generated: '2026-07-15' method: generated source: openapi/ping-identity-openapi.yaml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 54 by_action_class: connected: 25 acting: 29 by_consequence: read: 25 write: 28 physical: 1 human_in_the_loop_required: 0 operations: - path: /environments method: get operationId: getEnvironments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments method: post operationId: createEnvironment x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID} method: get operationId: getEnvironmentById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID} method: put operationId: replaceEnvironmentById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID} method: delete operationId: deleteEnvironmentById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/billOfMaterials method: get operationId: getBillOfMaterialsByEnvironmentId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/billOfMaterials method: put operationId: replaceBillOfMaterialsByEnvironmentId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/connectorInstances method: get operationId: getConnectorInstances x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/connectorInstances method: post operationId: createConnectorInstance x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/connectorInstances/{connectorInstanceID} method: get operationId: getConnectorInstanceById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/connectorInstances/{connectorInstanceID} method: post operationId: createConnectorInstanceById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/connectorInstances/{connectorInstanceID} method: put operationId: replaceConnectorInstanceById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/connectorInstances/{connectorInstanceID} method: delete operationId: deleteConnectorInstanceById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/connectors method: get operationId: getConnectors x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/connectors/{connectorID} method: get operationId: getConnectorById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/connectors/{connectorID}/details method: get operationId: getDetailsByConnectorId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/davinciApplications method: get operationId: getDavinciApplications x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/davinciApplications method: post operationId: createDavinciApplication x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/davinciApplications/{davinciApplicationID} method: get operationId: getDavinciApplicationById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/davinciApplications/{davinciApplicationID} method: put operationId: replaceDavinciApplicationById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/davinciApplications/{davinciApplicationID} method: delete operationId: deleteDavinciApplicationById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/flowPolicies method: get operationId: getFlowPoliciesByDavinciApplicationId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/flowPolicies method: post operationId: createFlowPolicyByDavinciApplicationId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/flowPolicies/{flowPolicyID} method: get operationId: getFlowPolicyByIdUsingDavinciApplicationId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/flowPolicies/{flowPolicyID} method: put operationId: replaceFlowPolicyByIdUsingDavinciApplicationId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/flowPolicies/{flowPolicyID} method: delete operationId: deleteFlowPolicyByIdUsingDavinciApplicationId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/flowPolicies/{flowPolicyID}/events method: get operationId: getEventsByDavinciApplicationIdAndFlowPolicyId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/key method: post operationId: rotateKeyByDavinciApplicationId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/secret method: post operationId: rotateSecretByDavinciApplicationId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/flowPolicies/{flowPolicyID} method: get operationId: getFlowPolicyById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/flows method: get operationId: getFlows x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/flows method: post operationId: createFlow x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/flows/{flowID} method: get operationId: getFlowById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/flows/{flowID} method: put operationId: replaceFlowById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/flows/{flowID} method: delete operationId: deleteFlowById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/flows/{flowID}#clone+json method: post operationId: cloneFlowByIdAsCloneJson x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/flows/{flowID}#deploy+json method: post operationId: deployFlowByIdAsDeployJson x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/flows/{flowID}#validate+json method: post operationId: validateFlowByIdAsValidateJson x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/flows/{flowID}/enabled method: put operationId: updateEnabledByFlowId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/flows/{flowID}/versions method: get operationId: getVersionsByFlowId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/flows/{flowID}/versions/{versionID} method: get operationId: getVersionByIdUsingFlowId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/flows/{flowID}/versions/{versionID} method: delete operationId: deleteVersionByIdUsingFlowId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/flows/{flowID}/versions/{versionID}/alias method: put operationId: replaceAliasByFlowIdAndVersionId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/flows/{flowID}/versions/{versionID}/details method: get operationId: getDetailsByFlowIdAndVersionId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/snapshots method: post operationId: createSnapshot x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/snapshots/{snapshotID} method: get operationId: getSnapshotById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/snapshots/{snapshotID}/versions method: get operationId: getVersionsBySnapshotId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/snapshots/{snapshotID}/versions/{versionID} method: get operationId: getVersionByIdUsingSnapshotId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/totalIdentities method: get operationId: getTotalIdentities x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/variables method: get operationId: getVariables x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/variables method: post operationId: createVariable x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/variables/{variableID} method: get operationId: getVariableById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /environments/{environmentID}/variables/{variableID} method: put operationId: replaceVariableById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /environments/{environmentID}/variables/{variableID} method: delete operationId: deleteVariableById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required