: string default: [] send_ca_dn: description: Sends the distinguished names (DN) of the configured CA list in the TLS handshake message. type: boolean default: false skip_consumer_lookup: description: Skip consumer lookup once certificate is trusted against the configured CA list. type: boolean default: false ssl_verify: description: This option enables verification of the certificate presented by the server of the OCSP responder's URL and by the server of the CRL Distribution Point. type: boolean default: true required: - ca_certificates name: const: mtls-auth protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config StatsdPluginConfig: x-speakeasy-entity: PluginStatsd properties: config: type: object properties: allow_status_codes: description: List of status code ranges that are allowed to be logged in metrics. type: array items: type: string consumer_identifier_default: type: string default: custom_id enum: - consumer_id - custom_id - username flush_timeout: type: number host: description: The IP address or hostname of StatsD server to send data to. type: string default: localhost hostname_in_prefix: type: boolean default: false metrics: description: List of metrics to be logged. type: array items: properties: consumer_identifier: description: Authenticated user detail. type: string enum: - consumer_id - custom_id - username name: description: StatsD metric’s name. type: string enum: - cache_datastore_hits_total - cache_datastore_misses_total - kong_latency - latency - request_count - request_per_user - request_size - response_size - shdict_usage - status_count - status_count_per_user - status_count_per_user_per_route - status_count_per_workspace - unique_users - upstream_latency sample_rate: description: Sampling rate type: number service_identifier: description: Service detail. type: string enum: - service_host - service_id - service_name - service_name_or_host stat_type: description: Determines what sort of event a metric represents. type: string enum: - counter - gauge - histogram - meter - set - timer workspace_identifier: description: Workspace detail. type: string enum: - workspace_id - workspace_name required: - name - stat_type type: object port: description: The port of StatsD server to send data to. type: integer default: 8125 maximum: 65535 minimum: 0 prefix: description: String to prefix to each metric's name. type: string default: kong queue: type: object properties: concurrency_limit: description: The number of of queue delivery timers. -1 indicates unlimited. type: integer default: 1 enum: - -1 - 1 initial_retry_delay: description: Time in seconds before the initial retry is made for a failing batch. type: number default: 0.01 maximum: 1000000 minimum: 0.001 max_batch_size: description: Maximum number of entries that can be processed at a time. type: integer default: 1 maximum: 1000000 minimum: 1 max_bytes: description: Maximum number of bytes that can be waiting on a queue, requires string content. type: integer max_coalescing_delay: description: Maximum number of (fractional) seconds to elapse after the first entry was queued before the queue starts calling the handler. type: number default: 1 maximum: 3600 minimum: 0 max_entries: description: Maximum number of entries that can be waiting on the queue. type: integer default: 10000 maximum: 1000000 minimum: 1 max_retry_delay: description: Maximum time in seconds between retries, caps exponential backoff. type: number default: 60 maximum: 1000000 minimum: 0.001 max_retry_time: description: Time in seconds before the queue gives up calling a failed handler for a batch. type: number default: 60 queue_size: type: integer retry_count: type: integer service_identifier_default: type: string default: service_name_or_host enum: - service_host - service_id - service_name - service_name_or_host tag_style: type: string enum: - dogstatsd - influxdb - librato - signalfx udp_packet_size: type: number default: 0 maximum: 65507 minimum: 0 use_tcp: type: boolean default: false workspace_identifier_default: type: string default: workspace_id enum: - workspace_id - workspace_name consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: statsd protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string RouteTransformerAdvancedPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/RouteTransformerAdvancedPluginConfig' OpaPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/OpaPluginConfig' HeaderCertAuthPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/HeaderCertAuthPluginConfig' UdpLogPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/UdpLogPluginConfig' ExitTransformerPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/ExitTransformerPluginConfig' AiLlmAsJudgePlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiLlmAsJudgePluginConfig' AiA2aProxyPluginConfig: x-speakeasy-entity: PluginAiA2aProxy properties: config: type: object properties: logging: type: object properties: log_payloads: description: If enabled, logs request/response bodies to Kong log plugin(s) output. Requires log_statistics to be enabled. type: boolean default: false log_statistics: description: If enabled, adds A2A metrics to Kong log plugin(s) output. type: boolean default: false max_payload_size: description: Maximum size in bytes for logged request/response payloads. Payloads exceeding this size will be truncated. type: integer default: 1048576 max_request_body_size: description: Maximum size of request body to parse for A2A metadata. Set to 0 for unlimited. type: integer default: 1048576 name: const: ai-a2a-proxy protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string OasValidationPluginConfig: x-speakeasy-entity: PluginOasValidation properties: config: type: object properties: allowed_header_parameters: description: List of header parameters in the request that will be ignored when performing HTTP header validation. These are additional headers added to an API request beyond those defined in the API specification. For example, you might include the HTTP header `User-Agent`, which lets servers and network peers identify the application, operating system, vendor, and/or version of the requesting user agent. type: string default: Host,Content-Type,User-Agent,Accept,Content-Length api_spec: description: The API specification defined using either Swagger or the OpenAPI. This can be either a JSON or YAML based file. If using a YAML file, the spec needs to be URI-Encoded to preserve the YAML format. type: string api_spec_encoded: description: Indicates whether the api_spec is URI-Encoded. type: boolean default: true collect_all_errors: description: 'If set to true, collects all validation errors instead of stopping at the first error. Note: Enabling this option with OpenAPI 3.0 will affect performance.' type: boolean default: false custom_base_path: description: The base path to be used for path match evaluation. This value is ignored if `include_base_path` is set to `false`. type: string header_parameter_check: description: If set to true, checks if HTTP header parameters in the request exist in the API specification. type: boolean default: false include_base_path: description: Indicates whether to include the base path when performing path match evaluation. type: boolean default: false notify_only_request_validation_failure: description: If set to true, notifications via event hooks are enabled, but request based validation failures don't affect the request flow. type: boolean default: false notify_only_response_body_validation_failure: description: If set to true, notifications via event hooks are enabled, but response validation failures don't affect the response flow. type: boolean default: false query_parameter_check: description: If set to true, checks if query parameters in the request exist in the API specification. type: boolean default: false validate_request_body: description: If set to true, validates the request body content against the API specification. type: boolean default: true validate_request_header_params: description: If set to true, validates HTTP header parameters against the API specification. type: boolean default: true validate_request_query_params: description: If set to true, validates query parameters against the API specification. type: boolean default: true validate_request_uri_params: description: If set to true, validates URI parameters in the request against the API specification. type: boolean default: true validate_response_body: description: If set to true, validates the response from the upstream services against the API specification. If validation fails, it results in an `HTTP 406 Not Acceptable` status code. type: boolean default: false verbose_response: description: If set to true, returns a detailed error message for invalid requests & responses. This is useful while testing. type: boolean default: false required: - api_spec consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: oas-validation protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config LdapAuthPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/LdapAuthPluginConfig' JsonThreatProtectionPluginConfig: x-speakeasy-entity: PluginJsonThreatProtection properties: config: type: object properties: allow_duplicate_object_entry_name: description: Allow or disallow duplicate object entry name. type: boolean default: true allow_non_json_requests: description: Allow non-json requests to bypass the rules type: boolean default: false enforcement_mode: description: Enforcement mode of the security policy. type: string default: block enum: - block - log_only error_message: description: The response message when validation fails type: string default: Bad Request error_status_code: description: The response status code when validation fails. type: integer default: 400 maximum: 499 minimum: 400 max_array_element_count: description: Max number of elements in an array. -1 means unlimited. type: integer default: -1 maximum: 2147483648 minimum: -1 max_body_size: description: Max size of the request body. -1 means unlimited. type: integer default: 8192 maximum: 2147483648 minimum: -1 max_container_depth: description: Max nested depth of objects and arrays. -1 means unlimited. type: integer default: -1 maximum: 2147483648 minimum: -1 max_object_entry_count: description: Max number of entries in an object. -1 means unlimited. type: integer default: -1 maximum: 2147483648 minimum: -1 max_object_entry_name_length: description: Max string length of object name. -1 means unlimited. type: integer default: -1 maximum: 2147483648 minimum: -1 max_string_value_length: description: Max string value length. -1 means unlimited. type: integer default: -1 maximum: 2147483648 minimum: -1 name: const: json-threat-protection protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string SamlPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/SamlPluginConfig' Oauth2Plugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/Oauth2PluginConfig' Oauth2PluginConfig: x-speakeasy-entity: PluginOauth2 properties: config: type: object properties: accept_http_if_already_terminated: description: Accepts HTTPs requests that have already been terminated by a proxy or load balancer. type: boolean default: false anonymous: description: An optional string (consumer UUID or username) value to use as an “anonymous” consumer if authentication fails. type: string auth_header_name: description: The name of the header that is supposed to carry the access token. type: string default: authorization enable_authorization_code: description: An optional boolean value to enable the three-legged Authorization Code flow (RFC 6742 Section 4.1). type: boolean default: false enable_client_credentials: description: An optional boolean value to enable the Client Credentials Grant flow (RFC 6742 Section 4.4). type: boolean default: false enable_implicit_grant: description: An optional boolean value to enable the Implicit Grant flow which allows to provision a token as a result of the authorization process (RFC 6742 Section 4.2). type: boolean default: false enable_password_grant: description: An optional boolean value to enable the Resource Owner Password Credentials Grant flow (RFC 6742 Section 4.3). type: boolean default: false global_credentials: description: An optional boolean value that allows using the same OAuth credentials generated by the plugin with any other service whose OAuth 2.0 plugin configuration also has `config.global_credentials=true`. type: boolean default: false hide_credentials: description: An optional boolean value telling the plugin to show or hide the credential from the upstream service. type: boolean default: true mandatory_scope: description: An optional boolean value telling the plugin to require at least one `scope` to be authorized by the end user. type: boolean default: false persistent_refresh_token: type: boolean default: false pkce: description: Specifies a mode of how the Proof Key for Code Exchange (PKCE) should be handled by the plugin. type: string default: lax enum: - lax - none - strict provision_key: description: The unique key the plugin has generated when it has been added to the Service. type: string x-encrypted: true realm: description: When authentication fails the plugin sends `WWW-Authenticate` header with `realm` attribute value. type: string refresh_token_ttl: description: Time-to-live value for data type: number default: 1209600 maximum: 100000000 minimum: 0 reuse_refresh_token: description: An optional boolean value that indicates whether an OAuth refresh token is reused when refreshing an access token. type: boolean default: false scopes: description: Describes an array of scope names that will be available to the end user. If `mandatory_scope` is set to `true`, then `scopes` are required. type: array items: type: string token_expiration: description: An optional integer value telling the plugin how many seconds a token should last, after which the client will need to refresh the token. Set to `0` to disable the expiration. type: number default: 7200 name: const: oauth2 protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string SessionPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/SessionPluginConfig' JweDecryptPluginConfig: x-speakeasy-entity: PluginJweDecrypt properties: config: type: object properties: forward_header_name: description: The name of the header that is used to set the decrypted value. type: string default: Authorization key_sets: description: Denote the name or names of all Key Sets that should be inspected when trying to find a suitable key to decrypt the JWE token. type: array items: type: string lookup_header_name: description: The name of the header to look for the JWE token. type: string default: Authorization strict: description: Defines how the plugin behaves in cases where no token was found in the request. When using `strict` mode, the request requires a token to be present and subsequently raise an error if none could be found. type: boolean default: true required: - key_sets name: const: jwe-decrypt protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config RequestTransformerPluginConfig: x-speakeasy-entity: PluginRequestTransformer properties: config: type: object properties: add: type: object properties: body: type: array items: type: string default: [] headers: type: array items: type: string default: [] querystring: type: array items: type: string default: [] append: type: object properties: body: type: array items: type: string default: [] headers: type: array items: type: string default: [] querystring: type: array items: type: string default: [] http_method: description: A string representing an HTTP method, such as GET, POST, PUT, or DELETE. The string must contain only uppercase letters. type: string remove: type: object properties: body: type: array items: type: string default: [] headers: type: array items: type: string default: [] querystring: type: array items: type: string default: [] rename: type: object properties: body: type: array items: type: string default: [] headers: type: array items: type: string default: [] querystring: type: array items: type: string default: [] replace: type: object properties: body: type: array items: type: string default: [] headers: type: array items: type: string default: [] querystring: type: array items: type: string default: [] uri: type: string consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: request-transformer protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string XmlThreatProtectionPluginConfig: x-speakeasy-entity: PluginXmlThreatProtection properties: config: type: object properties: allow_dtd: description: Indicates whether an XML Document Type Definition (DTD) section is allowed. type: boolean default: false allowed_content_types: description: A list of Content-Type values with payloads that are allowed, but aren't validated. type: array items: type: string default: [] attribute: description: Maximum size of the attribute value. type: integer default: 1048576 bla_max_amplification: description: Sets the maximum allowed amplification. This protects against the Billion Laughs Attack. type: number default: 100 minimum: 1 bla_threshold: description: Sets the threshold after which the protection starts. This protects against the Billion Laughs Attack. type: integer default: 8388608 minimum: 1024 buffer: description: Maximum size of the unparsed buffer (see below). type: integer default: 1048576 checked_content_types: description: A list of Content-Type values with payloads that must be validated. type: array items: type: string default: - application/xml comment: description: Maximum size of comments. type: integer default: 1024 document: description: Maximum size of the entire document. type: integer default: 10485760 entity: description: Maximum size of entity values in EntityDecl. type: integer default: 1024 entityname: description: Maximum size of entity names in EntityDecl. type: integer default: 1024 entityproperty: description: Maximum size of systemId, publicId, or notationName in EntityDecl. type: integer default: 1024 localname: description: Maximum size of the localname. This applies to tags and attributes. type: integer default: 1024 max_attributes: description: 'Maximum number of attributes allowed on a tag, including default ones. Note: If namespace-aware parsing is disabled, then the namespaces definitions are counted as attributes.' type: integer default: 100 max_children: description: 'Maximum number of children allowed (Element, Text, Comment, ProcessingInstruction, CDATASection). Note: Adjacent text and CDATA sections are counted as one. For example, text-cdata-text-cdata is one child.' type: integer default: 100 max_depth: description: Maximum depth of tags. Child elements such as Text or Comments are not counted as another level. type: integer default: 50 max_namespaces: description: Maximum number of namespaces defined on a tag. This value is required if parsing is namespace-aware. type: integer default: 20 namespace_aware: description: If not parsing namespace aware, all prefixes and namespace attributes will be counted as regular attributes and element names, and validated as such. type: boolean default: true namespaceuri: description: Maximum size of the namespace URI. This value is required if parsing is namespace-aware. type: integer default: 1024 pidata: description: Maximum size of processing instruction data. type: integer default: 1024 pitarget: description: Maximum size of processing instruction targets. type: integer default: 1024 prefix: description: Maximum size of the prefix. This applies to tags and attributes. This value is required if parsing is namespace-aware. type: integer default: 1024 text: description: Maximum text inside tags (counted over all adjacent text/CDATA elements combined). type: integer default: 1048576 consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: xml-threat-protection protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string RequestSizeLimitingPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/RequestSizeLimitingPluginConfig' MockingPluginConfig: x-speakeasy-entity: PluginMocking properties: config: type: object properties: api_specification: description: The contents of the specification file. You must use this option for hybrid or DB-less mode. You can include the full specification as part of the configuration. In Kong Manager, you can copy and paste the contents of the spec directly into the `Config.Api Specification` text field. type: string api_specification_filename: description: The path and name of the specification file loaded into Kong Gateway's database. You cannot use this option for DB-less or hybrid mode. type: string custom_base_path: description: The base path to be used for path match evaluation. This value is ignored if `include_base_path` is set to `false`. type: string include_base_path: description: Indicates whether to include the base path when performing path match evaluation. type: boolean default: false included_status_codes: description: A global list of the HTTP status codes that can only be selected and returned. type: array items: type: integer max_delay_time: description: The maximum value in seconds of delay time. Set this value when `random_delay` is enabled and you want to adjust the default. The value must be greater than the `min_delay_time`. type: number default: 1 min_delay_time: description: The minimum value in seconds of delay time. Set this value when `random_delay` is enabled and you want to adjust the default. The value must be less than the `max_delay_time`. type: number default: 0.001 random_delay: description: Enables a random delay in the mocked response. Introduces delays to simulate real-time response times by APIs. type: boolean default: false random_examples: description: Randomly selects one example and returns it. This parameter requires the spec to have multiple examples configured. type: boolean default: false random_status_code: description: Determines whether to randomly select an HTTP status code from the responses of the corresponding API method. The default value is `false`, which means the minimum HTTP status code is always selected and returned. type: boolean default: false consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: mocking protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string ACLPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/ACLPluginConfig' AiRequestTransformerPluginConfig: x-speakeasy-entity: PluginAiRequestTransformer properties: config: type: object properties: http_proxy_host: description: A string representing a host name, such as example.com. type: string http_proxy_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 http_timeout: description: Timeout in milliseconds for the AI upstream service. type: integer default: 60000 https_proxy_host: description: A string representing a host name, such as example.com. type: string https_proxy_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 https_verify: description: Verify the TLS certificate of the AI upstream service. type: boolean default: true llm: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true description: description: The semantic description of the target, required if using semantic load balancing. Specially, setting this to 'CATCHALL' will indicate such target to be used when no other targets match the semantic threshold. Only used by ai-proxy-advanced. type: string logging: type: object properties: log_payloads: description: If enabled, will log the request and response body into the Kong log plugin(s) output.Furthermore if Opentelemetry instrumentation is enabled the traces will contain this data as well. type: boolean default: false log_statistics: description: If enabled and supported by the driver, will add model usage and token metrics into the Kong log plugin(s) output. type: boolean default: false metadata: description: 'For internal use only. ' type: object additionalProperties: true nullable: true x-speakeasy-type-override: any model: type: object properties: model_alias: description: The model name parameter from the request that this model should map to. type: string name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: anthropic_version: description: Defines the schema/API version, if using Anthropic provider. type: string azure_api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' azure_deployment_id: description: Deployment ID for Azure OpenAI instances. type: string azure_instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string cohere: type: object properties: embedding_input_type: description: The purpose of the input text to calculate embedding vectors. type: string default: classification enum: - classification - clustering - image - search_document - search_query wait_for_model: description: Wait for the model if it is not ready type: boolean dashscope: type: object properties: international: description: 'Two Dashscope endpoints are available, and the international endpoint will be used when this is set to `true`. It is recommended to set this to `true` when using international version of dashscope. ' type: boolean default: true databricks: type: object properties: workspace_instance_id: description: Workspace Instance ID ('dbc-xxx-yyy') for Databricks model serving. type: string embeddings_dimensions: description: If using embeddings models, set the number of dimensions to generate. type: integer gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string endpoint_id: description: If running Gemini on Vertex Model Garden, specify the endpoint ID. type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean input_cost: description: Defines the cost per 1M tokens in your prompt. type: number llama2_format: description: If using llama2 provider, select the upstream message format. type: string enum: - ollama - openai - raw max_tokens: description: Defines the max_tokens, if using chat or completion models. type: integer mistral_format: description: If using mistral provider, select the upstream message format. type: string enum: - ollama - openai output_cost: description: Defines the cost per 1M tokens in the output of the AI. type: number temperature: description: Defines the matching temperature, if using chat or completion models. type: number maximum: 5 minimum: 0 top_k: description: Defines the top-k most likely tokens, if supported. type: integer maximum: 500 minimum: 0 top_p: description: Defines the top-p probability mass, if supported. type: number maximum: 1 minimum: 0 upstream_path: description: Manually specify or override the AI operation path, used when e.g. using the 'preserve' route_type. type: string upstream_url: description: Manually specify or override the full URL to the AI operation endpoints, when calling (self-)hosted models, or for running via a private endpoint. type: string provider: description: AI provider request format - Kong translates requests to and from the specified backend compatible formats. type: string enum: - anthropic - azure - bedrock - cerebras - cohere - dashscope - databricks - deepseek - gemini - huggingface - llama2 - mistral - ollama - openai - vllm - xai required: - provider route_type: description: 'The model''s operation implementation, for this provider. ' type: string enum: - audio/v1/audio/speech - audio/v1/audio/transcriptions - audio/v1/audio/translations - image/v1/images/edits - image/v1/images/generations - llm/v1/assistants - llm/v1/batches - llm/v1/chat - llm/v1/completions - llm/v1/embeddings - llm/v1/files - llm/v1/responses - preserve - realtime/v1/realtime - video/v1/videos/generations weight: description: The weight this target gets within the upstream loadbalancer (1-65535). Only used by ai-proxy-advanced. type: integer default: 100 maximum: 65535 minimum: 1 required: - model - route_type max_request_body_size: description: max allowed body size allowed to be introspected. 0 means unlimited, but the size of this body will still be limited by Nginx's client_max_body_size. type: integer default: 1048576 prompt: description: Use this prompt to tune the LLM system/assistant message for the incoming proxy request (from the client), and what you are expecting in return. type: string transformation_extract_pattern: description: Defines the regular expression that must match to indicate a successful AI transformation at the request phase. The first match will be set as the outgoing body. If the AI service's response doesn't match this pattern, it is marked as a failure. type: string required: - llm - prompt consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-request-transformer protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config JwtSignerPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/JwtSignerPluginConfig' StandardWebhooksPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/StandardWebhooksPluginConfig' ZipkinPluginConfig: x-speakeasy-entity: PluginZipkin properties: config: type: object properties: connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 default_header_type: description: Allows specifying the type of header to be added to requests with no pre-existing tracing headers and when `config.header_type` is set to `"preserve"`. When `header_type` is set to any other value, `default_header_type` is ignored. type: string default: b3 enum: - aws - b3 - b3-single - datadog - gcp - instana - jaeger - ot - w3c default_service_name: description: Set a default service name to override `unknown-service-name` in the Zipkin spans. type: string header_type: description: All HTTP requests going through the plugin are tagged with a tracing HTTP request. This property codifies what kind of tracing header the plugin expects on incoming requests type: string default: preserve enum: - aws - b3 - b3-single - datadog - gcp - ignore - instana - jaeger - ot - preserve - w3c http_endpoint: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string http_response_header_for_traceid: type: string http_span_name: description: Specify whether to include the HTTP path in the span name. type: string default: method enum: - method - method_path include_credential: description: Specify whether the credential of the currently authenticated consumer should be included in metadata sent to the Zipkin server. type: boolean default: true local_service_name: description: The name of the service as displayed in Zipkin. type: string default: kong phase_duration_flavor: description: Specify whether to include the duration of each phase as an annotation or a tag. type: string default: annotations enum: - annotations - tags propagation: type: object default: default_format: b3 properties: clear: description: Header names to clear after context extraction. This allows to extract the context from a certain header and then remove it from the request, useful when extraction and injection are performed on different header formats and the original header should not be sent to the upstream. If left empty, no headers are cleared. type: array items: type: string default_format: description: 'The default header format to use when extractors did not match any format in the incoming headers and `inject` is configured with the value: `preserve`. This can happen when no tracing header was found in the request, or the incoming tracing header formats were not included in `extract`.' type: string default: b3 enum: - aws - b3 - b3-single - datadog - gcp - instana - jaeger - ot - w3c extract: description: Header formats used to extract tracing context from incoming requests. If multiple values are specified, the first one found will be used for extraction. If left empty, Kong will not extract any tracing context information from incoming requests and generate a trace with no parent and a new trace ID. type: array items: enum: - aws - b3 - datadog - gcp - instana - jaeger - ot - w3c type: string inject: description: Header formats used to inject tracing context. The value `preserve` will use the same header format as the incoming request. If multiple values are specified, all of them will be used during injection. If left empty, Kong will not inject any tracing context information in outgoing requests. type: array items: enum: - aws - b3 - b3-single - datadog - gcp - instana - jaeger - ot - preserve - w3c type: string queue: type: object properties: concurrency_limit: description: The number of of queue delivery timers. -1 indicates unlimited. type: integer default: 1 enum: - -1 - 1 initial_retry_delay: description: Time in seconds before the initial retry is made for a failing batch. type: number default: 0.01 maximum: 1000000 minimum: 0.001 max_batch_size: description: Maximum number of entries that can be processed at a time. type: integer default: 1 maximum: 1000000 minimum: 1 max_bytes: description: Maximum number of bytes that can be waiting on a queue, requires string content. type: integer max_coalescing_delay: description: Maximum number of (fractional) seconds to elapse after the first entry was queued before the queue starts calling the handler. type: number default: 1 maximum: 3600 minimum: 0 max_entries: description: Maximum number of entries that can be waiting on the queue. type: integer default: 10000 maximum: 1000000 minimum: 1 max_retry_delay: description: Maximum time in seconds between retries, caps exponential backoff. type: number default: 60 maximum: 1000000 minimum: 0.001 max_retry_time: description: Time in seconds before the queue gives up calling a failed handler for a batch. type: number default: 60 read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 5000 maximum: 2147483646 minimum: 0 sample_ratio: description: 'How often to sample requests that do not contain trace IDs. Set to `0` to turn sampling off, or to `1` to sample **all** requests. ' type: number default: 0.001 maximum: 1 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 5000 maximum: 2147483646 minimum: 0 static_tags: description: The tags specified on this property will be added to the generated request traces. type: array items: properties: name: type: string value: type: string required: - name - value type: object tags_header: description: The Zipkin plugin will add extra headers to the tags associated with any HTTP requests that come with a header named as configured by this property. type: string default: Zipkin-Tags traceid_byte_count: description: The length in bytes of each request's Trace ID. type: integer default: 16 enum: - 8 - 16 consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: zipkin protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string RequestCalloutPluginConfig: x-speakeasy-entity: PluginRequestCallout properties: config: type: object properties: cache: description: Plugin global caching configuration. type: object properties: cache_ttl: description: TTL in seconds of cache entities. type: integer default: 300 memory: type: object properties: dictionary_name: description: The name of the shared dictionary in which to hold cache entities when the memory strategy is selected. Note that this dictionary currently must be defined manually in the Kong Nginx template. type: string default: kong_db_cache redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true strategy: description: 'The backing data store in which to hold cache entities. Accepted values are: `off`, `memory`, and `redis`.' type: string default: 'off' enum: - memory - 'off' - redis callouts: description: A collection of callout objects, where each object represents an HTTP request made in the context of a proxy request. type: array items: properties: cache: description: Callout caching configuration. type: object properties: bypass: description: If `true`, skips caching the callout response. type: boolean default: false depends_on: description: An array of callout names the current callout depends on. This dependency list determines the callout execution order via a topological sorting algorithm. type: array items: type: string default: [] name: description: A string identifier for a callout. A callout object is referenceable via its name in the `kong.ctx.shared.callouts.` type: string request: description: The customizations for the callout request. type: object properties: body: description: Callout request body customizations. type: object properties: custom: description: The custom body fields to be added to the callout HTTP request. Values can contain Lua expressions in the form $(some_lua_expression). The syntax is based on `request-transformer-advanced` templates. type: object additionalProperties: type: string x-referenceable: true decode: description: If `true`, decodes the request's body and make it available for customizations. Only JSON content type is supported. type: boolean default: false forward: description: If `true`, forwards the incoming request's body to the callout request. type: boolean default: false by_lua: description: Lua code that executes before the callout request is made. **Warning** can impact system behavior. Standard Lua sandboxing restrictions apply. type: string error: description: The error handling policy the plugin will apply to TCP and HTTP errors. type: object properties: error_response_code: description: The error code to respond with if `on_error` is `fail` or if `retries` is achieved. type: integer default: 400 error_response_msg: description: The error mesasge to respond with if `on_error` is set to `fail` or if `retries` is achieved. Templating with Lua expressions is supported. type: string default: service callout error http_statuses: description: The list of HTTP status codes considered errors under the error handling policy. type: array items: maximum: 999 minimum: 100 type: integer on_error: type: string default: fail enum: - continue - fail - retry retries: description: The number of retries the plugin will attempt on TCP and HTTP errors if `on_error` is set to `retry`. type: integer default: 2 headers: description: Callout request header customizations. type: object properties: custom: description: The custom headers to be added in the callout HTTP request. Values can contain Lua expressions in the form `$(some_lua_expression)`. The syntax is based on `request-transformer-advanced` templates. type: object additionalProperties: type: string x-referenceable: true forward: description: 'If `true`, forwards the incoming request''s headers to the callout request. ' type: boolean default: false http_opts: description: HTTP connection parameters. type: object properties: proxy: description: Proxy settings. type: object properties: auth_password: description: The password to authenticate with, if the forward proxy is protected by basic authentication. type: string x-encrypted: true x-referenceable: true auth_username: description: The username to authenticate with, if the forward proxy is protected by basic authentication. type: string x-referenceable: true http_proxy: description: The HTTP proxy URL. This proxy server will be used for HTTP requests. type: string https_proxy: description: The HTTPS proxy URL. This proxy server will be used for HTTPS requests. type: string ssl_server_name: description: The SNI used in the callout request. Defaults to host if omitted. type: string ssl_verify: description: If set to `true`, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your callout API. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true timeouts: description: Socket timeouts in milliseconds. All or none must be set. type: object properties: connect: description: The socket connect timeout. type: integer maximum: 2147483646 minimum: 0 read: description: 'The socket read timeout. ' type: integer maximum: 2147483646 minimum: 0 write: description: The socket write timeout. type: integer maximum: 2147483646 minimum: 0 method: description: The HTTP method that will be requested. type: string default: GET query: description: Callout request query param customizations. type: object properties: custom: description: The custom query params to be added in the callout HTTP request. Values can contain Lua expressions in the form `$(some_lua_expression)`. The syntax is based on `request-transformer-advanced` templates. type: object additionalProperties: type: string x-referenceable: true forward: description: 'If `true`, forwards the incoming request''s query params to the callout request. ' type: boolean default: false url: description: The URL that will be requested. Values can contain Lua expressions in the form `$(some_lua_expression)`. The syntax is based on `request-transformer-advanced` templates. type: string x-referenceable: true required: - url response: description: Configurations of callout response handling. type: object properties: body: type: object properties: decode: description: If `true`, decodes the response body before storing into the context. Only JSON is supported. type: boolean default: false store: description: If `false`, skips storing the callout response body into kong.ctx.shared.callouts..response.body. type: boolean default: true by_lua: description: Lua code that executes after the callout response is received, before caching takes place. Can produce side effects. Standard Lua sandboxing restrictions apply. type: string headers: description: Callout response header customizations. type: object properties: store: description: If `false`, skips storing the callout response headers into kong.ctx.shared.callouts..response.headers. type: boolean default: true required: - name - request type: object upstream: description: Customizations to the upstream request. type: object properties: body: description: Callout request body customizations. type: object properties: custom: description: The custom body fields to be added in the upstream request body. Values can contain Lua expressions in the form $(some_lua_expression). The syntax is based on `request-transformer-advanced` templates. type: object additionalProperties: type: string x-referenceable: true decode: description: If `true`, decodes the request's body to make it available for upstream by_lua customizations. Only JSON content type is supported. type: boolean default: true forward: description: If `false`, skips forwarding the incoming request's body to the upstream request. type: boolean default: true by_lua: description: Lua code that executes before the upstream request is made. Can produce side effects. Standard Lua sandboxing restrictions apply. type: string headers: description: Callout request header customizations. type: object properties: custom: description: The custom headers to be added in the upstream HTTP request. Values can contain Lua expressions in the form $(some_lua_expression). The syntax is based on `request-transformer-advanced` templates. type: object additionalProperties: type: string x-referenceable: true forward: description: If `false`, does not forward request headers to upstream request. type: boolean default: true query: description: Upstream request query param customizations. type: object properties: custom: description: The custom query params to be added in the upstream HTTP request. Values can contain Lua expressions in the form `$(some_lua_expression)`. The syntax is based on `request-transformer-advanced` templates. type: object additionalProperties: type: string x-referenceable: true forward: description: If `false`, does not forward request query params to upstream request. type: boolean default: true required: - callouts consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: request-callout protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config UpstreamOauthPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/UpstreamOauthPluginConfig' Oauth2IntrospectionPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/Oauth2IntrospectionPluginConfig' PostFunctionPluginConfig: x-speakeasy-entity: PluginPostFunction properties: config: type: object properties: access: type: array items: type: string default: [] body_filter: type: array items: type: string default: [] certificate: type: array items: type: string default: [] header_filter: type: array items: type: string default: [] log: type: array items: type: string default: [] rewrite: type: array items: type: string default: [] ws_client_frame: type: array items: type: string default: [] ws_close: type: array items: type: string default: [] ws_handshake: type: array items: type: string default: [] ws_upstream_frame: type: array items: type: string default: [] name: const: post-function protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string CorsPluginConfig: x-speakeasy-entity: PluginCors properties: config: type: object properties: allow_origin_absent: description: A boolean value that skip cors response headers when origin header of request is empty type: boolean default: true credentials: description: Flag to determine whether the `Access-Control-Allow-Credentials` header should be sent with `true` as the value. type: boolean default: false exposed_headers: description: Value for the `Access-Control-Expose-Headers` header. If not specified, no custom headers are exposed. type: array items: type: string headers: description: Value for the `Access-Control-Allow-Headers` header. type: array items: type: string max_age: description: Indicates how long the results of the preflight request can be cached, in `seconds`. type: number methods: description: '''Value for the `Access-Control-Allow-Methods` header. Available options include `GET`, `HEAD`, `PUT`, `PATCH`, `POST`, `DELETE`, `OPTIONS`, `TRACE`, `CONNECT`. By default, all options are allowed.''' type: array items: enum: - CONNECT - DELETE - GET - HEAD - OPTIONS - PATCH - POST - PUT - TRACE type: string default: - CONNECT - DELETE - GET - HEAD - OPTIONS - PATCH - POST - PUT - TRACE origins: description: 'List of allowed domains for the `Access-Control-Allow-Origin` header. If you want to allow all origins, add `*` as a single value to this configuration field. The accepted values can either be flat strings or PCRE regexes. NOTE: If you don''t specify any allowed domains, all origins are allowed.' type: array items: type: string preflight_continue: description: A boolean value that instructs the plugin to proxy the `OPTIONS` preflight request to the Upstream service. type: boolean default: false private_network: description: Flag to determine whether the `Access-Control-Allow-Private-Network` header should be sent with `true` as the value. type: boolean default: false name: const: cors protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https minLength: 1 type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AiLakeraGuardPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiLakeraGuardPluginConfig' ConfluentConsumePlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/ConfluentConsumePluginConfig' PreFunctionPluginConfig: x-speakeasy-entity: PluginPreFunction properties: config: type: object properties: access: type: array items: type: string default: [] body_filter: type: array items: type: string default: [] certificate: type: array items: type: string default: [] header_filter: type: array items: type: string default: [] log: type: array items: type: string default: [] rewrite: type: array items: type: string default: [] ws_client_frame: type: array items: type: string default: [] ws_close: type: array items: type: string default: [] ws_handshake: type: array items: type: string default: [] ws_upstream_frame: type: array items: type: string default: [] name: const: pre-function protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string KeyAuthPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/KeyAuthPluginConfig' JwtSignerPluginConfig: x-speakeasy-entity: PluginJwtSigner properties: config: type: object properties: access_token_audience_claim: description: Specify the claim in an access token to verify against values of `config.access_token_audiences_allowed`. type: array items: type: string default: - aud access_token_audiences_allowed: description: The audiences allowed to be present in the access token claim specified by `config.access_token_audience_claim`. type: array items: type: string access_token_consumer_by: description: When the plugin tries to apply an access token to a Kong consumer mapping, it tries to find a matching Kong consumer from properties defined using this configuration parameter. The parameter can take an array of values. Valid values are `id`, `username`, and `custom_id`. type: array items: enum: - custom_id - id - username type: string default: - custom_id - username access_token_consumer_claim: description: When you set a value for this parameter, the plugin tries to map an arbitrary claim specified with this configuration parameter (for example, `sub` or `username`) in an access token to Kong consumer entity. type: array items: type: string access_token_endpoints_ssl_verify: description: Whether to verify the TLS certificate if any of `access_token_introspection_endpoint`, `access_token_jwks_uri`, or `access_token_keyset` is an HTTPS URI. type: boolean default: true access_token_expiry_claim: description: Specify the expiry claim in an access token to verify if the default `exp` is not used. type: array items: type: string default: - exp access_token_introspection_audience_claim: description: Specify the claim in an access token introspection to verify against values of `config.access_token_introspection_audiences_allowed`. type: array items: type: string default: - aud access_token_introspection_audiences_allowed: description: The audiences allowed to be present in the access token introspection claim specified by `config.access_token_introspection_audience_claim`. type: array items: type: string access_token_introspection_authorization: description: If the introspection endpoint requires client authentication (client being the JWT Signer plugin), you can specify the `Authorization` header's value with this configuration parameter. type: string access_token_introspection_body_args: description: 'This parameter allows you to pass URL encoded request body arguments. For example: `resource=` or `a=1&b=&c`.' type: string access_token_introspection_consumer_by: description: When the plugin tries to do access token introspection results to Kong consumer mapping, it tries to find a matching Kong consumer from properties defined using this configuration parameter. The parameter can take an array of values. type: array items: enum: - custom_id - id - username type: string default: - custom_id - username access_token_introspection_consumer_claim: description: When you set a value for this parameter, the plugin tries to map an arbitrary claim specified with this configuration parameter (such as `sub` or `username`) in access token introspection results to the Kong consumer entity. type: array items: type: string access_token_introspection_endpoint: description: When you use `opaque` access tokens and you want to turn on access token introspection, you need to specify the OAuth 2.0 introspection endpoint URI with this configuration parameter. type: string access_token_introspection_expiry_claim: description: Specify the expiry claim in an access token introspection to verify if the default `exp` is not used. type: array items: type: string default: - exp access_token_introspection_hint: description: If you need to give `hint` parameter when introspecting an access token, use this parameter to specify the value. By default, the plugin sends `hint=access_token`. type: string default: access_token access_token_introspection_issuer_claim: description: Specify the claim in an access token introspection to verify against values of `config.access_token_introspection_issuers_allowed`. type: array items: type: string default: - iss access_token_introspection_issuers_allowed: description: The issuers allowed to be present in the access token introspection claim specified by `config.access_token_introspection_issuer_claim`. type: array items: type: string access_token_introspection_jwt_claim: description: If your introspection endpoint returns an access token in one of the keys (or claims) within the introspection results (`JSON`). If the key cannot be found, the plugin responds with `401 Unauthorized`. Also if the key is found but cannot be decoded as JWT, it also responds with `401 Unauthorized`. type: array items: type: string access_token_introspection_leeway: description: Adjusts clock skew between the token issuer introspection results and Kong. The value will be used to time-related claim verification. For example, it will be added to introspection results (`JSON`) `exp` claim/property before checking token expiry against Kong servers current time in seconds. You can disable access token introspection `expiry` verification altogether with `config.verify_access_token_introspection_expiry`. type: number default: 0 access_token_introspection_notbefore_claim: description: Specify the notbefore claim in an access token introspection to verify if the default `nbf` is not used. type: array items: type: string default: - nbf access_token_introspection_optional_claims: description: Specify the optional claims of the access token introspection result. These claims are only validated when they are present. Every claim is specified by an array. If the array has multiple elements, it means the claim is inside a nested object of the payload. type: array items: items: type: string type: array access_token_introspection_required_claims: description: Specify the required claims that must be present in the access token introspection result. Every claim is specified by an array. If the array has multiple elements, it means the claim is inside a nested object of the payload. type: array items: items: type: string type: array access_token_introspection_scopes_claim: description: Specify the claim/property in access token introspection results (`JSON`) to be verified against values of `config.access_token_introspection_scopes_required`. This supports nested claims. For example, with Keycloak you could use `[ "realm_access", "roles" ]`, which can be given as `realm_access,roles` (form post). If the claim is not found in access token introspection results, and you have specified `config.access_token_introspection_scopes_required`, the plugin responds with `403 Forbidden`. type: array items: type: string default: - scope access_token_introspection_scopes_required: description: Specify the required values (or scopes) that are checked by an introspection claim/property specified by `config.access_token_introspection_scopes_claim`. type: array items: type: string access_token_introspection_subject_claim: description: Specify the claim in an access token introspection to verify against values of `config.access_token_introspection_subjects_allowed`. type: array items: type: string default: - sub access_token_introspection_subjects_allowed: description: The subjects allowed to be present in the access token introspection claim specified by `config.access_token_introspection_subject_claim`. type: array items: type: string access_token_introspection_timeout: description: Timeout in milliseconds for an introspection request. The plugin tries to introspect twice if the first request fails for some reason. If both requests timeout, then the plugin runs two times the `config.access_token_introspection_timeout` on access token introspection. type: number access_token_issuer: description: The `iss` claim of a signed or re-signed access token is set to this value. Original `iss` claim of the incoming token (possibly introspected) is stored in `original_iss` claim of the newly signed access token. type: string default: kong access_token_issuer_claim: description: Specify the claim in an access token to verify against values of `config.access_token_issuers_allowed`. type: array items: type: string default: - iss access_token_issuers_allowed: description: The issuers allowed to be present in the access token claim specified by `config.access_token_issuer_claim`. type: array items: type: string access_token_jwks_uri: description: Specify the URI where the plugin can fetch the public keys (JWKS) to verify the signature of the access token. type: string access_token_jwks_uri_client_certificate: description: The client certificate that will be used to authenticate Kong if `access_token_jwks_uri` is an https uri that requires mTLS Auth. type: object properties: id: type: string x-foreign: true access_token_jwks_uri_client_password: description: The client password that will be used to authenticate Kong if `access_token_jwks_uri` is a uri that requires Basic Auth. Should be configured together with `access_token_jwks_uri_client_username` type: string x-encrypted: true x-referenceable: true access_token_jwks_uri_client_username: description: The client username that will be used to authenticate Kong if `access_token_jwks_uri` is a uri that requires Basic Auth. Should be configured together with `access_token_jwks_uri_client_password` type: string x-referenceable: true access_token_jwks_uri_rotate_period: description: Specify the period (in seconds) to auto-rotate the jwks for `access_token_jwks_uri`. The default value 0 means no auto-rotation. type: number default: 0 access_token_keyset: description: The name of the keyset containing signing keys. type: string default: kong access_token_keyset_client_certificate: description: The client certificate that will be used to authenticate Kong if `access_token_keyset` is an https uri that requires mTLS Auth. type: object properties: id: type: string x-foreign: true access_token_keyset_client_password: description: The client password that will be used to authenticate Kong if `access_token_keyset` is a uri that requires Basic Auth. Should be configured together with `access_token_keyset_client_username` type: string x-encrypted: true x-referenceable: true access_token_keyset_client_username: description: The client username that will be used to authenticate Kong if `access_token_keyset` is a uri that requires Basic Auth. Should be configured together with `access_token_keyset_client_password` type: string x-referenceable: true access_token_keyset_rotate_period: description: Specify the period (in seconds) to auto-rotate the jwks for `access_token_keyset`. The default value 0 means no auto-rotation. type: number default: 0 access_token_leeway: description: Adjusts clock skew between the token issuer and Kong. The value will be used to time-related claim verification. For example, it will be added to the token's `exp` claim before checking token expiry against Kong servers' current time in seconds. You can disable access token `expiry` verification altogether with `config.verify_access_token_expiry`. type: number default: 0 access_token_notbefore_claim: description: Specify the notbefore claim in an access token to verify if the default `nbf` is not used. type: array items: type: string default: - nbf access_token_optional: description: If an access token is not provided or no `config.access_token_request_header` is specified, the plugin cannot verify the access token. In that case, the plugin normally responds with `401 Unauthorized` (client didn't send a token) or `500 Unexpected` (a configuration error). Use this parameter to allow the request to proceed even when there is no token to check. If the token is provided, then this parameter has no effect type: boolean default: false access_token_optional_claims: description: Specify the optional claims of the access token. These claims are only validated when they are present. Every claim is specified by an array. If the array has multiple elements, it means the claim is inside a nested object of the payload. type: array items: items: type: string type: array access_token_request_header: description: This parameter tells the name of the header where to look for the access token. type: string default: Authorization access_token_required_claims: description: Specify the required claims that must be present in the access token. Every claim is specified by an array. If the array has multiple elements, it means the claim is inside a nested object of the payload. type: array items: items: type: string type: array access_token_scopes_claim: description: Specify the claim in an access token to verify against values of `config.access_token_scopes_required`. type: array items: type: string default: - scope access_token_scopes_required: description: Specify the required values (or scopes) that are checked by a claim specified by `config.access_token_scopes_claim`. type: array items: type: string access_token_signing: description: Quickly turn access token signing or re-signing off and on as needed. If turned off, the plugin will not send the signed or resigned token to the upstream. type: boolean default: true access_token_signing_algorithm: description: When this plugin sets the upstream header as specified with `config.access_token_upstream_header`, re-signs the original access token using the private keys of the JWT Signer plugin. Specify the algorithm that is used to sign the token. The `config.access_token_issuer` specifies which `keyset` is used to sign the new token issued by Kong using the specified signing algorithm. type: string default: RS256 enum: - ES256 - ES384 - ES512 - EdDSA - HS256 - HS384 - HS512 - PS256 - PS384 - PS512 - RS256 - RS512 access_token_subject_claim: description: Specify the claim in an access token to verify against values of `config.access_token_subjects_allowed`. type: array items: type: string default: - sub access_token_subjects_allowed: description: The subjects allowed to be present in the access token claim specified by `config.access_token_subject_claim`. type: array items: type: string access_token_upstream_header: description: Removes the `config.access_token_request_header` from the request after reading its value. With `config.access_token_upstream_header`, you can specify the upstream header where the plugin adds the Kong signed token. If you don't specify a value, such as use `null` or `""` (empty string), the plugin does not even try to sign or re-sign the token. type: string default: Authorization:Bearer access_token_upstream_leeway: description: If you want to add or subtract (using a negative value) expiry time (in seconds) of the original access token, you can specify a value that is added to the original access token's `exp` claim. type: number default: 0 add_access_token_claims: description: Add customized claims if they are not present yet. Value can be a regular or JSON string; if JSON, decoded data is used as the claim's value. type: object default: {} additionalProperties: type: string add_channel_token_claims: description: Add customized claims if they are not present yet. Value can be a regular or JSON string; if JSON, decoded data is used as the claim's value. type: object default: {} additionalProperties: type: string add_claims: description: Add customized claims to both tokens if they are not present yet. Value can be a regular or JSON string; if JSON, decoded data is used as the claim's value. type: object default: {} additionalProperties: type: string cache_access_token_introspection: description: Whether to cache access token introspection results. type: boolean default: true cache_channel_token_introspection: description: Whether to cache channel token introspection results. type: boolean default: true channel_token_audience_claim: description: Specify the claim in a channel token to verify against values of `config.channel_token_audiences_allowed`. type: array items: type: string default: - aud channel_token_audiences_allowed: description: The audiences allowed to be present in the channel token claim specified by `config.channel_token_audience_claim`. type: array items: type: string channel_token_consumer_by: description: 'When the plugin tries to do channel token to Kong consumer mapping, it tries to find a matching Kong consumer from properties defined using this configuration parameter. The parameter can take an array of valid values: `id`, `username`, and `custom_id`.' type: array items: enum: - custom_id - id - username type: string default: - custom_id - username channel_token_consumer_claim: description: When you set a value for this parameter, the plugin tries to map an arbitrary claim specified with this configuration parameter. Kong consumers have an `id`, a `username`, and a `custom_id`. If this parameter is enabled but the mapping fails, such as when there's a non-existent Kong consumer, the plugin responds with `403 Forbidden`. type: array items: type: string channel_token_endpoints_ssl_verify: description: Whether to verify the TLS certificate if any of `channel_token_introspection_endpoint`, `channel_token_jwks_uri`, or `channel_token_keyset` is an HTTPS URI. type: boolean default: true channel_token_expiry_claim: description: Specify the expiry claim in a channel token to verify if the default `exp` is not used. type: array items: type: string default: - exp channel_token_introspection_audience_claim: description: Specify the claim in a channel token introspection to verify against values of `config.channel_token_introspection_audiences_allowed`. type: array items: type: string default: - aud channel_token_introspection_audiences_allowed: description: The audiences allowed to be present in the channel token introspection claim specified by `config.channel_token_introspection_audience_claim`. type: array items: type: string channel_token_introspection_authorization: description: When using `opaque` channel tokens, and you want to turn on channel token introspection, you need to specify the OAuth 2.0 introspection endpoint URI with this configuration parameter. Otherwise the plugin will not try introspection, and instead returns `401 Unauthorized` when using opaque channel tokens. type: string channel_token_introspection_body_args: description: 'If you need to pass additional body arguments to introspection endpoint when the plugin introspects the opaque channel token, you can use this config parameter to specify them. You should URL encode the value. For example: `resource=` or `a=1&b=&c`.' type: string channel_token_introspection_consumer_by: description: When the plugin tries to do channel token introspection results to Kong consumer mapping, it tries to find a matching Kong consumer from properties defined using this configuration parameter. The parameter can take an array of values. Valid values are `id`, `username` and `custom_id`. type: array items: enum: - custom_id - id - username type: string default: - custom_id - username channel_token_introspection_consumer_claim: description: When you set a value for this parameter, the plugin tries to map an arbitrary claim specified with this configuration parameter (such as `sub` or `username`) in channel token introspection results to Kong consumer entity type: array items: type: string channel_token_introspection_endpoint: description: When you use `opaque` access tokens and you want to turn on access token introspection, you need to specify the OAuth 2.0 introspection endpoint URI with this configuration parameter. Otherwise, the plugin does not try introspection and returns `401 Unauthorized` instead. type: string channel_token_introspection_expiry_claim: description: Specify the expiry claim in a channel token to verify if the default `exp` is not used. type: array items: type: string default: - exp channel_token_introspection_hint: description: If you need to give `hint` parameter when introspecting a channel token, you can use this parameter to specify the value of such parameter. By default, a `hint` isn't sent with channel token introspection. type: string channel_token_introspection_issuer_claim: description: Specify the claim in a channel token introspection to verify against values of `config.channel_token_introspection_issuers_allowed`. type: array items: type: string default: - iss channel_token_introspection_issuers_allowed: description: The issuers allowed to be present in the channel token introspection claim specified by `config.channel_token_introspection_issuer_claim`. type: array items: type: string channel_token_introspection_jwt_claim: description: If your introspection endpoint returns a channel token in one of the keys (or claims) in the introspection results (`JSON`), the plugin can use that value instead of the introspection results when doing expiry verification and signing of the new token issued by Kong. type: array items: type: string channel_token_introspection_leeway: description: You can use this parameter to adjust clock skew between the token issuer introspection results and Kong. The value will be used to time-related claim verification. For example, it will be added to introspection results (`JSON`) `exp` claim/property before checking token expiry against Kong servers current time (in seconds). You can disable channel token introspection `expiry` verification altogether with `config.verify_channel_token_introspection_expiry`. type: number default: 0 channel_token_introspection_notbefore_claim: description: Specify the notbefore claim in a channel token to verify if the default `nbf` is not used. type: array items: type: string default: - nbf channel_token_introspection_optional_claims: description: Specify the optional claims of the channel token introspection. These claims are only validated when they are present. Every claim is specified by an array. If the array has multiple elements, it means the claim is inside a nested object of the payload. type: array items: items: type: string type: array channel_token_introspection_required_claims: description: Specify the required claims that must be present in the channel token introspection. Every claim is specified by an array. If the array has multiple elements, it means the claim is inside a nested object of the payload. type: array items: items: type: string type: array channel_token_introspection_scopes_claim: description: Use this parameter to specify the claim/property in channel token introspection results (`JSON`) to be verified against values of `config.channel_token_introspection_scopes_required`. This supports nested claims. type: array items: type: string default: - scope channel_token_introspection_scopes_required: description: Use this parameter to specify the required values (or scopes) that are checked by an introspection claim/property specified by `config.channel_token_introspection_scopes_claim`. type: array items: type: string channel_token_introspection_subject_claim: description: Specify the claim in a channel token to verify against values of `config.channel_token_introspection_subjects_allowed`. type: array items: type: string default: - sub channel_token_introspection_subjects_allowed: description: The subjects allowed to be present in the channel token introspection claim specified by `config.channel_token_introspection_subject_claim`. type: array items: type: string channel_token_introspection_timeout: description: Timeout in milliseconds for an introspection request. The plugin tries to introspect twice if the first request fails for some reason. If both requests timeout, then the plugin runs two times the `config.access_token_introspection_timeout` on channel token introspection. type: number channel_token_issuer: description: The `iss` claim of the re-signed channel token is set to this value, which is `kong` by default. The original `iss` claim of the incoming token (possibly introspected) is stored in the `original_iss` claim of the newly signed channel token. type: string default: kong channel_token_issuer_claim: description: Specify the claim in a channel token to verify against values of `config.channel_token_issuers_allowed`. type: array items: type: string default: - iss channel_token_issuers_allowed: description: The issuers allowed to be present in the channel token claim specified by `config.channel_token_issuer_claim`. type: array items: type: string channel_token_jwks_uri: description: If you want to use `config.verify_channel_token_signature`, you must specify the URI where the plugin can fetch the public keys (JWKS) to verify the signature of the channel token. If you don't specify a URI and you pass a JWT token to the plugin, then the plugin responds with `401 Unauthorized`. type: string channel_token_jwks_uri_client_certificate: description: The client certificate that will be used to authenticate Kong if `channel_token_jwks_uri` is an https uri that requires mTLS Auth. type: object properties: id: type: string x-foreign: true channel_token_jwks_uri_client_password: description: The client password that will be used to authenticate Kong if `channel_token_jwks_uri` is a uri that requires Basic Auth. Should be configured together with `channel_token_jwks_uri_client_username` type: string x-encrypted: true x-referenceable: true channel_token_jwks_uri_client_username: description: The client username that will be used to authenticate Kong if `channel_token_jwks_uri` is a uri that requires Basic Auth. Should be configured together with `channel_token_jwks_uri_client_password` type: string x-referenceable: true channel_token_jwks_uri_rotate_period: description: Specify the period (in seconds) to auto-rotate the jwks for `channel_token_jwks_uri`. The default value 0 means no auto-rotation. type: number default: 0 channel_token_keyset: description: The name of the keyset containing signing keys. type: string default: kong channel_token_keyset_client_certificate: description: The client certificate that will be used to authenticate Kong if `channel_token_keyset` is an https uri that requires mTLS Auth. type: object properties: id: type: string x-foreign: true channel_token_keyset_client_password: description: The client password that will be used to authenticate Kong if `channel_token_keyset` is a uri that requires Basic Auth. Should be configured together with `channel_token_keyset_client_username` type: string x-encrypted: true x-referenceable: true channel_token_keyset_client_username: description: The client username that will be used to authenticate Kong if `channel_token_keyset` is a uri that requires Basic Auth. Should be configured together with `channel_token_keyset_client_password` type: string x-referenceable: true channel_token_keyset_rotate_period: description: Specify the period (in seconds) to auto-rotate the jwks for `channel_token_keyset`. The default value 0 means no auto-rotation. type: number default: 0 channel_token_leeway: description: Adjusts clock skew between the token issuer and Kong. The value will be used to time-related claim verification. For example, it will be added to token's `exp` claim before checking token expiry against Kong servers current time in seconds. You can disable channel token `expiry` verification altogether with `config.verify_channel_token_expiry`. type: number default: 0 channel_token_notbefore_claim: description: Specify the notbefore claim in a channel token to verify if the default `nbf` is not used. type: array items: type: string default: - nbf channel_token_optional: description: If a channel token is not provided or no `config.channel_token_request_header` is specified, the plugin cannot verify the channel token. In that case, the plugin normally responds with `401 Unauthorized` (client didn't send a token) or `500 Unexpected` (a configuration error). Enable this parameter to allow the request to proceed even when there is no channel token to check. If the channel token is provided, then this parameter has no effect type: boolean default: false channel_token_optional_claims: description: Specify the optional claims of the channel token. These claims are only validated when they are present. Every claim is specified by an array. If the array has multiple elements, it means the claim is inside a nested object of the payload. type: array items: items: type: string type: array channel_token_request_header: description: This parameter tells the name of the header where to look for the channel token. If you don't want to do anything with the channel token, then you can set this to `null` or `""` (empty string). type: string channel_token_required_claims: description: Specify the required claims that must be present in the channel token. Every claim is specified by an array. If the array has multiple elements, it means the claim is inside a nested object of the payload. type: array items: items: type: string type: array channel_token_scopes_claim: description: Specify the claim in a channel token to verify against values of `config.channel_token_scopes_required`. This supports nested claims. type: array items: type: string default: - scope channel_token_scopes_required: description: Specify the required values (or scopes) that are checked by a claim specified by `config.channel_token_scopes_claim`. type: array items: type: string channel_token_signing: description: Quickly turn channel token signing or re-signing off and on as needed. If turned off, the plugin will not send the signed or resigned token to the upstream. type: boolean default: true channel_token_signing_algorithm: description: When this plugin sets the upstream header as specified with `config.channel_token_upstream_header`, it also re-signs the original channel token using private keys of this plugin. Specify the algorithm that is used to sign the token. type: string default: RS256 enum: - ES256 - ES384 - ES512 - EdDSA - HS256 - HS384 - HS512 - PS256 - PS384 - PS512 - RS256 - RS512 channel_token_subject_claim: description: Specify the claim in a channel token to verify against values of `config.channel_token_subjects_allowed`. type: array items: type: string default: - sub channel_token_subjects_allowed: description: The subjects allowed to be present in the channel token claim specified by `config.channel_token_subject_claim`. type: array items: type: string channel_token_upstream_header: description: This plugin removes the `config.channel_token_request_header` from the request after reading its value. type: string channel_token_upstream_leeway: description: If you want to add or perhaps subtract (using negative value) expiry time of the original channel token, you can specify a value that is added to the original channel token's `exp` claim. type: number default: 0 enable_access_token_introspection: description: If you don't want to support opaque access tokens, change this configuration parameter to `false` to disable introspection. type: boolean default: true enable_channel_token_introspection: description: If you don't want to support opaque channel tokens, disable introspection by changing this configuration parameter to `false`. type: boolean default: true enable_hs_signatures: description: Tokens signed with HMAC algorithms such as `HS256`, `HS384`, or `HS512` are not accepted by default. If you need to accept such tokens for verification, enable this setting. type: boolean default: false enable_instrumentation: description: Writes log entries with some added information using `ngx.CRIT` (CRITICAL) level. type: boolean default: false original_access_token_upstream_header: description: The HTTP header name used to store the original access token. type: string original_channel_token_upstream_header: description: The HTTP header name used to store the original channel token. type: string realm: description: When authentication or authorization fails, or there is an unexpected error, the plugin sends a `WWW-Authenticate` header with the `realm` attribute value. type: string remove_access_token_claims: description: remove claims. It should be an array, and each element is a claim key string. type: array items: type: string default: [] remove_channel_token_claims: description: remove claims. It should be an array, and each element is a claim key string. type: array items: type: string default: [] set_access_token_claims: description: Set customized claims. If a claim is already present, it will be overwritten. Value can be a regular or JSON string; if JSON, decoded data is used as the claim's value. type: object default: {} additionalProperties: type: string set_channel_token_claims: description: Set customized claims. If a claim is already present, it will be overwritten. Value can be a regular or JSON string; if JSON, decoded data is used as the claim's value. type: object default: {} additionalProperties: type: string set_claims: description: Set customized claims to both tokens. If a claim is already present, it will be overwritten. Value can be a regular or JSON string; if JSON, decoded data is used as the claim's value. type: object default: {} additionalProperties: type: string trust_access_token_introspection: description: Use this parameter to enable and disable further checks on a payload before the new token is signed. If you set this to `true`, the expiry or scopes are not checked on a payload. type: boolean default: true trust_channel_token_introspection: description: Providing an opaque channel token for plugin introspection, and verifying expiry and scopes on introspection results may make further payload checks unnecessary before the plugin signs a new token. This also applies when using a JWT token with introspection JSON as per config.channel_token_introspection_jwt_claim. Use this parameter to manage additional payload checks before signing a new token. With true (default), payload's expiry or scopes aren't checked. type: boolean default: true verify_access_token_audience: description: Quickly turn off and on the access token required audiences verification, specified with `config.access_token_audiences_required`. type: boolean default: true verify_access_token_expiry: description: Quickly turn access token expiry verification off and on as needed. type: boolean default: true verify_access_token_introspection_audience: description: Quickly turn off and on the access token introspection required audiences verification, specified with `config.access_token_introspection_audiences_required`. type: boolean default: true verify_access_token_introspection_expiry: description: Quickly turn access token introspection expiry verification off and on as needed. type: boolean default: true verify_access_token_introspection_issuer: description: Quickly turn off and on the access token introspection allowed issuers verification, specified with `config.access_token_introspection_issuers_allowed`. type: boolean default: true verify_access_token_introspection_notbefore: description: Quickly turn off and on the access token introspection notbefore verification. type: boolean default: false verify_access_token_introspection_scopes: description: Quickly turn off and on the access token introspection scopes verification, specified with `config.access_token_introspection_scopes_required`. type: boolean default: true verify_access_token_introspection_subject: description: Quickly turn off and on the access token introspection required subjects verification, specified with `config.access_token_introspection_subjects_required`. type: boolean default: true verify_access_token_issuer: description: Quickly turn off and on the access token allowed issuers verification, specified with `config.access_token_issuers_allowed`. type: boolean default: true verify_access_token_notbefore: description: Quickly turn off and on the access token notbefore verification. type: boolean default: false verify_access_token_scopes: description: Quickly turn off and on the access token required scopes verification, specified with `config.access_token_scopes_required`. type: boolean default: true verify_access_token_signature: description: Quickly turn access token signature verification off and on as needed. type: boolean default: true verify_access_token_subject: description: Quickly turn off and on the access token required subjects verification, specified with `config.access_token_subjects_required`. type: boolean default: true verify_channel_token_audience: description: Quickly turn off and on the channel token required audiences verification, specified with `config.channel_token_audiences_required`. type: boolean default: true verify_channel_token_expiry: type: boolean default: true verify_channel_token_introspection_audience: description: Quickly turn off and on the channel token introspection required audiences verification, specified with `config.channel_token_introspection_audiences_required`. type: boolean default: true verify_channel_token_introspection_expiry: description: Quickly turn on/off the channel token introspection expiry verification. type: boolean default: true verify_channel_token_introspection_issuer: description: Quickly turn off and on the channel token introspection allowed issuers verification, specified with `config.channel_token_introspection_issuers_allowed`. type: boolean default: true verify_channel_token_introspection_notbefore: description: Quickly turn off and on the channel token introspection notbefore verification. type: boolean default: false verify_channel_token_introspection_scopes: description: Quickly turn on/off the channel token introspection scopes verification specified with `config.channel_token_introspection_scopes_required`. type: boolean default: true verify_channel_token_introspection_subject: description: Quickly turn off and on the channel token introspection required subjects verification, specified with `config.channel_token_introspection_subjects_required`. type: boolean default: true verify_channel_token_issuer: description: Quickly turn off and on the channel token allowed issuers verification, specified with `config.channel_token_issuers_allowed`. type: boolean default: true verify_channel_token_notbefore: description: Quickly turn off and on the channel token notbefore verification. type: boolean default: false verify_channel_token_scopes: description: Quickly turn on/off the channel token required scopes verification specified with `config.channel_token_scopes_required`. type: boolean default: true verify_channel_token_signature: description: Quickly turn on/off the channel token signature verification. type: boolean default: true verify_channel_token_subject: description: Quickly turn off and on the channel token required subjects verification, specified with `config.channel_token_subjects_required`. type: boolean default: true name: const: jwt-signer protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string KafkaUpstreamPluginConfig: x-speakeasy-entity: PluginKafkaUpstream properties: config: type: object properties: allowed_topics: description: The list of allowed topic names to which messages can be sent. The default topic configured in the `topic` field is always allowed, regardless of its inclusion in `allowed_topics`. type: array items: type: string authentication: type: object properties: mechanism: description: 'The SASL authentication mechanism. Supported options: `PLAIN`, `SCRAM-SHA-256`, or `SCRAM-SHA-512`.' type: string enum: - PLAIN - SCRAM-SHA-256 - SCRAM-SHA-512 password: description: Password for SASL authentication. type: string x-encrypted: true x-referenceable: true strategy: description: The authentication strategy for the plugin, the only option for the value is `sasl`. type: string enum: - sasl tokenauth: description: Enable this to indicate `DelegationToken` authentication. type: boolean user: description: Username for SASL authentication. type: string x-encrypted: true x-referenceable: true bootstrap_servers: description: 'Set of bootstrap brokers in a `{host: host, port: port}` list format.' type: array items: properties: host: description: A string representing a host name, such as example.com. type: string port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 required: - host - port type: object cluster_name: description: An identifier for the Kafka cluster. By default, this field generates a random string. You can also set your own custom cluster identifier. If more than one Kafka plugin is configured without a `cluster_name` (that is, if the default autogenerated value is removed), these plugins will use the same producer, and by extension, the same cluster. Logs will be sent to the leader of the cluster. type: string forward_body: description: 'Include the request body in the message. At least one of these must be true: `forward_method`, `forward_uri`, `forward_headers`, `forward_body`.' type: boolean default: true forward_headers: description: 'Include the request headers in the message. At least one of these must be true: `forward_method`, `forward_uri`, `forward_headers`, `forward_body`.' type: boolean default: false forward_method: description: 'Include the request method in the message. At least one of these must be true: `forward_method`, `forward_uri`, `forward_headers`, `forward_body`.' type: boolean default: false forward_uri: description: 'Include the request URI and URI arguments (as in, query arguments) in the message. At least one of these must be true: `forward_method`, `forward_uri`, `forward_headers`, `forward_body`.' type: boolean default: false keepalive: description: Keepalive timeout in milliseconds. type: integer default: 60000 keepalive_enabled: type: boolean default: false key_query_arg: description: The request query parameter name that contains the Kafka message key. If specified, messages with the same key will be sent to the same Kafka partition, ensuring consistent ordering. type: string message_by_lua_functions: description: The Lua functions that manipulates the message being sent to the Kafka topic. type: array items: type: string producer_async: description: Flag to enable asynchronous mode. type: boolean default: true producer_async_buffering_limits_messages_in_memory: description: Maximum number of messages that can be buffered in memory in asynchronous mode. type: integer default: 50000 producer_async_flush_timeout: description: Maximum time interval in milliseconds between buffer flushes in asynchronous mode. type: integer default: 1000 producer_request_acks: description: 'The number of acknowledgments the producer requires the leader to have received before considering a request complete. Allowed values: 0 for no acknowledgments; 1 for only the leader; and -1 for the full ISR (In-Sync Replica set).' type: integer default: 1 enum: - -1 - 0 - 1 producer_request_limits_bytes_per_request: description: Maximum size of a Produce request in bytes. type: integer default: 1048576 producer_request_limits_messages_per_request: description: Maximum number of messages to include into a single producer request. type: integer default: 200 producer_request_retries_backoff_timeout: description: Backoff interval between retry attempts in milliseconds. type: integer default: 100 producer_request_retries_max_attempts: description: Maximum number of retry attempts per single Produce request. type: integer default: 10 producer_request_timeout: description: Time to wait for a Produce response in milliseconds. type: integer default: 2000 schema_registry: description: The plugin-global schema registry configuration. This can be overwritten by the topic configuration. type: object properties: confluent: type: object properties: authentication: type: object properties: basic: type: object properties: password: type: string x-encrypted: true x-referenceable: true username: type: string x-encrypted: true x-referenceable: true required: - password - username mode: description: Authentication mode to use with the schema registry. type: string default: none enum: - basic - none - oauth2 oauth2: type: object properties: audience: description: List of audiences passed to the IdP when obtaining a new token. type: array items: type: string default: [] client_id: description: The client ID for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true client_secret: description: The client secret for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true grant_type: description: The OAuth grant type to be used. type: string default: client_credentials enum: - client_credentials - password password: description: The password to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true scopes: description: List of scopes to request from the IdP when obtaining a new token. type: array items: type: string default: - openid token_endpoint: description: The token endpoint URI. type: string token_headers: description: Extra headers to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true token_post_args: description: Extra post arguments to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true username: description: The username to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true required: - token_endpoint oauth2_client: type: object properties: auth_method: description: 'The authentication method used in client requests to the IdP. Supported values are: `client_secret_basic` to send `client_id` and `client_secret` in the `Authorization: Basic` header, `client_secret_post` to send `client_id` and `client_secret` as part of the request body, or `client_secret_jwt` to send a JWT signed with the `client_secret` using the client assertion as part of the body.' type: string default: client_secret_post enum: - client_secret_basic - client_secret_jwt - client_secret_post - none client_secret_jwt_alg: description: The algorithm to use with JWT when using `client_secret_jwt` authentication. type: string default: HS512 enum: - HS256 - HS512 http_proxy: description: The proxy to use when making HTTP requests to the IdP. type: string http_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `http_proxy`. type: string http_version: description: 'The HTTP version used for requests made by this plugin. Supported values: `1.1` for HTTP 1.1 and `1.0` for HTTP 1.0.' type: number default: 1.1 https_proxy: description: The proxy to use when making HTTPS requests to the IdP. type: string https_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `https_proxy`. type: string keep_alive: description: Whether to use keepalive connections to the IdP. type: boolean default: true no_proxy: description: A comma-separated list of hosts that should not be proxied. type: string ssl_verify: description: Whether to verify the certificate presented by the IdP when using HTTPS. type: boolean default: true timeout: description: Network I/O timeout for requests to the IdP in milliseconds. type: integer default: 10000 maximum: 2147483646 minimum: 0 key_schema: type: object properties: schema_version: description: The schema version to use for serialization/deserialization. Use 'latest' to always fetch the most recent version. type: string subject_name: description: The name of the subject type: string ssl_verify: description: Set to false to disable SSL certificate verification when connecting to the schema registry. type: boolean default: true ttl: description: The TTL in seconds for the schema registry cache. type: number maximum: 3600 minimum: 0 url: description: The URL of the schema registry. type: string value_schema: type: object properties: schema_version: description: The schema version to use for serialization/deserialization. Use 'latest' to always fetch the most recent version. type: string subject_name: description: The name of the subject type: string security: type: object properties: certificate_id: description: UUID of certificate entity for mTLS authentication. type: string ssl: description: Enables TLS. type: boolean ssl_verify: description: When using TLS, this option enables verification of the certificate presented by the server. type: boolean default: true timeout: description: Socket timeout in milliseconds. type: integer default: 10000 topic: description: The default Kafka topic to publish to if the query parameter defined in the `topics_query_arg` does not exist in the request type: string topics_query_arg: description: The request query parameter name that contains the topics to publish to type: string required: - topic consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: kafka-upstream protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config GraphqlRateLimitingAdvancedPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/GraphqlRateLimitingAdvancedPluginConfig' OasValidationPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/OasValidationPluginConfig' CorrelationIdPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/CorrelationIdPluginConfig' KafkaConsumePlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/KafkaConsumePluginConfig' WebsocketValidatorPluginConfig: x-speakeasy-entity: PluginWebsocketValidator properties: config: type: object properties: client: type: object properties: binary: type: object properties: schema: description: Schema used to validate upstream-originated binary frames. The semantics of this field depend on the validation type set by `config.upstream.binary.type`. type: string type: description: The corresponding validation library for `config.upstream.binary.schema`. Currently, only `draft4` is supported. type: string enum: - draft4 required: - schema - type text: type: object properties: schema: description: Schema used to validate upstream-originated binary frames. The semantics of this field depend on the validation type set by `config.upstream.binary.type`. type: string type: description: The corresponding validation library for `config.upstream.binary.schema`. Currently, only `draft4` is supported. type: string enum: - draft4 required: - schema - type upstream: type: object properties: binary: type: object properties: schema: description: Schema used to validate upstream-originated binary frames. The semantics of this field depend on the validation type set by `config.upstream.binary.type`. type: string type: description: The corresponding validation library for `config.upstream.binary.schema`. Currently, only `draft4` is supported. type: string enum: - draft4 required: - schema - type text: type: object properties: schema: description: Schema used to validate upstream-originated binary frames. The semantics of this field depend on the validation type set by `config.upstream.binary.type`. type: string type: description: The corresponding validation library for `config.upstream.binary.schema`. Currently, only `draft4` is supported. type: string enum: - draft4 required: - schema - type consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: websocket-validator protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - ws - wss type: string format: set default: - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AzureFunctionsPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AzureFunctionsPluginConfig' VaultAuthPluginConfig: x-speakeasy-entity: PluginVaultAuth properties: config: type: object properties: access_token_name: description: Describes an array of comma-separated parameter names where the plugin looks for an access token. The client must send the access token in one of those key names, and the plugin will try to read the credential from a header or the querystring parameter with the same name. The key names can only contain [a-z], [A-Z], [0-9], [_], and [-]. type: string default: access_token anonymous: description: An optional string (consumer UUID or username) value to use as an “anonymous” consumer if authentication fails. If empty (default null), the request fails with an authentication failure `4xx`. Note that this value must refer to the consumer `id` or `username` attribute, and **not** its `custom_id`. type: string hide_credentials: description: An optional boolean value telling the plugin to show or hide the credential from the upstream service. If `true`, the plugin will strip the credential from the request (i.e. the header or querystring containing the key) before proxying it. type: boolean default: true run_on_preflight: description: A boolean value that indicates whether the plugin should run (and try to authenticate) on `OPTIONS` preflight requests. If set to `false`, then `OPTIONS` requests will always be allowed. type: boolean default: true secret_token_name: description: Describes an array of comma-separated parameter names where the plugin looks for a secret token. The client must send the secret in one of those key names, and the plugin will try to read the credential from a header or the querystring parameter with the same name. The key names can only contain [a-z], [A-Z], [0-9], [_], and [-]. type: string default: secret_token tokens_in_body: description: If enabled, the plugin will read the request body (if said request has one and its MIME type is supported) and try to find the key in it. Supported MIME types are `application/www-form-urlencoded`, `application/json`, and `multipart/form-data`. type: boolean default: false vault: description: A reference to an existing `vault` object within the database. `vault` entities define the connection and authentication parameters used to connect to a Vault HTTP(S) API. type: object properties: id: type: string x-foreign: true name: const: vault-auth protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string JsonThreatProtectionPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/JsonThreatProtectionPluginConfig' GrpcGatewayPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/GrpcGatewayPluginConfig' PluginWithoutParents: description: A Plugin entity represents a plugin configuration that will be executed during the HTTP request/response lifecycle. It is how you can add functionalities to Services that run behind Kong, like Authentication or Rate Limiting for example. You can find more information about how to install and what values each plugin takes by visiting the [Kong Hub](https://docs.konghq.com/hub/). When adding a Plugin Configuration to a Service, every request made by a client to that Service will run said Plugin. If a Plugin needs to be tuned to different values for some specific Consumers, you can do so by creating a separate plugin instance that specifies both the Service and the Consumer, through the `service` and `consumer` fields. type: object properties: condition: description: An expression used for conditional control over plugin execution. If the expression evaluates to `true` during the request flow, the plugin is executed; otherwise, it is skipped. type: string maxLength: 1024 nullable: true config: description: The configuration properties for the Plugin which can be found on the plugins documentation page in the [Kong Hub](https://docs.konghq.com/hub/). type: object additionalProperties: true nullable: true consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object nullable: true properties: id: type: string x-foreign: true consumer_group: description: If set, the plugin will activate only for requests where the specified group has been authenticated type: object nullable: true properties: id: type: string x-foreign: true created_at: description: Unix epoch when the resource was created. type: integer nullable: true enabled: description: Whether the plugin is applied. type: boolean default: true nullable: true id: description: A string representing a UUID (universally unique identifier). type: string minLength: 1 nullable: true instance_name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true name: description: The name of the Plugin that's going to be added. Currently, the Plugin must be installed in every Kong instance separately. type: string minLength: 1 ordering: type: object nullable: true properties: after: type: object properties: access: type: array items: type: string before: type: object properties: access: type: array items: type: string partials: description: A list of partials to be used by the plugin. type: array items: properties: id: description: A string representing a UUID (universally unique identifier). type: string minLength: 1 name: description: A unique string representing a UTF-8 encoded name. type: string path: type: string type: object nullable: true protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support `"tcp"` and `"tls"`. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string x-speakeasy-unknown-values: allow default: - grpc - grpcs - http - https nullable: true route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the Route being used. type: object nullable: true properties: id: type: string x-foreign: true service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object nullable: true properties: id: type: string x-foreign: true tags: description: An optional set of strings associated with the Plugin for grouping and filtering. type: array items: description: A string representing a tag. type: string nullable: true updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true example: config: anonymous: null hide_credentials: false key_in_body: false key_in_header: true key_in_query: true key_names: - apikey run_on_preflight: true enabled: true id: 3fd1eea1-885a-4011-b986-289943ff8177 name: key-auth partials: - id: cff1230a-00f7-4ae8-b376-c370f0eb4dae name: foo-partial path: config.redis - id: 129ee345-cba8-4e55-9d6d-93c223ff91ae name: bar-partial path: config.redis protocols: - grpc - grpcs - http - https additionalProperties: false required: - name AiAwsGuardrailsPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiAwsGuardrailsPluginConfig' DatakitPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/DatakitPluginConfig' KeyAuthEncPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/KeyAuthEncPluginConfig' ConfluentPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/ConfluentPluginConfig' OpentelemetryPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/OpentelemetryPluginConfig' PaginationNextResponse: description: URI to the next page (may be null) type: string BasicAuthPluginConfig: x-speakeasy-entity: PluginBasicAuth properties: config: type: object properties: anonymous: description: An optional string (Consumer UUID or username) value to use as an “anonymous” consumer if authentication fails. If empty (default null), the request will fail with an authentication failure `4xx`. Please note that this value must refer to the Consumer `id` or `username` attribute, and **not** its `custom_id`. type: string brute_force_protection: type: object properties: redis: description: Redis configuration type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string x-referenceable: true password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true strategy: description: 'The brute force protection strategy to use for retrieving and incrementing the limits. Available values are: `cluster`, `redis`, `memory`, and `off`.' type: string default: 'off' enum: - cluster - memory - 'off' - redis hide_credentials: description: An optional boolean value telling the plugin to show or hide the credential from the upstream service. If `true`, the plugin will strip the credential from the request (i.e. the `Authorization` header) before proxying it. type: boolean default: true realm: description: When authentication fails the plugin sends `WWW-Authenticate` header with `realm` attribute value. type: string default: service name: const: basic-auth protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string OpentelemetryPluginConfig: x-speakeasy-entity: PluginOpentelemetry properties: config: type: object properties: access_logs: type: object properties: custom_attributes_by_lua: description: A key-value map that dynamically modifies access log fields using Lua code. type: object additionalProperties: minLength: 1 type: string endpoint: description: An HTTP URL endpoint where access logs (e.g. request/response, route/service, latency, etc.) are exported. type: string x-referenceable: true batch_flush_delay: description: The delay, in seconds, between two consecutive batches. type: integer batch_span_count: description: The number of spans to be sent in a single batch. type: integer connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 1000 maximum: 2147483646 minimum: 0 header_type: type: string default: preserve enum: - aws - b3 - b3-single - datadog - gcp - ignore - instana - jaeger - ot - preserve - w3c headers: description: The custom headers to be added in the HTTP request sent to the OTLP server. This setting is useful for adding the authentication headers (token) for the APM backend. type: object additionalProperties: type: string http_response_header_for_traceid: type: string logs_endpoint: description: An HTTP URL endpoint where internal logs are exported. type: string x-referenceable: true metrics: type: object properties: enable_ai_metrics: description: A boolean value that determines if AI metrics should be collected. If enabled, `gen_ai.*`, `mcp.*`, `kong.gen_ai.*`, `kong.gen_ai.a2a.*` and `kong.mcp.*` metrics will be exported. To enable latency metrics for AI metrics, `enable_latency_metrics` must also be set to `true`. To enable `error.type` attribute for AI metrics, `enable_request_metrics` must also be set to `true`. type: boolean default: false enable_bandwidth_metrics: description: A boolean value that determines if bandwidth metrics should be collected. If enabled, `http.server.request.size` and `http.server.response.size` metrics will be exported. type: boolean default: false enable_consumer_attribute: description: A boolean value that determines if `http.server.request.count`, `http.server.request.size` and `http.server.response.size` metrics should fill in the consumer attribute when available. type: boolean default: false enable_latency_metrics: description: A boolean value that determines if latency metrics should be collected. If enabled, `kong.latency.total`, `kong.latency.internal` and `kong.latency.upstream` metrics will be exported. type: boolean default: false enable_request_metrics: description: A boolean value that determines if request count metrics should be collected. If enabled, `http.server.request.count` metrics will be exported. type: boolean default: false enable_upstream_health_metrics: description: A boolean value that determines if upstream health metrics should be collected. If enabled, `kong.upstream.target.status` metrics will be exported. type: boolean default: false endpoint: description: An HTTP URL endpoint where metrics are exported. type: string x-referenceable: true push_interval: description: The interval in seconds at which metrics are pushed to the OTLP server. This setting is only applicable when `endpoint` is set. type: number default: 60 propagation: type: object default: default_format: w3c properties: clear: description: Header names to clear after context extraction. This allows to extract the context from a certain header and then remove it from the request, useful when extraction and injection are performed on different header formats and the original header should not be sent to the upstream. If left empty, no headers are cleared. type: array items: type: string default_format: description: 'The default header format to use when extractors did not match any format in the incoming headers and `inject` is configured with the value: `preserve`. This can happen when no tracing header was found in the request, or the incoming tracing header formats were not included in `extract`.' type: string default: w3c enum: - aws - b3 - b3-single - datadog - gcp - instana - jaeger - ot - w3c extract: description: Header formats used to extract tracing context from incoming requests. If multiple values are specified, the first one found will be used for extraction. If left empty, Kong will not extract any tracing context information from incoming requests and generate a trace with no parent and a new trace ID. type: array items: enum: - aws - b3 - datadog - gcp - instana - jaeger - ot - w3c type: string inject: description: Header formats used to inject tracing context. The value `preserve` will use the same header format as the incoming request. If multiple values are specified, all of them will be used during injection. If left empty, Kong will not inject any tracing context information in outgoing requests. type: array items: enum: - aws - b3 - b3-single - datadog - gcp - instana - jaeger - ot - preserve - w3c type: string queue: type: object default: max_batch_size: 200 properties: concurrency_limit: description: The number of of queue delivery timers. -1 indicates unlimited. type: integer default: 1 enum: - -1 - 1 initial_retry_delay: description: Time in seconds before the initial retry is made for a failing batch. type: number default: 0.01 maximum: 1000000 minimum: 0.001 max_batch_size: description: Maximum number of entries that can be processed at a time. type: integer default: 200 maximum: 1000000 minimum: 1 max_bytes: description: Maximum number of bytes that can be waiting on a queue, requires string content. type: integer max_coalescing_delay: description: Maximum number of (fractional) seconds to elapse after the first entry was queued before the queue starts calling the handler. type: number default: 1 maximum: 3600 minimum: 0 max_entries: description: Maximum number of entries that can be waiting on the queue. type: integer default: 10000 maximum: 1000000 minimum: 1 max_retry_delay: description: Maximum time in seconds between retries, caps exponential backoff. type: number default: 60 maximum: 1000000 minimum: 0.001 max_retry_time: description: Time in seconds before the queue gives up calling a failed handler for a batch. type: number default: 60 read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 5000 maximum: 2147483646 minimum: 0 resource_attributes: type: object additionalProperties: type: string x-lua-required: true sampling_rate: description: Tracing sampling rate for configuring the probability-based sampler. When set, this value supersedes the global `tracing_sampling_rate` setting from kong.conf. type: number maximum: 1 minimum: 0 sampling_strategy: description: The sampling strategy to use for OTLP `traces`. Set `parent_drop_probability_fallback` if you want parent-based sampling when the parent span contains a `false` sampled flag, and fallback to probability-based sampling otherwise. Set `parent_probability_fallback` if you want parent-based sampling when the parent span contains a valid sampled flag (`true` or `false`), and fallback to probability-based sampling otherwise. type: string default: parent_drop_probability_fallback enum: - parent_drop_probability_fallback - parent_probability_fallback send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 5000 maximum: 2147483646 minimum: 0 traces_endpoint: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string x-referenceable: true consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: opentelemetry protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string MeteringAndBillingPluginConfig: x-speakeasy-entity: PluginMeteringAndBilling properties: config: type: object properties: api_token: description: Bearer token for authenticating with the ingest endpoint. type: string x-encrypted: true x-referenceable: true attributes: description: Capture custom properties to the usage event data payload for pricing dimensions or reporting. Attributes add dimensions like provider, department or project that your billing model needs for tiered or per-dimension pricing. type: array items: properties: event_property_name: description: The property name in the usage event data payload. type: string look_up_value_in: description: The header name or query parameter that contains the value, e.g 'x-department-id' type: string source: description: Where to find this attribute in the request. type: string enum: - header - query required: - event_property_name - look_up_value_in - source type: object ingest_endpoint: description: The HTTP endpoint where usage events are sent. type: string x-referenceable: true keepalive: description: How long in milliseconds an idle connection to the ingest endpoint is kept open before being closed. type: number default: 60000 meter_ai_token_usage: description: Emit events for LLM input and output tokens on AI Gateway requests. type: boolean default: true meter_api_requests: description: Emit a usage event for each API Gateway request. type: boolean default: true queue: type: object properties: concurrency_limit: description: The number of of queue delivery timers. -1 indicates unlimited. type: integer default: 1 enum: - -1 - 1 initial_retry_delay: description: Time in seconds before the initial retry is made for a failing batch. type: number default: 0.01 maximum: 1000000 minimum: 0.001 max_batch_size: description: Maximum number of entries that can be processed at a time. type: integer default: 1 maximum: 1000000 minimum: 1 max_bytes: description: Maximum number of bytes that can be waiting on a queue, requires string content. type: integer max_coalescing_delay: description: Maximum number of (fractional) seconds to elapse after the first entry was queued before the queue starts calling the handler. type: number default: 1 maximum: 3600 minimum: 0 max_entries: description: Maximum number of entries that can be waiting on the queue. type: integer default: 10000 maximum: 1000000 minimum: 1 max_retry_delay: description: Maximum time in seconds between retries, caps exponential backoff. type: number default: 60 maximum: 1000000 minimum: 0.001 max_retry_time: description: Time in seconds before the queue gives up calling a failed handler for a batch. type: number default: 60 ssl_verify: description: Verify the TLS certificate presented by the ingest endpoint. type: boolean default: true subject: description: The subject identifies who gets billed for each request. Choose where the plugin should look for the customer identifier. type: object properties: field: description: The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id' type: string look_up_value_in: description: Where to find the customer identifier in the request. type: string default: consumer enum: - application - consumer - header - query timeout: description: Maximum time in milliseconds to wait for a response from the ingest endpoint. type: number default: 10000 required: - api_token - ingest_endpoint consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: metering-and-billing protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config ConfluentPluginConfig: x-speakeasy-entity: PluginConfluent properties: config: type: object properties: allowed_topics: description: The list of allowed topic names to which messages can be sent. The default topic configured in the `topic` field is always allowed, regardless of its inclusion in `allowed_topics`. type: array items: type: string bootstrap_servers: description: 'Set of bootstrap brokers in a `{host: host, port: port}` list format.' type: array items: properties: host: description: A string representing a host name, such as example.com. type: string port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 required: - host - port type: object cluster_api_key: description: Username/Apikey for SASL authentication. type: string x-encrypted: true x-referenceable: true cluster_api_secret: description: Password/ApiSecret for SASL authentication. type: string x-encrypted: true x-referenceable: true cluster_name: description: An identifier for the Kafka cluster. By default, this field generates a random string. You can also set your own custom cluster identifier. If more than one Kafka plugin is configured without a `cluster_name` (that is, if the default autogenerated value is removed), these plugins will use the same producer, and by extension, the same cluster. Logs will be sent to the leader of the cluster. type: string confluent_cloud_api_key: description: Apikey for authentication with Confluent Cloud. This allows for management tasks such as creating topics, ACLs, etc. type: string x-encrypted: true x-referenceable: true confluent_cloud_api_secret: description: The corresponding secret for the Confluent Cloud API key. type: string x-encrypted: true x-referenceable: true forward_body: description: 'Include the request body in the message. At least one of these must be true: `forward_method`, `forward_uri`, `forward_headers`, `forward_body`.' type: boolean default: true forward_headers: description: 'Include the request headers in the message. At least one of these must be true: `forward_method`, `forward_uri`, `forward_headers`, `forward_body`.' type: boolean default: false forward_method: description: 'Include the request method in the message. At least one of these must be true: `forward_method`, `forward_uri`, `forward_headers`, `forward_body`.' type: boolean default: false forward_uri: description: 'Include the request URI and URI arguments (as in, query arguments) in the message. At least one of these must be true: `forward_method`, `forward_uri`, `forward_headers`, `forward_body`.' type: boolean default: false keepalive: description: Keepalive timeout in milliseconds. type: integer default: 60000 keepalive_enabled: type: boolean default: false key_query_arg: description: The request query parameter name that contains the Kafka message key. If specified, messages with the same key will be sent to the same Kafka partition, ensuring consistent ordering. type: string message_by_lua_functions: description: The Lua functions that manipulates the message being sent to the Kafka topic. type: array items: type: string producer_async: description: Flag to enable asynchronous mode. type: boolean default: true producer_async_buffering_limits_messages_in_memory: description: Maximum number of messages that can be buffered in memory in asynchronous mode. type: integer default: 50000 producer_async_flush_timeout: description: Maximum time interval in milliseconds between buffer flushes in asynchronous mode. type: integer default: 1000 producer_request_acks: description: 'The number of acknowledgments the producer requires the leader to have received before considering a request complete. Allowed values: 0 for no acknowledgments; 1 for only the leader; and -1 for the full ISR (In-Sync Replica set).' type: integer default: 1 enum: - -1 - 0 - 1 producer_request_limits_bytes_per_request: description: Maximum size of a Produce request in bytes. type: integer default: 1048576 producer_request_limits_messages_per_request: description: Maximum number of messages to include into a single producer request. type: integer default: 200 producer_request_retries_backoff_timeout: description: Backoff interval between retry attempts in milliseconds. type: integer default: 100 producer_request_retries_max_attempts: description: Maximum number of retry attempts per single Produce request. type: integer default: 10 producer_request_timeout: description: Time to wait for a Produce response in milliseconds. type: integer default: 2000 schema_registry: description: The plugin-global schema registry configuration. This can be overwritten by the topic configuration. type: object properties: confluent: type: object properties: authentication: type: object properties: basic: type: object properties: password: type: string x-encrypted: true x-referenceable: true username: type: string x-encrypted: true x-referenceable: true required: - password - username mode: description: Authentication mode to use with the schema registry. type: string default: none enum: - basic - none - oauth2 oauth2: type: object properties: audience: description: List of audiences passed to the IdP when obtaining a new token. type: array items: type: string default: [] client_id: description: The client ID for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true client_secret: description: The client secret for the application registration in the IdP. type: string x-encrypted: true x-referenceable: true grant_type: description: The OAuth grant type to be used. type: string default: client_credentials enum: - client_credentials - password password: description: The password to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true scopes: description: List of scopes to request from the IdP when obtaining a new token. type: array items: type: string default: - openid token_endpoint: description: The token endpoint URI. type: string token_headers: description: Extra headers to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true token_post_args: description: Extra post arguments to be passed in the token endpoint request. type: object additionalProperties: type: string x-referenceable: true username: description: The username to use if `config.oauth.grant_type` is set to `password`. type: string x-encrypted: true x-referenceable: true required: - token_endpoint oauth2_client: type: object properties: auth_method: description: 'The authentication method used in client requests to the IdP. Supported values are: `client_secret_basic` to send `client_id` and `client_secret` in the `Authorization: Basic` header, `client_secret_post` to send `client_id` and `client_secret` as part of the request body, or `client_secret_jwt` to send a JWT signed with the `client_secret` using the client assertion as part of the body.' type: string default: client_secret_post enum: - client_secret_basic - client_secret_jwt - client_secret_post - none client_secret_jwt_alg: description: The algorithm to use with JWT when using `client_secret_jwt` authentication. type: string default: HS512 enum: - HS256 - HS512 http_proxy: description: The proxy to use when making HTTP requests to the IdP. type: string http_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `http_proxy`. type: string http_version: description: 'The HTTP version used for requests made by this plugin. Supported values: `1.1` for HTTP 1.1 and `1.0` for HTTP 1.0.' type: number default: 1.1 https_proxy: description: The proxy to use when making HTTPS requests to the IdP. type: string https_proxy_authorization: description: The `Proxy-Authorization` header value to be used with `https_proxy`. type: string keep_alive: description: Whether to use keepalive connections to the IdP. type: boolean default: true no_proxy: description: A comma-separated list of hosts that should not be proxied. type: string ssl_verify: description: Whether to verify the certificate presented by the IdP when using HTTPS. type: boolean default: true timeout: description: Network I/O timeout for requests to the IdP in milliseconds. type: integer default: 10000 maximum: 2147483646 minimum: 0 key_schema: type: object properties: schema_version: description: The schema version to use for serialization/deserialization. Use 'latest' to always fetch the most recent version. type: string subject_name: description: The name of the subject type: string ssl_verify: description: Set to false to disable SSL certificate verification when connecting to the schema registry. type: boolean default: true ttl: description: The TTL in seconds for the schema registry cache. type: number maximum: 3600 minimum: 0 url: description: The URL of the schema registry. type: string value_schema: type: object properties: schema_version: description: The schema version to use for serialization/deserialization. Use 'latest' to always fetch the most recent version. type: string subject_name: description: The name of the subject type: string security: type: object properties: ssl_verify: description: Enables verification of the certificate presented by the server. type: boolean default: true timeout: description: Socket timeout in milliseconds. type: integer default: 10000 topic: description: The default Kafka topic to publish to if the query parameter defined in the `topics_query_arg` does not exist in the request type: string topics_query_arg: description: The request query parameter name that contains the topics to publish to type: string required: - cluster_api_key - cluster_api_secret - topic consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: confluent protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config FileLogPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/FileLogPluginConfig' GraphqlProxyCacheAdvancedPluginConfig: x-speakeasy-entity: PluginGraphqlProxyCacheAdvanced properties: config: type: object properties: bypass_on_err: description: Unhandled errors while trying to retrieve a cache entry (such as redis down) are resolved with `Bypass`, with the request going upstream. type: boolean default: false cache_ttl: description: TTL in seconds of cache entities. Must be a value greater than 0. type: integer default: 300 memory: type: object properties: dictionary_name: description: The name of the shared dictionary in which to hold cache entities when the memory strategy is selected. This dictionary currently must be defined manually in the Kong Nginx template. type: string default: kong_db_cache redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true strategy: description: The backing data store in which to hold cached entities. Accepted value is `memory`. type: string default: memory enum: - memory - redis vary_headers: description: Relevant headers considered for the cache key. If undefined, none of the headers are taken into consideration. type: array items: type: string consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: graphql-proxy-cache-advanced protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string PluginBase: description: A Plugin entity represents a plugin configuration that will be executed during the HTTP request/response lifecycle. It is how you can add functionalities to Services that run behind Kong, like Authentication or Rate Limiting for example. You can find more information about how to install and what values each plugin takes by visiting the [Kong Hub](https://docs.konghq.com/hub/). When adding a Plugin Configuration to a Service, every request made by a client to that Service will run said Plugin. If a Plugin needs to be tuned to different values for some specific Consumers, you can do so by creating a separate plugin instance that specifies both the Service and the Consumer, through the `service` and `consumer` fields. type: object properties: condition: description: An expression used for conditional control over plugin execution. If the expression evaluates to `true` during the request flow, the plugin is executed; otherwise, it is skipped. type: string maxLength: 1024 nullable: true created_at: description: Unix epoch when the resource was created. type: integer nullable: true enabled: description: Whether the plugin is applied. type: boolean default: true nullable: true id: description: A string representing a UUID (universally unique identifier). type: string minLength: 1 nullable: true instance_name: description: A unique string representing a UTF-8 encoded name. type: string nullable: true name: description: The name of the Plugin that's going to be added. Currently, the Plugin must be installed in every Kong instance separately. type: string minLength: 1 ordering: type: object nullable: true properties: after: type: object properties: access: type: array items: type: string before: type: object properties: access: type: array items: type: string partials: description: A list of partials to be used by the plugin. type: array items: properties: id: description: A string representing a UUID (universally unique identifier). type: string minLength: 1 name: description: A unique string representing a UTF-8 encoded name. type: string path: type: string type: object tags: description: An optional set of strings associated with the Plugin for grouping and filtering. type: array items: description: A string representing a tag. type: string nullable: true updated_at: description: Unix epoch when the resource was last updated. type: integer nullable: true additionalProperties: false required: - name OpenidConnectPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/OpenidConnectPluginConfig' AppDynamicsPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AppDynamicsPluginConfig' RequestTerminationPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/RequestTerminationPluginConfig' GraphqlRateLimitingAdvancedPluginConfig: x-speakeasy-entity: PluginGraphqlRateLimitingAdvanced properties: config: type: object properties: cost_strategy: description: Strategy to use to evaluate query costs. Either `default` or `node_quantifier`. type: string default: default enum: - default - node_quantifier dictionary_name: description: The shared dictionary where counters will be stored until the next sync cycle. type: string default: kong_rate_limiting_counters hide_client_headers: description: 'Optionally hide informative response headers. Available options: `true` or `false`.' type: boolean default: false identifier: description: How to define the rate limit key. Can be `ip`, `credential`, `consumer`. type: string default: consumer enum: - consumer - credential - ip limit: description: One or more requests-per-window limits to apply. type: array items: type: number max_cost: description: A defined maximum cost per query. 0 means unlimited. type: number default: 0 namespace: description: 'The rate limiting namespace to use for this plugin instance. This namespace is used to share rate limiting counters across different instances. If it is not provided, a random UUID is generated. NOTE: For the plugin instances sharing the same namespace, all the configurations that are required for synchronizing counters, e.g. `strategy`, `redis`, `sync_rate`, `window_size`, `dictionary_name`, need to be the same.' type: string pass_all_downstream_headers: description: pass all downstream headers to the upstream graphql server in introspection request type: boolean default: false redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true score_factor: description: A scoring factor to multiply (or divide) the cost. The `score_factor` must always be greater than 0. type: number default: 1 strategy: description: The rate-limiting strategy to use for retrieving and incrementing the limits. type: string default: cluster enum: - cluster - redis sync_rate: description: How often to sync counter data to the central data store. A value of 0 results in synchronous behavior; a value of -1 ignores sync behavior entirely and only stores counters in node memory. A value greater than 0 syncs the counters in that many number of seconds. type: number window_size: description: One or more window sizes to apply a limit to (defined in seconds). type: array items: type: number window_type: description: Sets the time window to either `sliding` or `fixed`. type: string default: sliding enum: - fixed - sliding required: - limit - sync_rate - window_size consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: graphql-rate-limiting-advanced protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config AiProxyAdvancedPluginConfig: x-speakeasy-entity: PluginAiProxyAdvanced properties: config: type: object properties: acls: description: Optional ACL rules. Deny rules take precedence over allow rules. type: object properties: allow: description: Requests matching any allow rule are permitted unless also matched by a deny rule. type: array items: description: ACL rule composed of one or more match conditions. properties: match: description: All conditions must match for the rule to apply (logical AND). type: array items: description: Single match condition (e.g. user or model value). properties: key: description: 'Helper key used by some types: consumer (id|username), consumer_group (id|name), header (header name).' type: string type: description: The attribute to match against. type: string enum: - consumer - consumer_group - header - ip - model - path - provider values: description: Allowed values for the selected type. type: array items: type: string minLength: 1 required: - type - values type: object minLength: 1 required: - match type: object minLength: 1 deny: description: Requests matching any deny rule are blocked. Deny rules take precedence over allow rules. type: array items: description: ACL rule composed of one or more match conditions. properties: match: description: All conditions must match for the rule to apply (logical AND). type: array items: description: Single match condition (e.g. user or model value). properties: key: description: 'Helper key used by some types: consumer (id|username), consumer_group (id|name), header (header name).' type: string type: description: The attribute to match against. type: string enum: - consumer - consumer_group - header - ip - model - path - provider values: description: Allowed values for the selected type. type: array items: type: string minLength: 1 required: - type - values type: object minLength: 1 required: - match type: object minLength: 1 balancer: type: object properties: algorithm: description: Which load balancing algorithm to use. type: string default: round-robin enum: - consistent-hashing - least-connections - lowest-latency - lowest-usage - priority - round-robin - semantic connect_timeout: type: integer default: 60000 maximum: 2147483646 minimum: 1 fail_timeout: description: The period of time (in milliseconds) the target will be considered unavailable after the number of unsuccessful attempts reaches `max_fails`. type: integer default: 10000 maximum: 2147483646 minimum: 1 failover_criteria: description: Specifies in which cases an upstream response should be failover to the next target. Each option in the array is equivalent to the function of http://nginx.org/en/docs/http/ngx_http_proxy_module.html#proxy_next_upstream type: array items: enum: - error - http_403 - http_404 - http_429 - http_500 - http_502 - http_503 - http_504 - invalid_header - non_idempotent - timeout type: string default: - error - timeout hash_on_header: description: The header to use for consistent-hashing. type: string default: X-Kong-LLM-Request-ID latency_strategy: description: 'What metrics to use for latency. Available values are: `tpot` (time-per-output-token) and `e2e`.' type: string default: tpot enum: - e2e - tpot max_fails: description: Number of unsuccessful attempts to communicate with a target that should occur in the duration defined by `fail_timeout` before the target is considered unavailable. The zero value disables the circuit breaker. What is considered an unsuccessful attempt is defined by `failover_criteria`. Note the cases of `error`, `timeout` and `invalid_header` are always considered unsuccessful attempts, while the cases of `http_403` and `http_404` are never considered unsuccessful attempts. type: integer default: 0 maximum: 32767 minimum: 0 read_timeout: type: integer default: 60000 maximum: 2147483646 minimum: 1 retries: description: The number of retries to execute upon failure to proxy. type: integer default: 5 maximum: 32767 minimum: 0 slots: description: The number of slots in the load balancer algorithm. type: integer default: 10000 maximum: 65536 minimum: 10 tokens_count_strategy: description: 'What tokens to use for usage calculation. Available values are: `total_tokens` `prompt_tokens`, `completion_tokens` and `cost`.' type: string default: total-tokens enum: - completion-tokens - cost - llm-accuracy - prompt-tokens - total-tokens write_timeout: type: integer default: 60000 maximum: 2147483646 minimum: 1 embeddings: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true model: type: object properties: name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: azure: type: object properties: api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' deployment_id: description: Deployment ID for Azure OpenAI instances. type: string instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean upstream_url: description: upstream url for the embeddings type: string provider: description: AI provider format to use for embeddings API type: string enum: - azure - bedrock - gemini - huggingface - mistral - ollama - openai required: - name - provider required: - model genai_category: description: Generative AI category of the request type: string default: text/generation enum: - audio/speech - audio/transcription - image/generation - realtime/generation - text/embeddings - text/generation - video/generation llm_format: description: LLM input and output format and schema to use type: string default: openai enum: - anthropic - bedrock - cohere - gemini - huggingface - openai max_request_body_size: description: max allowed body size allowed to be introspected. 0 means unlimited, but the size of this body will still be limited by Nginx's client_max_body_size. type: integer default: 1048576 model_name_header: description: Display the model name selected in the X-Kong-LLM-Model response header type: boolean default: true response_streaming: description: Whether to 'optionally allow', 'deny', or 'always' (force) the streaming of answers via server sent events. type: string default: allow enum: - allow - always - deny targets: type: array items: properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true description: description: The semantic description of the target, required if using semantic load balancing. Specially, setting this to 'CATCHALL' will indicate such target to be used when no other targets match the semantic threshold. Only used by ai-proxy-advanced. type: string logging: type: object properties: log_payloads: description: If enabled, will log the request and response body into the Kong log plugin(s) output.Furthermore if Opentelemetry instrumentation is enabled the traces will contain this data as well. type: boolean default: false log_statistics: description: If enabled and supported by the driver, will add model usage and token metrics into the Kong log plugin(s) output. type: boolean default: false metadata: description: 'For internal use only. ' type: object additionalProperties: true nullable: true x-speakeasy-type-override: any model: type: object properties: model_alias: description: The model name parameter from the request that this model should map to. type: string name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: anthropic_version: description: Defines the schema/API version, if using Anthropic provider. type: string azure_api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' azure_deployment_id: description: Deployment ID for Azure OpenAI instances. type: string azure_instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string cohere: type: object properties: embedding_input_type: description: The purpose of the input text to calculate embedding vectors. type: string default: classification enum: - classification - clustering - image - search_document - search_query wait_for_model: description: Wait for the model if it is not ready type: boolean dashscope: type: object properties: international: description: 'Two Dashscope endpoints are available, and the international endpoint will be used when this is set to `true`. It is recommended to set this to `true` when using international version of dashscope. ' type: boolean default: true databricks: type: object properties: workspace_instance_id: description: Workspace Instance ID ('dbc-xxx-yyy') for Databricks model serving. type: string embeddings_dimensions: description: If using embeddings models, set the number of dimensions to generate. type: integer gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string endpoint_id: description: If running Gemini on Vertex Model Garden, specify the endpoint ID. type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean input_cost: description: Defines the cost per 1M tokens in your prompt. type: number llama2_format: description: If using llama2 provider, select the upstream message format. type: string enum: - ollama - openai - raw max_tokens: description: Defines the max_tokens, if using chat or completion models. type: integer mistral_format: description: If using mistral provider, select the upstream message format. type: string enum: - ollama - openai output_cost: description: Defines the cost per 1M tokens in the output of the AI. type: number temperature: description: Defines the matching temperature, if using chat or completion models. type: number maximum: 5 minimum: 0 top_k: description: Defines the top-k most likely tokens, if supported. type: integer maximum: 500 minimum: 0 top_p: description: Defines the top-p probability mass, if supported. type: number maximum: 1 minimum: 0 upstream_path: description: Manually specify or override the AI operation path, used when e.g. using the 'preserve' route_type. type: string upstream_url: description: Manually specify or override the full URL to the AI operation endpoints, when calling (self-)hosted models, or for running via a private endpoint. type: string provider: description: AI provider request format - Kong translates requests to and from the specified backend compatible formats. type: string enum: - anthropic - azure - bedrock - cerebras - cohere - dashscope - databricks - deepseek - gemini - huggingface - llama2 - mistral - ollama - openai - vllm - xai required: - provider route_type: description: 'The model''s operation implementation, for this provider. ' type: string enum: - audio/v1/audio/speech - audio/v1/audio/transcriptions - audio/v1/audio/translations - image/v1/images/edits - image/v1/images/generations - llm/v1/assistants - llm/v1/batches - llm/v1/chat - llm/v1/completions - llm/v1/embeddings - llm/v1/files - llm/v1/responses - preserve - realtime/v1/realtime - video/v1/videos/generations weight: description: The weight this target gets within the upstream loadbalancer (1-65535). Only used by ai-proxy-advanced. type: integer default: 100 maximum: 65535 minimum: 1 required: - model - route_type type: object vectordb: type: object properties: dimensions: description: the desired dimensionality for the vectors type: integer distance_metric: description: the distance metric to use for vector searches type: string enum: - cosine - euclidean pgvector: type: object properties: database: description: the database of the pgvector database type: string default: kong-pgvector host: description: the host of the pgvector database type: string default: 127.0.0.1 password: description: the password of the pgvector database type: string x-encrypted: true x-referenceable: true port: description: the port of the pgvector database type: integer default: 5432 ssl: description: whether to use ssl for the pgvector database type: boolean default: false ssl_cert: description: the path of ssl cert to use for the pgvector database type: string ssl_cert_key: description: the path of ssl cert key to use for the pgvector database type: string ssl_required: description: whether ssl is required for the pgvector database type: boolean default: false ssl_verify: description: whether to verify ssl for the pgvector database type: boolean default: true ssl_version: description: the ssl version to use for the pgvector database type: string default: tlsv1_2 enum: - any - tlsv1_2 - tlsv1_3 timeout: description: the timeout of the pgvector database type: number default: 5000 user: description: the user of the pgvector database type: string default: postgres x-referenceable: true redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true strategy: description: which vector database driver to use type: string enum: - pgvector - redis threshold: description: the default similarity threshold for accepting semantic search results (float). Higher threshold means more results are considered similar. type: number required: - dimensions - distance_metric - strategy required: - targets consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-proxy-advanced protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config AiProxyAdvancedPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiProxyAdvancedPluginConfig' SolaceLogPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/SolaceLogPluginConfig' OpenidConnectPluginConfig: x-speakeasy-entity: PluginOpenidConnect properties: config: type: object properties: anonymous: description: An optional string (consumer UUID or username) value that functions as an “anonymous” consumer if authentication fails. If empty (default null), requests that fail authentication will return a `4xx` HTTP status code. This value must refer to the consumer `id` or `username` attribute, and **not** its `custom_id`. type: string audience: description: The audience passed to the authorization endpoint. type: array items: type: string audience_claim: description: The claim that contains the audience. If multiple values are set, it means the claim is inside a nested object of the token payload. type: array items: type: string default: - aud audience_required: description: The audiences (`audience_claim` claim) required to be present in the access token (or introspection results) for successful authorization. This config parameter works in both **AND** / **OR** cases. type: array items: type: string auth_methods: description: Types of credentials/grants to enable. type: array items: enum: - authorization_code - bearer - client_credentials - introspection - kong_oauth2 - password - refresh_token - session - userinfo type: string default: - authorization_code - bearer - client_credentials - introspection - kong_oauth2 - password - refresh_token - session - userinfo authenticated_groups_claim: description: The claim that contains authenticated groups. This setting can be used together with ACL plugin, but it also enables IdP managed groups with other applications and integrations. If multiple values are set, it means the claim is inside a nested object of the token payload. type: array items: type: string authorization_cookie_domain: description: The authorization cookie Domain flag. type: string authorization_cookie_http_only: description: Forbids JavaScript from accessing the cookie, for example, through the `Document.cookie` property. type: boolean default: true authorization_cookie_name: description: The authorization cookie name. type: string default: authorization authorization_cookie_path: description: The authorization cookie Path flag. type: string default: / authorization_cookie_same_site: description: Controls whether a cookie is sent with cross-origin requests, providing some protection against cross-site request forgery attacks. type: string default: Default enum: - Default - Lax - None - Strict authorization_cookie_secure: description: 'Cookie is only sent to the server when a request is made with the https: scheme (except on localhost), and therefore is more resistant to man-in-the-middle attacks.' type: boolean authorization_endpoint: description: The authorization endpoint. If set it overrides the value in `authorization_endpoint` returned by the discovery endpoint. type: string authorization_query_args_client: description: Extra query arguments passed from the client to the authorization endpoint. type: array items: type: string authorization_query_args_names: description: Extra query argument names passed to the authorization endpoint. type: array items: type: string authorization_query_args_values: description: Extra query argument values passed to the authorization endpoint. type: array items: type: string authorization_rolling_timeout: description: Specifies how long the session used for the authorization code flow can be used in seconds until it needs to be renewed. 0 disables the checks and rolling. type: number default: 600 bearer_token_cookie_name: description: The name of the cookie in which the bearer token is passed. type: string bearer_token_param_type: description: 'Where to look for the bearer token: - `header`: search the `Authorization`, `access-token`, and `x-access-token` HTTP headers - `query`: search the URL''s query string - `body`: search the HTTP request body - `cookie`: search the HTTP request cookies specified with `config.bearer_token_cookie_name`.' type: array items: enum: - body - cookie - header - query type: string default: - body - header - query by_username_ignore_case: description: If `consumer_by` is set to `username`, specify whether `username` can match consumers case-insensitively. type: boolean default: false cache_introspection: description: Cache the introspection endpoint requests. type: boolean default: true cache_token_exchange: description: Cache the legacy token exchange endpoint requests. type: boolean default: true cache_tokens: description: Cache the token endpoint requests. type: boolean default: true cache_tokens_salt: description: Salt used for generating the cache key that is used for caching the token endpoint requests. type: string cache_ttl: description: The default cache ttl in seconds that is used in case the cached object does not specify the expiry. type: number default: 3600 cache_ttl_max: description: The maximum cache ttl in seconds (enforced). type: number cache_ttl_min: description: The minimum cache ttl in seconds (enforced). type: number cache_ttl_neg: description: The negative cache ttl in seconds. type: number cache_ttl_resurrect: description: The resurrection ttl in seconds. type: number cache_user_info: description: Cache the user info requests. type: boolean default: true claims_forbidden: description: If given, these claims are forbidden in the token payload. type: array items: type: string client_alg: description: The algorithm to use for client_secret_jwt (only HS***) or private_key_jwt authentication. type: array items: enum: - ES256 - ES384 - ES512 - EdDSA - HS256 - HS384 - HS512 - PS256 - PS384 - PS512 - RS256 - RS384 - RS512 type: string client_arg: description: The client to use for this request (the selection is made with a request parameter with the same name). type: string default: client_id client_auth: description: 'The default OpenID Connect client authentication method is ''client_secret_basic'' (using ''Authorization: Basic'' header), ''client_secret_post'' (credentials in body), ''client_secret_jwt'' (signed client assertion in body), ''private_key_jwt'' (private key-signed assertion), ''tls_client_auth'' (client certificate), ''self_signed_tls_client_auth'' (self-signed client certificate), and ''none'' (no authentication).' type: array items: enum: - client_secret_basic - client_secret_jwt - client_secret_post - none - private_key_jwt - self_signed_tls_client_auth - tls_client_auth type: string client_credentials_param_type: description: 'Where to look for the client credentials: - `header`: search the HTTP headers - `query`: search the URL''s query string - `body`: search from the HTTP request body.' type: array items: enum: - body - header - query type: string default: - body - header - query client_id: description: The client id(s) that the plugin uses when it calls authenticated endpoints on the identity provider. type: array items: type: string x-referenceable: true x-encrypted: true client_jwk: description: The JWK used for the private_key_jwt authentication. type: array items: properties: alg: type: string crv: type: string d: type: string x-encrypted: true x-referenceable: true dp: type: string x-encrypted: true x-referenceable: true dq: type: string x-encrypted: true x-referenceable: true e: type: string issuer: type: string k: type: string x-encrypted: true x-referenceable: true key_ops: type: array items: type: string kid: type: string kty: type: string n: type: string oth: type: string x-encrypted: true x-referenceable: true p: type: string x-encrypted: true x-referenceable: true q: type: string x-encrypted: true x-referenceable: true qi: type: string x-encrypted: true x-referenceable: true r: type: string x-encrypted: true x-referenceable: true t: type: string x-encrypted: true x-referenceable: true use: type: string x: type: string x5c: type: array items: type: string x5t: type: string x5t#S256: type: string x5u: type: string y: type: string type: object client_secret: description: The client secret. type: array items: type: string x-referenceable: true x-encrypted: true cluster_cache_redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true cluster_cache_strategy: description: The strategy to use for the cluster cache. If set, the plugin will share cache with nodes configured with the same strategy backend. Currentlly only introspection cache is shared. type: string default: 'off' enum: - 'off' - redis consumer_by: description: 'Consumer fields used for mapping: - `id`: try to find the matching Consumer by `id` - `username`: try to find the matching Consumer by `username` - `custom_id`: try to find the matching Consumer by `custom_id`.' type: array items: enum: - custom_id - id - username type: string default: - custom_id - username consumer_claims: description: The claims used for consumer mapping. Each entry represents a claim path inside the token payload. The paths are evaluated in order, and the first matching claim is used. type: array items: description: A path of strings representing the location of the claim in a nested object. For example, to map to `user.info.id`, set `[ "user", "info", "id" ]`. items: type: string type: array consumer_groups_claim: description: The claim used for consumer groups mapping. If multiple values are set, it means the claim is inside a nested object of the token payload. type: array items: type: string consumer_groups_optional: description: Do not terminate the request if consumer groups mapping fails. type: boolean default: false consumer_optional: description: Do not terminate the request if consumer mapping fails. type: boolean default: false credential_claim: description: The claim used to derive virtual credentials (e.g. to be consumed by the rate-limiting plugin), in case the consumer mapping is not used. If multiple values are set, it means the claim is inside a nested object of the token payload. type: array items: type: string default: - sub disable_session: description: Disable issuing the session cookie with the specified grants. type: array items: enum: - authorization_code - bearer - client_credentials - introspection - kong_oauth2 - password - refresh_token - session - userinfo type: string discovery_headers_names: description: Extra header names passed to the discovery endpoint. type: array items: type: string discovery_headers_values: description: Extra header values passed to the discovery endpoint. type: array items: type: string display_errors: description: Display errors on failure responses. type: boolean default: false domains: description: The allowed values for the `hd` claim. type: array items: type: string downstream_access_token_header: description: The downstream access token header. type: string downstream_access_token_jwk_header: description: The downstream access token JWK header. type: string downstream_headers: description: The downstream claim to header mappings. type: array items: properties: header: description: The name of the header. type: string path: description: The path of the header value. type: array items: type: string minLength: 1 required: - header - path type: object downstream_headers_claims: description: The downstream header claims. Only top level claims are supported. type: array items: type: string downstream_headers_names: description: The downstream header names for the claim values. type: array items: type: string downstream_id_token_header: description: The downstream id token header. type: string downstream_id_token_jwk_header: description: The downstream id token JWK header. type: string downstream_introspection_header: description: The downstream introspection header. type: string downstream_introspection_jwt_header: description: The downstream introspection JWT header. type: string downstream_refresh_token_header: description: The downstream refresh token header. type: string downstream_session_id_header: description: The downstream session id header. type: string downstream_user_info_header: description: The downstream user info header. type: string downstream_user_info_jwt_header: description: The downstream user info JWT header (in case the user info returns a JWT response). type: string dpop_proof_lifetime: description: Specifies the lifetime in seconds of the DPoP proof. It determines how long the same proof can be used after creation. The creation time is determined by the nonce creation time if a nonce is used, and the iat claim otherwise. type: number default: 300 dpop_use_nonce: description: Specifies whether to challenge the client with a nonce value for DPoP proof. When enabled it will also be used to calculate the DPoP proof lifetime. type: boolean default: false enable_hs_signatures: description: Enable shared secret, for example, HS256, signatures (when disabled they will not be accepted). type: boolean default: false end_session_endpoint: description: The end session endpoint. If set it overrides the value in `end_session_endpoint` returned by the discovery endpoint. type: string expose_error_code: description: Specifies whether to expose the error code header, as defined in RFC 6750. If an authorization request fails, this header is sent in the response. Set to `false` to disable. type: boolean default: true extra_jwks_uris: description: JWKS URIs whose public keys are trusted (in addition to the keys found with the discovery). type: array items: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string x-referenceable: true forbidden_destroy_session: description: Destroy any active session for the forbidden requests. type: boolean default: true forbidden_error_message: description: The error message for the forbidden requests (when not using the redirection). type: string default: Forbidden forbidden_redirect_uri: description: Where to redirect the client on forbidden requests. type: array items: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string groups_claim: description: The claim that contains the groups. If multiple values are set, it means the claim is inside a nested object of the token payload. type: array items: type: string default: - groups groups_required: description: The groups (`groups_claim` claim) required to be present in the access token (or introspection results) for successful authorization. This config parameter works in both **AND** / **OR** cases. type: array items: type: string hide_credentials: description: Remove the credentials used for authentication from the request. If multiple credentials are sent with the same request, the plugin will remove those that were used for successful authentication. type: boolean default: true http_proxy: description: The HTTP proxy. type: string http_proxy_authorization: description: The HTTP proxy authorization. type: string x-referenceable: true http_version: description: 'The HTTP version used for the requests by this plugin: - `1.1`: HTTP 1.1 (the default) - `1.0`: HTTP 1.0.' type: number default: 1.1 https_proxy: description: The HTTPS proxy. type: string https_proxy_authorization: description: The HTTPS proxy authorization. type: string x-referenceable: true id_token_param_name: description: The name of the parameter used to pass the id token. type: string id_token_param_type: description: 'Where to look for the id token: - `header`: search the HTTP headers - `query`: search the URL''s query string - `body`: search the HTTP request body.' type: array items: enum: - body - header - query type: string default: - body - header - query ignore_signature: description: 'Skip the token signature verification on certain grants: - `password`: OAuth password grant - `client_credentials`: OAuth client credentials grant - `authorization_code`: authorization code flow - `refresh_token`: OAuth refresh token grant - `session`: session cookie authentication - `introspection`: OAuth introspection - `userinfo`: OpenID Connect user info endpoint authentication.' type: array items: enum: - authorization_code - client_credentials - introspection - password - refresh_token - session - userinfo type: string default: [] introspect_jwt_tokens: description: Specifies whether to introspect the JWT access tokens (can be used to check for revocations). type: boolean default: false introspection_accept: description: 'The value of `Accept` header for introspection requests: - `application/json`: introspection response as JSON - `application/token-introspection+jwt`: introspection response as JWT (from the current IETF draft document) - `application/jwt`: introspection response as JWT (from the obsolete IETF draft document).' type: string default: application/json enum: - application/json - application/jwt - application/token-introspection+jwt introspection_check_active: description: Check that the introspection response has an `active` claim with a value of `true`. type: boolean default: true introspection_endpoint: description: The introspection endpoint. If set it overrides the value in `introspection_endpoint` returned by the discovery endpoint. type: string x-referenceable: true introspection_endpoint_auth_method: description: 'The introspection endpoint authentication method: : `client_secret_basic`, `client_secret_post`, `client_secret_jwt`, `private_key_jwt`, `tls_client_auth`, `self_signed_tls_client_auth`, or `none`: do not authenticate' type: string enum: - client_secret_basic - client_secret_jwt - client_secret_post - none - private_key_jwt - self_signed_tls_client_auth - tls_client_auth introspection_headers_client: description: Extra headers passed from the client to the introspection endpoint. type: array items: type: string introspection_headers_names: description: Extra header names passed to the introspection endpoint. type: array items: type: string introspection_headers_values: description: Extra header values passed to the introspection endpoint. type: array items: type: string x-referenceable: true x-encrypted: true introspection_hint: description: Introspection hint parameter value passed to the introspection endpoint. type: string default: access_token introspection_post_args_client: description: Extra post arguments passed from the client to the introspection endpoint. type: array items: type: string introspection_post_args_client_headers: description: Extra post arguments passed from the client headers to the introspection endpoint. type: array items: type: string introspection_post_args_names: description: Extra post argument names passed to the introspection endpoint. type: array items: type: string introspection_post_args_values: description: Extra post argument values passed to the introspection endpoint. type: array items: type: string introspection_token_param_name: description: Designate token's parameter name for introspection. type: string default: token issuer: description: The discovery endpoint (or the issuer identifier). When there is no discovery endpoint, please also configure `config.using_pseudo_issuer=true`. type: string x-referenceable: true issuers_allowed: description: The issuers allowed to be present in the tokens (`iss` claim). type: array items: type: string x-referenceable: true jwks_endpoint: description: Overrides the `jwks_uri` returned by discovery. Use when the IdP exposes a non-standard JWKS endpoint. type: string jwt_session_claim: description: The claim to match against the JWT session cookie. type: string default: sid jwt_session_cookie: description: The name of the JWT session cookie. type: string keepalive: description: Use keepalive with the HTTP client. type: boolean default: true leeway: description: Defines leeway time (in seconds) for `auth_time`, `exp`, `iat`, and `nbf` claims type: number default: 0 login_action: description: 'What to do after successful login: - `upstream`: proxy request to upstream service - `response`: terminate request with a response - `redirect`: redirect to a different location.' type: string default: upstream enum: - redirect - response - upstream login_methods: description: Enable login functionality with specified grants. type: array items: enum: - authorization_code - bearer - client_credentials - introspection - kong_oauth2 - password - refresh_token - session - userinfo type: string default: - authorization_code login_redirect_mode: description: 'Where to place `login_tokens` when using `redirect` `login_action`: - `query`: place tokens in query string - `fragment`: place tokens in url fragment (not readable by servers).' type: string default: fragment enum: - fragment - query login_redirect_uri: description: Where to redirect the client when `login_action` is set to `redirect`. type: array items: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string x-referenceable: true login_tokens: description: 'What tokens to include in `response` body or `redirect` query string or fragment: - `id_token`: include id token - `access_token`: include access token - `refresh_token`: include refresh token - `tokens`: include the full token endpoint response - `introspection`: include introspection response.' type: array items: enum: - access_token - id_token - introspection - refresh_token - tokens type: string default: - id_token logout_methods: description: 'The request methods that can activate the logout: - `POST`: HTTP POST method - `GET`: HTTP GET method - `DELETE`: HTTP DELETE method.' type: array items: enum: - DELETE - GET - POST type: string default: - DELETE - POST logout_post_arg: description: The request body argument that activates the logout. type: string logout_query_arg: description: The request query argument that activates the logout. type: string logout_redirect_uri: description: Where to redirect the client after the logout. type: array items: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string x-referenceable: true logout_revoke: description: 'Revoke tokens as part of the logout. For more granular token revocation, you can also adjust the `logout_revoke_access_token` and `logout_revoke_refresh_token` parameters.' type: boolean default: false logout_revoke_access_token: description: Revoke the access token as part of the logout. Requires `logout_revoke` to be set to `true`. type: boolean default: true logout_revoke_refresh_token: description: Revoke the refresh token as part of the logout. Requires `logout_revoke` to be set to `true`. type: boolean default: true logout_uri_suffix: description: The request URI suffix that activates the logout. type: string max_age: description: The maximum age (in seconds) compared to the `auth_time` claim. type: number mtls_introspection_endpoint: description: Alias for the introspection endpoint to be used for mTLS client authentication. If set it overrides the value in `mtls_endpoint_aliases` returned by the discovery endpoint. type: string mtls_revocation_endpoint: description: Alias for the introspection endpoint to be used for mTLS client authentication. If set it overrides the value in `mtls_endpoint_aliases` returned by the discovery endpoint. type: string mtls_token_endpoint: description: Alias for the token endpoint to be used for mTLS client authentication. If set it overrides the value in `mtls_endpoint_aliases` returned by the discovery endpoint. type: string no_proxy: description: Do not use proxy with these hosts. type: string password_param_type: description: 'Where to look for the username and password: - `header`: search the HTTP headers - `query`: search the URL''s query string - `body`: search the HTTP request body.' type: array items: enum: - body - header - query type: string default: - body - header - query preserve_query_args: description: With this parameter, you can preserve request query arguments even when doing authorization code flow. type: boolean default: false proof_of_possession_auth_methods_validation: description: If set to true, only the auth_methods that are compatible with Proof of Possession (PoP) can be configured when PoP is enabled. If set to false, all auth_methods will be configurable and PoP checks will be silently skipped for those auth_methods that are not compatible with PoP. type: boolean default: true proof_of_possession_dpop: description: Enable Demonstrating Proof-of-Possession (DPoP). If set to strict, all request are verified despite the presence of the DPoP key claim (cnf.jkt). If set to optional, only tokens bound with DPoP's key are verified with the proof. type: string default: 'off' enum: - 'off' - optional - strict proof_of_possession_mtls: description: 'Enable mtls proof of possession. If set to strict, all tokens (from supported auth_methods: bearer, introspection, and session granted with bearer or introspection) are verified, if set to optional, only tokens that contain the certificate hash claim are verified. If the verification fails, the request will be rejected with 401.' type: string default: 'off' enum: - 'off' - optional - strict pushed_authorization_request_endpoint: description: The pushed authorization endpoint. If set it overrides the value in `pushed_authorization_request_endpoint` returned by the discovery endpoint. type: string pushed_authorization_request_endpoint_auth_method: description: 'The pushed authorization request endpoint authentication method: `client_secret_basic`, `client_secret_post`, `client_secret_jwt`, `private_key_jwt`, `tls_client_auth`, `self_signed_tls_client_auth`, or `none`: do not authenticate' type: string enum: - client_secret_basic - client_secret_jwt - client_secret_post - none - private_key_jwt - self_signed_tls_client_auth - tls_client_auth redirect_uri: description: The redirect URI passed to the authorization and token endpoints. type: array items: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true prefix: description: The Redis session key prefix. type: string read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true socket: description: The Redis unix socket path. type: string ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true rediscovery_lifetime: description: Specifies how long (in seconds) the plugin waits between discovery attempts. Discovery is still triggered on an as-needed basis. type: number default: 30 refresh_token_param_name: description: The name of the parameter used to pass the refresh token. type: string refresh_token_param_type: description: 'Where to look for the refresh token: - `header`: search the HTTP headers - `query`: search the URL''s query string - `body`: search the HTTP request body.' type: array items: enum: - body - header - query type: string default: - body - header - query refresh_tokens: description: Specifies whether the plugin should try to refresh (soon to be) expired access tokens if the plugin has a `refresh_token` available. type: boolean default: true require_proof_key_for_code_exchange: description: Forcibly enable or disable the proof key for code exchange. When not set the value is determined through the discovery using the value of `code_challenge_methods_supported`, and enabled automatically (in case the `code_challenge_methods_supported` is missing, the PKCE will not be enabled). type: boolean require_pushed_authorization_requests: description: Forcibly enable or disable the pushed authorization requests. When not set the value is determined through the discovery using the value of `require_pushed_authorization_requests` (which defaults to `false`). type: boolean require_signed_request_object: description: Forcibly enable or disable the usage of signed request object on authorization or pushed authorization endpoint. When not set the value is determined through the discovery using the value of `require_signed_request_object`, and enabled automatically (in case the `require_signed_request_object` is missing, the feature will not be enabled). type: boolean resolve_distributed_claims: description: Distributed claims are represented by the `_claim_names` and `_claim_sources` members of the JSON object containing the claims. If this parameter is set to `true`, the plugin explicitly resolves these distributed claims. type: boolean default: false response_mode: description: 'Response mode passed to the authorization endpoint: - `query`: for parameters in query string - `form_post`: for parameters in request body - `fragment`: for parameters in uri fragment (rarely useful as the plugin itself cannot read it) - `query.jwt`, `form_post.jwt`, `fragment.jwt`: similar to `query`, `form_post` and `fragment` but the parameters are encoded in a JWT - `jwt`: shortcut that indicates the default encoding for the requested response type.' type: string default: query enum: - form_post - form_post.jwt - fragment - fragment.jwt - jwt - query - query.jwt response_type: description: The response type passed to the authorization endpoint. type: array items: type: string default: - code reverify: description: Specifies whether to always verify tokens stored in the session. type: boolean default: false revocation_endpoint: description: The revocation endpoint. If set it overrides the value in `revocation_endpoint` returned by the discovery endpoint. type: string revocation_endpoint_auth_method: description: 'The revocation endpoint authentication method: : `client_secret_basic`, `client_secret_post`, `client_secret_jwt`, `private_key_jwt`, `tls_client_auth`, `self_signed_tls_client_auth`, or `none`: do not authenticate' type: string enum: - client_secret_basic - client_secret_jwt - client_secret_post - none - private_key_jwt - self_signed_tls_client_auth - tls_client_auth revocation_token_param_name: description: Designate token's parameter name for revocation. type: string default: token roles_claim: description: The claim that contains the roles. If multiple values are set, it means the claim is inside a nested object of the token payload. type: array items: type: string default: - roles roles_required: description: The roles (`roles_claim` claim) required to be present in the access token (or introspection results) for successful authorization. This config parameter works in both **AND** / **OR** cases. type: array items: type: string run_on_preflight: description: Specifies whether to run this plugin on pre-flight (`OPTIONS`) requests. type: boolean default: true scopes: description: The scopes passed to the authorization and token endpoints. type: array items: type: string x-referenceable: true default: - openid scopes_claim: description: The claim that contains the scopes. If multiple values are set, it means the claim is inside a nested object of the token payload. type: array items: type: string default: - scope scopes_required: description: The scopes (`scopes_claim` claim) required to be present in the access token (or introspection results) for successful authorization. This config parameter works in both **AND** / **OR** cases. type: array items: type: string search_user_info: description: Specify whether to use the user info endpoint to get additional claims for consumer mapping, credential mapping, authenticated groups, and upstream and downstream headers. type: boolean default: false session_absolute_timeout: description: Limits how long the session can be renewed in seconds, until re-authentication is required. 0 disables the checks. type: number default: 86400 session_audience: description: The session audience, which is the intended target application. For example `"my-application"`. type: string default: default session_bind: description: Bind the session to data acquired from the HTTP request or connection. type: array items: enum: - ip - scheme - user-agent type: string session_cookie_domain: description: The session cookie Domain flag. type: string session_cookie_http_only: description: Forbids JavaScript from accessing the cookie, for example, through the `Document.cookie` property. type: boolean default: true session_cookie_name: description: The session cookie name. type: string default: session session_cookie_path: description: The session cookie Path flag. type: string default: / session_cookie_same_site: description: Controls whether a cookie is sent with cross-origin requests, providing some protection against cross-site request forgery attacks. type: string default: Lax enum: - Default - Lax - None - Strict session_cookie_secure: description: 'Cookie is only sent to the server when a request is made with the https: scheme (except on localhost), and therefore is more resistant to man-in-the-middle attacks.' type: boolean session_enforce_same_subject: description: When set to `true`, audiences are forced to share the same subject. type: boolean default: false session_hash_storage_key: description: When set to `true`, the storage key (session ID) is hashed for extra security. Hashing the storage key means it is impossible to decrypt data from the storage without a cookie. type: boolean default: false session_hash_subject: description: When set to `true`, the value of subject is hashed before being stored. Only applies when `session_store_metadata` is enabled. type: boolean default: false session_idling_timeout: description: Specifies how long the session can be inactive until it is considered invalid in seconds. 0 disables the checks and touching. type: number default: 900 session_memcached_host: description: The memcached host. type: string default: 127.0.0.1 session_memcached_port: description: The memcached port. type: integer default: 11211 maximum: 65535 minimum: 0 session_memcached_prefix: description: The memcached session key prefix. type: string session_memcached_socket: description: The memcached unix socket path. type: string session_memcached_ssl: description: If set to true, uses SSL to connect to memcached type: boolean session_memcached_ssl_verify: description: If set to true, verifies the validity of the memcached server SSL certificate type: boolean default: true session_remember: description: Enables or disables persistent sessions. type: boolean default: false session_remember_absolute_timeout: description: Limits how long the persistent session can be renewed in seconds, until re-authentication is required. 0 disables the checks. type: number default: 2592000 session_remember_cookie_name: description: Persistent session cookie name. Use with the `remember` configuration parameter. type: string default: remember session_remember_rolling_timeout: description: Specifies how long the persistent session is considered valid in seconds. 0 disables the checks and rolling. type: number default: 604800 session_request_headers: description: Set of headers to send to upstream, use id, audience, subject, timeout, idling-timeout, rolling-timeout, absolute-timeout. E.g. `[ "id", "timeout" ]` will set Session-Id and Session-Timeout request headers. type: array items: enum: - absolute-timeout - audience - id - idling-timeout - rolling-timeout - subject - timeout type: string session_response_headers: description: Set of headers to send to downstream, use id, audience, subject, timeout, idling-timeout, rolling-timeout, absolute-timeout. E.g. `[ "id", "timeout" ]` will set Session-Id and Session-Timeout response headers. type: array items: enum: - absolute-timeout - audience - id - idling-timeout - rolling-timeout - subject - timeout type: string session_rolling_timeout: description: Specifies how long the session can be used in seconds until it needs to be renewed. 0 disables the checks and rolling. type: number default: 3600 session_secret: description: The session secret. type: string x-encrypted: true x-referenceable: true session_storage: description: 'The session storage for session data: - `cookie`: stores session data with the session cookie (the session cannot be invalidated or revoked without changing session secret, but is stateless, and doesn''t require a database) - `memcache`: stores session data in memcached - `redis`: stores session data in Redis.' type: string default: cookie enum: - cookie - memcache - memcached - redis session_store_metadata: description: Configures whether or not session metadata should be stored. This metadata includes information about the active sessions for a specific audience belonging to a specific subject. type: boolean default: false ssl_verify: description: Verify identity provider server certificate. If set to `true`, the plugin uses the CA certificate set in the `kong.conf` config parameter `lua_ssl_trusted_certificate`. type: boolean default: true timeout: description: Network IO timeout in milliseconds. type: number default: 10000 tls_client_auth_cert_id: description: ID of the Certificate entity representing the client certificate to use for mTLS client authentication for connections between Kong and the Auth Server. type: string tls_client_auth_ssl_verify: description: Verify identity provider server certificate during mTLS client authentication. type: boolean default: true token_cache_key_include_scope: description: Include the scope in the token cache key, so token with different scopes are considered diffrent tokens. type: boolean default: false token_endpoint: description: The token endpoint. If set it overrides the value in `token_endpoint` returned by the discovery endpoint. type: string token_endpoint_auth_method: description: 'The token endpoint authentication method: `client_secret_basic`, `client_secret_post`, `client_secret_jwt`, `private_key_jwt`, `tls_client_auth`, `self_signed_tls_client_auth`, or `none`: do not authenticate' type: string enum: - client_secret_basic - client_secret_jwt - client_secret_post - none - private_key_jwt - self_signed_tls_client_auth - tls_client_auth token_exchange: description: Details on how to accept tokens from other identity providers. type: object properties: cache: description: Cache support for token exchange type: object properties: enabled: description: Whether to enable caching. type: boolean default: true ttl: description: Cache ttl in seconds used when caching exchanged tokens, use it to override `conf.cache_ttl`. Token expiry will be used if shorter than this value. type: integer request: description: Parameters used in the token exchange request. type: object properties: audience: description: Audiences used in the token exchange request. Values defined here override those defined in `config.audience`. type: array items: type: string empty_audience: description: Use empty audiences. Use this field to override audiences defined in `config.audience`. type: boolean default: false empty_scopes: description: Use empty scopes. Use this field to override scopes defined in `config.scopes`. type: boolean default: false scopes: description: Scopes used in the token exchange request. Values defined here override those defined in `config.scopes`. type: array items: type: string subject_token_issuers: description: Trusted token issuers from which the upstream may accept tokens to be exchanged. If a JWT bearer matches all the conditions of a subject token issuer item, the token will be exchanged. type: array items: properties: conditions: description: A tokens will only be exchange when it matches all these criteria. To exchanging tokens issued from a different issuer, conditions must not be defined; On the contrary, to exchange tokens issued from the target issuer itself, conditions must be defined. type: object properties: has_audience: type: array items: type: string has_scopes: type: array items: type: string missing_audience: type: array items: type: string missing_scopes: type: array items: type: string issuer: description: Tokens of whose iss claim matches this value will be exchanged. type: string required: - issuer type: object minLength: 1 required: - subject_token_issuers token_exchange_endpoint: description: Endpoint used to perform the legacy token exchange. type: string token_headers_client: description: Extra headers passed from the client to the token endpoint. type: array items: type: string token_headers_grants: description: 'Enable the sending of the token endpoint response headers only with certain grants: - `password`: with OAuth password grant - `client_credentials`: with OAuth client credentials grant - `authorization_code`: with authorization code flow - `refresh_token` with refresh token grant.' type: array items: enum: - authorization_code - client_credentials - password - refresh_token type: string token_headers_names: description: Extra header names passed to the token endpoint. type: array items: type: string token_headers_prefix: description: Add a prefix to the token endpoint response headers before forwarding them to the downstream client. type: string token_headers_replay: description: The names of token endpoint response headers to forward to the downstream client. type: array items: type: string token_headers_values: description: Extra header values passed to the token endpoint. type: array items: type: string token_post_args_client: description: 'Pass extra arguments from the client to the OpenID-Connect plugin. If arguments exist, the client can pass them using: - Query parameters - Request Body - Request Header This parameter can be used with `scope` values, like this: `config.token_post_args_client=scope` In this case, the token would take the `scope` value from the query parameter or from the request body or from the header and send it to the token endpoint.' type: array items: type: string token_post_args_names: description: Extra post argument names passed to the token endpoint. type: array items: type: string token_post_args_values: description: Extra post argument values passed to the token endpoint. type: array items: type: string unauthorized_destroy_session: description: Destroy any active session for the unauthorized requests. type: boolean default: true unauthorized_error_message: description: The error message for the unauthorized requests (when not using the redirection). type: string default: Unauthorized unauthorized_redirect_uri: description: Where to redirect the client on unauthorized requests. type: array items: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string unexpected_redirect_uri: description: Where to redirect the client when unexpected errors happen with the requests. type: array items: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string upstream_access_token_header: description: The upstream access token header. type: string default: authorization:bearer upstream_access_token_jwk_header: description: The upstream access token JWK header. type: string upstream_headers: description: The upstream claim to header mappings. type: array items: properties: header: description: The name of the header. type: string path: description: The path of the header value. type: array items: type: string minLength: 1 required: - header - path type: object upstream_headers_claims: description: The upstream header claims. Only top level claims are supported. type: array items: type: string upstream_headers_names: description: The upstream header names for the claim values. type: array items: type: string upstream_id_token_header: description: The upstream id token header. type: string upstream_id_token_jwk_header: description: The upstream id token JWK header. type: string upstream_introspection_header: description: The upstream introspection header. type: string upstream_introspection_jwt_header: description: The upstream introspection JWT header. type: string upstream_refresh_token_header: description: The upstream refresh token header. type: string upstream_session_id_header: description: The upstream session id header. type: string upstream_user_info_header: description: The upstream user info header. type: string upstream_user_info_jwt_header: description: The upstream user info JWT header (in case the user info returns a JWT response). type: string userinfo_accept: description: 'The value of `Accept` header for user info requests: - `application/json`: user info response as JSON - `application/jwt`: user info response as JWT (from the obsolete IETF draft document).' type: string default: application/json enum: - application/json - application/jwt userinfo_endpoint: description: The user info endpoint. If set it overrides the value in `userinfo_endpoint` returned by the discovery endpoint. type: string userinfo_headers_client: description: Extra headers passed from the client to the user info endpoint. type: array items: type: string userinfo_headers_names: description: Extra header names passed to the user info endpoint. type: array items: type: string userinfo_headers_values: description: Extra header values passed to the user info endpoint. type: array items: type: string userinfo_query_args_client: description: Extra query arguments passed from the client to the user info endpoint. type: array items: type: string userinfo_query_args_names: description: Extra query argument names passed to the user info endpoint. type: array items: type: string userinfo_query_args_values: description: Extra query argument values passed to the user info endpoint. type: array items: type: string using_pseudo_issuer: description: If the plugin uses a pseudo issuer. When set to true, the plugin will not discover the configuration from the issuer URL specified with `config.issuer`. type: boolean default: false verify_claims: description: Verify tokens for standard claims. type: boolean default: true verify_nonce: description: Verify nonce on authorization code flow. type: boolean default: true verify_parameters: description: Verify plugin configuration against discovery. type: boolean default: false verify_signature: description: Verify signature of tokens. type: boolean default: true required: - issuer name: const: openid-connect protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config CorsPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/CorsPluginConfig' AcmePluginConfig: x-speakeasy-entity: PluginAcme properties: config: type: object properties: account_email: description: The account identifier. Can be reused in a different plugin instance. type: string x-encrypted: true x-referenceable: true account_key: description: The private key associated with the account. type: object properties: key_id: description: The Key ID. type: string x-encrypted: true key_set: description: The name of the key set to associate the Key ID with. type: string x-encrypted: true required: - key_id allow_any_domain: description: If set to `true`, the plugin allows all domains and ignores any values in the `domains` list. type: boolean default: false api_uri: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string default: https://acme-v02.api.letsencrypt.org/directory cert_type: description: The certificate type to create. The possible values are `rsa` for RSA certificate or `ecc` for EC certificate. type: string default: rsa enum: - ecc - rsa domains: description: An array of strings representing hosts. A valid host is a string containing one or more labels separated by periods, with at most one wildcard label ('*') type: array items: type: string eab_hmac_key: description: External account binding (EAB) base64-encoded URL string of the HMAC key. You usually don't need to set this unless it is explicitly required by the CA. type: string x-encrypted: true x-referenceable: true eab_kid: description: External account binding (EAB) key id. You usually don't need to set this unless it is explicitly required by the CA. type: string x-encrypted: true x-referenceable: true enable_ipv4_common_name: description: A boolean value that controls whether to include the IPv4 address in the common name field of generated certificates. type: boolean default: true fail_backoff_minutes: description: 'Minutes to wait for each domain that fails to create a certificate. This applies to both a new certificate and a renewal certificate.' type: number default: 5 preferred_chain: description: A string value that specifies the preferred certificate chain to use when generating certificates. type: string renew_threshold_days: description: Days remaining to renew the certificate before it expires. type: number default: 14 rsa_key_size: description: RSA private key size for the certificate. The possible values are 2048, 3072, or 4096. type: integer default: 4096 enum: - 2048 - 3072 - 4096 storage: description: The backend storage type to use. In DB-less mode and Konnect, `kong` storage is unavailable. In hybrid mode and Konnect, `shm` storage is unavailable. `shm` storage does not persist during Kong restarts and does not work for Kong running on different machines, so consider using one of `kong`, `redis`, `consul`, or `vault` in production. type: string default: shm enum: - consul - kong - redis - shm - vault storage_config: type: object properties: consul: type: object properties: host: description: A string representing a host name, such as example.com. type: string https: description: Boolean representation of https. type: boolean default: false kv_path: description: KV prefix path. type: string port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 timeout: description: Timeout in milliseconds. type: number token: description: Consul ACL token. type: string x-encrypted: true x-referenceable: true kong: type: object additionalProperties: true redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 extra_options: description: Custom ACME Redis options type: object properties: namespace: description: A namespace to prepend to all keys stored in Redis. type: string default: '' scan_count: description: The number of keys to return in Redis SCAN calls. type: number default: 10 host: description: A string representing a host name, such as example.com. type: string x-referenceable: true password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true shm: type: object properties: shm_name: description: Name of shared memory zone used for Kong API gateway storage type: string default: kong vault: type: object properties: auth_method: description: Auth Method, default to token, can be 'token' or 'kubernetes'. type: string default: token enum: - kubernetes - token auth_path: description: Vault's authentication path to use. type: string auth_role: description: The role to try and assign. type: string host: description: A string representing a host name, such as example.com. type: string https: description: Boolean representation of https. type: boolean default: false jwt_path: description: The path to the JWT. type: string kv_path: description: KV prefix path. type: string port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 timeout: description: Timeout in milliseconds. type: number tls_server_name: description: SNI used in request, default to host if omitted. type: string tls_verify: description: Turn on TLS verification. type: boolean default: true token: description: Consul ACL token. type: string x-encrypted: true x-referenceable: true tos_accepted: description: If you are using Let's Encrypt, you must set this to `true` to agree the terms of service. type: boolean default: false required: - account_email name: const: acme protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https required: - config AiA2aProxyPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiA2aProxyPluginConfig' AwsLambdaPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AwsLambdaPluginConfig' PaginationOffsetResponse: description: Offset is used to paginate through the API. Provide this value to the next list operation to fetch the next page type: string AiRateLimitingAdvancedPluginConfig: x-speakeasy-entity: PluginAiRateLimitingAdvanced properties: config: type: object properties: custom_cost_count_function: description: If defined, it uses custom function to generate cost for the inference request type: string decrease_by_fractions_in_redis: description: By default, Kong decreates the AI rate limiting counters by whole number in Redis. This setting allows to decrease the counters by float number. type: boolean default: false dictionary_name: description: The shared dictionary where counters are stored. When the plugin is configured to synchronize counter data externally (that is `config.strategy` is `cluster` or `redis` and `config.sync_rate` isn't `-1`), this dictionary serves as a buffer to populate counters in the data store on each synchronization cycle. The dictionary must be defined in the nginx configuration using `lua_shared_dict` directive (e.g., `lua_shared_dict kong_rate_limiting_counters 12m`). type: string default: kong_rate_limiting_counters disable_penalty: description: If set to `true`, this doesn't count denied requests (status = `429`). If set to `false`, all requests, including denied ones, are counted. This parameter only affects the `sliding` window_type and the request prompt provider. type: boolean default: false error_code: description: Set a custom error code to return when the rate limit is exceeded. type: number default: 429 error_hide_providers: description: Optionally hide informative response that would otherwise provide information about the provider in the error message. type: boolean default: false error_message: description: Set a custom error message to return when the rate limit is exceeded. type: string default: 'AI token rate limit exceeded for provider(s): ' header_name: description: A string representing an HTTP header name. type: string hide_client_headers: description: Optionally hide informative response headers that would otherwise provide information about the current status of limits and counters. type: boolean default: false identifier: description: The type of identifier used to generate the rate limit key. Defines the scope used to increment the rate limiting counters. Can be `ip`, `credential`, `consumer`, `service`, `header`, `path` or `consumer-group`. Note if `identifier` is `consumer-group`, the plugin must be applied on a consumer group entity. Because a consumer may belong to multiple consumer groups, the plugin needs to know explicitly which consumer group to limit the rate. type: string default: consumer enum: - consumer - consumer-group - credential - header - ip - path - service llm_format: description: LLM input and output format and schema to use type: string enum: - anthropic - bedrock - cohere - gemini - huggingface - openai llm_providers: description: The provider config. Takes an array of `name`, `limit` and `window size` values. Mutually exclusive with `policies`. type: array items: properties: limit: description: One or more requests-per-window limits to apply. There must be a matching number of window limits and sizes specified. type: array items: type: number name: description: The LLM provider to which the rate limit applies. type: string enum: - anthropic - azure - bedrock - cohere - customCost - gemini - huggingface - llama2 - mistral - openai - requestPrompt window_size: description: One or more window sizes to apply a limit to (defined in seconds). There must be a matching number of window limits and sizes specified. type: array items: type: number required: - limit - name - window_size type: object namespace: description: 'The rate limiting library namespace to use for this plugin instance. Counter data and sync configuration is isolated in each namespace. NOTE: For the plugin instances sharing the same namespace, all the configurations that are required for synchronizing counters, e.g. `strategy`, `redis`, `sync_rate`, `dictionary_name`, need to be the same.' type: string path: description: A string representing a URL path, such as /path/to/resource. Must start with a forward slash (/) and must not contain empty segments (i.e., two consecutive forward slashes). type: string policies: description: Policy-based rate limiting. Each policy defines match conditions and limits. Mutually exclusive with `llm_providers`. type: array items: properties: id: description: UUID reference to a reusable ai_rate_limiting_policies DAO entity. Mutually exclusive with inline limits. type: string limits: description: Rate limits to enforce when this policy matches. type: array items: properties: limit: description: The rate limit threshold for this window. type: number tokens_count_strategy: description: 'What to count for this limit. Supported strategies: total_tokens, prompt_tokens, completion_tokens, cost.' type: string default: total_tokens enum: - completion_tokens - cost - prompt_tokens - total_tokens window_size: description: The window size in seconds. type: integer required: - limit - window_size type: object minLength: 1 match: description: Array of match conditions (AND logic). If omitted, this policy acts as a fallback for unmatched requests. type: array items: properties: key: description: Sub-key for consumer (id|username|custom_id), consumer_group (id|name), or header (header name). type: string partition_by: description: If true, the matched value contributes to the composite rate limit counter key. type: boolean default: false type: description: The attribute to match against. type: string enum: - consumer - consumer_group - header - ip - model - path - provider values: description: Values to match. If omitted, matches any value of this type. type: array items: type: string required: - type type: object window_type: description: The time window type for this policy. type: string default: sliding enum: - fixed - sliding type: object redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true request_prompt_count_function: description: If defined, it use custom function to count requests for the request prompt provider type: string retry_after_jitter_max: description: The upper bound of a jitter (random delay) in seconds to be added to the `Retry-After` header of denied requests (status = `429`) in order to prevent all the clients from coming back at the same time. The lower bound of the jitter is `0`; in this case, the `Retry-After` header is equal to the `RateLimit-Reset` header. type: number default: 0 strategy: description: 'The rate-limiting strategy to use for retrieving and incrementing the limits. Available values are: `local`, `redis` and `cluster`.' type: string default: local enum: - cluster - local - redis sync_rate: description: How often to sync counter data to the central data store. A value of 0 results in synchronous behavior; a value of -1 ignores sync behavior entirely and only stores counters in node memory. A value greater than 0 will sync the counters in the specified number of seconds. The minimum allowed interval is 0.02 seconds (20ms). type: number tokens_count_strategy: description: 'What tokens to use for cost calculation. Available values are: `total_tokens` `prompt_tokens`, `completion_tokens` or `cost`.' type: string default: total_tokens enum: - completion_tokens - cost - prompt_tokens - total_tokens window_type: description: Sets the time window type to either `sliding` (default) or `fixed`. Sliding windows apply the rate limiting logic while taking into account previous hit rates (from the window that immediately precedes the current) using a dynamic weight. Fixed windows consist of buckets that are statically assigned to a definitive time range, each request is mapped to only one fixed window based on its timestamp and will affect only that window's counters. type: string default: sliding enum: - fixed - sliding consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-rate-limiting-advanced protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AcePluginConfig: x-speakeasy-entity: PluginAce properties: config: type: object properties: anonymous: description: An optional string (consumer UUID or username) value to use as an `anonymous` consumer if authentication fails. If empty (default null), the request will fail with an authentication failure `4xx`. When set, the plugin will skip ACE processing for requests that are already authenticated by other plugins with higher priority. type: string match_policy: description: Determines how the ACE plugin will behave when a request doesn't match an existing operation from an API or API package in Dev Portal. The `required` setting requires every incoming request to match a defined operation. If a request doesn't match, ACE rejects the request outright with a 404. The `if_present` setting makes the ACE plugin only engage with a request when it matches an operation, allowing a request to still be processed by other plugins with a lower priority than ACE. type: string default: if_present enum: - if_present - required rate_limiting: type: object properties: redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true sync_rate: description: How often to sync counter data to the central data store. A value of 0 results in synchronous behavior (counter synchronization happens in each request's context and contributes directly to the latency of the request). A value greater than 0 results in asynchronous behavior and specifies the interval (in seconds) for synchronizing counters. The minimum allowed interval is 0.02 seconds (20ms). If omitted, the plugin ignores sync behavior entirely and only stores counters in node memory. type: number maximum: 3600 minimum: 0 name: const: ace protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string UdpLogPluginConfig: x-speakeasy-entity: PluginUdpLog properties: config: type: object properties: custom_fields_by_lua: description: Lua code as a key-value map type: object additionalProperties: type: string host: description: A string representing a host name, such as example.com. type: string port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 timeout: description: An optional timeout in milliseconds when sending data to the upstream server. type: number default: 10000 required: - host - port consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: udp-log protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config AiResponseTransformerPluginConfig: x-speakeasy-entity: PluginAiResponseTransformer properties: config: type: object properties: http_proxy_host: description: A string representing a host name, such as example.com. type: string http_proxy_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 http_timeout: description: Timeout in milliseconds for the AI upstream service. type: integer default: 60000 https_proxy_host: description: A string representing a host name, such as example.com. type: string https_proxy_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 https_verify: description: Verify the TLS certificate of the AI upstream service. type: boolean default: true llm: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true description: description: The semantic description of the target, required if using semantic load balancing. Specially, setting this to 'CATCHALL' will indicate such target to be used when no other targets match the semantic threshold. Only used by ai-proxy-advanced. type: string logging: type: object properties: log_payloads: description: If enabled, will log the request and response body into the Kong log plugin(s) output.Furthermore if Opentelemetry instrumentation is enabled the traces will contain this data as well. type: boolean default: false log_statistics: description: If enabled and supported by the driver, will add model usage and token metrics into the Kong log plugin(s) output. type: boolean default: false metadata: description: 'For internal use only. ' type: object additionalProperties: true nullable: true x-speakeasy-type-override: any model: type: object properties: model_alias: description: The model name parameter from the request that this model should map to. type: string name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: anthropic_version: description: Defines the schema/API version, if using Anthropic provider. type: string azure_api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' azure_deployment_id: description: Deployment ID for Azure OpenAI instances. type: string azure_instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string cohere: type: object properties: embedding_input_type: description: The purpose of the input text to calculate embedding vectors. type: string default: classification enum: - classification - clustering - image - search_document - search_query wait_for_model: description: Wait for the model if it is not ready type: boolean dashscope: type: object properties: international: description: 'Two Dashscope endpoints are available, and the international endpoint will be used when this is set to `true`. It is recommended to set this to `true` when using international version of dashscope. ' type: boolean default: true databricks: type: object properties: workspace_instance_id: description: Workspace Instance ID ('dbc-xxx-yyy') for Databricks model serving. type: string embeddings_dimensions: description: If using embeddings models, set the number of dimensions to generate. type: integer gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string endpoint_id: description: If running Gemini on Vertex Model Garden, specify the endpoint ID. type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean input_cost: description: Defines the cost per 1M tokens in your prompt. type: number llama2_format: description: If using llama2 provider, select the upstream message format. type: string enum: - ollama - openai - raw max_tokens: description: Defines the max_tokens, if using chat or completion models. type: integer mistral_format: description: If using mistral provider, select the upstream message format. type: string enum: - ollama - openai output_cost: description: Defines the cost per 1M tokens in the output of the AI. type: number temperature: description: Defines the matching temperature, if using chat or completion models. type: number maximum: 5 minimum: 0 top_k: description: Defines the top-k most likely tokens, if supported. type: integer maximum: 500 minimum: 0 top_p: description: Defines the top-p probability mass, if supported. type: number maximum: 1 minimum: 0 upstream_path: description: Manually specify or override the AI operation path, used when e.g. using the 'preserve' route_type. type: string upstream_url: description: Manually specify or override the full URL to the AI operation endpoints, when calling (self-)hosted models, or for running via a private endpoint. type: string provider: description: AI provider request format - Kong translates requests to and from the specified backend compatible formats. type: string enum: - anthropic - azure - bedrock - cerebras - cohere - dashscope - databricks - deepseek - gemini - huggingface - llama2 - mistral - ollama - openai - vllm - xai required: - provider route_type: description: 'The model''s operation implementation, for this provider. ' type: string enum: - audio/v1/audio/speech - audio/v1/audio/transcriptions - audio/v1/audio/translations - image/v1/images/edits - image/v1/images/generations - llm/v1/assistants - llm/v1/batches - llm/v1/chat - llm/v1/completions - llm/v1/embeddings - llm/v1/files - llm/v1/responses - preserve - realtime/v1/realtime - video/v1/videos/generations weight: description: The weight this target gets within the upstream loadbalancer (1-65535). Only used by ai-proxy-advanced. type: integer default: 100 maximum: 65535 minimum: 1 required: - model - route_type max_request_body_size: description: max allowed body size allowed to be introspected. 0 means unlimited, but the size of this body will still be limited by Nginx's client_max_body_size. type: integer default: 1048576 parse_llm_response_json_instructions: description: Set true to read specific response format from the LLM, and accordingly set the status code / body / headers that proxy back to the client. You need to engineer your LLM prompt to return the correct format, see plugin docs 'Overview' page for usage instructions. type: boolean default: false prompt: description: Use this prompt to tune the LLM system/assistant message for the returning proxy response (from the upstream), adn what response format you are expecting. type: string transformation_extract_pattern: description: Defines the regular expression that must match to indicate a successful AI transformation at the response phase. The first match will be set as the returning body. If the AI service's response doesn't match this pattern, a failure is returned to the client. type: string required: - llm - prompt consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-response-transformer protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config UpstreamTimeoutPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/UpstreamTimeoutPluginConfig' AiSemanticPromptGuardPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiSemanticPromptGuardPluginConfig' KafkaLogPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/KafkaLogPluginConfig' StandardWebhooksPluginConfig: x-speakeasy-entity: PluginStandardWebhooks properties: config: type: object properties: secret_v1: description: Webhook secret type: string x-encrypted: true x-referenceable: true tolerance_second: description: Tolerance of the webhook timestamp in seconds. If the webhook timestamp is older than this number of seconds, it will be rejected with a '400' response. type: integer default: 300 required: - secret_v1 consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: standard-webhooks protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config TcpLogPluginConfig: x-speakeasy-entity: PluginTcpLog properties: config: type: object properties: custom_fields_by_lua: description: A list of key-value pairs, where the key is the name of a log field and the value is a chunk of Lua code, whose return value sets or replaces the log field value. type: object additionalProperties: type: string host: description: The IP address or host name to send data to. type: string keepalive: description: An optional value in milliseconds that defines how long an idle connection lives before being closed. type: number default: 60000 port: description: The port to send data to on the upstream server. type: integer maximum: 65535 minimum: 0 ssl_verify: description: When using TLS, this option enables verification of the certificate presented by the server. type: boolean default: true timeout: description: An optional timeout in milliseconds when sending data to the upstream server. type: number default: 10000 tls: description: Indicates whether to perform a TLS handshake against the remote server. type: boolean default: false tls_sni: description: An optional string that defines the SNI (Server Name Indication) hostname to send in the TLS handshake. type: string required: - host - port consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: tcp-log protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config RequestTransformerPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/RequestTransformerPluginConfig' ACLPluginConfig: x-speakeasy-entity: PluginACL properties: config: type: object properties: allow: description: Arbitrary group names that are allowed to consume the service or route. One of `config.allow` or `config.deny` must be specified. type: array items: type: string always_use_authenticated_groups: description: If enabled (`true`), the authenticated groups will always be used even when an authenticated consumer already exists. If the authenticated groups don't exist, it will fallback to use the groups associated with the consumer. By default the authenticated groups will only be used when there is no consumer or the consumer is anonymous. type: boolean default: false deny: description: Arbitrary group names that are not allowed to consume the service or route. One of `config.allow` or `config.deny` must be specified. type: array items: type: string hide_groups_header: description: If enabled (`true`), prevents the `X-Consumer-Groups` header from being sent in the request to the upstream service. type: boolean default: false include_consumer_groups: description: If enabled (`true`), allows the consumer-groups to be used in the `allow|deny` fields type: boolean default: false name: const: acl protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string VaultAuthPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/VaultAuthPluginConfig' SolaceConsumePlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/SolaceConsumePluginConfig' AiMcpProxyPluginConfig: x-speakeasy-entity: PluginAiMcpProxy properties: config: type: object properties: access_token_claim_field: description: 'The claim in the OAuth2 access token to use as the subject for ACL evaluation when ''acl_attribute_type'' is set to ''oauth_access_token''. Nested claim can be fetched by using a jq filter starts with dot, e.g., ".user.email": https://jqlang.org/manual/#object-identifier-index.' type: string minLength: 1 acl_attribute_type: description: The type of attributes that ACL is evaluated with. Should only be configured on listener modes, not conversion-only. type: string default: consumer enum: - consumer - oauth_access_token consumer_identifier: description: Which subject type entries in ACL lists refer to for per-consumer matching. Should only be configured on listener modes, not conversion-only. type: string default: username enum: - consumer_id - custom_id - username default_acl: description: 'Optional list of default ACL rules keyed by scope (for example: tools).' type: array items: description: Default ACL entry for the given scope. `deny` has higher precedence than `allow`. properties: allow: description: Subjects (e.g. Consumer name, Consumer Groups, or Claim values depending on configuration) explicitly allowed to access this scope. type: array items: type: string deny: description: Subjects (e.g. Consumer name, Consumer Groups, or Claim values depending on configuration) explicitly denied from this scope. `deny` takes precedence over `allow`. type: array items: type: string scope: description: 'Scope for this default ACL entry (for example: ''tools''). Defaults to ''tools''.' type: string default: tools type: object include_consumer_groups: description: If enabled (true), allows Consumer Group names to be used in default and per-primitive ACL. Should only be configured on listener modes, not conversion-only. type: boolean default: false logging: type: object properties: log_audits: description: If true, emit audit logs for ACL evaluations. type: boolean default: false log_payloads: description: If enabled, will log the request and response body into the Kong log plugin(s) output. type: boolean default: false log_statistics: description: If enabled, will add mcp metrics into the Kong log plugin(s) output. type: boolean default: false max_request_body_size: description: max allowed body size allowed to be handled as MCP request. 0 means unlimited, but the size of this body will still be limited by Nginx's client_max_body_size. type: integer default: 1048576 mode: description: 'The mode of the MCP proxy. Possible values are: ''passthrough-listener'', ''conversion-listener'', ''conversion-only'', ''listener''.' type: string enum: - conversion-listener - conversion-only - listener - passthrough-listener server: type: object properties: forward_client_headers: description: Whether to forward the client request headers to the upstream server when calling the tools. type: boolean default: true session: description: Enable managed session when Kong responds as MCP server in listener or conversion-listener modes. This doesn't affect the passthrough-listener mode as the state in that mode is maintained by the upstream MCP servers. type: object properties: client: description: The configuration for client-side session storage. type: object properties: secrets: description: The secrets that are used in session encryption. Required when the strategy is 'client'. The first secret is used for encryption, while all secrets are used for decryption to support key rotation. type: array items: minLength: 8 type: string x-encrypted: true x-referenceable: true minLength: 1 managed: description: If enabled, Kong will maintain managed sessions with the MCP server. type: boolean default: true redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true session_ttl: description: The time-to-live (TTL) for each session in seconds. type: number default: 86400 strategy: description: The strategy for the session. If the value is 'client', the session is encrypted into MCP session id assigned to the client. If the value is not 'client', the session is stored in the configured database. type: string enum: - client - redis tag: description: 'The tag of the MCP server. This is used to filter the exported MCP tools. The field should contain exactly one tag. ' type: string timeout: description: The timeout for calling the tools in milliseconds. type: number default: 10000 tools: type: array items: properties: acl: description: Optional per-primitive ACL. `deny` has higher precedence than `allow`. type: object properties: allow: description: Subjects (e.g. Consumer name, Consumer Groups, or Claim values depending on configuration) explicitly allowed to use this primitive. type: array items: type: string deny: description: Subjects (e.g. Consumer name, Consumer Groups, or Claim values depending on configuration) explicitly denied from using this primitive. `deny` takes precedence over `allow`. type: array items: type: string annotations: type: object properties: destructive_hint: description: If true, the tool may perform destructive updates type: boolean idempotent_hint: description: If true, repeated calls with same args have no additional effect type: boolean open_world_hint: description: If true, tool interacts with external entities type: boolean read_only_hint: description: If true, the tool does not modify its environment type: boolean title: description: Human-readable title for the tool type: string description: description: The description of the MCP tool. This is used to provide information about the tool's functionality and usage. type: string headers: description: The headers of the exported API. By default, Kong will extract the headers from API configuration. If the configured headers are not exactly matched, this field is required. type: object additionalProperties: items: type: string type: array host: description: The host of the exported API, which must match the route's hosts. It should be the route's host. By default, Kong will extract the host from API configuration. If the configured host is wildcard, this field is required. type: string method: description: The method of the exported API, which must be one of the route's method. By default, Kong will extract the method from API configuration. If the configured method is not exactly matched, this field is required. type: string enum: - DELETE - GET - PATCH - POST - PUT name: description: Tool identifier. In passthrough-listener mode, used to match remote MCP Server tools for ACL enforcement. In other modes, it is also used as the tool name (overrides tools.annotations.title if present). type: string parameters: description: 'The API parameters specification defined in OpenAPI JSON format. For example, ''[{"name": "city", "in": "query", "description": "Name of the city to get the weather for", "required": true, "schema": {"type": "string"}}]''.See https://swagger.io/docs/specification/v3_0/describing-parameters/ for more details.' items: additionalProperties: true type: object x-speakeasy-type-override: any nullable: true type: array path: description: The path of the exported API, which must match the route's paths. Path not starting with '/' are treated as relative path and the route path will be added as the prefix. If the upstream path is different from the route one, to match the route's path, use relative path and strip_path to strip the added prefix. Relative path is unsupported when the route path is regex. By default, Kong will extract the path from API configuration. type: string query: description: The query arguments of the exported API. If the generated query arguments are not exactly matched, this field is required. type: object additionalProperties: items: type: string type: array request_body: description: The API requestBody specification defined in OpenAPI JSON format. For example, '{"content":{"application/x-www-form-urlencoded":{"schema":{"type":"object","properties":{"color":{"type":"array","items":{"type":"string"}}}}}}'.See https://swagger.io/docs/specification/v3_0/describing-request-body/describing-request-body/ for more details. Note that `$ref` is not supported so we need to inline the schema. type: object additionalProperties: true nullable: true x-speakeasy-type-override: any responses: description: The API responses specification defined in OpenAPI JSON format. This specification will be used to validate the upstream response and map it back to the structuredOutput. For example, '{"200":{"content":{"application/json":{"schema":{"type":"object","properties":{"result":{"type":"string"}}}}}}}'.See https://swagger.io/docs/specification/v3_0/describing-responses/ for more details.Only one non-error (status code < 400) response is supported. Note that `$ref` is not supported. additionalProperties: true nullable: true type: object x-speakeasy-type-override: any scheme: description: The scheme of the exported API, which must be one of the route's scheme. By default, Kong will extract the scheme from API configuration. If the configured scheme is not expected, this field can be used to override it. type: string enum: - http - https required: - description type: object required: - mode name: const: ai-mcp-proxy protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config AiRequestTransformerPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiRequestTransformerPluginConfig' MtlsAuthPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/MtlsAuthPluginConfig' AiPromptCompressorPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiPromptCompressorPluginConfig' ResponseTransformerAdvancedPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/ResponseTransformerAdvancedPluginConfig' AiCustomGuardrailPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiCustomGuardrailPluginConfig' GatewayUnauthorizedError: type: object properties: message: type: string status: type: integer required: - message - status ResponseRatelimitingPluginConfig: x-speakeasy-entity: PluginResponseRatelimiting properties: config: type: object properties: block_on_first_violation: description: A boolean value that determines if the requests should be blocked as soon as one limit is being exceeded. This will block requests that are supposed to consume other limits too. type: boolean default: false fault_tolerant: description: A boolean value that determines if the requests should be proxied even if Kong has troubles connecting a third-party datastore. If `true`, requests will be proxied anyway, effectively disabling the rate-limiting function until the datastore is working again. If `false`, then the clients will see `500` errors. type: boolean default: true header_name: description: The name of the response header used to increment the counters. type: string default: x-kong-limit hide_client_headers: description: Optionally hide informative response headers. type: boolean default: false limit_by: description: 'The entity that will be used when aggregating the limits: `consumer`, `credential`, `ip`. If the `consumer` or the `credential` cannot be determined, the system will always fallback to `ip`.' type: string default: consumer enum: - consumer - credential - ip limits: description: A map that defines rate limits for the plugin. type: object additionalProperties: properties: day: type: number hour: type: number minute: type: number month: type: number second: type: number year: type: number type: object minLength: 1 policy: description: The rate-limiting policies to use for retrieving and incrementing the limits. type: string default: local enum: - cluster - local - redis redis: description: Redis configuration type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string x-referenceable: true password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: response-ratelimiting protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string PrometheusPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/PrometheusPluginConfig' PostFunctionPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/PostFunctionPluginConfig' LdapAuthPluginConfig: x-speakeasy-entity: PluginLdapAuth properties: config: type: object properties: anonymous: description: An optional string (consumer UUID or username) value to use as an “anonymous” consumer if authentication fails. If empty (default null), the request fails with an authentication failure `4xx`. type: string attribute: description: Attribute to be used to search the user; e.g. cn type: string base_dn: description: Base DN as the starting point for the search; e.g., dc=example,dc=com type: string cache_ttl: description: Cache expiry time in seconds. type: number default: 60 header_type: description: An optional string to use as part of the Authorization header type: string default: ldap hide_credentials: description: An optional boolean value telling the plugin to hide the credential to the upstream server. It will be removed by Kong before proxying the request. type: boolean default: true keepalive: description: An optional value in milliseconds that defines how long an idle connection to LDAP server will live before being closed. type: number default: 60000 ldap_host: description: A string representing a host name, such as example.com. type: string ldap_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 389 maximum: 65535 minimum: 0 ldaps: description: Set to `true` to connect using the LDAPS protocol (LDAP over TLS). When `ldaps` is configured, you must use port 636. If the `ldap` setting is enabled, ensure the `start_tls` setting is disabled. type: boolean default: false realm: description: When authentication fails the plugin sends `WWW-Authenticate` header with `realm` attribute value. type: string start_tls: description: Set it to `true` to issue StartTLS (Transport Layer Security) extended operation over `ldap` connection. If the `start_tls` setting is enabled, ensure the `ldaps` setting is disabled. type: boolean default: false timeout: description: An optional timeout in milliseconds when waiting for connection with LDAP server. type: number default: 10000 verify_ldap_host: description: Set to `true` to authenticate LDAP server. The server certificate will be verified according to the CA certificates specified by the `lua_ssl_trusted_certificate` directive. type: boolean default: true required: - attribute - base_dn - ldap_host name: const: ldap-auth protocols: description: A list of the request protocols that will trigger this plugin. The default value, as well as the possible values allowed on this field, may change depending on the plugin type. For example, plugins that only work in stream mode will only support tcp and tls. type: array items: enum: - grpc - grpcs - http - https - ws - wss type: string format: set default: - grpc - grpcs - http - https - ws - wss route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config LdapAuthAdvancedPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/LdapAuthAdvancedPluginConfig' MockingPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/MockingPluginConfig' RequestSizeLimitingPluginConfig: x-speakeasy-entity: PluginRequestSizeLimiting properties: config: type: object properties: allowed_payload_size: description: Allowed request payload size in megabytes. Default is `128` megabytes (128000000 bytes). type: integer default: 128 require_content_length: description: Set to `true` to ensure a valid `Content-Length` header exists before reading the request body. type: boolean default: false size_unit: description: Size unit can be set either in `bytes`, `kilobytes`, or `megabytes` (default). This configuration is not available in versions prior to Kong Gateway 1.3 and Kong Gateway (OSS) 2.0. type: string default: megabytes enum: - bytes - kilobytes - megabytes consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: request-size-limiting protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AiSanitizerPluginConfig: x-speakeasy-entity: PluginAiSanitizer properties: config: type: object properties: allow_all_conversation_history: description: If false, will ignore all previous chat messages from the conversation history. type: boolean default: true anonymize: description: List of types to be anonymized type: array items: enum: - all - all_and_credentials - bank - credentials - creditcard - crypto - custom - date - domain - driverlicense - email - general - ip - medical - nationalid - nrp - passport - phone - ssn - url type: string default: - all_and_credentials block_if_detected: description: Whether to block requests containing PII data type: boolean default: false custom_patterns: description: List of custom patterns to be used for anonymization type: array items: properties: name: type: string regex: type: string score: type: number default: 0.5 maximum: 1 minimum: 0 required: - name - regex type: object minLength: 1 host: description: The host of the sanitizer type: string default: localhost keepalive_timeout: description: The keepalive timeout for the established http connnection type: number default: 60000 port: description: The port of the sanitizer type: number default: 8080 recover_redacted: description: Whether to recover redacted data. This doesn't apply to the redacted output. type: boolean default: true redact_type: description: What value to be used to redacted to type: string default: placeholder enum: - placeholder - synthetic sanitization_mode: description: The sanitization mode to use for the request type: string default: INPUT enum: - BOTH - INPUT - OUTPUT scheme: description: The protocol can be http and https type: string default: http skip_logging_sanitized_items: description: Whether to log sanitized items in the Kong log plugins. Turn it on if you want to hide sensitive data from logs. type: boolean default: false stop_on_error: description: Stop processing if an error occurs. type: boolean default: true timeout: description: Connection timeout with the sanitizer type: number default: 10000 consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-sanitizer protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string FileLogPluginConfig: x-speakeasy-entity: PluginFileLog properties: config: type: object properties: custom_fields_by_lua: description: Lua code as a key-value map type: object additionalProperties: type: string path: description: The file path of the output log file. The plugin creates the log file if it doesn't exist yet. type: string reopen: description: Determines whether the log file is closed and reopened on every request. type: boolean default: false required: - path consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: file-log protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config AiGcpModelArmorPluginConfig: x-speakeasy-entity: PluginAiGcpModelArmor properties: config: type: object properties: enable_multi_language_detection: description: Enables multi-language detection mode. Must be used with 'source_language'. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT` or from the instance/container metadata service. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false guarding_mode: description: The guardrail mode to use for the request type: string default: INPUT enum: - BOTH - INPUT - OUTPUT location_id: description: GCP Location ID for the GCP Model Armor subscription. type: string log_blocked_content: description: Whether to log prompts and responses that are blocked by the guardrail. type: boolean default: false project_id: description: GCP Project ID for the GCP Model Armor subscription. type: string request_failure_message: description: The message to return when a failure occurs on the request phase. type: string default: Request was filtered by GCP Model Armor response_buffer_size: description: The amount of bytes receiving from upstream to be buffered before sending to the model armor service. This only applies to the response content guard. type: number default: 100 response_failure_message: description: The message to return when a failure occurs on the response phase. type: string default: Response was filtered by GCP Model Armor reveal_failure_categories: description: Whether to reveal failure categories in the response to the caller. type: boolean default: false source_language: description: Source language (ISO code) to use when 'enable_multi_language_detection' is enabled. type: string stop_on_error: description: Stop processing if an error occurs. type: boolean default: true template_id: description: GCP Model Armor Template ID to enforce. type: string text_source: description: Select where to pick the 'text' for the GCP Model Armor Services request. type: string default: last_message enum: - concatenate_all_content - concatenate_user_content - last_message timeout: description: Connection timeout with the GCP Model Armor service type: number default: 10000 required: - location_id - project_id - template_id consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-gcp-model-armor protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config AiSemanticResponseGuardPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiSemanticResponseGuardPluginConfig' RateLimitingPluginConfig: x-speakeasy-entity: PluginRateLimiting properties: config: type: object properties: day: description: The number of HTTP requests that can be made per day. type: number error_code: description: Set a custom error code to return when the rate limit is exceeded. type: number default: 429 error_message: description: Set a custom error message to return when the rate limit is exceeded. type: string default: API rate limit exceeded fault_tolerant: description: A boolean value that determines if the requests should be proxied even if Kong has troubles connecting a third-party data store. If `true`, requests will be proxied anyway, effectively disabling the rate-limiting function until the data store is working again. If `false`, then the clients will see `500` errors. type: boolean default: true header_name: description: A string representing an HTTP header name. type: string hide_client_headers: description: Optionally hide informative response headers. type: boolean default: false hour: description: The number of HTTP requests that can be made per hour. type: number limit_by: description: The entity that is used when aggregating the limits. type: string default: consumer enum: - consumer - consumer-group - credential - header - ip - path - service minute: description: The number of HTTP requests that can be made per minute. type: number month: description: The number of HTTP requests that can be made per month. type: number path: description: A string representing a URL path, such as /path/to/resource. Must start with a forward slash (/) and must not contain empty segments (i.e., two consecutive forward slashes). type: string policy: description: The rate-limiting policies to use for retrieving and incrementing the limits. type: string default: local enum: - cluster - local - redis redis: description: Redis configuration type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string x-referenceable: true password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true second: description: The number of HTTP requests that can be made per second. type: number sync_rate: description: How often to sync counter data to the central data store. A value of -1 results in synchronous behavior. type: number default: -1 year: description: The number of HTTP requests that can be made per year. type: number consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: rate-limiting protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string AiAzureContentSafetyPluginConfig: x-speakeasy-entity: PluginAiAzureContentSafety properties: config: type: object properties: azure_api_version: description: Sets the ?api-version URL parameter, used for defining the Azure Content Services interchange format. type: string default: '2023-10-01' minLength: 1 azure_client_id: description: If `azure_use_managed_identity` is true, set the client ID if required. type: string azure_client_secret: description: If `azure_use_managed_identity` is true, set the client secret if required. type: string x-encrypted: true azure_tenant_id: description: If `azure_use_managed_identity` is true, set the tenant ID if required. type: string azure_use_managed_identity: description: If checked, uses (if set) `azure_client_id`, `azure_client_secret`, and/or `azure_tenant_id` for Azure authentication, via Managed or User-assigned identity type: boolean default: false blocklist_names: description: Use these configured blocklists (in Azure Content Services) when inspecting content. type: array items: type: string categories: description: Array of categories, and their thresholds, to measure on. type: array items: properties: name: type: string rejection_level: type: integer required: - name - rejection_level type: object content_safety_key: description: If `azure_use_managed_identity` is true, set the API key to call Content Safety. type: string x-encrypted: true x-referenceable: true content_safety_url: description: Full URL, inc protocol, of the Azure Content Safety instance. type: string x-referenceable: true guarding_mode: description: The guard mode to use for the request type: string default: INPUT enum: - BOTH - INPUT - OUTPUT halt_on_blocklist_hit: description: Tells Azure to reject the request if any blocklist filter is hit. type: boolean default: true log_blocked_content: description: Whether to log prompts and responses that are blocked by the guardrail. type: boolean default: false output_type: description: See https://learn.microsoft.com/en-us/azure/ai-services/openai/concepts/content-filter#content-filtering-categories type: string default: FourSeverityLevels enum: - EightSeverityLevels - FourSeverityLevels response_buffer_size: description: The amount of bytes receiving from upstream to be buffered before sending to the guardrails service. This only applies to the response content guard. type: number default: 100 reveal_failure_reason: description: Set true to tell the caller why their request was rejected, if so. type: boolean default: true ssl_verify: description: Whether to verify the certificate presented by the Azure Content Safety service when using HTTPS. type: boolean default: true stop_on_error: description: Stop processing if an error occurs type: boolean default: true text_source: description: Select where to pick the 'text' for the Azure Content Services request. type: string default: concatenate_all_content enum: - concatenate_all_content - concatenate_user_content required: - content_safety_url name: const: ai-azure-content-safety protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config StatsdAdvancedPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/StatsdAdvancedPluginConfig' RateLimitingAdvancedPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/RateLimitingAdvancedPluginConfig' AcePlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AcePluginConfig' BotDetectionPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/BotDetectionPluginConfig' RequestValidatorPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/RequestValidatorPluginConfig' ResponseTransformerAdvancedPluginConfig: x-speakeasy-entity: PluginResponseTransformerAdvanced properties: config: type: object properties: add: type: object properties: headers: type: array items: type: string default: [] if_status: type: array items: type: string default: [] json: type: array items: type: string default: [] json_types: type: array items: enum: - boolean - number - string type: string default: [] allow: type: object properties: json: type: array items: type: string append: type: object properties: headers: type: array items: type: string default: [] if_status: type: array items: type: string default: [] json: type: array items: type: string default: [] json_types: type: array items: enum: - boolean - number - string type: string default: [] dots_in_keys: description: Whether dots (for example, `customers.info.phone`) should be treated as part of a property name or used to descend into nested JSON objects.. type: boolean default: true remove: type: object properties: headers: type: array items: type: string default: [] if_status: type: array items: type: string default: [] json: type: array items: type: string default: [] rename: type: object properties: headers: type: array items: type: string default: [] if_status: type: array items: type: string default: [] replace: type: object properties: body: description: String with which to replace the entire response body. type: string headers: type: array items: type: string default: [] if_status: type: array items: type: string default: [] json: type: array items: type: string default: [] json_types: type: array items: enum: - boolean - number - string type: string default: [] transform: type: object properties: functions: type: array items: type: string default: [] if_status: type: array items: type: string default: [] json: type: array items: type: string default: [] consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: response-transformer-advanced protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string KafkaUpstreamPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/KafkaUpstreamPluginConfig' DatadogPluginConfig: x-speakeasy-entity: PluginDatadog properties: config: type: object properties: consumer_tag: description: String to be attached as tag of the consumer. type: string default: consumer flush_timeout: description: Optional time in seconds. If `queue_size` > 1, this is the max idle time before sending a log with less than `queue_size` records. type: number host: description: A string representing a host name, such as example.com. type: string default: localhost x-referenceable: true metrics: description: List of metrics to be logged. type: array items: properties: consumer_identifier: description: Authenticated user detail type: string enum: - consumer_id - custom_id - username name: description: Datadog metric’s name type: string enum: - kong_latency - latency - request_count - request_size - response_size - upstream_latency sample_rate: description: Sampling rate type: number maximum: 1 minimum: 0 stat_type: description: Determines what sort of event the metric represents type: string enum: - counter - distribution - gauge - histogram - meter - set - timer tags: description: List of tags type: array items: type: string required: - name - stat_type type: object port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 8125 maximum: 65535 minimum: 0 prefix: description: String to be attached as a prefix to a metric's name. type: string default: kong queue: type: object properties: concurrency_limit: description: The number of of queue delivery timers. -1 indicates unlimited. type: integer default: 1 enum: - -1 - 1 initial_retry_delay: description: Time in seconds before the initial retry is made for a failing batch. type: number default: 0.01 maximum: 1000000 minimum: 0.001 max_batch_size: description: Maximum number of entries that can be processed at a time. type: integer default: 1 maximum: 1000000 minimum: 1 max_bytes: description: Maximum number of bytes that can be waiting on a queue, requires string content. type: integer max_coalescing_delay: description: Maximum number of (fractional) seconds to elapse after the first entry was queued before the queue starts calling the handler. type: number default: 1 maximum: 3600 minimum: 0 max_entries: description: Maximum number of entries that can be waiting on the queue. type: integer default: 10000 maximum: 1000000 minimum: 1 max_retry_delay: description: Maximum time in seconds between retries, caps exponential backoff. type: number default: 60 maximum: 1000000 minimum: 0.001 max_retry_time: description: Time in seconds before the queue gives up calling a failed handler for a batch. type: number default: 60 queue_size: description: Maximum number of log entries to be sent on each message to the upstream server. type: integer retry_count: description: Number of times to retry when sending data to the upstream server. type: integer route_name_tag: description: String to be attached as tag of the route name or ID. type: string service_name_tag: description: String to be attached as the name of the service. type: string default: name status_tag: description: String to be attached as the tag of the HTTP status. type: string default: status consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: datadog protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string ServiceProtectionPluginConfig: x-speakeasy-entity: PluginServiceProtection properties: config: type: object properties: dictionary_name: description: The shared dictionary where counters are stored. When the plugin is configured to synchronize counter data externally (that is `config.strategy` is `cluster` or `redis` and `config.sync_rate` isn't `-1`), this dictionary serves as a buffer to populate counters in the data store on each synchronization cycle. type: string default: kong_rate_limiting_counters disable_penalty: description: If set to `true`, this doesn't count denied requests (status = `429`). If set to `false`, all requests, including denied ones, are counted. This parameter only affects the `sliding` window_type. type: boolean default: false error_code: description: Set a custom error code to return when the rate limit is exceeded. type: number default: 429 error_message: description: Set a custom error message to return when the rate limit is exceeded. type: string default: API rate limit exceeded hide_client_headers: description: Optionally hide informative response headers that would otherwise provide information about the current status of limits and counters. type: boolean default: false limit: description: One or more requests-per-window limits to apply. There must be a matching number of window limits and sizes specified. type: array items: type: number lock_dictionary_name: description: The shared dictionary where concurrency control locks are stored. The default shared dictionary is `kong_locks`. The shared dictionary should be declared in nginx-kong.conf. type: string default: kong_locks namespace: description: 'The rate limiting library namespace to use for this plugin instance. Counter data and sync configuration is isolated in each namespace. NOTE: For the plugin instances sharing the same namespace, all the configurations that are required for synchronizing counters, e.g. `strategy`, `redis`, `sync_rate`, `dictionary_name`, need to be the same.' type: string redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true retry_after_jitter_max: description: The upper bound of a jitter (random delay) in seconds to be added to the `Retry-After` header of denied requests (status = `429`) in order to prevent all the clients from coming back at the same time. The lower bound of the jitter is `0`; in this case, the `Retry-After` header is equal to the `RateLimit-Reset` header. type: number default: 0 strategy: description: 'The rate-limiting strategy to use for retrieving and incrementing the limits. Available values are: `local`, `redis` and `cluster`.' type: string default: local enum: - cluster - local - redis sync_rate: description: How often to sync counter data to the central data store. A value of 0 results in synchronous behavior; a value of -1 ignores sync behavior entirely and only stores counters in node memory. A value greater than 0 will sync the counters in the specified number of seconds. The minimum allowed interval is 0.02 seconds (20ms). type: number window_size: description: One or more window sizes to apply a limit to (defined in seconds). There must be a matching number of window limits and sizes specified. type: array items: type: number window_type: description: Sets the time window type to either `sliding` (default) or `fixed`. Sliding windows apply the rate limiting logic while taking into account previous hit rates (from the window that immediately precedes the current) using a dynamic weight. Fixed windows consist of buckets that are statically assigned to a definitive time range, each request is mapped to only one fixed window based on its timestamp and will affect only that window's counters. type: string default: sliding enum: - fixed - sliding required: - limit - window_size name: const: service-protection protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config StatsdAdvancedPluginConfig: x-speakeasy-entity: PluginStatsdAdvanced properties: config: type: object properties: allow_status_codes: description: List of status code ranges that are allowed to be logged in metrics. type: array items: type: string consumer_identifier_default: description: The default consumer identifier for metrics. This will take effect when a metric's consumer identifier is omitted. Allowed values are `custom_id`, `consumer_id`, `username`. type: string default: custom_id enum: - consumer_id - custom_id - username host: description: A string representing a host name, such as example.com. type: string default: localhost hostname_in_prefix: description: Include the `hostname` in the `prefix` for each metric name. type: boolean default: false metrics: description: List of Metrics to be logged. type: array items: properties: consumer_identifier: type: string enum: - consumer_id - custom_id - username name: type: string enum: - cache_datastore_hits_total - cache_datastore_misses_total - kong_latency - latency - request_count - request_per_user - request_size - response_size - shdict_usage - status_count - status_count_per_user - status_count_per_user_per_route - status_count_per_workspace - unique_users - upstream_latency sample_rate: type: number service_identifier: type: string enum: - service_host - service_id - service_name - service_name_or_host stat_type: type: string enum: - counter - gauge - histogram - meter - set - timer workspace_identifier: type: string enum: - workspace_id - workspace_name required: - name - stat_type type: object port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 8125 maximum: 65535 minimum: 0 prefix: description: String to prefix to each metric's name. type: string default: kong queue: type: object properties: concurrency_limit: description: The number of of queue delivery timers. -1 indicates unlimited. type: integer default: 1 enum: - -1 - 1 initial_retry_delay: description: Time in seconds before the initial retry is made for a failing batch. type: number default: 0.01 maximum: 1000000 minimum: 0.001 max_batch_size: description: Maximum number of entries that can be processed at a time. type: integer default: 1 maximum: 1000000 minimum: 1 max_bytes: description: Maximum number of bytes that can be waiting on a queue, requires string content. type: integer max_coalescing_delay: description: Maximum number of (fractional) seconds to elapse after the first entry was queued before the queue starts calling the handler. type: number default: 1 maximum: 3600 minimum: 0 max_entries: description: Maximum number of entries that can be waiting on the queue. type: integer default: 10000 maximum: 1000000 minimum: 1 max_retry_delay: description: Maximum time in seconds between retries, caps exponential backoff. type: number default: 60 maximum: 1000000 minimum: 0.001 max_retry_time: description: Time in seconds before the queue gives up calling a failed handler for a batch. type: number default: 60 service_identifier_default: description: The default service identifier for metrics. This will take effect when a metric's service identifier is omitted. Allowed values are `service_name_or_host`, `service_id`, `service_name`, `service_host`. type: string default: service_name_or_host enum: - service_host - service_id - service_name - service_name_or_host udp_packet_size: description: Combine UDP packet up to the size configured. If zero (0), don't combine the UDP packet. Must be a number between 0 and 65507 (inclusive). type: number default: 0 maximum: 65507 minimum: 0 use_tcp: description: Use TCP instead of UDP. type: boolean default: false workspace_identifier_default: description: 'The default workspace identifier for metrics. This will take effect when a metric''s workspace identifier is omitted. Allowed values are `workspace_id`, `workspace_name`. ' type: string default: workspace_id enum: - workspace_id - workspace_name consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: statsd-advanced protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string ProxyCachePluginConfig: x-speakeasy-entity: PluginProxyCache properties: config: type: object properties: cache_control: description: When enabled, respect the Cache-Control behaviors defined in RFC7234. type: boolean default: false cache_ttl: description: TTL, in seconds, of cache entities. type: integer default: 300 content_type: description: Upstream response content types considered cacheable. The plugin performs an **exact match** against each specified value. type: array items: type: string default: - application/json - text/plain ignore_uri_case: type: boolean default: false memory: type: object properties: dictionary_name: description: The name of the shared dictionary in which to hold cache entities when the memory strategy is selected. Note that this dictionary currently must be defined manually in the Kong Nginx template. type: string default: kong_db_cache request_method: description: Downstream request methods considered cacheable. type: array items: enum: - GET - HEAD - PATCH - POST - PUT type: string default: - GET - HEAD response_code: description: Upstream response status code considered cacheable. type: array items: maximum: 900 minimum: 100 type: integer default: - 200 - 301 - 404 minLength: 1 response_headers: description: Caching related diagnostic headers that should be included in cached responses type: object properties: X-Cache-Key: type: boolean default: true X-Cache-Status: type: boolean default: true age: type: boolean default: true storage_ttl: description: Number of seconds to keep resources in the storage backend. This value is independent of `cache_ttl` or resource TTLs defined by Cache-Control behaviors. type: integer strategy: description: The backing data store in which to hold cache entities. type: string enum: - memory vary_headers: description: Relevant headers considered for the cache key. If undefined, none of the headers are taken into consideration. type: array items: type: string vary_query_params: description: Relevant query parameters considered for the cache key. If undefined, all params are taken into consideration. type: array items: type: string required: - strategy consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: proxy-cache protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config UpstreamTimeoutPluginConfig: x-speakeasy-entity: PluginUpstreamTimeout properties: config: type: object properties: connect_timeout: description: The timeout in milliseconds for establishing a connection to the upstream server. Must be an integer between 1 and 2^31-2. type: integer maximum: 2147483646 minimum: 0 read_timeout: description: The timeout in milliseconds between two successive read operations for transmitting a request to the upstream server. Must be an integer between 1 and 2^31-2. type: integer maximum: 2147483646 minimum: 0 send_timeout: description: The timeout in milliseconds between two successive write operations for transmitting a request to the upstream server. Must be an integer between 1 and 2^31-2. type: integer maximum: 2147483646 minimum: 0 consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: upstream-timeout protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string GrpcWebPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/GrpcWebPluginConfig' HmacAuthPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/HmacAuthPluginConfig' AiSemanticPromptGuardPluginConfig: x-speakeasy-entity: PluginAiSemanticPromptGuard properties: config: type: object properties: embeddings: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true model: type: object properties: name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: azure: type: object properties: api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' deployment_id: description: Deployment ID for Azure OpenAI instances. type: string instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean upstream_url: description: upstream url for the embeddings type: string provider: description: AI provider format to use for embeddings API type: string enum: - azure - bedrock - gemini - huggingface - mistral - ollama - openai required: - name - provider required: - model genai_category: description: Generative AI category of the request type: string default: text/generation enum: - audio/speech - audio/transcription - image/generation - realtime/generation - text/embeddings - text/generation - video/generation llm_format: description: LLM input and output format and schema to use type: string default: openai enum: - anthropic - bedrock - cohere - gemini - huggingface - openai max_request_body_size: description: max allowed body size allowed to be introspected. 0 means unlimited, but the size of this body will still be limited by Nginx's client_max_body_size. type: integer default: 1048576 rules: type: object properties: allow_prompts: description: List of prompts to allow. type: array items: maxLength: 500 minLength: 1 type: string maxLength: 100 deny_prompts: description: List of prompts to deny. type: array items: maxLength: 500 minLength: 1 type: string maxLength: 100 match_all_conversation_history: description: If false, will ignore all previous chat prompts from the conversation history. type: boolean default: false match_all_roles: description: If true, will match all roles in addition to 'user' role in conversation history. type: boolean default: false max_request_body_size: description: max allowed body size allowed to be introspected. 0 means unlimited, but the size of this body will still be limited by Nginx's client_max_body_size. type: integer search: type: object properties: threshold: description: Threshold for the similarity score to be considered a match. type: number default: 0.5 vectordb: type: object properties: dimensions: description: the desired dimensionality for the vectors type: integer distance_metric: description: the distance metric to use for vector searches type: string enum: - cosine - euclidean pgvector: type: object properties: database: description: the database of the pgvector database type: string default: kong-pgvector host: description: the host of the pgvector database type: string default: 127.0.0.1 password: description: the password of the pgvector database type: string x-encrypted: true x-referenceable: true port: description: the port of the pgvector database type: integer default: 5432 ssl: description: whether to use ssl for the pgvector database type: boolean default: false ssl_cert: description: the path of ssl cert to use for the pgvector database type: string ssl_cert_key: description: the path of ssl cert key to use for the pgvector database type: string ssl_required: description: whether ssl is required for the pgvector database type: boolean default: false ssl_verify: description: whether to verify ssl for the pgvector database type: boolean default: true ssl_version: description: the ssl version to use for the pgvector database type: string default: tlsv1_2 enum: - any - tlsv1_2 - tlsv1_3 timeout: description: the timeout of the pgvector database type: number default: 5000 user: description: the user of the pgvector database type: string default: postgres x-referenceable: true redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true strategy: description: which vector database driver to use type: string enum: - pgvector - redis threshold: description: the default similarity threshold for accepting semantic search results (float). Higher threshold means more results are considered similar. type: number required: - dimensions - distance_metric - strategy required: - embeddings - vectordb consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-semantic-prompt-guard protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config HeaderCertAuthPluginConfig: x-speakeasy-entity: PluginHeaderCertAuth properties: config: type: object properties: allow_partial_chain: description: Allow certificate verification with only an intermediate certificate. When this is enabled, you don't need to upload the full chain to Kong Certificates. type: boolean default: false anonymous: description: An optional string (consumer UUID or username) value to use as an “anonymous” consumer if authentication fails. If empty (default null), the request fails with an authentication failure `4xx`. Note that this value must refer to the consumer `id` or `username` attribute, and **not** its `custom_id`. type: string authenticated_group_by: description: Certificate property to use as the authenticated group. Valid values are `CN` (Common Name) or `DN` (Distinguished Name). Once `skip_consumer_lookup` is applied, any client with a valid certificate can access the Service/API. To restrict usage to only some of the authenticated users, also add the ACL plugin (not covered here) and create allowed or denied groups of users. type: string default: CN enum: - CN - DN ca_certificates: description: List of CA Certificates strings to use as Certificate Authorities (CA) when validating a client certificate. At least one is required but you can specify as many as needed. The value of this array is comprised of primary keys (`id`). type: array items: type: string cache_ttl: description: Cache expiry time in seconds. type: number default: 60 cert_cache_ttl: description: The length of time in milliseconds between refreshes of the revocation check status cache. type: number default: 60000 certificate_header_format: description: 'Format of the certificate header. Supported formats: `base64_encoded`, `url_encoded`.' type: string enum: - base64_encoded - url_encoded certificate_header_name: description: Name of the header that contains the certificate, received from the WAF or other L7 downstream proxy. type: string consumer_by: description: Whether to match the subject name of the client-supplied certificate against consumer's `username` and/or `custom_id` attribute. If set to `[]` (the empty array), then auto-matching is disabled. type: array items: enum: - custom_id - username type: string default: - custom_id - username default_consumer: description: The UUID or username of the consumer to use when a trusted client certificate is presented but no consumer matches. Note that this value must refer to the consumer `id` or `username` attribute, and **not** its `custom_id`. type: string http_proxy_host: description: A string representing a host name, such as example.com. type: string http_proxy_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 http_timeout: description: HTTP timeout threshold in milliseconds when communicating with the OCSP server or downloading CRL. type: number default: 30000 https_proxy_host: description: A string representing a host name, such as example.com. type: string https_proxy_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 revocation_check_mode: description: Controls client certificate revocation check behavior. If set to `SKIP`, no revocation check is performed. If set to `IGNORE_CA_ERROR`, the plugin respects the revocation status when either OCSP or CRL URL is set, and doesn't fail on network issues. If set to `STRICT`, the plugin only treats the certificate as valid when it's able to verify the revocation status. type: string default: IGNORE_CA_ERROR enum: - IGNORE_CA_ERROR - SKIP - STRICT secure_source: description: Whether to secure the source of the request. If set to `true`, the plugin will only allow requests from trusted IPs (configured by the `trusted_ips` config option). type: boolean default: true skip_consumer_lookup: description: Skip consumer lookup once certificate is trusted against the configured CA list. type: boolean default: false ssl_verify: description: This option enables verification of the certificate presented by the server of the OCSP responder's URL and by the server of the CRL Distribution Point. type: boolean default: true required: - ca_certificates - certificate_header_format - certificate_header_name name: const: header-cert-auth protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config DegraphqlPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/DegraphqlPluginConfig' SyslogPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/SyslogPluginConfig' MeteringAndBillingPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/MeteringAndBillingPluginConfig' AiPromptDecoratorPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiPromptDecoratorPluginConfig' ForwardProxyPluginConfig: x-speakeasy-entity: PluginForwardProxy properties: config: type: object properties: auth_password: description: 'The password to authenticate with, if the forward proxy is protected by basic authentication.' type: string x-encrypted: true x-referenceable: true auth_username: description: 'The username to authenticate with, if the forward proxy is protected by basic authentication.' type: string x-referenceable: true http_proxy_host: description: A string representing a host name, such as example.com. type: string http_proxy_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 https_proxy_host: description: A string representing a host name, such as example.com. type: string https_proxy_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 https_verify: description: Whether the server certificate will be verified according to the CA certificates specified in lua_ssl_trusted_certificate. type: boolean default: true proxy_scheme: description: The proxy scheme to use when connecting. Only `http` is supported. type: string default: http enum: - http x_headers: description: Determines how to handle headers when forwarding the request. type: string default: append enum: - append - delete - transparent consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: forward-proxy protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string LogglyPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/LogglyPluginConfig' AiPromptDecoratorPluginConfig: x-speakeasy-entity: PluginAiPromptDecorator properties: config: type: object properties: llm_format: description: LLM input and output format and schema to use type: string default: openai enum: - anthropic - bedrock - cohere - gemini - huggingface - openai max_request_body_size: description: max allowed body size allowed to be introspected. 0 means unlimited, but the size of this body will still be limited by Nginx's client_max_body_size. type: integer default: 1048576 prompts: type: object properties: append: description: Insert chat messages at the end of the chat message array. This array preserves exact order when adding messages. type: array items: properties: content: maxLength: 100000 minLength: 1 type: string role: type: string default: system enum: - assistant - system - user required: - content type: object maxLength: 15 prepend: description: Insert chat messages at the beginning of the chat message array. This array preserves exact order when adding messages. type: array items: properties: content: maxLength: 100000 minLength: 1 type: string role: type: string default: system enum: - assistant - system - user required: - content type: object maxLength: 15 consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-prompt-decorator protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string JweDecryptPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/JweDecryptPluginConfig' AiPromptGuardPluginConfig: x-speakeasy-entity: PluginAiPromptGuard properties: config: type: object properties: allow_all_conversation_history: description: If true, will ignore all previous chat prompts from the conversation history. type: boolean default: false allow_patterns: description: Array of valid regex patterns, or valid questions from the 'user' role in chat. type: array items: maxLength: 500 minLength: 1 type: string maxLength: 10 deny_patterns: description: Array of invalid regex patterns, or invalid questions from the 'user' role in chat. type: array items: maxLength: 500 minLength: 1 type: string maxLength: 10 genai_category: description: Generative AI category of the request type: string default: text/generation enum: - audio/speech - audio/transcription - image/generation - realtime/generation - text/embeddings - text/generation - video/generation llm_format: description: LLM input and output format and schema to use type: string default: openai enum: - anthropic - bedrock - cohere - gemini - huggingface - openai match_all_roles: description: If true, will match all roles in addition to 'user' role in conversation history. type: boolean default: false max_request_body_size: description: max allowed body size allowed to be introspected. 0 means unlimited, but the size of this body will still be limited by Nginx's client_max_body_size. type: integer default: 1048576 consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-prompt-guard protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string RateLimitingPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/RateLimitingPluginConfig' AzureFunctionsPluginConfig: x-speakeasy-entity: PluginAzureFunctions properties: config: type: object properties: apikey: description: The apikey to access the Azure resources. If provided, it is injected as the `x-functions-key` header. type: string x-encrypted: true x-referenceable: true appname: description: The Azure app name. type: string clientid: description: The `clientid` to access the Azure resources. If provided, it is injected as the `x-functions-clientid` header. type: string x-encrypted: true x-referenceable: true functionname: description: Name of the Azure function to invoke. type: string hostdomain: description: The domain where the function resides. type: string default: azurewebsites.net https: description: Use of HTTPS to connect with the Azure Functions server. type: boolean default: true https_verify: description: Set to `true` to authenticate the Azure Functions server. type: boolean default: true keepalive: description: Time in milliseconds during which an idle connection to the Azure Functions server lives before being closed. type: number default: 60000 routeprefix: description: Route prefix to use. type: string default: api timeout: description: Timeout in milliseconds before closing a connection to the Azure Functions server. type: number default: 600000 required: - appname - functionname consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: azure-functions protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config AiPromptCompressorPluginConfig: x-speakeasy-entity: PluginAiPromptCompressor properties: config: type: object properties: compression_ranges: description: What value to be used to compress with. The 'value' is interpreted as rate or target_token depending on compressor_type. type: array items: properties: max_tokens: type: integer min_tokens: type: integer value: type: number required: - max_tokens - min_tokens - value type: object compressor_type: description: What compression type to use to compress with type: string default: rate enum: - rate - target_token compressor_url: description: The url of the compressor type: string default: http://localhost:8080 keepalive_timeout: description: The keepalive timeout for the established http connnection type: number default: 60000 log_text_data: description: Log the text data type: boolean default: false message_type: type: array items: enum: - assistant - system - user type: string default: - user stop_on_error: description: Stop processing if an error occurs type: boolean default: true timeout: description: Connection timeout with the compressor type: number default: 10000 required: - compression_ranges consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-prompt-compressor protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config JqPluginConfig: x-speakeasy-entity: PluginJq properties: config: type: object properties: request_if_media_type: type: array items: type: string default: - application/json request_jq_program: type: string request_jq_program_options: type: object default: {} properties: ascii_output: type: boolean default: false compact_output: type: boolean default: true join_output: type: boolean default: false raw_output: type: boolean default: false sort_keys: type: boolean default: false response_if_media_type: type: array items: type: string default: - application/json response_if_status_code: type: array items: maximum: 599 minimum: 100 type: integer default: - 200 response_jq_program: type: string response_jq_program_options: type: object default: {} properties: ascii_output: type: boolean default: false compact_output: type: boolean default: true join_output: type: boolean default: false raw_output: type: boolean default: false sort_keys: type: boolean default: false consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: jq protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string GrpcGatewayPluginConfig: x-speakeasy-entity: PluginGrpcGateway properties: config: type: object properties: proto: description: Describes the gRPC types and methods. type: string consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: grpc-gateway protocols: description: A set of strings representing protocols. type: array items: description: A string representing a protocol, such as HTTP or HTTPS. enum: - grpc - grpcs - http - https - tcp - tls - tls_passthrough - udp - ws - wss type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string RedirectPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/RedirectPluginConfig' AiLlmAsJudgePluginConfig: x-speakeasy-entity: PluginAiLlmAsJudge properties: config: type: object properties: http_proxy_host: description: A string representing a host name, such as example.com. type: string http_proxy_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 http_timeout: description: Timeout in milliseconds for the AI upstream service. type: integer default: 60000 https_proxy_host: description: A string representing a host name, such as example.com. type: string https_proxy_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer maximum: 65535 minimum: 0 https_verify: description: Verify the TLS certificate of the AI upstream service. type: boolean default: true ignore_assistant_prompts: description: Ignore and discard any assistant prompts when evaluating the request type: boolean default: true ignore_system_prompts: description: Ignore and discard any system prompts when evaluating the request type: boolean default: true ignore_tool_prompts: description: Ignore and discard any tool prompts when evaluating the request type: boolean default: true llm: type: object properties: auth: type: object properties: allow_override: description: If enabled, the authorization header or parameter can be overridden in the request by the value configured in the plugin. type: boolean default: false aws_access_key_id: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_ACCESS_KEY_ID environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: Set this if you are using an AWS provider (Bedrock) and you are authenticating using static IAM User credentials. Setting this will override the AWS_SECRET_ACCESS_KEY environment variable for this plugin instance. type: string x-encrypted: true x-referenceable: true azure_client_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client ID. type: string x-referenceable: true azure_client_secret: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the client secret. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: If azure_use_managed_identity is set to true, and you need to use a different user-assigned identity for this LLM instance, set the tenant ID. type: string x-referenceable: true azure_use_managed_identity: description: Set true to use the Azure Cloud Managed Identity (or user-assigned identity) to authenticate with Azure-provider models. type: boolean default: false gcp_metadata_url: description: Custom metadata URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google metadata endpoint. type: string x-referenceable: true gcp_oauth_token_url: description: Custom OAuth token URL for GCP authentication. Useful for restricted network environments or custom GCP endpoints. If null, Kong will use the default Google OAuth token endpoint. type: string x-referenceable: true gcp_service_account_json: description: Set this field to the full JSON of the GCP service account to authenticate, if required. If null (and gcp_use_service_account is true), Kong will attempt to read from environment variable `GCP_SERVICE_ACCOUNT`. type: string x-encrypted: true x-referenceable: true gcp_use_service_account: description: Use service account auth for GCP-based providers and models. type: boolean default: false header_name: description: If AI model requires authentication via Authorization or API key header, specify its name here. type: string x-referenceable: true header_value: description: Specify the full auth header value for 'header_name', for example 'Bearer key' or just 'key'. type: string x-encrypted: true x-referenceable: true param_location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string enum: - body - query param_name: description: If AI model requires authentication via query parameter, specify its name here. type: string x-referenceable: true param_value: description: Specify the full parameter value for 'param_name'. type: string x-encrypted: true x-referenceable: true description: description: The semantic description of the target, required if using semantic load balancing. Specially, setting this to 'CATCHALL' will indicate such target to be used when no other targets match the semantic threshold. Only used by ai-proxy-advanced. type: string logging: type: object properties: log_payloads: description: If enabled, will log the request and response body into the Kong log plugin(s) output.Furthermore if Opentelemetry instrumentation is enabled the traces will contain this data as well. type: boolean default: false log_statistics: description: If enabled and supported by the driver, will add model usage and token metrics into the Kong log plugin(s) output. type: boolean default: false metadata: description: 'For internal use only. ' type: object additionalProperties: true nullable: true x-speakeasy-type-override: any model: type: object properties: model_alias: description: The model name parameter from the request that this model should map to. type: string name: description: Model name to execute. type: string options: description: Key/value settings for the model type: object properties: anthropic_version: description: Defines the schema/API version, if using Anthropic provider. type: string azure_api_version: description: '''api-version'' for Azure OpenAI instances.' type: string default: '2023-05-15' azure_deployment_id: description: Deployment ID for Azure OpenAI instances. type: string azure_instance: description: Instance name for Azure OpenAI hosted models. type: string bedrock: type: object properties: aws_assume_role_arn: description: If using AWS providers (Bedrock) you can assume a different role after authentication with the current IAM context is successful. type: string aws_region: description: If using AWS providers (Bedrock) you can override the `AWS_REGION` environment variable by setting this option. type: string aws_role_session_name: description: If using AWS providers (Bedrock), set the identifier of the assumed role session. type: string aws_sts_endpoint_url: description: If using AWS providers (Bedrock), override the STS endpoint URL when assuming a different role. type: string batch_bucket_prefix: description: S3 URI prefix (s3://bucket/prefix/) where Bedrock will get input files from and store results to for native batch API. type: string batch_role_arn: description: AWS role arn used for calling batch API. Try to get the value from request if ommited. type: string embeddings_normalize: description: If using AWS providers (Bedrock), set to true to normalize the embeddings. type: boolean default: false performance_config_latency: description: Force the client's performance configuration 'latency' for all requests. Leave empty to let the consumer select the performance configuration. type: string video_output_s3_uri: description: S3 URI (s3://bucket/prefix) where Bedrock will store generated video files. Required for video generation. type: string cohere: type: object properties: embedding_input_type: description: The purpose of the input text to calculate embedding vectors. type: string default: classification enum: - classification - clustering - image - search_document - search_query wait_for_model: description: Wait for the model if it is not ready type: boolean dashscope: type: object properties: international: description: 'Two Dashscope endpoints are available, and the international endpoint will be used when this is set to `true`. It is recommended to set this to `true` when using international version of dashscope. ' type: boolean default: true databricks: type: object properties: workspace_instance_id: description: Workspace Instance ID ('dbc-xxx-yyy') for Databricks model serving. type: string embeddings_dimensions: description: If using embeddings models, set the number of dimensions to generate. type: integer gemini: type: object properties: api_endpoint: description: If running Gemini on Vertex, specify the regional API endpoint (hostname only). type: string endpoint_id: description: If running Gemini on Vertex Model Garden, specify the endpoint ID. type: string location_id: description: If running Gemini on Vertex, specify the location ID. type: string project_id: description: If running Gemini on Vertex, specify the project ID. type: string huggingface: type: object properties: use_cache: description: Use the cache layer on the inference API type: boolean wait_for_model: description: Wait for the model if it is not ready type: boolean input_cost: description: Defines the cost per 1M tokens in your prompt. type: number llama2_format: description: If using llama2 provider, select the upstream message format. type: string enum: - ollama - openai - raw max_tokens: description: Defines the max_tokens, if using chat or completion models. type: integer mistral_format: description: If using mistral provider, select the upstream message format. type: string enum: - ollama - openai output_cost: description: Defines the cost per 1M tokens in the output of the AI. type: number temperature: description: Defines the matching temperature, if using chat or completion models. type: number maximum: 5 minimum: 0 top_k: description: Defines the top-k most likely tokens, if supported. type: integer maximum: 500 minimum: 0 top_p: description: Defines the top-p probability mass, if supported. type: number maximum: 1 minimum: 0 upstream_path: description: Manually specify or override the AI operation path, used when e.g. using the 'preserve' route_type. type: string upstream_url: description: Manually specify or override the full URL to the AI operation endpoints, when calling (self-)hosted models, or for running via a private endpoint. type: string provider: description: AI provider request format - Kong translates requests to and from the specified backend compatible formats. type: string enum: - anthropic - azure - bedrock - cerebras - cohere - dashscope - databricks - deepseek - gemini - huggingface - llama2 - mistral - ollama - openai - vllm - xai required: - provider route_type: description: 'The model''s operation implementation, for this provider. ' type: string enum: - audio/v1/audio/speech - audio/v1/audio/transcriptions - audio/v1/audio/translations - image/v1/images/edits - image/v1/images/generations - llm/v1/assistants - llm/v1/batches - llm/v1/chat - llm/v1/completions - llm/v1/embeddings - llm/v1/files - llm/v1/responses - preserve - realtime/v1/realtime - video/v1/videos/generations weight: description: The weight this target gets within the upstream loadbalancer (1-65535). Only used by ai-proxy-advanced. type: integer default: 100 maximum: 65535 minimum: 1 required: - model - route_type message_countback: description: Number of messages in the chat history to use for evaluating the request type: number default: 1 maximum: 1000 minimum: 1 prompt: description: Use this prompt to tune the LLM system/assistant message for the llm as a judge prompt. type: string default: 'You are a strict evaluator. You will be given a prompt and a response. Your task is to judge whether the response is correct or incorrect. You must assign a score between 1 and 100, where: 100 represents a completely correct and ideal response, 1 represents a completely incorrect or irrelevant response. Your score must be a single number only — no text, labels, or explanations. Use the full range of values (e.g., 13, 47, 86), not just round numbers like 10, 50, or 100. Be accurate and consistent, as this score will be used by another model for learning and evaluation.' sampling_rate: description: Judging request sampling rate for configuring the probability-based sampler. type: number default: 1 maximum: 1 minimum: 0 required: - llm consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-llm-as-judge protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config SamlPluginConfig: x-speakeasy-entity: PluginSaml properties: config: type: object properties: anonymous: description: An optional string (consumer UUID or username) value to use as an “anonymous” consumer. If not set, a Kong Consumer must exist for the SAML IdP user credentials, mapping the username format to the Kong Consumer username. type: string assertion_consumer_path: description: A string representing a URL path, such as /path/to/resource. Must start with a forward slash (/) and must not contain empty segments (i.e., two consecutive forward slashes). type: string idp_certificate: description: The public certificate provided by the IdP. This is used to validate responses from the IdP. Only include the contents of the certificate. Do not include the header (`BEGIN CERTIFICATE`) and footer (`END CERTIFICATE`) lines. type: string x-encrypted: true x-referenceable: true idp_sso_url: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string issuer: description: The unique identifier of the IdP application. Formatted as a URL containing information about the IdP so the SP can validate that the SAML assertions it receives are issued from the correct IdP. type: string nameid_format: description: 'The requested `NameId` format. Options available are: - `Unspecified` - `EmailAddress` - `Persistent` - `Transient`' type: string default: EmailAddress enum: - EmailAddress - Persistent - Transient - Unspecified redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true prefix: description: The Redis session key prefix. type: string read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true socket: description: The Redis unix socket path. type: string ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true request_digest_algorithm: description: 'The digest algorithm for Authn requests: - `SHA256` - `SHA1`' type: string default: SHA256 enum: - SHA1 - SHA256 request_signature_algorithm: description: 'The signature algorithm for signing Authn requests. Options available are: - `SHA256` - `SHA384` - `SHA512`' type: string default: SHA256 enum: - SHA256 - SHA384 - SHA512 request_signing_certificate: description: The certificate for signing requests. type: string x-encrypted: true x-referenceable: true request_signing_key: description: The private key for signing requests. If this parameter is set, requests sent to the IdP are signed. The `request_signing_certificate` parameter must be set as well. type: string x-encrypted: true x-referenceable: true response_digest_algorithm: description: 'The algorithm for verifying digest in SAML responses: - `SHA256` - `SHA1`' type: string default: SHA256 enum: - SHA1 - SHA256 response_encryption_key: description: The private encryption key required to decrypt encrypted assertions. type: string x-encrypted: true x-referenceable: true response_signature_algorithm: description: 'The algorithm for validating signatures in SAML responses. Options available are: - `SHA256` - `SHA384` - `SHA512`' type: string default: SHA256 enum: - SHA256 - SHA384 - SHA512 session_absolute_timeout: description: The session cookie absolute timeout in seconds. Specifies how long the session can be used until it is no longer valid. type: number default: 86400 session_audience: description: The session audience, for example "my-application" type: string default: default session_cookie_domain: description: The session cookie domain flag. type: string session_cookie_http_only: description: Forbids JavaScript from accessing the cookie, for example, through the `Document.cookie` property. type: boolean default: true session_cookie_name: description: The session cookie name. type: string default: session session_cookie_path: description: A string representing a URL path, such as /path/to/resource. Must start with a forward slash (/) and must not contain empty segments (i.e., two consecutive forward slashes). type: string default: / session_cookie_same_site: description: Controls whether a cookie is sent with cross-origin requests, providing some protection against cross-site request forgery attacks. type: string default: Lax enum: - Default - Lax - None - Strict session_cookie_secure: description: The cookie is only sent to the server when a request is made with the https:scheme (except on localhost), and therefore is more resistant to man-in-the-middle attacks. type: boolean session_enforce_same_subject: description: When set to `true`, audiences are forced to share the same subject. type: boolean default: false session_hash_storage_key: description: When set to `true`, the storage key (session ID) is hashed for extra security. Hashing the storage key means it is impossible to decrypt data from the storage without a cookie. type: boolean default: false session_hash_subject: description: When set to `true`, the value of subject is hashed before being stored. Only applies when `session_store_metadata` is enabled. type: boolean default: false session_idling_timeout: description: The session cookie idle time in seconds. type: number default: 900 session_memcached_host: description: The memcached host. type: string default: 127.0.0.1 session_memcached_port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 11211 maximum: 65535 minimum: 0 session_memcached_prefix: description: The memcached session key prefix. type: string session_memcached_socket: description: The memcached unix socket path. type: string session_remember: description: Enables or disables persistent sessions type: boolean default: false session_remember_absolute_timeout: description: Persistent session absolute timeout in seconds. type: number default: 2592000 session_remember_cookie_name: description: Persistent session cookie name type: string default: remember session_remember_rolling_timeout: description: Persistent session rolling timeout in seconds. type: number default: 604800 session_request_headers: type: array items: enum: - absolute-timeout - audience - id - idling-timeout - rolling-timeout - subject - timeout type: string session_response_headers: type: array items: enum: - absolute-timeout - audience - id - idling-timeout - rolling-timeout - subject - timeout type: string session_rolling_timeout: description: The session cookie absolute timeout in seconds. Specifies how long the session can be used until it is no longer valid. type: number default: 3600 session_secret: description: The session secret. This must be a random string of 32 characters from the base64 alphabet (letters, numbers, `/`, `_` and `+`). It is used as the secret key for encrypting session data as well as state information that is sent to the IdP in the authentication exchange. type: string maxLength: 32 minLength: 32 x-encrypted: true x-referenceable: true session_storage: description: 'The session storage for session data: - `cookie`: stores session data with the session cookie. The session cannot be invalidated or revoked without changing the session secret, but is stateless, and doesn''t require a database. - `memcached`: stores session data in memcached - `redis`: stores session data in Redis' type: string default: cookie enum: - cookie - memcache - memcached - redis session_store_metadata: description: Configures whether or not session metadata should be stored. This includes information about the active sessions for the `specific_audience` belonging to a specific subject. type: boolean default: false validate_assertion_signature: description: Enable signature validation for SAML responses. type: boolean default: true required: - assertion_consumer_path - idp_sso_url - issuer - session_secret name: const: saml protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config AiRateLimitingAdvancedPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/AiRateLimitingAdvancedPluginConfig' ZipkinPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/ZipkinPluginConfig' AiCustomGuardrailPluginConfig: x-speakeasy-entity: PluginAiCustomGuardrail properties: config: type: object properties: allow_masking: description: Allow to masking the request/response instead of blocking it. Streaming will be disabled if this is enabled. type: boolean default: false custom_metrics: description: A list of custom metrics to be recorded. type: object additionalProperties: type: string functions: description: Custom functions to be used in expression templates. type: object additionalProperties: type: string x-lua-required: true guarding_mode: description: The guardrail mode to use for the request type: string default: INPUT enum: - BOTH - INPUT - OUTPUT metrics: type: object properties: block_detail: description: Metric to indicate the detail for blocking the input. type: string block_reason: description: Metric to indicate the reason for blocking the input. type: string masked: description: Metric to indicate whether the input was masked. type: string params: description: Parameters to be used in the guardrail service request. Keys are the parameter name and values can be either Lua expressions in the form `$(some_lua_expression)`or string. For expression, it will be evaluated as the value for the corresponding key. For string, it will be attempted to be parsed as string in JSON format, otherwise it will be used as is. type: object additionalProperties: type: string x-lua-required: true x-referenceable: true request: description: Configuration specific to guardrail request. type: object properties: auth: description: Authentication configuration for HTTP request. type: object properties: location: description: Specify whether the 'param_name' and 'param_value' options go in a query string, or the POST form/JSON body. type: string default: header enum: - body - header - query name: description: Specify name here. type: string x-referenceable: true value: description: Specify the full token value for 'name'. type: string x-encrypted: true x-referenceable: true body: description: A map used to evaluate a JSON object. Keys are the field names in the new object, and values can be either Lua expressions in the form `$(some_lua_expression)`or string. For expression, it will be evaluated as the value for the corresponding key. For string, it will be decoded as string in JSON format or be used as is. type: object additionalProperties: type: string x-referenceable: true headers: description: A map used to evaluate a JSON object. Keys are the field names in the new object, and values can be either Lua expressions in the form `$(some_lua_expression)`or string. For expression, it will be evaluated as the value for the corresponding key. For string, it will be decoded as string in JSON format or be used as is. type: object additionalProperties: type: string x-referenceable: true queries: description: A map used to evaluate a JSON object. Keys are the field names in the new object, and values can be either Lua expressions in the form `$(some_lua_expression)`or string. For expression, it will be evaluated as the value for the corresponding key. For string, it will be decoded as string in JSON format or be used as is. type: object additionalProperties: type: string x-referenceable: true url: description: the url string or a template to generate one type: string required: - url response: description: Configuration specific to parse guardrail response. type: object properties: block: description: template or string to evaluate block field type: string block_message: description: template or string to evaluate block_message field type: string required: - block - block_message response_buffer_size: description: The amount of bytes receiving from upstream to be buffered before sending to the guardrail service. This only applies to the response content guard. type: number default: 100 ssl_verify: description: Whether to verify SSL certificate when Kong makes request to guardrail service. type: boolean default: true stop_on_error: description: Stop processing if an error occurs. type: boolean default: true text_source: description: Select where to pick the 'text' for the guardrail service request. type: string default: last_message enum: - concatenate_all_content - concatenate_user_content - last_message timeout: description: Connection timeout with the guardrail service type: number default: 10000 required: - request - response consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: ai-custom-guardrail protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config BasicAuthPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/BasicAuthPluginConfig' RouteTransformerAdvancedPluginConfig: x-speakeasy-entity: PluginRouteTransformerAdvanced properties: config: type: object properties: escape_path: type: boolean default: false host: type: string path: type: string port: type: string consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string name: const: route-transformer-advanced protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string ProxyCachePlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/ProxyCachePluginConfig' DatakitPluginConfig: x-speakeasy-entity: PluginDatakit properties: config: type: object properties: debug: type: boolean default: false nodes: type: array items: oneOf: - description: Execute different nodes based on some input condition properties: else: description: nodes to execute if the input condition is `false` type: array items: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. maxLength: 255 minLength: 1 type: string maxLength: 64 minLength: 1 input: description: branch node input type: string maxLength: 255 minLength: 1 name: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. type: string maxLength: 255 minLength: 1 x-lua-required: true output: description: branch node output type: string maxLength: 255 minLength: 1 outputs: description: branch node outputs type: object properties: else: description: node output type: string maxLength: 255 minLength: 1 then: description: node output type: string maxLength: 255 minLength: 1 then: description: nodes to execute if the input condition is `true` type: array items: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. maxLength: 255 minLength: 1 type: string maxLength: 64 minLength: 1 type: type: string enum: - branch x-terraform-transform-const: true title: branch type: object - description: Fetch cached data properties: bypass_on_error: type: boolean input: description: cache node input type: string maxLength: 255 minLength: 1 inputs: description: cache node inputs type: object properties: data: description: The data to be cached. type: string maxLength: 255 minLength: 1 key: description: The cache key. type: string maxLength: 255 minLength: 1 ttl: description: The TTL in seconds. type: string maxLength: 255 minLength: 1 name: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. type: string maxLength: 255 minLength: 1 x-lua-required: true output: description: cache node output type: string maxLength: 255 minLength: 1 outputs: description: cache node outputs type: object properties: data: description: The data that was cached. type: string maxLength: 255 minLength: 1 hit: description: Signals a cache hit. type: string maxLength: 255 minLength: 1 miss: description: Signals a cache miss. type: string maxLength: 255 minLength: 1 stored: description: Signals whether data was stored in cache. type: string maxLength: 255 minLength: 1 ttl: type: integer type: type: string enum: - cache x-terraform-transform-const: true title: cache type: object - description: Make an external HTTP request properties: input: description: call node input type: string maxLength: 255 minLength: 1 inputs: description: call node inputs type: object properties: body: description: HTTP request body type: string maxLength: 255 minLength: 1 headers: description: HTTP request headers type: string maxLength: 255 minLength: 1 http_proxy: description: The HTTP proxy URL. This proxy server will be used for HTTP requests. type: string maxLength: 255 minLength: 1 https_proxy: description: The HTTPS proxy URL. This proxy server will be used for HTTPS requests. type: string maxLength: 255 minLength: 1 proxy_auth_password: description: The password to authenticate with, if the forward proxy is protected by basic authentication. type: string maxLength: 255 minLength: 1 proxy_auth_username: description: The username to authenticate with, if the forward proxy is protected by basic authentication. type: string maxLength: 255 minLength: 1 query: description: HTTP request query type: string maxLength: 255 minLength: 1 url: description: HTTP request URL type: string maxLength: 255 minLength: 1 method: description: A string representing an HTTP method, such as GET, POST, PUT, or DELETE. The string must contain only uppercase letters. type: string default: GET maxLength: 32 minLength: 1 name: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. type: string maxLength: 255 minLength: 1 x-lua-required: true output: description: call node output type: string maxLength: 255 minLength: 1 outputs: description: call node outputs type: object properties: body: description: HTTP response body type: string maxLength: 255 minLength: 1 headers: description: HTTP response headers type: string maxLength: 255 minLength: 1 raw_body: description: The raw, non-decoded HTTP response body type: string maxLength: 255 minLength: 1 status: description: HTTP response status code type: string maxLength: 255 minLength: 1 ssl_server_name: description: A string representing an SNI (server name indication) value for TLS. type: string ssl_verify: description: Whether to verify the TLS certificate when making HTTPS requests. type: boolean default: true timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer maximum: 2147483646 minimum: 0 type: type: string enum: - call x-terraform-transform-const: true url: description: A string representing a URL, such as https://example.com/path/to/resource?q=search. type: string title: call type: object - description: Terminate the request and send a response to the client properties: input: description: exit node input type: string maxLength: 255 minLength: 1 inputs: description: exit node inputs type: object properties: body: description: HTTP response body type: string maxLength: 255 minLength: 1 headers: description: HTTP response headers type: string maxLength: 255 minLength: 1 name: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. type: string maxLength: 255 minLength: 1 x-lua-required: true status: description: HTTP status code type: integer default: 200 maximum: 599 minimum: 200 type: type: string enum: - exit x-terraform-transform-const: true warn_headers_sent: type: boolean title: exit type: object - description: Process data using `jq` syntax properties: input: description: filter input(s) type: string maxLength: 255 minLength: 1 inputs: description: filter input(s) type: object additionalProperties: maxLength: 255 minLength: 1 type: string jq: description: The jq filter text. Refer to https://jqlang.org/manual/ for full documentation. type: string maxLength: 10240 minLength: 1 name: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. type: string maxLength: 255 minLength: 1 x-lua-required: true output: description: filter output(s) type: string maxLength: 255 minLength: 1 type: type: string enum: - jq x-terraform-transform-const: true required: - jq title: jq type: object - description: transform JSON or lua table to XML properties: attributes_block_name: type: string maxLength: 32 minLength: 1 attributes_name_prefix: type: string maxLength: 32 minLength: 1 input: description: JSON string or table type: string maxLength: 255 minLength: 1 inputs: description: JSON string or table type: object additionalProperties: maxLength: 255 minLength: 1 type: string name: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. type: string maxLength: 255 minLength: 1 x-lua-required: true output: description: XML document converted from JSON type: string maxLength: 255 minLength: 1 root_element_name: type: string maxLength: 64 minLength: 1 text_block_name: description: The name of the block to treat as XML text content. type: string default: '#text' maxLength: 32 minLength: 1 type: type: string enum: - json_to_xml x-terraform-transform-const: true title: json_to_xml type: object - description: Decode JWT without signature verification properties: input: description: JWT token (with or without Bearer prefix) type: string maxLength: 255 minLength: 1 name: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. type: string maxLength: 255 minLength: 1 x-lua-required: true output: description: jwt_decode node output type: string maxLength: 255 minLength: 1 outputs: description: jwt_decode node outputs type: object properties: header: description: Decoded JWT header (alg, kid, typ) type: string maxLength: 255 minLength: 1 payload: description: Decoded JWT payload (claims) type: string maxLength: 255 minLength: 1 signature: description: Raw signature (base64url encoded) type: string maxLength: 255 minLength: 1 type: type: string enum: - jwt_decode x-terraform-transform-const: true title: jwt_decode type: object - description: Create and sign a JWT properties: algorithm: description: Signing algorithm type: string enum: - ES256 - ES384 - ES512 - EdDSA - HS256 - HS384 - HS512 - PS256 - PS384 - PS512 - RS256 - RS384 - RS512 expires_in: description: Seconds until token expires (for exp claim) type: integer default: 300 input: description: jwt_sign node input type: string maxLength: 255 minLength: 1 inputs: description: jwt_sign node inputs type: object properties: claims: description: Dynamic claims to include type: string maxLength: 255 minLength: 1 key: description: Signing key (PEM, JWK JSON string, or HMAC secret) type: string maxLength: 255 minLength: 1 kid: description: Key ID for header type: string name: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. type: string maxLength: 255 minLength: 1 x-lua-required: true not_before: description: Seconds until token becomes valid (for nbf claim) type: integer default: 0 output: description: jwt_sign node output type: string maxLength: 255 minLength: 1 outputs: description: jwt_sign node outputs type: object properties: claims: description: Complete claims used type: string maxLength: 255 minLength: 1 header: description: JWT header type: string maxLength: 255 minLength: 1 token: description: Signed JWT type: string maxLength: 255 minLength: 1 static_claims: description: Static claims always included type: object default: {} additionalProperties: type: string typ: description: Token type for header type: string default: JWT type: type: string enum: - jwt_sign x-terraform-transform-const: true required: - algorithm title: jwt_sign type: object - description: Verify JWT signature and validate claims properties: allowed_algorithms: description: Allowed signing algorithms (empty = any supported) type: array items: enum: - ES256 - ES384 - ES512 - EdDSA - HS256 - HS384 - HS512 - PS256 - PS384 - PS512 - RS256 - RS384 - RS512 type: string default: [] audiences: description: Allowed audiences (empty = any) type: array items: type: string default: [] input: description: jwt_verify node input type: string maxLength: 255 minLength: 1 inputs: description: jwt_verify node inputs type: object properties: key: description: 'Verification key: JWKS, JWK, PEM string, or HMAC secret' type: string maxLength: 255 minLength: 1 token: description: JWT token (with or without Bearer prefix) type: string maxLength: 255 minLength: 1 issuers: description: Allowed issuers (empty = any) type: array items: type: string default: [] leeway: description: Allowed clock skew in seconds for exp/nbf validation type: integer default: 0 name: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. type: string maxLength: 255 minLength: 1 x-lua-required: true output: description: jwt_verify node output type: string maxLength: 255 minLength: 1 outputs: description: jwt_verify node outputs type: object properties: claims: description: JWT payload claims type: string maxLength: 255 minLength: 1 header: description: JWT header type: string maxLength: 255 minLength: 1 required_claims: description: Claims that must be present type: array items: type: string default: [] type: type: string enum: - jwt_verify x-terraform-transform-const: true validate_exp: description: Validate expiration claim type: boolean default: true validate_nbf: description: Validate not-before claim type: boolean default: true title: jwt_verify type: object - description: Get or set a property properties: content_type: description: The expected mime type of the property value. When set to `application/json`, SET operations will JSON-encode input data before writing it, and GET operations will JSON-decode output data after reading it. Otherwise, this setting has no effect. type: string enum: - application/json - application/octet-stream - text/plain input: description: Property input source. When connected, this node operates in SET mode and writes input data to the property. Otherwise, the node operates in GET mode and reads the property. type: string maxLength: 255 minLength: 1 name: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. type: string maxLength: 255 minLength: 1 x-lua-required: true output: description: Property output. This can be connected regardless of whether the node is operating in GET mode or SET mode. type: string maxLength: 255 minLength: 1 property: description: The property name to get/set type: string maxLength: 255 minLength: 1 type: type: string enum: - property x-terraform-transform-const: true required: - property title: property type: object - description: Produce reusable outputs from statically-configured values properties: name: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. type: string maxLength: 255 minLength: 1 x-lua-required: true output: description: The entire `.values` map type: string maxLength: 255 minLength: 1 outputs: description: Individual items from `.values`, referenced by key type: object additionalProperties: maxLength: 255 minLength: 1 type: string type: type: string enum: - static x-terraform-transform-const: true values: description: An object with string keys and freeform values type: object additionalProperties: true x-speakeasy-type-override: any required: - values title: static type: object - description: convert XML to JSON properties: attributes_block_name: type: string maxLength: 32 minLength: 1 attributes_name_prefix: type: string maxLength: 32 minLength: 1 input: description: XML document string type: string maxLength: 255 minLength: 1 name: description: A label that uniquely identifies the node within the plugin configuration so that it can be used for input/output connections. Must be valid `snake_case` or `kebab-case`. type: string maxLength: 255 minLength: 1 x-lua-required: true output: description: a map object converted from XML document. If connected to `request.body` or `response.body`, the output will be a JSON object. type: string maxLength: 255 minLength: 1 recognize_type: type: boolean default: true text_as_property: type: boolean default: false text_block_name: type: string default: '#text' maxLength: 32 minLength: 1 type: type: string enum: - xml_to_json x-terraform-transform-const: true xpath: type: string maxLength: 256 minLength: 1 title: xml_to_json type: object maxLength: 64 minLength: 1 resources: type: object properties: cache: type: object properties: memory: type: object properties: dictionary_name: description: The name of the shared dictionary in which to hold cache entities when the memory strategy is selected. Note that this dictionary currently must be defined manually in the Kong Nginx template. type: string default: kong_db_cache redis: type: object properties: cloud_authentication: description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance. type: object properties: auth_provider: description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance. type: string enum: - aws - azure - gcp x-referenceable: true aws_access_key_id: description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true aws_assume_role_arn: description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens. type: string x-encrypted: true x-referenceable: true aws_cache_name: description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_is_serverless: description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`. type: boolean default: true aws_region: description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`. type: string x-referenceable: true aws_role_session_name: description: The session name for the temporary credentials when assuming the IAM role. type: string x-encrypted: true x-referenceable: true aws_secret_access_key: description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`. type: string x-encrypted: true x-referenceable: true azure_client_id: description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_client_secret: description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true azure_tenant_id: description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`. type: string x-encrypted: true x-referenceable: true gcp_service_account_json: description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`. type: string x-encrypted: true x-referenceable: true cluster_max_redirections: description: Maximum retry attempts for redirection. type: integer default: 5 cluster_nodes: description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. type: array items: properties: ip: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 connect_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 connection_is_proxied: description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address. type: boolean default: false database: description: Database to use for the Redis connection when using the `redis` strategy type: integer default: 0 host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 x-referenceable: true keepalive_backlog: description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`. type: integer maximum: 2147483646 minimum: 0 keepalive_pool_size: description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. type: integer default: 256 maximum: 2147483646 minimum: 1 password: description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis. type: string x-encrypted: true x-referenceable: true port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 x-referenceable: true read_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 send_timeout: description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. type: integer default: 2000 maximum: 2147483646 minimum: 0 sentinel_master: description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel. type: string sentinel_nodes: description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. type: array items: properties: host: description: A string representing a host name, such as example.com. type: string default: 127.0.0.1 port: description: An integer representing a port number between 0 and 65535, inclusive. type: integer default: 6379 maximum: 65535 minimum: 0 type: object minLength: 1 sentinel_password: description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels. type: string x-encrypted: true x-referenceable: true sentinel_role: description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel. type: string enum: - any - master - slave sentinel_username: description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+. type: string x-referenceable: true server_name: description: A string representing an SNI (server name indication) value for TLS. type: string x-referenceable: true ssl: description: If set to true, uses SSL to connect to Redis. type: boolean default: false ssl_verify: description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly. type: boolean default: true username: description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`. type: string x-referenceable: true strategy: description: 'The backing data store in which to hold cache entities. Accepted values are: `memory` and `redis`.' type: string enum: - memory - redis vault: type: object additionalProperties: maxLength: 4095 minLength: 1 type: string x-lua-required: true x-referenceable: true maxLength: 64 minLength: 1 required: - nodes consumer: description: If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer. type: object additionalProperties: false properties: id: type: string consumer_group: description: If set, the plugin will activate only for requests where the specified consumer group has been authenticated. (Note that some plugins can not be restricted to consumers groups this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer Groups type: object additionalProperties: false properties: id: type: string name: const: datakit protocols: description: A set of strings representing HTTP protocols. type: array items: enum: - grpc - grpcs - http - https type: string format: set default: - grpc - grpcs - http - https route: description: If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used. type: object additionalProperties: false properties: id: type: string service: description: If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched. type: object additionalProperties: false properties: id: type: string required: - config RouteByHeaderPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/RouteByHeaderPluginConfig' JwtPlugin: allOf: - $ref: '#/components/schemas/PluginBase' - $ref: '#/components/schemas/JwtPluginConfig' parameters: PaginationOffset: allowEmptyValue: true description: Offset from which to return the next set of resources. Use the value of the 'offset' field from the response of a list operation as input here to paginate through all the resources in: query name: offset schema: type: string ConsumerGroupId: description: ID of the Consumer Group to lookup example: '' in: path name: ConsumerGroupId required: true schema: type: string Workspace: description: The name of the workspace in: path name: workspace required: true schema: type: string example: team-payments default: default PaginationTagsFilter: allowEmptyValue: true description: A list of tags to filter the list of resources on. Multiple tags can be concatenated using ',' to mean AND or using '/' to mean OR. example: tag1,tag2 in: query name: tags schema: type: string PaginationSize: description: Number of resources to be returned. in: query name: size schema: type: integer default: 100 maximum: 1000 minimum: 1 PluginId_2: description: ID of the Plugin to lookup example: 3473c251-5b6c-4f45-b1ff-7ede735a366d in: path name: PluginId required: true schema: type: string ExpandPartials: description: Expand partials for the plugin. example: true in: query name: expand_partials schema: type: boolean ConsumerIdForNestedEntities: description: Consumer ID for nested entities example: '' in: path name: ConsumerIdForNestedEntities required: true schema: type: string RouteId: description: ID of the Route to lookup example: a4326a41-aa12-44e3-93e4-6b6e58bfb9d7 in: path name: RouteId required: true schema: type: string PluginId: description: ID of the Plugin to lookup example: 3473c251-5b6c-4f45-b1ff-7ede735a366d in: path name: PluginId required: true schema: type: string x-speakeasy-match: id NameEqualsFilter: description: Filter routes by their name. example: john in: query name: filter[name][eq] schema: type: string ServiceId: description: ID of the Service to lookup example: 7fca84d6-7d37-4a74-a7b0-93e576089a41 in: path name: ServiceId required: true schema: type: string NameContainsFilter: description: Filter routes by a substring of the name. example: john in: query name: filter[name][contains] schema: type: string controlPlaneId: name: controlPlaneId in: path required: true schema: type: string format: uuid example: 9524ec7d-36d9-465d-a8c5-83a3c9390458 description: The UUID of your control plane. This variable is available in the Konnect manager. x-speakeasy-param-force-new: true responses: HTTP401Error: description: Unauthorized content: application/json: examples: DuplicateApiKey: summary: Duplicate API key found value: message: Duplicate API key found status: 401 InvalidAuthCred: summary: Invalid authentication credentials value: message: Unauthorized status: 401 NoAPIKey: summary: No API key found value: message: No API key found in request status: 401 schema: $ref: '#/components/schemas/GatewayUnauthorizedError' HTTP401Error_2: description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/GatewayUnauthorizedError' GetPluginSchemaResponse: description: The schema for the plugin content: application/json: schema: type: object properties: fields: type: array items: additionalProperties: true type: object securitySchemes: adminToken: in: header name: Kong-Admin-Token type: apiKey externalDocs: description: Documentation for Kong Gateway and its APIs url: https://developer.konghq.com