openapi: 3.2.0 info: description: 'Use the Managed Access API to approve access requests, create and manage templates, and manage resource approval settings. For more information, see [Managed Access Overview](https://docs.oracle.com/iaas/Content/managed-access/home.htm). Use the table of contents and search tool to explore the Managed Access API. ' title: Managed Access Approval Template API version: '20220126' x-provenance: method: harvested first_party: true publisher: Oracle source: https://docs.oracle.com/en-us/iaas/api/specs/f397c9292e6f977d1885091f8a6e9a9c3cdcb882c49d89bc55720e8eec0c02d1.yaml harvested: '2026-08-04' note: Published by Oracle as the contract for the Managed Access API OCI service and stored verbatim; API Evangelist added only this provenance block. x-evidence: - url: https://docs.oracle.com/en-us/iaas/api/specs/index.json what: Oracle's own index of every OCI service specification - url: https://docs.oracle.com/en-us/iaas/api/specs/f397c9292e6f977d1885091f8a6e9a9c3cdcb882c49d89bc55720e8eec0c02d1.yaml what: the harvested document for Managed Access API servers: - url: http://127.0.0.1/20220126 - url: https://127.0.0.1/20220126 tags: - name: approvalTemplate paths: /approvalTemplates: get: description: 'Retrieves a list of ApprovalTemplateSummary objects in a compartment. ' operationId: ListApprovalTemplates parameters: - $ref: '#/components/parameters/RequestIdHeader' - $ref: '#/components/parameters/CompartmentIdQueryParam' - $ref: '#/components/parameters/IdentifierQueryParam' - $ref: '#/components/parameters/DisplayNameQueryParam' - $ref: '#/components/parameters/ApprovalTemplateLifecycleStateQueryParam' - $ref: '#/components/parameters/PaginationLimitQueryParam' - $ref: '#/components/parameters/PaginationTokenQueryParam' - $ref: '#/components/parameters/SortOrderQueryParam' - $ref: '#/components/parameters/SortByQueryParam' responses: 200: description: A page of ApprovalTemplateSummary objects. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' schema: type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string content: application/json: schema: $ref: '#/components/schemas/ApprovalTemplateCollection' 400: $ref: '#/components/responses/400' 401: $ref: '#/components/responses/401' 404: $ref: '#/components/responses/404' 429: $ref: '#/components/responses/429' 500: $ref: '#/components/responses/500' default: $ref: '#/components/responses/default' summary: Retrieves a list of all approval templates in a compartment. tags: - approvalTemplate x-related-resource: '#/definitions/ApprovalTemplateCollection' post: description: 'Creates a new approval template. ' operationId: CreateApprovalTemplate parameters: - $ref: '#/components/parameters/RetryTokenHeader' - $ref: '#/components/parameters/RequestIdHeader' responses: 201: description: Successfully accepted the request. The approval template is created. headers: etag: description: 'For optimistic concurrency control. See `if-match`. ' schema: type: string location: description: 'this contains the full URI for the get request, e.g. "https://iaas.us-phoenix-1.oraclecloud.com/20210331/lockbox/" ' schema: type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string content: application/json: schema: $ref: '#/components/schemas/ApprovalTemplate' 400: $ref: '#/components/responses/400' 401: $ref: '#/components/responses/401' 404: $ref: '#/components/responses/404' 409: $ref: '#/components/responses/409' 429: $ref: '#/components/responses/429' 500: $ref: '#/components/responses/500' default: $ref: '#/components/responses/default' summary: Creates a new approval template. tags: - approvalTemplate x-related-resource: '#/definitions/ApprovalTemplate' requestBody: content: application/json: schema: $ref: '#/components/schemas/CreateApprovalTemplateDetails' description: Details for the new approval template. required: true /approvalTemplates/{approvalTemplateId}: delete: description: Deletes an ApprovalTemplate resource by identifier operationId: DeleteApprovalTemplate parameters: - $ref: '#/components/parameters/ApprovalTemplateIdentifierPathParam' - $ref: '#/components/parameters/IfMatchHeader' - $ref: '#/components/parameters/RequestIdHeader' responses: 204: description: Accepted the request. The ApprovalTemplate will be deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string 400: $ref: '#/components/responses/400' 401: $ref: '#/components/responses/401' 404: $ref: '#/components/responses/404' 412: $ref: '#/components/responses/412' 429: $ref: '#/components/responses/429' 500: $ref: '#/components/responses/500' default: $ref: '#/components/responses/default' summary: Delete a provisioned Approval Template tags: - approvalTemplate x-related-resource: '#/definitions/ApprovalTemplate' get: description: Retrieves an approval template identified by the approval template ID. operationId: GetApprovalTemplate parameters: - $ref: '#/components/parameters/ApprovalTemplateIdentifierPathParam' - $ref: '#/components/parameters/RequestIdHeader' responses: 200: description: Successfully retrieved the approval template. headers: etag: description: 'For optimistic concurrency control. See `if-match`. ' schema: type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string content: application/json: schema: $ref: '#/components/schemas/ApprovalTemplate' 400: $ref: '#/components/responses/400' 401: $ref: '#/components/responses/401' 404: $ref: '#/components/responses/404' 429: $ref: '#/components/responses/429' 500: $ref: '#/components/responses/500' default: $ref: '#/components/responses/default' summary: Retrieves an approval template tags: - approvalTemplate put: description: Updates the ApprovalTemplate operationId: UpdateApprovalTemplate parameters: - $ref: '#/components/parameters/ApprovalTemplateIdentifierPathParam' - $ref: '#/components/parameters/IfMatchHeader' - $ref: '#/components/parameters/RequestIdHeader' responses: 200: description: The ApprovalTemplate is updated. headers: etag: description: 'For optimistic concurrency control. See `if-match`. ' schema: type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string content: application/json: schema: $ref: '#/components/schemas/ApprovalTemplate' 400: $ref: '#/components/responses/400' 401: $ref: '#/components/responses/401' 404: $ref: '#/components/responses/404' 405: $ref: '#/components/responses/405' 412: $ref: '#/components/responses/412' 429: $ref: '#/components/responses/429' 500: $ref: '#/components/responses/500' default: $ref: '#/components/responses/default' summary: Update the ApprovalTemplate identified by the id tags: - approvalTemplate x-related-resource: '#/definitions/ApprovalTemplate' requestBody: content: application/json: schema: $ref: '#/components/schemas/UpdateApprovalTemplateDetails' description: The information to be updated. required: true /approvalTemplates/{approvalTemplateId}/actions/changeCompartment: post: description: Moves an ApprovalTemplate resource from one compartment identifier to another. When provided, If-Match is checked against ETag values of the resource. operationId: ChangeApprovalTemplateCompartment parameters: - $ref: '#/components/parameters/ApprovalTemplateIdentifierPathParam' - $ref: '#/components/parameters/IfMatchHeader' - $ref: '#/components/parameters/RequestIdHeader' - $ref: '#/components/parameters/RetryTokenHeader' responses: 204: description: Accepted the request. The ApprovalTemplate resource will be moved into a different compartment. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string 401: $ref: '#/components/responses/401' 404: $ref: '#/components/responses/404' 409: $ref: '#/components/responses/409' 412: $ref: '#/components/responses/412' 429: $ref: '#/components/responses/429' 500: $ref: '#/components/responses/500' summary: Moves a resource into a different compartment. tags: - approvalTemplate x-related-resource: '#/definitions/ApprovalTemplate' requestBody: content: application/json: schema: $ref: '#/components/schemas/ChangeApprovalTemplateCompartmentDetails' description: The information to be updated. required: true components: schemas: UpdateApprovalTemplateDetails: description: The action to be updated. properties: approverLevels: $ref: '#/components/schemas/ApproverLevels' autoApprovalState: description: The auto approval state of the lockbox. enum: - ENABLED - DISABLED type: string x-obmcs-top-level-enum: '#/definitions/LockboxAutoApprovalState' definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing predefined tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"foo-namespace": {"bar-key": "value"}}` ' type: object displayName: description: approval template identifier type: string freeformTags: additionalProperties: type: string description: 'Simple key-value pair that is applied without any predefined name, type or scope. Exists for cross-compatibility only. Example: `{"bar-key": "value"}` ' type: object type: object Error: description: Error Information. properties: code: description: A short error code that defines the error, meant for programmatic parsing. type: string message: description: A human-readable error string. type: string required: - code - message ApprovalTemplate: description: Group/User OCIDs of those who can approve/deny/revoke operator's request to access associated resources. properties: approverLevels: $ref: '#/components/schemas/ApproverLevels' autoApprovalState: description: The auto approval state of the lockbox. enum: - ENABLED - DISABLED type: string x-obmcs-top-level-enum: '#/definitions/LockboxAutoApprovalState' compartmentId: description: The unique identifier (OCID) of the customer compartment where the approval template is located. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing predefined tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"foo-namespace": {"bar-key": "value"}}` ' type: object displayName: description: The approval template display name. type: string freeformTags: additionalProperties: type: string description: 'Simple key-value pair that is applied without any predefined name, type or scope. Exists for cross-compatibility only. Example: `{"bar-key": "value"}` ' type: object id: description: The unique identifier (OCID) of the approval template, which can't be changed after creation. type: string lifecycleState: description: The current state of the approval template. enum: - ACTIVE - CREATING - UPDATING - DELETING - DELETED - FAILED type: string systemTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing system tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Usage of system tag keys. These predefined keys are scoped to namespaces. Example: `{"orcl-cloud": {"free-tier-retained": "true"}}` ' type: object timeCreated: description: The time the the approval template was created. An RFC3339 formatted datetime string format: date-time type: string timeUpdated: description: The time the approval template was updated. An RFC3339 formatted datetime string format: date-time type: string required: - id - displayName - compartmentId - timeCreated type: object ChangeApprovalTemplateCompartmentDetails: description: The information to be updated. properties: compartmentId: description: The unique identifier (OCID) of the compartment where the resource is located. maxLength: 255 minLength: 1 type: string required: - compartmentId type: object CreateApprovalTemplateDetails: description: The configuration details for a new approval template. properties: approverLevels: $ref: '#/components/schemas/ApproverLevels' autoApprovalState: description: The auto approval state of the lockbox. enum: - ENABLED - DISABLED type: string x-obmcs-top-level-enum: '#/definitions/LockboxAutoApprovalState' compartmentId: description: The unique identifier (OCID) of the compartment where the resource is located. maxLength: 255 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing predefined tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"foo-namespace": {"bar-key": "value"}}` ' type: object displayName: description: approval template identifier type: string freeformTags: additionalProperties: type: string description: 'Simple key-value pair that is applied without any predefined name, type or scope. Exists for cross-compatibility only. Example: `{"bar-key": "value"}` ' type: object required: - compartmentId type: object ApprovalTemplateCollection: description: Results of approval template search. Contains both ApprovalTemplateSummary items and other information, such as metadata. properties: items: description: List of ApprovalTemplateSummary. items: $ref: '#/components/schemas/ApprovalTemplateSummary' type: array required: - items type: object ApprovalTemplateSummary: description: Summary info for an approval tmeplate. properties: approverLevels: $ref: '#/components/schemas/ApproverLevels' autoApprovalState: description: The auto approval state of the lockbox. enum: - ENABLED - DISABLED type: string x-obmcs-top-level-enum: '#/definitions/LockboxAutoApprovalState' compartmentId: description: The unique identifier (OCID) of the customer compartment where the approval template is located. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing predefined tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"foo-namespace": {"bar-key": "value"}}` ' type: object displayName: description: The approval template display name. type: string freeformTags: additionalProperties: type: string description: 'Simple key-value pair that is applied without any predefined name, type or scope. Exists for cross-compatibility only. Example: `{"bar-key": "value"}` ' type: object id: description: The unique identifier (OCID) of the approval template, which can't be changed after creation. type: string lifecycleState: description: The current state of the approval template. type: string x-obmcs-enumref: '#/definitions/ApprovalTemplate/lifecycleState' systemTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing system tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Usage of system tag keys. These predefined keys are scoped to namespaces. Example: `{"orcl-cloud": {"free-tier-retained": "true"}}` ' type: object timeCreated: description: The time the the approval template was created. An RFC3339 formatted datetime string format: date-time type: string timeUpdated: description: The time the approval template was updated. An RFC3339 formatted datetime string format: date-time type: string required: - id - displayName - compartmentId - timeCreated type: object ApproverInfo: description: The approver data for this approver level. properties: approverId: description: The group or user ocid of the approver for this approver level. type: string approverType: description: The approver type of this approver level. enum: - GROUP - USER type: string x-obmcs-top-level-enum: '#/definitions/ApproverType' domainId: description: The identity domain ocid of the approver. type: string required: - approverType - approverId type: object ApproverLevels: description: The approver levels. properties: level1: $ref: '#/components/schemas/ApproverInfo' level2: $ref: '#/components/schemas/ApproverInfo' level3: $ref: '#/components/schemas/ApproverInfo' required: - level1 type: object parameters: PaginationTokenQueryParam: description: A token representing the position at which to start retrieving results. This must come from the `opc-next-page` header field of a previous response. in: query name: page x-default-description: 'null' schema: type: string minLength: 1 SortByQueryParam: description: 'The field to sort by. Only one sort order may be provided. Default order for timeCreated is descending. Default order for displayName is ascending. ' in: query name: sortBy schema: type: string enum: - timeCreated - displayName - id default: timeCreated IdentifierQueryParam: description: A generic Id query param used to filter lockbox, access request and approval template by Id. in: query name: id x-default-description: 'null' schema: type: string maxLength: 255 minLength: 1 CompartmentIdQueryParam: description: The ID of the compartment in which to list resources. in: query name: compartmentId x-default-description: 'null' schema: type: string IfMatchHeader: description: 'For optimistic concurrency control. In the PUT or DELETE call for a resource, set the `if-match` parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource''s current etag value. ' in: header name: if-match required: false schema: type: string PaginationLimitQueryParam: description: The maximum number of items to return. in: query name: limit schema: type: integer default: 10 maximum: 1000 minimum: 1 SortOrderQueryParam: description: The sort order to use, either 'ASC' or 'DESC'. in: query name: sortOrder x-default-description: 'The default value depends upon `sortBy`, and in general is ''DESC'' when sorting by time and ''ASC'' otherwise. ' x-obmcs-top-level-enum: '#/definitions/SortOrder' schema: type: string enum: - ASC - DESC RetryTokenHeader: description: 'A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations. For example, if a resource has been deleted and purged from the system, then a retry of the original creation request might be rejected. ' in: header name: opc-retry-token required: false schema: type: string maxLength: 64 minLength: 1 ApprovalTemplateLifecycleStateQueryParam: description: A filter to return only resources for which their lifecycleState matches the given lifecycleState. in: query name: lifecycleState x-default-description: 'null' x-obmcs-enumref: '#/definitions/ApprovalTemplate/lifecycleState' schema: type: string DisplayNameQueryParam: description: A filter to return only resources that match the entire display name given. in: query name: displayName x-default-description: 'null' schema: type: string maxLength: 255 minLength: 1 RequestIdHeader: description: The client request ID for tracing. in: header name: opc-request-id schema: type: string ApprovalTemplateIdentifierPathParam: description: The unique identifier (OCID) of the approval template. in: path name: approvalTemplateId required: true schema: type: string responses: default: description: Unknown Error headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' schema: type: string content: application/json: schema: $ref: '#/components/schemas/Error' x-anchors: x-headers: etag: description: 'For optimistic concurrency control. See `if-match`. ' type: string location: description: 'this contains the full URI for the get request, e.g. "https://iaas.us-phoenix-1.oraclecloud.com/20210331/lockbox/" ' type: string opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'Unique Oracle-assigned identifier for the asynchronous work. You can use this to query its status. ' type: string retry-after: description: A decimal number representing the number of seconds the client should wait before polling this endpoint again. type: integer x-properties: compartmentId: description: The unique identifier (OCID) of the compartment where the resource is located. maxLength: 255 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing predefined tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"foo-namespace": {"bar-key": "value"}}` ' type: object freeformTags: additionalProperties: type: string description: 'Simple key-value pair that is applied without any predefined name, type or scope. Exists for cross-compatibility only. Example: `{"bar-key": "value"}` ' type: object systemTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string type is supported. ' type: object description: 'Key-value pair representing system tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Usage of system tag keys. These predefined keys are scoped to namespaces. Example: `{"orcl-cloud": {"free-tier-retained": "true"}}` ' type: object x-obmcs-client-retries-enabled: true x-oracle-package: com.oracle.pic.lockbox