generated: '2026-07-15' method: generated source: openapi/logto-openapi-original.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 335 by_action_class: connected: 112 acting: 223 by_consequence: read: 112 write: 212 safety-critical: 6 physical: 5 human_in_the_loop_required: 6 operations: - path: /api/applications method: get operationId: ListApplications x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/applications method: post operationId: CreateApplication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{id} method: get operationId: GetApplication x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/applications/{id} method: patch operationId: UpdateApplication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{id} method: delete operationId: DeleteApplication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{applicationId}/custom-data method: patch operationId: UpdateApplicationCustomData x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{applicationId}/roles method: get operationId: ListApplicationRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/applications/{applicationId}/roles method: post operationId: AssignApplicationRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{applicationId}/roles method: put operationId: ReplaceApplicationRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{applicationId}/roles/{roleId} method: delete operationId: DeleteApplicationRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{id}/protected-app-metadata/custom-domains method: get operationId: ListApplicationProtectedAppMetadataCustomDomains x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/applications/{id}/protected-app-metadata/custom-domains method: post operationId: CreateApplicationProtectedAppMetadataCustomDomain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{id}/protected-app-metadata/custom-domains/{domain} method: delete operationId: DeleteApplicationProtectedAppMetadataCustomDomain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{id}/organizations method: get operationId: ListApplicationOrganizations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/applications/{id}/legacy-secret method: delete operationId: DeleteApplicationLegacySecret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{id}/secrets method: get operationId: ListApplicationSecrets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/applications/{id}/secrets method: post operationId: CreateApplicationSecret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{id}/secrets/{name} method: delete operationId: DeleteApplicationSecret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{id}/secrets/{name} method: patch operationId: UpdateApplicationSecret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{applicationId}/user-consent-scopes method: post operationId: CreateApplicationUserConsentScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{applicationId}/user-consent-scopes method: get operationId: ListApplicationUserConsentScopes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/applications/{applicationId}/user-consent-scopes/{scopeType}/{scopeId} method: delete operationId: DeleteApplicationUserConsentScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{applicationId}/sign-in-experience method: put operationId: ReplaceApplicationSignInExperience x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{applicationId}/sign-in-experience method: get operationId: GetApplicationSignInExperience x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/applications/{id}/users/{userId}/consent-organizations method: get operationId: ListApplicationUserConsentOrganizations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/applications/{id}/users/{userId}/consent-organizations method: put operationId: ReplaceApplicationUserConsentOrganizations x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{id}/users/{userId}/consent-organizations method: post operationId: CreateApplicationUserConsentOrganization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/applications/{id}/users/{userId}/consent-organizations/{organizationId} method: delete operationId: DeleteApplicationUserConsentOrganization x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required scope: - all - path: /api/configs/admin-console method: get operationId: GetAdminConsoleConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/configs/admin-console method: patch operationId: UpdateAdminConsoleConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/configs/oidc/session method: get operationId: GetOidcSessionConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/configs/oidc/session method: patch operationId: UpdateOidcSessionConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/configs/oidc/{keyType} method: get operationId: GetOidcKeys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/configs/oidc/{keyType}/{keyId} method: delete operationId: DeleteOidcKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/configs/oidc/{keyType}/rotate method: post operationId: RotateOidcKeys x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/configs/jwt-customizer/{tokenTypePath} method: put operationId: UpsertJwtCustomizer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/configs/jwt-customizer/{tokenTypePath} method: patch operationId: UpdateJwtCustomizer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/configs/jwt-customizer/{tokenTypePath} method: get operationId: GetJwtCustomizer x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/configs/jwt-customizer/{tokenTypePath} method: delete operationId: DeleteJwtCustomizer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/configs/jwt-customizer method: get operationId: ListJwtCustomizers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/configs/jwt-customizer/test method: post operationId: TestJwtCustomizer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/configs/id-token method: get operationId: GetIdTokenConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/configs/id-token method: put operationId: UpsertIdTokenConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/connectors method: post operationId: CreateConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/connectors method: get operationId: ListConnectors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/connectors/{id} method: get operationId: GetConnector x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/connectors/{id} method: patch operationId: UpdateConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/connectors/{id} method: delete operationId: DeleteConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/connectors/{factoryId}/test method: post operationId: CreateConnectorTest x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/connectors/{connectorId}/authorization-uri method: post operationId: CreateConnectorAuthorizationUri x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/connector-factories method: get operationId: ListConnectorFactories x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/connector-factories/{id} method: get operationId: GetConnectorFactory x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/resources method: get operationId: ListResources x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/resources method: post operationId: CreateResource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/resources/{id} method: get operationId: GetResource x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/resources/{id} method: patch operationId: UpdateResource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/resources/{id} method: delete operationId: DeleteResource x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/resources/{id}/is-default method: patch operationId: UpdateResourceIsDefault x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/resources/{resourceId}/scopes method: get operationId: ListResourceScopes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/resources/{resourceId}/scopes method: post operationId: CreateResourceScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/resources/{resourceId}/scopes/{scopeId} method: patch operationId: UpdateResourceScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/resources/{resourceId}/scopes/{scopeId} method: delete operationId: DeleteResourceScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/sign-in-exp method: get operationId: GetSignInExp x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/sign-in-exp method: patch operationId: UpdateSignInExp x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/sign-in-exp/default/check-password method: post operationId: CheckPasswordWithDefaultSignInExperience x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/sign-in-exp/default/custom-ui-assets method: post operationId: UploadCustomUiAssets x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId} method: get operationId: GetUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId} method: patch operationId: UpdateUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId} method: delete operationId: DeleteUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/custom-data method: get operationId: ListUserCustomData x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/custom-data method: patch operationId: UpdateUserCustomData x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/logto-configs method: get operationId: ListUserLogtoConfigs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/logto-configs method: patch operationId: UpdateUserLogtoConfigs x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/profile method: patch operationId: UpdateUserProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users method: post operationId: CreateUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users method: get operationId: ListUsers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/password method: patch operationId: UpdateUserPassword x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/password/verify method: post operationId: VerifyUserPassword x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/has-password method: get operationId: GetUserHasPassword x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/is-suspended method: patch operationId: UpdateUserIsSuspended x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/roles method: get operationId: ListUserRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/roles method: post operationId: AssignUserRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/roles method: put operationId: ReplaceUserRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/roles/{roleId} method: delete operationId: DeleteUserRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/identities/{target} method: put operationId: ReplaceUserIdentity x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/identities/{target} method: delete operationId: DeleteUserIdentity x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/identities/{target} method: get operationId: GetUserIdentity x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/identities method: post operationId: CreateUserIdentity x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/organizations method: get operationId: ListUserOrganizations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/grants method: get operationId: ListUserGrants x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/grants/{grantId} method: delete operationId: DeleteUserGrant x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required scope: - all - path: /api/users/{userId}/mfa-verifications method: get operationId: ListUserMfaVerifications x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/mfa-verifications method: post operationId: CreateUserMfaVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/mfa-verifications/{verificationId} method: delete operationId: DeleteUserMfaVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/personal-access-tokens method: get operationId: ListUserPersonalAccessTokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/personal-access-tokens method: post operationId: CreateUserPersonalAccessToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/personal-access-tokens method: patch operationId: UpdatePersonalAccessTokenName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/personal-access-tokens/{name} method: delete operationId: DeleteUserPersonalAccessToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/personal-access-tokens/{name} method: patch operationId: UpdateUserPersonalAccessToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/personal-access-tokens/delete method: post operationId: DeletePersonalAccessTokenPost x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/users/{userId}/sso-identities/{ssoConnectorId} method: get operationId: GetUserSsoIdentity x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/all-identities method: get operationId: ListUserAllIdentities x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/sessions method: get operationId: ListUserSessions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/sessions/{sessionId} method: get operationId: GetUserSession x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/users/{userId}/sessions/{sessionId} method: delete operationId: DeleteUserSession x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required scope: - all - path: /api/logs method: get operationId: ListLogs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/logs/{id} method: get operationId: GetLog x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/roles method: get operationId: ListRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/roles method: post operationId: CreateRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/roles/{id} method: get operationId: GetRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/roles/{id} method: patch operationId: UpdateRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/roles/{id} method: delete operationId: DeleteRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/roles/{id}/users method: get operationId: ListRoleUsers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/roles/{id}/users method: post operationId: CreateRoleUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/roles/{id}/users/{userId} method: delete operationId: DeleteRoleUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/roles/{id}/applications method: get operationId: ListRoleApplications x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/roles/{id}/applications method: post operationId: CreateRoleApplication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/roles/{id}/applications/{applicationId} method: delete operationId: DeleteRoleApplication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/roles/{id}/scopes method: get operationId: ListRoleScopes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/roles/{id}/scopes method: post operationId: CreateRoleScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/roles/{id}/scopes/{scopeId} method: delete operationId: DeleteRoleScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/dashboard/users/total method: get operationId: GetTotalUserCount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/dashboard/users/new method: get operationId: GetNewUserCounts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/dashboard/users/active method: get operationId: GetActiveUserCounts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/custom-phrases method: get operationId: ListCustomPhrases x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/custom-phrases/{languageTag} method: get operationId: GetCustomPhrase x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/custom-phrases/{languageTag} method: put operationId: ReplaceCustomPhrase x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/custom-phrases/{languageTag} method: delete operationId: DeleteCustomPhrase x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/hooks method: get operationId: ListHooks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/hooks method: post operationId: CreateHook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/hooks/{id} method: get operationId: GetHook x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/hooks/{id} method: patch operationId: UpdateHook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/hooks/{id} method: delete operationId: DeleteHook x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/hooks/{id}/recent-logs method: get operationId: ListHookRecentLogs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/hooks/{id}/test method: post operationId: CreateHookTest x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/hooks/{id}/signing-key method: patch operationId: UpdateHookSigningKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/verification-codes method: post operationId: CreateVerificationCode x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/verification-codes/verify method: post operationId: VerifyVerificationCode x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/user-assets/service-status method: get operationId: GetUserAssetServiceStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/user-assets method: post operationId: CreateUserAsset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/domains method: get operationId: ListDomains x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/domains method: post operationId: CreateDomain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/domains/{id} method: get operationId: GetDomain x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/domains/{id} method: delete operationId: DeleteDomain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/domains/cleanup method: post operationId: CleanupDomains x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-roles/{id} method: get operationId: GetOrganizationRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organization-roles/{id} method: patch operationId: UpdateOrganizationRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-roles/{id} method: delete operationId: DeleteOrganizationRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-roles method: get operationId: ListOrganizationRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organization-roles method: post operationId: CreateOrganizationRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-roles/{id}/scopes method: get operationId: ListOrganizationRoleScopes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organization-roles/{id}/scopes method: post operationId: CreateOrganizationRoleScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-roles/{id}/scopes method: put operationId: ReplaceOrganizationRoleScopes x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-roles/{id}/scopes/{organizationScopeId} method: delete operationId: DeleteOrganizationRoleScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-roles/{id}/resource-scopes method: get operationId: ListOrganizationRoleResourceScopes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organization-roles/{id}/resource-scopes method: post operationId: CreateOrganizationRoleResourceScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-roles/{id}/resource-scopes method: put operationId: ReplaceOrganizationRoleResourceScopes x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-roles/{id}/resource-scopes/{scopeId} method: delete operationId: DeleteOrganizationRoleResourceScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-scopes method: get operationId: ListOrganizationScopes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organization-scopes method: post operationId: CreateOrganizationScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-scopes/{id} method: get operationId: GetOrganizationScope x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organization-scopes/{id} method: patch operationId: UpdateOrganizationScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-scopes/{id} method: delete operationId: DeleteOrganizationScope x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-invitations/{id} method: get operationId: GetOrganizationInvitation x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organization-invitations/{id} method: delete operationId: DeleteOrganizationInvitation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-invitations method: get operationId: ListOrganizationInvitations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organization-invitations method: post operationId: CreateOrganizationInvitation x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-invitations/{id}/message method: post operationId: CreateOrganizationInvitationMessage x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organization-invitations/{id}/status method: put operationId: ReplaceOrganizationInvitationStatus x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations method: post operationId: CreateOrganization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations method: get operationId: ListOrganizations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organizations/{id} method: get operationId: GetOrganization x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organizations/{id} method: patch operationId: UpdateOrganization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id} method: delete operationId: DeleteOrganization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/users method: get operationId: ListOrganizationUsers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organizations/{id}/users method: post operationId: AddOrganizationUsers x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/users method: put operationId: ReplaceOrganizationUsers x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/users/{userId} method: delete operationId: DeleteOrganizationUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/users/roles method: post operationId: AssignOrganizationRolesToUsers x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/users/{userId}/roles method: get operationId: ListOrganizationUserRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organizations/{id}/users/{userId}/roles method: post operationId: AssignOrganizationRolesToUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/users/{userId}/roles method: put operationId: ReplaceOrganizationUserRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/users/{userId}/roles/{organizationRoleId} method: delete operationId: DeleteOrganizationUserRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/users/{userId}/scopes method: get operationId: ListOrganizationUserScopes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organizations/{id}/applications method: post operationId: AddOrganizationApplications x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/applications method: put operationId: ReplaceOrganizationApplications x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/applications method: get operationId: ListOrganizationApplications x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organizations/{id}/applications/{applicationId} method: delete operationId: DeleteOrganizationApplication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/applications/roles method: post operationId: AssignOrganizationRolesToApplications x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/applications/{applicationId}/roles method: get operationId: ListOrganizationApplicationRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organizations/{id}/applications/{applicationId}/roles method: post operationId: AssignOrganizationRolesToApplication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/applications/{applicationId}/roles method: put operationId: ReplaceOrganizationApplicationRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/applications/{applicationId}/roles/{organizationRoleId} method: delete operationId: DeleteOrganizationApplicationRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/jit/email-domains method: get operationId: ListOrganizationJitEmailDomains x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organizations/{id}/jit/email-domains method: post operationId: CreateOrganizationJitEmailDomain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/jit/email-domains method: put operationId: ReplaceOrganizationJitEmailDomains x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/jit/email-domains/{emailDomain} method: delete operationId: DeleteOrganizationJitEmailDomain x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/jit/roles method: get operationId: ListOrganizationJitRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organizations/{id}/jit/roles method: post operationId: CreateOrganizationJitRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/jit/roles method: put operationId: ReplaceOrganizationJitRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/jit/roles/{organizationRoleId} method: delete operationId: DeleteOrganizationJitRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/jit/sso-connectors method: get operationId: ListOrganizationJitSsoConnectors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/organizations/{id}/jit/sso-connectors method: post operationId: CreateOrganizationJitSsoConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/jit/sso-connectors method: put operationId: ReplaceOrganizationJitSsoConnectors x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/organizations/{id}/jit/sso-connectors/{ssoConnectorId} method: delete operationId: DeleteOrganizationJitSsoConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/sso-connector-providers method: get operationId: ListSsoConnectorProviders x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/sso-connectors method: post operationId: CreateSsoConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/sso-connectors method: get operationId: ListSsoConnectors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/sso-connectors/{id} method: get operationId: GetSsoConnector x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/sso-connectors/{id} method: delete operationId: DeleteSsoConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/sso-connectors/{id} method: patch operationId: UpdateSsoConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/systems/application method: get operationId: GetSystemApplicationConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/subject-tokens method: post operationId: CreateSubjectToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/account-center method: get operationId: GetAccountCenterSettings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/account-center method: patch operationId: UpdateAccountCenterSettings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/saml-applications method: post operationId: CreateSamlApplication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/saml-applications/{id} method: get operationId: GetSamlApplication x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/saml-applications/{id} method: patch operationId: UpdateSamlApplication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/saml-applications/{id} method: delete operationId: DeleteSamlApplication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/saml-applications/{id}/secrets method: post operationId: CreateSamlApplicationSecret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/saml-applications/{id}/secrets method: get operationId: ListSamlApplicationSecrets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/saml-applications/{id}/secrets/{secretId} method: delete operationId: DeleteSamlApplicationSecret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/saml-applications/{id}/secrets/{secretId} method: patch operationId: UpdateSamlApplicationSecret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/email-templates method: put operationId: ReplaceEmailTemplates x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/email-templates method: get operationId: ListEmailTemplates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/email-templates method: delete operationId: DeleteEmailTemplates x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/email-templates/{id} method: get operationId: GetEmailTemplate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/email-templates/{id} method: delete operationId: DeleteEmailTemplate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/email-templates/{id}/details method: patch operationId: UpdateEmailTemplateDetails x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/one-time-tokens method: get operationId: ListOneTimeTokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/one-time-tokens method: post operationId: AddOneTimeTokens x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/one-time-tokens/{id} method: get operationId: GetOneTimeToken x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/one-time-tokens/{id} method: delete operationId: DeleteOneTimeToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/one-time-tokens/verify method: post operationId: VerifyOneTimeToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/one-time-tokens/{id}/status method: put operationId: ReplaceOneTimeTokenStatus x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/captcha-provider method: get operationId: GetCaptchaProvider x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/captcha-provider method: put operationId: UpdateCaptchaProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/captcha-provider method: delete operationId: DeleteCaptchaProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/sentinel-activities/delete method: post operationId: DeleteSentinelActivities x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/custom-profile-fields method: get operationId: ListCustomProfileFields x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/custom-profile-fields method: post operationId: CreateCustomProfileField x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/custom-profile-fields/{name} method: get operationId: GetCustomProfileFieldByName x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/custom-profile-fields/{name} method: put operationId: UpdateCustomProfileFieldByName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/custom-profile-fields/{name} method: delete operationId: DeleteCustomProfileFieldByName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/custom-profile-fields/batch method: post operationId: CreateCustomProfileFieldsBatch x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/custom-profile-fields/properties/sie-order method: post operationId: UpdateCustomProfileFieldsSieOrder x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/secrets/{id} method: delete operationId: DeleteSecret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/.well-known/sign-in-exp method: get operationId: GetSignInExperienceConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/.well-known/phrases method: get operationId: GetSignInExperiencePhrases x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/.well-known/experience method: get operationId: GetWellKnownExperience x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/.well-known/account-center method: get operationId: GetWellKnownAccountCenter x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/status method: get operationId: GetStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/authn/hasura method: get operationId: GetHasuraAuth x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/authn/saml/{connectorId} method: post operationId: AssertSaml x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/authn/single-sign-on/saml/{connectorId} method: post operationId: AssertSingleSignOnSaml x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/saml-applications/{id}/metadata method: get operationId: ListSamlApplicationMetadata x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/saml-applications/{id}/callback method: get operationId: GetSamlApplicationCallback x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/saml/{id}/authn method: get operationId: GetSamlAuthn x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/saml/{id}/authn method: post operationId: CreateSamlAuthn x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/.well-known/management.openapi.json method: get operationId: GetWellKnownManagementOpenapiJson x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/.well-known/experience.openapi.json method: get operationId: GetWellKnownExperienceOpenapiJson x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/.well-known/user.openapi.json method: get operationId: GetWellKnownUserOpenapiJson x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/swagger.json method: get operationId: GetSwaggerJson x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/experience method: put operationId: InitInteraction x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/interaction-event method: put operationId: UpdateInteractionEvent x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/identification method: post operationId: IdentifyUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/submit method: post operationId: SubmitInteraction x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/interaction method: get operationId: GetInteraction x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/experience/verification/password method: post operationId: CreatePasswordVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/verification-code method: post operationId: CreateAndSendVerificationCode x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/verification-code/verify method: post operationId: VerifyVerificationCodeVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/mfa-verification-code method: post operationId: CreateAndSendMfaVerificationCode x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/mfa-verification-code/verify method: post operationId: VerifyMfaVerificationCode x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/social/{connectorId}/authorization-uri method: post operationId: CreateSocialVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/social/{connectorId}/verify method: post operationId: VerifySocialVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/sso/{connectorId}/authorization-uri method: post operationId: CreateEnterpriseSsoVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/sso/{connectorId}/verify method: post operationId: VerifyEnterpriseSsoVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/totp/secret method: post operationId: CreateTotpSecret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/totp/verify method: post operationId: VerifyTotpVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/web-authn/registration method: post operationId: CreateWebAuthnRegistrationVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/web-authn/registration/verify method: post operationId: VerifyWebAuthnRegistrationVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/web-authn/authentication method: post operationId: CreateWebAuthnAuthenticationVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/web-authn/authentication/verify method: post operationId: VerifyWebAuthnAuthenticationVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/sign-in-passkey/authentication method: post operationId: CreateSignInPasskeyAuthenticationWithIdentifier x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/sign-in-passkey/authentication/verify method: post operationId: VerifySignInPasskeyAuthentication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/backup-code/generate method: post operationId: GenerateBackupCodes x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/backup-code/verify method: post operationId: VerifyBackupCode x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/new-password-identity method: post operationId: CreateNewPasswordIdentityVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/verification/one-time-token/verify method: post operationId: VerifyOneTimeTokenVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/profile method: post operationId: AddUserProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/profile/password method: put operationId: ResetUserPassword x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required scope: - all - path: /api/experience/profile/mfa/mfa-enabled method: post operationId: MarkMfaEnabled x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/profile/mfa/mfa-skipped method: post operationId: SkipMfaBindingFlow x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/profile/mfa/mfa-suggestion-skipped method: post operationId: SkipMfaSuggestion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/profile/mfa/passkey-skipped method: post operationId: SkipPasskeyBinding x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/profile/mfa/passkey method: post operationId: BindPasskey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/profile/mfa method: post operationId: BindMfaVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/experience/sso-connectors method: get operationId: GetEnabledSsoConnectors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/experience/preflight/sign-in-passkey/authentication method: post operationId: CreateSignInPasskeyAuthentication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account method: get operationId: GetProfile x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/my-account method: patch operationId: UpdateProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/profile method: patch operationId: UpdateOtherProfile x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/password method: post operationId: UpdatePassword x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/mfa-settings method: get operationId: GetMfaSettings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/my-account/mfa-settings method: patch operationId: UpdateMfaSettings x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/logto-configs method: get operationId: GetLogtoConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/my-account/logto-configs method: patch operationId: UpdateLogtoConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/identities/{target}/access-token method: get operationId: GetSocialIdentityAccessToken x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/my-account/identities/{target}/access-token method: put operationId: UpdateSocialIdentityAccessTokenByVerificationId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/sso-identities/{connectorId}/access-token method: get operationId: GetEnterpriseSsoIdentityAccessToken x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/my-account/primary-email method: post operationId: UpdatePrimaryEmail x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/primary-email method: delete operationId: DeletePrimaryEmail x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/primary-phone method: post operationId: UpdatePrimaryPhone x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/primary-phone method: delete operationId: DeletePrimaryPhone x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/identities method: post operationId: AddUserIdentities x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/identities/{target} method: delete operationId: DeleteIdentity x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/mfa-verifications method: get operationId: GetMfaVerifications x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/my-account/mfa-verifications method: post operationId: AddMfaVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/mfa-verifications/totp method: put operationId: CreateOrReplaceTotpMfaVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/mfa-verifications/totp-secret/generate method: post operationId: GenerateTotpSecret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/mfa-verifications/backup-codes/generate method: post operationId: GenerateMyAccountBackupCodes x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/mfa-verifications/backup-codes method: get operationId: GetBackupCodes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/my-account/mfa-verifications/{verificationId}/name method: patch operationId: UpdateMfaVerificationName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/mfa-verifications/{verificationId} method: delete operationId: DeleteMfaVerification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/my-account/sessions method: get operationId: GetSessions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/my-account/sessions/{sessionId} method: delete operationId: DeleteSessionById x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required scope: - all - path: /api/my-account/grants method: get operationId: GetGrants x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none scope: - all - path: /api/my-account/grants/{grantId} method: delete operationId: DeleteGrantById x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required scope: - all - path: /api/verifications/password method: post operationId: CreateVerificationByPassword x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/verifications/verification-code method: post operationId: CreateVerificationByVerificationCode x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/verifications/verification-code/verify method: post operationId: VerifyVerificationByVerificationCode x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/verifications/social method: post operationId: CreateVerificationBySocial x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/verifications/social/verify method: post operationId: VerifyVerificationBySocial x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/verifications/web-authn/registration method: post operationId: GenerateWebAuthnRegistrationOptions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all - path: /api/verifications/web-authn/registration/verify method: post operationId: VerifyWebAuthnRegistration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required scope: - all