generated: '2026-10-09' method: generated source: openapi/pipeshub-openapi.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 381 by_action_class: connected: 154 acting: 227 by_consequence: read: 154 write: 197 safety-critical: 29 physical: 1 human_in_the_loop_required: 29 operations: - path: /notifications method: get operationId: listInAppNotifications x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /notifications/stats method: get operationId: getNotificationStats x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /notifications/read-all method: patch operationId: markAllInAppNotificationsRead x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /notifications/{id}/read method: patch operationId: markInAppNotificationRead x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /notifications/{id}/unread method: patch operationId: markInAppNotificationUnread x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /notifications/{id}/archive method: patch operationId: archiveInAppNotification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /notifications/{id}/unarchive method: patch operationId: unarchiveInAppNotification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /notifications/{id} method: delete operationId: dismissInAppNotification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth2/authorize method: get operationId: oauthAuthorize x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth2/authorize method: post operationId: oauthAuthorizeConsent x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth2/token method: post operationId: oauthToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth2/revoke method: post operationId: oauthRevoke x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /oauth2/introspect method: post operationId: oauthIntrospect x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth2/userinfo method: get operationId: oauthUserInfo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /.well-known/openid-configuration method: get operationId: openidConfiguration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /.well-known/oauth-authorization-server method: get operationId: oauthAuthorizationServerMetadata x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /.well-known/jwks.json method: get operationId: jwks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /.well-known/oauth-protected-resource/mcp method: get operationId: oauthProtectedResource x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth-clients method: get operationId: listOAuthApps x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth-clients method: post operationId: createOAuthApp x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth-clients/scopes method: get operationId: listOAuthScopes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth-clients/{appId} method: get operationId: getOAuthApp x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth-clients/{appId} method: put operationId: updateOAuthApp x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth-clients/{appId} method: delete operationId: deleteOAuthApp x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth-clients/{appId}/regenerate-secret method: post operationId: regenerateOAuthAppSecret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth-clients/{appId}/suspend method: post operationId: suspendOAuthApp x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth-clients/{appId}/activate method: post operationId: activateOAuthApp x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth-clients/{appId}/tokens method: get operationId: listOAuthAppTokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth-clients/{appId}/revoke-all-tokens method: post operationId: revokeAllOAuthAppTokens x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /personal-access-tokens method: get operationId: listPersonalAccessTokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /personal-access-tokens method: post operationId: createPersonalAccessToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /personal-access-tokens/scopes method: get operationId: listPersonalAccessTokenScopes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /personal-access-tokens/{tokenId} method: delete operationId: revokePersonalAccessToken x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /personal-access-tokens/admin method: get operationId: adminListPersonalAccessTokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /personal-access-tokens/admin/{tokenId} method: delete operationId: adminRevokePersonalAccessToken x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /userAccount/initAuth method: post operationId: initAuth x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userAccount/authenticate method: post operationId: authenticate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userAccount/login/otp/generate method: post operationId: generateLoginOtp x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userAccount/password/forgot method: post operationId: forgotPassword x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /userAccount/password/reset/token method: post operationId: resetPasswordWithToken x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /userAccount/oauth/exchange method: post operationId: exchangeOAuthCode x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userAccount/validateEmailChange method: put operationId: validateEmailChangeToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userAccount/refresh/token method: post operationId: refreshToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userAccount/logout/manual method: post operationId: logout x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userAccount/password/reset method: post operationId: resetPassword x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /orgAuthConfig/authMethods method: get operationId: getAuthMethods x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /orgAuthConfig/updateAuthMethod method: post operationId: updateAuthMethod x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /orgAuthConfig method: post operationId: setUpAuthConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /saml/signIn method: get operationId: signInViaSAML x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /saml/signIn/callback method: post operationId: samlSignInCallback x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /saml/updateAppConfig method: post operationId: updateSamlAppConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/health method: get operationId: getUsersHealth x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /users method: get operationId: getAllUsers x-agentic-access: action-class: connected consequence: read subject: optional scope: - user:read token: max-ttl: 3600 audit: none - path: /users method: post operationId: createUser x-agentic-access: action-class: acting consequence: write subject: required scope: - user:invite audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id} method: get operationId: getUserById x-agentic-access: action-class: connected consequence: read subject: optional scope: - user:read token: max-ttl: 3600 audit: none - path: /users/{id} method: put operationId: updateUser x-agentic-access: action-class: acting consequence: write subject: required scope: - user:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id} method: delete operationId: deleteUser x-agentic-access: action-class: acting consequence: write subject: required scope: - user:delete audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id}/email method: get operationId: getUserEmailById x-agentic-access: action-class: connected consequence: read subject: optional scope: - user:read token: max-ttl: 3600 audit: none - path: /users/{id}/email method: patch operationId: updateEmail x-agentic-access: action-class: acting consequence: write subject: required scope: - user:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/dp method: put operationId: uploadUserDisplayPicture x-agentic-access: action-class: acting consequence: write subject: required scope: - user:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/dp method: get operationId: getUserDisplayPicture x-agentic-access: action-class: connected consequence: read subject: optional scope: - user:read token: max-ttl: 3600 audit: none - path: /users/dp method: delete operationId: removeUserDisplayPicture x-agentic-access: action-class: acting consequence: write subject: required scope: - user:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/bulk/invite method: post operationId: bulkInviteUsers x-agentic-access: action-class: acting consequence: write subject: required scope: - user:invite audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/bulk/invite/upload method: post operationId: bulkInviteUsersFromFile x-agentic-access: action-class: acting consequence: write subject: required scope: - user:invite audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id}/resend-invite method: post operationId: resendUserInvite x-agentic-access: action-class: acting consequence: physical subject: required scope: - user:invite audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/graph/list method: get operationId: listUsersGraph x-agentic-access: action-class: connected consequence: read subject: optional scope: - user:read token: max-ttl: 3600 audit: none - path: /users/{id}/unblock method: put operationId: unblockUser x-agentic-access: action-class: acting consequence: write subject: required scope: - user:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/fetch/with-groups method: get operationId: getAllUsersWithGroups x-agentic-access: action-class: connected consequence: read subject: optional scope: - user:read token: max-ttl: 3600 audit: none - path: /users/by-ids method: post operationId: getUsersByIds x-agentic-access: action-class: connected consequence: read subject: optional scope: - user:read token: max-ttl: 3600 audit: none - path: /users/{id}/fullname method: patch operationId: updateFullName x-agentic-access: action-class: acting consequence: write subject: required scope: - user:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id}/firstName method: patch operationId: updateFirstName x-agentic-access: action-class: acting consequence: write subject: required scope: - user:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id}/lastName method: patch operationId: updateLastName x-agentic-access: action-class: acting consequence: write subject: required scope: - user:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id}/designation method: patch operationId: updateDesignation x-agentic-access: action-class: acting consequence: write subject: required scope: - user:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /users/{id}/adminCheck method: get operationId: adminCheck x-agentic-access: action-class: connected consequence: read subject: optional scope: - user:read token: max-ttl: 3600 audit: none - path: /users/me/role method: get operationId: getMyRole x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth-clients/{appId}/token-identity method: put operationId: setOAuthAppTokenIdentity x-agentic-access: action-class: acting consequence: write subject: required scope: - user:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /service-accounts method: get operationId: listServiceAccounts x-agentic-access: action-class: connected consequence: read subject: optional scope: - user:read token: max-ttl: 3600 audit: none - path: /service-accounts method: post operationId: createServiceAccount x-agentic-access: action-class: acting consequence: write subject: required scope: - user:invite audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /service-accounts/{id} method: get operationId: getServiceAccount x-agentic-access: action-class: connected consequence: read subject: optional scope: - user:read token: max-ttl: 3600 audit: none - path: /service-accounts/{id} method: patch operationId: updateServiceAccount x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - user:write audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /service-accounts/{id} method: delete operationId: deleteServiceAccount x-agentic-access: action-class: acting consequence: write subject: required scope: - user:delete audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /service-tokens method: get operationId: listServiceTokens x-agentic-access: action-class: connected consequence: read subject: optional scope: - user:read token: max-ttl: 3600 audit: none - path: /service-tokens method: post operationId: createServiceToken x-agentic-access: action-class: acting consequence: write subject: required scope: - user:invite audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /service-tokens/scopes method: get operationId: listServiceTokenScopes x-agentic-access: action-class: connected consequence: read subject: optional scope: - user:read token: max-ttl: 3600 audit: none - path: /service-tokens/{tokenId} method: delete operationId: revokeServiceToken x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - user:delete audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /teams method: post operationId: createTeam x-agentic-access: action-class: acting consequence: write subject: required scope: - team:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/user/teams method: get operationId: getUserTeams x-agentic-access: action-class: connected consequence: read subject: optional scope: - team:read token: max-ttl: 3600 audit: none - path: /teams/{teamId} method: get operationId: getTeamById x-agentic-access: action-class: connected consequence: read subject: optional scope: - team:read token: max-ttl: 3600 audit: none - path: /teams/{teamId} method: put operationId: updateTeam x-agentic-access: action-class: acting consequence: write subject: required scope: - team:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{teamId} method: delete operationId: deleteTeam x-agentic-access: action-class: acting consequence: write subject: required scope: - team:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /teams/{teamId}/users method: get operationId: getTeamUsers x-agentic-access: action-class: connected consequence: read subject: optional scope: - team:read token: max-ttl: 3600 audit: none - path: /org/exists method: get operationId: checkOrgExists x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /org/health method: get operationId: getOrgHealth x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /org method: post operationId: createOrganization x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /org method: get operationId: getCurrentOrganization x-agentic-access: action-class: connected consequence: read subject: optional scope: - org:read token: max-ttl: 3600 audit: none - path: /org method: put operationId: updateOrganization x-agentic-access: action-class: acting consequence: write subject: required scope: - org:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /org method: delete operationId: deleteOrganization x-agentic-access: action-class: acting consequence: write subject: required scope: - org:admin audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /org/logo method: put operationId: uploadOrganizationLogo x-agentic-access: action-class: acting consequence: write subject: required scope: - org:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /org/logo method: get operationId: getOrganizationLogo x-agentic-access: action-class: connected consequence: read subject: optional scope: - org:read token: max-ttl: 3600 audit: none - path: /org/logo method: delete operationId: deleteOrganizationLogo x-agentic-access: action-class: acting consequence: write subject: required scope: - org:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /org/onboarding-status method: get operationId: getOnboardingStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /org/onboarding-status method: put operationId: updateOnboardingStatus x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userGroups method: post operationId: createUserGroup x-agentic-access: action-class: acting consequence: write subject: required scope: - usergroup:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userGroups method: get operationId: getAllUserGroups x-agentic-access: action-class: connected consequence: read subject: optional scope: - usergroup:read token: max-ttl: 3600 audit: none - path: /userGroups/{groupId} method: get operationId: getUserGroupById x-agentic-access: action-class: connected consequence: read subject: optional scope: - usergroup:read token: max-ttl: 3600 audit: none - path: /userGroups/{groupId} method: put operationId: updateUserGroup x-agentic-access: action-class: acting consequence: write subject: required scope: - usergroup:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userGroups/{groupId} method: delete operationId: deleteUserGroup x-agentic-access: action-class: acting consequence: write subject: required scope: - usergroup:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userGroups/add-users method: post operationId: addUsersToGroup x-agentic-access: action-class: acting consequence: write subject: required scope: - usergroup:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userGroups/remove-users method: post operationId: removeUsersFromGroup x-agentic-access: action-class: acting consequence: write subject: required scope: - usergroup:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /userGroups/users/{userId} method: get operationId: getGroupsForUser x-agentic-access: action-class: connected consequence: read subject: optional scope: - usergroup:read token: max-ttl: 3600 audit: none - path: /userGroups/{groupId}/users method: get operationId: getUsersInGroup x-agentic-access: action-class: connected consequence: read subject: optional scope: - usergroup:read token: max-ttl: 3600 audit: none - path: /userGroups/stats/list method: get operationId: getGroupStatistics x-agentic-access: action-class: connected consequence: read subject: optional scope: - usergroup:read token: max-ttl: 3600 audit: none - path: /userGroups/health method: get operationId: getUserGroupsHealth x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /document/internal/upload method: post operationId: internalUploadDocument x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /document/internal/placeholder method: post operationId: internalCreatePlaceholderDocument x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /document/internal/{documentId} method: get operationId: internalGetDocumentById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /document/internal/{documentId}/ method: delete operationId: internalDeleteDocumentById x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /document/internal/{documentId}/download method: get operationId: internalDownloadDocument x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /document/internal/{documentId}/buffer method: get operationId: internalGetDocumentBuffer x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /document/internal/{documentId}/buffer method: put operationId: internalUpdateDocumentBuffer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /document/internal/{documentId}/uploadNextVersion method: post operationId: internalUploadNextVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /document/internal/{documentId}/rollBack method: post operationId: internalRollBackToPreviousVersion x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /document/internal/{documentId}/directUpload method: post operationId: internalDirectUpload x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /document/internal/{documentId}/isModified method: get operationId: internalIsDocumentModified x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /knowledgeBase method: post operationId: createKnowledgeBase x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase method: get operationId: listKnowledgeBases x-agentic-access: action-class: connected consequence: read subject: optional scope: - kb:read token: max-ttl: 3600 audit: none - path: /knowledgeBase/{kbId} method: get operationId: getKnowledgeBase x-agentic-access: action-class: connected consequence: read subject: optional scope: - kb:read token: max-ttl: 3600 audit: none - path: /knowledgeBase/{kbId} method: put operationId: updateKnowledgeBase x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/{kbId} method: delete operationId: deleteKnowledgeBase x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:delete audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/record/{recordId} method: get operationId: getRecordById x-agentic-access: action-class: connected consequence: read subject: optional scope: - kb:read token: max-ttl: 3600 audit: none - path: /knowledgeBase/record/{recordId} method: put operationId: updateRecord x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/record/{recordId} method: delete operationId: deleteRecord x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:delete audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/stream/record/{recordId} method: get operationId: streamRecordBuffer x-agentic-access: action-class: connected consequence: read subject: optional scope: - kb:read token: max-ttl: 3600 audit: none - path: /knowledgeBase/{kbId}/folder method: post operationId: createFolder x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/{kbId}/folder/{folderId} method: put operationId: updateFolder x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/{kbId}/folder/{folderId} method: delete operationId: deleteFolder x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:delete audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/{kbId}/upload method: post operationId: uploadRecords x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:upload audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/limits method: get operationId: getUploadLimits x-agentic-access: action-class: connected consequence: read subject: optional scope: - kb:read token: max-ttl: 3600 audit: none - path: /knowledgeBase/demo-data/status method: get operationId: getDemoDataStatus x-agentic-access: action-class: connected consequence: read subject: optional scope: - kb:read token: max-ttl: 3600 audit: none - path: /knowledgeBase/demo-data/preference method: put operationId: setDemoDataPreference x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/demo-data/workspace method: put operationId: setDemoDataForEveryone x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /kb/record/{recordId} method: put operationId: updateRecordKbConnector x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/reindex/record/{recordId} method: post operationId: reindexRecord x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/reindex/record-group/{recordGroupId} method: post operationId: reindexRecordGroup x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/{kbId}/record/{recordId}/move method: put operationId: moveRecord x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/{kbId}/permissions method: post operationId: createKBPermission x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/{kbId}/permissions method: get operationId: listKBPermissions x-agentic-access: action-class: connected consequence: read subject: optional scope: - kb:read token: max-ttl: 3600 audit: none - path: /knowledgeBase/{kbId}/permissions method: put operationId: updateKBPermissions x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/{kbId}/permissions method: delete operationId: deleteKBPermissions x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:delete audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /knowledgeBase/knowledge-hub/nodes method: get operationId: getKnowledgeHubRootNodes x-agentic-access: action-class: connected consequence: read subject: optional scope: - kb:read token: max-ttl: 3600 audit: none - path: /knowledgeBase/knowledge-hub/nodes/{parentType}/{parentId} method: get operationId: getKnowledgeHubChildNodes x-agentic-access: action-class: connected consequence: read subject: optional scope: - kb:read token: max-ttl: 3600 audit: none - path: /conversations/create method: post operationId: createConversation x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/stream method: post operationId: streamChat x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:chat audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/attachments/upload method: post operationId: uploadConversationChatAttachments x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:chat audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/attachments/{recordId} method: delete operationId: deleteConversationChatAttachment x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:chat audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations method: get operationId: getAllConversations x-agentic-access: action-class: connected consequence: read subject: optional scope: - conversation:read token: max-ttl: 3600 audit: none - path: /conversations/show/archives method: get operationId: getArchivedConversations x-agentic-access: action-class: connected consequence: read subject: optional scope: - conversation:read token: max-ttl: 3600 audit: none - path: /conversations/show/archives/search method: get operationId: searchArchivedConversations x-agentic-access: action-class: connected consequence: read subject: optional scope: - conversation:read token: max-ttl: 3600 audit: none - path: /conversations/{conversationId} method: get operationId: getConversationById x-agentic-access: action-class: connected consequence: read subject: optional scope: - conversation:read token: max-ttl: 3600 audit: none - path: /conversations/{conversationId} method: delete operationId: deleteConversationById x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/{conversationId}/messages method: post operationId: addMessage x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:chat audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/{conversationId}/messages/stream method: post operationId: addMessageStream x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:chat audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/{conversationId}/share method: post operationId: shareConversation x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/{conversationId}/title method: patch operationId: updateConversationTitle x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/{conversationId}/archive method: patch operationId: archiveConversation x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/{conversationId}/unarchive method: patch operationId: unarchiveConversation x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/{conversationId}/message/{messageId}/regenerate method: post operationId: regenerateAnswer x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:chat audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/{conversationId}/cancel method: post operationId: cancelConversationStream x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:chat audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/{conversationId}/message/{messageId}/feedback method: post operationId: updateMessageFeedback x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/{conversationId}/unshare method: post operationId: unshareConversationById x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/{conversationId}/project method: put operationId: setConversationProject x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /conversations/{conversationId}/project-visibility method: patch operationId: setConversationProjectVisibility x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - conversation:write audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /projects method: post operationId: createProject x-agentic-access: action-class: acting consequence: write subject: required scope: - project:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects method: get operationId: listProjects x-agentic-access: action-class: connected consequence: read subject: optional scope: - project:read token: max-ttl: 3600 audit: none - path: /projects/{projectId} method: get operationId: getProjectById x-agentic-access: action-class: connected consequence: read subject: optional scope: - project:read token: max-ttl: 3600 audit: none - path: /projects/{projectId} method: patch operationId: updateProject x-agentic-access: action-class: acting consequence: write subject: required scope: - project:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{projectId} method: delete operationId: deleteProject x-agentic-access: action-class: acting consequence: write subject: required scope: - project:delete audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{projectId}/archive method: post operationId: archiveProject x-agentic-access: action-class: acting consequence: write subject: required scope: - project:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{projectId}/unarchive method: post operationId: unarchiveProject x-agentic-access: action-class: acting consequence: write subject: required scope: - project:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{projectId}/pin method: post operationId: pinProject x-agentic-access: action-class: acting consequence: write subject: required scope: - project:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{projectId}/unpin method: post operationId: unpinProject x-agentic-access: action-class: acting consequence: write subject: required scope: - project:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{projectId}/conversations method: get operationId: getProjectConversations x-agentic-access: action-class: connected consequence: read subject: optional scope: - project:read token: max-ttl: 3600 audit: none - path: /projects/{projectId}/knowledge-base method: post operationId: ensureProjectKnowledgeBase x-agentic-access: action-class: acting consequence: write subject: required scope: - project:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{projectId}/members method: get operationId: listProjectMembers x-agentic-access: action-class: connected consequence: read subject: optional scope: - project:read token: max-ttl: 3600 audit: none - path: /projects/{projectId}/members method: put operationId: upsertProjectMembers x-agentic-access: action-class: acting consequence: write subject: required scope: - project:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /projects/{projectId}/members/{memberUserId} method: delete operationId: removeProjectMember x-agentic-access: action-class: acting consequence: write subject: required scope: - project:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /chat/transcribe method: post operationId: transcribeChatAudio x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:chat audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /chat/speak method: post operationId: synthesizeChatSpeech x-agentic-access: action-class: acting consequence: write subject: required scope: - conversation:chat audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /chat/speech/capabilities method: get operationId: getChatSpeechCapabilities x-agentic-access: action-class: connected consequence: read subject: optional scope: - conversation:chat token: max-ttl: 3600 audit: none - path: /search method: post operationId: search x-agentic-access: action-class: connected consequence: read subject: optional scope: - semantic:write token: max-ttl: 3600 audit: none - path: /search method: get operationId: searchHistory x-agentic-access: action-class: connected consequence: read subject: optional scope: - semantic:read token: max-ttl: 3600 audit: none - path: /search method: delete operationId: deleteSearchHistory x-agentic-access: action-class: acting consequence: write subject: required scope: - semantic:delete audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /search/{searchId} method: get operationId: getSearchById x-agentic-access: action-class: connected consequence: read subject: optional scope: - semantic:read token: max-ttl: 3600 audit: none - path: /search/{searchId} method: delete operationId: deleteSearchById x-agentic-access: action-class: acting consequence: write subject: required scope: - semantic:delete audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /search/{searchId}/archive method: patch operationId: archiveSearch x-agentic-access: action-class: acting consequence: write subject: required scope: - semantic:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /search/{searchId}/unarchive method: patch operationId: unarchiveSearch x-agentic-access: action-class: acting consequence: write subject: required scope: - semantic:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents method: get operationId: listAgents x-agentic-access: action-class: connected consequence: read subject: optional scope: - agent:read token: max-ttl: 3600 audit: none - path: /agents/create method: post operationId: createAgent x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey} method: get operationId: getAgent x-agentic-access: action-class: connected consequence: read subject: optional scope: - agent:read token: max-ttl: 3600 audit: none - path: /agents/{agentKey} method: put operationId: updateAgent x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey} method: delete operationId: deleteAgent x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/conversations/show/archives method: get operationId: listAgentArchivedConversationsGrouped x-agentic-access: action-class: connected consequence: read subject: optional scope: - agent:read token: max-ttl: 3600 audit: none - path: /agents/{agentKey}/conversations/show/archives method: get operationId: listAgentConversationArchives x-agentic-access: action-class: connected consequence: read subject: optional scope: - agent:read token: max-ttl: 3600 audit: none - path: /agents/{agentKey}/conversations/attachments/upload method: post operationId: uploadAgentConversationChatAttachments x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:execute audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/attachments/{recordId} method: delete operationId: deleteAgentConversationChatAttachment x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:execute audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/stream method: post operationId: streamAgentConversation x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:execute audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/{conversationId}/messages/stream method: post operationId: streamAgentConversationMessage x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:execute audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/{conversationId}/message/{messageId}/regenerate method: post operationId: regenerateAgentConversationMessage x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:execute audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/{conversationId}/cancel method: post operationId: cancelAgentConversationStream x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:execute audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/{conversationId}/message/{messageId}/feedback method: post operationId: updateAgentConversationMessageFeedback x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:execute audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/{conversationId}/messages method: post operationId: addAgentConversationMessage x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:execute audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/{conversationId}/archive method: post operationId: archiveAgentConversation x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/{conversationId}/unarchive method: post operationId: unarchiveAgentConversation x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/{conversationId}/title method: patch operationId: updateAgentConversationTitle x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/{conversationId}/project method: put operationId: setAgentConversationProject x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/{conversationId}/project-visibility method: patch operationId: setAgentConversationProjectVisibility x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - agent:write audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /agents/{agentKey}/conversations/{conversationId} method: delete operationId: deleteAgentConversationById x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /agents/{agentKey}/conversations/{conversationId} method: get operationId: getAgentConversationById x-agentic-access: action-class: connected consequence: read subject: optional scope: - agent:read token: max-ttl: 3600 audit: none - path: /agents/{agentKey}/conversations method: get operationId: listAgentConversations x-agentic-access: action-class: connected consequence: read subject: optional scope: - agent:read token: max-ttl: 3600 audit: none - path: /agents/{agentKey}/conversations method: post operationId: createAgentConversation x-agentic-access: action-class: acting consequence: write subject: required scope: - agent:execute audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /connectors/registry method: get operationId: getConnectorRegistry x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/registry/{connectorType}/schema method: get operationId: getConnectorSchema x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors method: get operationId: listConnectorInstances x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors method: post operationId: createConnectorInstance x-agentic-access: action-class: acting consequence: write subject: required scope: - connector:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /connectors/active method: get operationId: listActiveConnectors x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/inactive method: get operationId: listInactiveConnectors x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/configured method: get operationId: listConfiguredConnectors x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/agents/active method: get operationId: listActiveAgentConnectors x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/{connectorId} method: get operationId: getConnectorInstance x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/{connectorId} method: delete operationId: deleteConnectorInstance x-agentic-access: action-class: acting consequence: write subject: required scope: - connector:delete audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /connectors/{connectorId}/stats method: get operationId: getConnectorStats x-agentic-access: action-class: connected consequence: read subject: optional scope: - kb:read token: max-ttl: 3600 audit: none - path: /connectors/record/{recordId}/content method: get operationId: getRecordContent x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/navigate method: get operationId: navigateKnowledgeGraph x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/record/lookup method: get operationId: lookupRecordByIdentifier x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/{connectorId}/reindex method: post operationId: reindexConnector x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /connectors/{connectorId}/resync method: post operationId: resyncConnector x-agentic-access: action-class: acting consequence: write subject: required scope: - kb:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /connectors/{connectorId}/name method: put operationId: updateConnectorName x-agentic-access: action-class: acting consequence: write subject: required scope: - connector:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /connectors/{connectorId}/config method: get operationId: getConnectorConfig x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/{connectorId}/config method: put operationId: updateConnectorConfig x-agentic-access: action-class: acting consequence: write subject: required scope: - connector:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /connectors/{connectorId}/config/auth method: put operationId: updateConnectorAuthConfig x-agentic-access: action-class: acting consequence: write subject: required scope: - connector:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /connectors/{connectorId}/config/filters-sync method: put operationId: updateConnectorFiltersSyncConfig x-agentic-access: action-class: acting consequence: write subject: required scope: - connector:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /connectors/{connectorId}/toggle method: post operationId: toggleConnector x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - connector:write audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /connectors/{connectorId}/oauth/authorize method: get operationId: getOAuthAuthorizationUrl x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/oauth/callback method: get operationId: handleOAuthCallback x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /connectors/{connectorId}/filters method: get operationId: getConnectorFilters x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/{connectorId}/filters method: post operationId: saveConnectorFilters x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /connectors/{connectorId}/filters/{filterKey}/options method: get operationId: getFilterFieldOptions x-agentic-access: action-class: connected consequence: read subject: optional scope: - connector:read token: max-ttl: 3600 audit: none - path: /connectors/getTokenFromCode method: post operationId: getTokenFromCode x-agentic-access: action-class: acting consequence: write subject: required scope: - connector:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/registry method: get operationId: listToolsetRegistry x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/registry/{toolsetType}/schema method: get operationId: getToolsetSchema x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets method: post operationId: createToolset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/configured method: get operationId: listConfiguredToolsets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/{toolsetId}/status method: get operationId: checkToolsetStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/{toolsetId}/config method: get operationId: getToolsetConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/{toolsetId}/config method: post operationId: saveToolsetConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/{toolsetId}/config method: put operationId: updateToolsetConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/{toolsetId}/config method: delete operationId: deleteToolsetConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/{toolsetId}/reauthenticate method: post operationId: reauthenticateToolset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/{toolsetId}/oauth/authorize method: get operationId: getToolsetOAuthUrl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/oauth/callback method: get operationId: handleToolsetOAuthCallback x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/my-toolsets method: get operationId: getMyToolsets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/agents/{agentKey} method: get operationId: getAgentToolsets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/agents/{agentKey}/instances/{instanceId}/authenticate method: post operationId: authenticateAgentToolset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/agents/{agentKey}/instances/{instanceId}/credentials method: put operationId: updateAgentToolsetCredentials x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/agents/{agentKey}/instances/{instanceId}/credentials method: delete operationId: removeAgentToolsetCredentials x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/agents/{agentKey}/instances/{instanceId}/reauthenticate method: post operationId: reauthenticateAgentToolset x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/agents/{agentKey}/instances/{instanceId}/oauth/authorize method: get operationId: getAgentToolsetOAuthUrl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/instances method: get operationId: getToolsetInstances x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/instances method: post operationId: createToolsetInstance x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/instances/{instanceId} method: get operationId: getToolsetInstance x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/instances/{instanceId} method: put operationId: updateToolsetInstance x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/instances/{instanceId} method: delete operationId: deleteToolsetInstance x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/instances/{instanceId}/authenticate method: post operationId: authenticateToolsetInstance x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/instances/{instanceId}/credentials method: put operationId: updateToolsetCredentials x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/instances/{instanceId}/credentials method: delete operationId: removeToolsetCredentials x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/instances/{instanceId}/reauthenticate method: post operationId: reauthenticateToolsetInstance x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/instances/{instanceId}/oauth/authorize method: get operationId: getInstanceOAuthAuthorizationUrl x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/instances/{instanceId}/status method: get operationId: getToolsetInstanceStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/oauth-configs/{toolsetType} method: get operationId: listToolsetOAuthConfigs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /toolsets/oauth-configs/{toolsetType}/{oauthConfigId} method: put operationId: updateToolsetOAuthConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /toolsets/oauth-configs/{toolsetType}/{oauthConfigId} method: delete operationId: deleteToolsetOAuthConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /skills method: get operationId: listSkills x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /skills method: post operationId: createSkill x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/categories method: get operationId: getSkillCategories x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /skills/search method: get operationId: searchSkills x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /skills/candidates/pending method: get operationId: getPendingSkillCandidates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /skills/candidates/{candidateId}/approve method: post operationId: approveSkillCandidate x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/candidates/{candidateId}/reject method: post operationId: rejectSkillCandidate x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/import/npm/preview method: post operationId: previewNpmSkillImport x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/import/url/preview method: post operationId: previewUrlSkillImport x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/import/upload/preview method: post operationId: previewUploadSkillImport x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/import/finalize method: post operationId: finalizeSkillImport x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/{name} method: get operationId: getSkill x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /skills/{name} method: put operationId: updateSkill x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/{name} method: delete operationId: deleteSkill x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/{name}/export method: get operationId: exportSkill x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /skills/{name}/body method: patch operationId: patchSkillBody x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/{name}/deprecate method: post operationId: deprecateSkill x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/{name}/disable method: post operationId: disableSkill x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/{name}/enable method: post operationId: enableSkill x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/{name}/usage method: get operationId: getSkillUsage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /skills/{name}/versions method: get operationId: listSkillVersions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /skills/{name}/versions/{version} method: get operationId: getSkillVersion x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /skills/{name}/rollback method: post operationId: rollbackSkill x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/{name}/resource method: get operationId: getSkillResource x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /skills/{name}/resource method: put operationId: writeSkillResource x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /skills/{name}/resource method: delete operationId: removeSkillResource x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /oauth/registry method: get operationId: getOAuthRegistry x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth/registry/{connectorType} method: get operationId: getOAuthConnectorType x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth method: get operationId: listOAuthConfigs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth/{connectorType} method: get operationId: listOAuthConfigsByType x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth/{connectorType} method: post operationId: createOAuthConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth/{connectorType}/{configId} method: get operationId: getOAuthConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth/{connectorType}/{configId} method: put operationId: updateOAuthConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth/{connectorType}/{configId} method: delete operationId: deleteOAuthConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/storageConfig method: get operationId: getStorageConfig x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/storageConfig method: post operationId: createStorageConfig x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/smtpConfig method: post operationId: createSMTPConfig x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/smtpConfig method: get operationId: getSMTPConfig x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/smtpConfig/status method: get operationId: getSMTPConfigStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /configurationManager/authConfig/azureAd method: post operationId: setAzureAdAuthConfig x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/authConfig/azureAd method: get operationId: getAzureAdAuthConfig x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/authConfig/microsoft method: post operationId: setMicrosoftAuthConfig x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/authConfig/microsoft method: get operationId: getMicrosoftAuthConfig x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/authConfig/google method: post operationId: setGoogleAuthConfig x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/authConfig/google method: get operationId: getGoogleAuthConfig x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/authConfig/sso method: post operationId: setSsoAuthConfig x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/authConfig/sso method: get operationId: getSsoAuthConfig x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/authConfig/oauth method: post operationId: setOAuthConfig x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/authConfig/oauth method: get operationId: getGenericOAuthConfig x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/ai-models/{modelType} method: get operationId: getModelsByType x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/ai-models/available/{modelType} method: get operationId: getAvailableModelsByType x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/ai-models/providers method: post operationId: addAIModelProvider x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/ai-models/providers/{modelType}/{modelKey} method: put operationId: updateAIModelProvider x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/ai-models/providers/{modelType}/{modelKey} method: delete operationId: deleteAIModelProvider x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/ai-models/default/{modelType}/{modelKey} method: put operationId: setDefaultAIModel x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/ai-models/prepare-model method: post operationId: prepareEmbeddingModel x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/ai-models/download-progress method: get operationId: streamEmbeddingDownloadProgress x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/web-search method: get operationId: getWebSearchProviders x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/web-search/settings method: put operationId: updateWebSearchSettings x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/web-search/providers method: post operationId: addWebSearchProvider x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/web-search/providers/{providerKey} method: put operationId: updateWebSearchProvider x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/web-search/providers/{providerKey} method: delete operationId: deleteWebSearchProvider x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/web-search/default/{providerKey} method: put operationId: updateDefaultWebSearchProvider x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/frontendPublicUrl method: post operationId: setFrontendPublicUrl x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/frontendPublicUrl method: get operationId: getFrontendPublicUrl x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/connectorPublicUrl method: post operationId: setConnectorPublicUrl x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/connectorPublicUrl method: get operationId: getConnectorPublicUrl x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/platform/settings method: post operationId: setPlatformSettings x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/platform/settings method: get operationId: getPlatformSettings x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/platform/feature-flags/available method: get operationId: getAvailableFeatureFlags x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/platform/feature-flags/effective method: get operationId: getEffectivePlatformFeatureFlags x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /configurationManager/prompts/system method: put operationId: setCustomSystemPrompt x-agentic-access: action-class: acting consequence: write subject: required scope: - config:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/prompts/system method: get operationId: getCustomSystemPrompt x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/metricsCollection method: get operationId: getMetricsCollection x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/metricsCollection/toggle method: put operationId: toggleMetricsCollection x-agentic-access: action-class: acting consequence: safety-critical subject: required scope: - config:write audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /configurationManager/slack-bot method: get operationId: getSlackBotConfigs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /configurationManager/slack-bot method: post operationId: createSlackBotConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/slack-bot/{configId} method: put operationId: updateSlackBotConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/slack-bot/{configId} method: delete operationId: deleteSlackBotConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/metricsCollection/pushInterval method: patch operationId: setMetricsCollectionPushInterval x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/metricsCollection/serverUrl method: patch operationId: setMetricsCollectionRemoteServer x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/aiModelsConfig method: get operationId: getAIModelsConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /configurationManager/aiModelsConfig method: post operationId: createAIModelsConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/ai-models method: get operationId: getAIModelsProviders x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /configurationManager/ai-models/roles method: get operationId: getModelRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /configurationManager/ai-models/roles method: put operationId: updateModelRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /configurationManager/ai-models/registry method: get operationId: getAIModelRegistry x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/ai-models/registry/capabilities method: get operationId: getAIModelRegistryCapabilities x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /configurationManager/ai-models/registry/{providerId}/schema method: get operationId: getAIModelProviderSchema x-agentic-access: action-class: connected consequence: read subject: optional scope: - config:read token: max-ttl: 3600 audit: none - path: /crawlingManager/{connector}/{connectorId}/schedule method: post operationId: scheduleCrawlingJob x-agentic-access: action-class: acting consequence: write subject: required scope: - crawl:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /crawlingManager/{connector}/{connectorId}/schedule method: get operationId: getCrawlingJobStatus x-agentic-access: action-class: connected consequence: read subject: optional scope: - crawl:read token: max-ttl: 3600 audit: none - path: /crawlingManager/{connector}/{connectorId}/remove method: delete operationId: removeCrawlingJob x-agentic-access: action-class: acting consequence: write subject: required scope: - crawl:delete audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /crawlingManager/schedule/all method: get operationId: getAllCrawlingJobStatus x-agentic-access: action-class: connected consequence: read subject: optional scope: - crawl:read token: max-ttl: 3600 audit: none - path: /crawlingManager/schedule/all method: delete operationId: removeAllCrawlingJob x-agentic-access: action-class: acting consequence: write subject: required scope: - crawl:delete audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /crawlingManager/{connector}/{connectorId}/pause method: post operationId: pauseCrawlingJob x-agentic-access: action-class: acting consequence: write subject: required scope: - crawl:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /crawlingManager/{connector}/{connectorId}/resume method: post operationId: resumeCrawlingJob x-agentic-access: action-class: acting consequence: write subject: required scope: - crawl:write audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /crawlingManager/stats method: get operationId: getQueueStats x-agentic-access: action-class: connected consequence: read subject: optional scope: - crawl:read token: max-ttl: 3600 audit: none - path: /connectors/internal/all-scheduled method: get operationId: getAllScheduledConnectorInstancesInternal x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /mcp method: post operationId: handleMCPRequest x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /mcp method: get operationId: handleMCPStreamingRequest x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none