generated: '2026-07-15' method: generated source: openapi/opensearch-security-openapi.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 47 by_action_class: connected: 20 acting: 27 by_consequence: read: 20 write: 27 human_in_the_loop_required: 0 operations: - path: /_plugins/_security/api/account method: get operationId: getAccount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/account method: put operationId: changePassword x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/internalusers method: get operationId: listInternalUsers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/internalusers/{username} method: get operationId: getInternalUser x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/internalusers/{username} method: put operationId: createOrReplaceInternalUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/internalusers/{username} method: delete operationId: deleteInternalUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/internalusers/{username} method: patch operationId: patchInternalUser x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/roles method: get operationId: listRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/roles/{name} method: get operationId: getRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/roles/{name} method: put operationId: createOrReplaceRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/roles/{name} method: delete operationId: deleteRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/roles/{name} method: patch operationId: patchRole x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/rolesmapping method: get operationId: listRoleMappings x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/rolesmapping/{name} method: get operationId: getRoleMapping x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/rolesmapping/{name} method: put operationId: createOrReplaceRoleMapping x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/rolesmapping/{name} method: delete operationId: deleteRoleMapping x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/rolesmapping/{name} method: patch operationId: patchRoleMapping x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/actiongroups method: get operationId: listActionGroups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/actiongroups/{name} method: get operationId: getActionGroup x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/actiongroups/{name} method: put operationId: createOrReplaceActionGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/actiongroups/{name} method: delete operationId: deleteActionGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/actiongroups/{name} method: patch operationId: patchActionGroup x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/tenants method: get operationId: listTenants x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/tenants/{name} method: get operationId: getTenant x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/tenants/{name} method: put operationId: createOrReplaceTenant x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/tenants/{name} method: delete operationId: deleteTenant x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/tenants/{name} method: patch operationId: patchTenant x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/securityconfig method: get operationId: getSecurityConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/securityconfig method: patch operationId: patchSecurityConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/securityconfig/config method: put operationId: replaceSecurityConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/audit method: get operationId: getAuditConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/audit/config method: put operationId: replaceAuditConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/audit/config method: patch operationId: patchAuditConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/allowlist method: get operationId: getAllowlist x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/allowlist method: put operationId: replaceAllowlist x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/allowlist method: patch operationId: patchAllowlist x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/nodesdn method: get operationId: listNodesDn x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/nodesdn/{name} method: get operationId: getNodesDn x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/nodesdn/{name} method: put operationId: createOrReplaceNodesDn x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/nodesdn/{name} method: delete operationId: deleteNodesDn x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/ssl/certs method: get operationId: getCertificates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/api/ssl/transport/reloadcerts method: put operationId: reloadTransportCerts x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/ssl/http/reloadcerts method: put operationId: reloadHttpCerts x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/api/cache method: delete operationId: flushSecurityCache x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /_plugins/_security/health method: get operationId: securityHealth x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/authinfo method: get operationId: authInfo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /_plugins/_security/sslinfo method: get operationId: sslInfo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none