generated: '2026-07-15' method: generated source: openapi/slashid-api-openapi.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 156 by_action_class: acting: 97 connected: 59 by_consequence: write: 91 safety-critical: 6 read: 59 human_in_the_loop_required: 6 operations: - path: /token/validate method: post operationId: PostTokenValidate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /token/revoke method: post operationId: PostTokenRevoke x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /organizations/sso/saml/provider-credentials method: get operationId: GetOrganizationsSamlProviderCredentials x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/sso/saml/provider-credentials method: post operationId: PostOrganizationsSamlProviderCredentials x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/sso/saml/provider-credentials/{saml_provider_credentials_id} method: get operationId: GetOrganizationsSsoSamlProviderCredentialsSamlProviderCredentialsId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/sso/saml/provider-credentials/{saml_provider_credentials_id} method: delete operationId: DeleteOrganizationsSsoSamlProviderCredentialsSamlProviderCredentialsId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/sso/saml/provider-credentials/{saml_provider_credentials_id} method: patch operationId: PatchOrganizationsSsoSamlProviderCredentialsSamlProviderCredentialsId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /sso/oidc/tokens/revoke method: post operationId: PostSsoOidcTokensRevoke x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /sso/oidc/tokens/revoke/v2 method: post operationId: PostSsoOidcTokensRevokeV2 x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /sso/oidc/tokens method: get operationId: GetSsoOidcTokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /sso/oidc/tokens/query method: post operationId: PostSsoOidcTokensQuery x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/direct-id method: post operationId: PostPersonsPersonIdDirectId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/mint-token method: post operationId: PostPersonsPersonIdMintToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/credentials method: get operationId: GetPersonsPersonIdCredentials x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons/{person_id}/credentials method: post operationId: PostPersonsPersonIdCredentials x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/credentials method: delete operationId: DeletePersonsPersonIdCredentials x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/credentials/{credential_id} method: delete operationId: DeletePersonsPersonIdCredentialsCredentialId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/credentials/password method: put operationId: PutPersonsPersonIdCredentialsPassword x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/credentials/password-reset method: post operationId: PostPersonsPersonIdCredentialsPasswordReset x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /persons/{person_id}/credentials/password-rotate method: post operationId: PostPersonsPersonIdCredentialsPasswordRotate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/attributes method: patch operationId: PatchPersonsPersonIdAttributes x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/attributes method: put operationId: PutPersonsPersonIdAttributes x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/attributes method: get operationId: GetPersonsPersonIdAttributes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons/{person_id}/attributes/{bucket_name} method: patch operationId: PatchPersonsPersonIdAttributesBucketName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/attributes/{bucket_name} method: put operationId: PutPersonsPersonIdAttributesBucketName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/attributes/{bucket_name} method: get operationId: GetPersonsPersonIdAttributesBucketName x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons/{person_id}/attributes/{bucket_name} method: delete operationId: DeletePersonsPersonIdAttributesBucketName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/consent/gdpr method: get operationId: GetPersonsPersonIdConsentGdpr x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons/{person_id}/consent/gdpr method: post operationId: PostPersonsPersonIdConsentGdpr x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/consent/gdpr method: put operationId: PutPersonsPersonIdConsentGdpr x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/consent/gdpr method: delete operationId: DeletePersonsPersonIdConsentGdpr x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /consent/gdpr method: get operationId: GetConsentGdpr x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /consent/gdpr method: post operationId: PostConsentGdpr x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /consent/gdpr method: put operationId: PutConsentGdpr x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /consent/gdpr method: delete operationId: DeleteConsentGdpr x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id} method: get operationId: GetPersonsPersonId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons/{person_id} method: delete operationId: DeletePersonsPersonId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id} method: patch operationId: PatchPersonsPersonId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/handles method: post operationId: PostPersonsPersonIdHandles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/handles method: get operationId: GetPersonsPersonIdHandles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons/{person_id}/handles/{handle} method: delete operationId: DeletePersonsPersonIdHandlesHandle x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/groups method: get operationId: GetPersonsPersonIdGroups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons/{person_id}/groups method: put operationId: PutPersonsPersonIdGroups x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/permissions method: get operationId: GetPersonsPersonIdPermissions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons/{person_id}/additional-permissions method: get operationId: GetPersonsPersonIdAdditionalPermissions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons/{person_id}/additional-permissions method: put operationId: PutPersonsPersonIdPermissions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/roles method: get operationId: GetPersonsPersonIdRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons/{person_id}/roles method: put operationId: PutPersonsPersonIdRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons/{person_id}/organizations method: get operationId: GetPersonsPersonIdOrganizations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons method: post operationId: PostPersons x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons method: put operationId: PutPersons x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /persons method: get operationId: GetPersons x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons/bulk-import method: get operationId: GetPersonsBulkImport x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /persons/bulk-import method: post operationId: PostPersonsBulkImport x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /groups method: post operationId: PostGroups x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /groups method: get operationId: GetGroups x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{group_name} method: get operationId: GetGroupsGroupName x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{group_name} method: delete operationId: DeleteGroupsGroupName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /groups/{group_name}/persons method: post operationId: PostGroupsGroupNamePersons x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /groups/{group_name}/persons method: get operationId: GetGroupsGroupNamePersons x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /groups/{group_name}/persons/{person_id} method: delete operationId: DeleteGroupsGroupNamePersonsPersonId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /rbac/permissions method: post operationId: PostRBACPermissions x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /rbac/permissions method: get operationId: GetRBACPermissions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /rbac/permissions/{permission_name} method: get operationId: GetRBACPermissionsPermissionName x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /rbac/permissions/{permission_name} method: patch operationId: PatchRBACPermissionsPermissionName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /rbac/permissions/{permission_name} method: delete operationId: DeleteRBACPermissionsPermissionName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /rbac/roles method: post operationId: PostRBACRoles x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /rbac/roles method: get operationId: GetRBACRoles x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /rbac/roles/{role_name} method: get operationId: GetRBACRolesRoleName x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /rbac/roles/{role_name} method: patch operationId: PatchRBACRolesRoleName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /rbac/roles/{role_name} method: delete operationId: DeleteRBACRolesRoleName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /rbac/check method: post operationId: PostRBACCheck x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/config/external-credentials method: get operationId: GetOrganizationsConfigExternalCredentials x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/config/external-credentials method: post operationId: PostOrganizationsConfigExternalCredentials x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/config/external-credentials method: delete operationId: DeleteOrganizationsConfigExternalCredentials x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/config/external-credentials/{cred_id} method: get operationId: GetOrganizationsConfigExternalCredentialsCredId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/config/external-credentials/{cred_id} method: patch operationId: PatchOrganizationsConfigExternalCredentialsCredId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/config/templates method: get operationId: GetOrganizationsConfigTemplates x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/config/templates/{template_name} method: get operationId: GetOrganizationsConfigTemplatesTemplateName x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/config/templates/{template_name} method: put operationId: PutOrganizationsConfigTemplatesTemplateName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/config/domains method: get operationId: GetOrganizationsConfigDomains x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/config/domains method: delete operationId: DeleteOrganizationsConfigDomains x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/config/domains method: post operationId: PostOrganizationsConfigDomains x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/config/token-template method: get operationId: GetOrganizationsConfigTokenTemplate x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/config/token-template method: put operationId: PutOrganizationsConfigTokenTemplate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/sso/oidc/provider-credentials method: get operationId: GetOrganizationsSsoOidcProviderCredentials x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/sso/oidc/provider-credentials method: post operationId: PostOrganizationsSsoOidcProviderCredentials x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/sso/oidc/provider-credentials/{oauth_client_id} method: get operationId: GetOrganizationsSsoOidcProviderCredentialsOauthClientId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/sso/oidc/provider-credentials/{oauth_client_id} method: delete operationId: DeleteOrganizationsSsoOidcProviderCredentialsOauthClientId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/sso/oidc/provider-credentials/{oauth_client_id} method: patch operationId: PatchOrganizationsSsoOidcProviderCredentialsOauthClientId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations method: get operationId: GetOrganizations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations method: delete operationId: DeleteOrganizations x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/attributes method: patch operationId: PatchOrganizationsAttributes x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/attributes method: put operationId: PutOrganizationsAttributes x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/attributes method: get operationId: GetOrganizationsAttributes x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/attributes/{bucket_name} method: patch operationId: PatchOrganizationsAttributesBucketName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/attributes/{bucket_name} method: put operationId: PutOrganizationsAttributesBucketName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/attributes/{bucket_name} method: get operationId: GetOrganizationsAttributesBucketName x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/attributes/{bucket_name} method: delete operationId: DeleteOrganizationsAttributesBucketName x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/suborganizations method: get operationId: GetOrganizationsSuborganizations x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/suborganizations method: post operationId: PostOrganizationsSuborganizations x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/api-keys method: put operationId: PutOrganizationsApiKeys x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/config method: get operationId: GetOrganizationsConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/config method: patch operationId: PatchOrganizationsConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/quota/current-tier method: get operationId: GetOrganizationsQuotaCurrentTier x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/quota/all-tiers method: get operationId: GetOrganizationsQuotaAllTiers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/quota/usage method: get operationId: GetOrganizationsQuotaUsage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/attribute-buckets method: get operationId: GetOrganizationsAttributeBuckets x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/config/kyc method: get operationId: GetOrganizationsConfigKyc x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/config/kyc method: patch operationId: PatchOrganizationsConfigKyc x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/webhooks method: post operationId: PostOrganizationsWebhooks x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/webhooks method: get operationId: GetOrganizationsWebhooks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/webhooks/{webhook_id} method: get operationId: GetOrganizationsWebhooksWebhookId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/webhooks/{webhook_id} method: patch operationId: PatchOrganizationsWebhooksWebhookId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/webhooks/{webhook_id} method: delete operationId: DeleteOrganizationsWebhooksWebhookId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/webhooks/{webhook_id}/triggers method: get operationId: GetOrganizationsWebhooksWebhookIdTriggers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /organizations/webhooks/{webhook_id}/triggers method: post operationId: PostOrganizationsWebhooksWebhookIdTriggers x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/webhooks/{webhook_id}/triggers method: delete operationId: DeleteOrganizationsWebhooksWebhookIdTriggers x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /organizations/webhooks/verification-jwks method: get operationId: GetOrganizationsWebhooksVerificationJwks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth2/clients method: post operationId: PostOauth2Clients x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth2/clients method: get operationId: GetOauth2Clients x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth2/clients/{oauth_client_id} method: get operationId: GetOauth2ClientsOauthClientId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth2/clients/{oauth_client_id} method: delete operationId: DeleteOauth2ClientsOauthClientId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth2/clients/{oauth_client_id} method: patch operationId: PatchOauth2ClientsOauthClientId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth2/clients/{oauth_client_id}/secret method: put operationId: PutOauth2ClientsOauthClientIdSecret x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth2/clients/{oauth_client_id}/ui-configuration method: get operationId: GetOauth2UiConfiguration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth2/clients/{oauth_client_id}/ui-configuration method: put operationId: PutOauth2UiConfiguration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth2/authorize method: get operationId: GetOauth2Authorize x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth2/tokens method: post operationId: PostOauth2Tokens x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth2/tokens/revoke method: post operationId: PostOauth2TokensRevoke x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /oauth2/tokens/revoke-all method: post operationId: PostOauth2TokensRevokeAll x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /oauth2/tokens/introspect method: post operationId: PostOauth2TokensIntrospect x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth2/tokens/mint method: post operationId: PostOauth2TokensMint x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /oauth2/userinfo method: get operationId: GetOauth2Userinfo x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /oauth2/userinfo method: post operationId: PostOauth2Userinfo x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /test-events method: post operationId: PostTestEvents x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /.well-known/openid-configuration method: get operationId: GetWellKnownOpenidConfiguration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /.well-known/jwks.json method: get operationId: GetWellKnownJwksJson x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /workflows method: post operationId: PostWorkflows x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workflows method: get operationId: GetWorkflows x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /workflows/{workflow_id} method: get operationId: GetWorkflowsWorkflowId x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /workflows/{workflow_id} method: patch operationId: PatchWorkflowsWorkflowId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workflows/{workflow_id} method: delete operationId: DeleteWorkflowsWorkflowId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workflows/{workflow_id}/versions method: get operationId: GetWorkflowsWorkflowIdVersions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /workflows/{workflow_id}/versions/{version} method: get operationId: GetWorkflowsWorkflowIdVersionsVersion x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /workflows/{workflow_id}/versions/{version} method: post operationId: PostWorkflowsWorkflowIdVersionsVersionRestore x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workflows/{workflow_id}/activate method: post operationId: PostWorkflowsWorkflowIdActivate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workflows/{workflow_id}/pause method: post operationId: PostWorkflowsWorkflowIdPause x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workflows/{workflow_id}/resume method: post operationId: PostWorkflowsWorkflowIdResume x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workflows/{workflow_id}/execute method: post operationId: PostWorkflowsWorkflowIdExecute x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workflows/{workflow_id}/scheduled-execute method: post operationId: PostWorkflowsWorkflowIdScheduledExecute x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /workflows/cypher-preview method: post operationId: PostWorkflowsCypherPreview x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /super-admins method: post operationId: PostSuperAdmins x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /super-admins method: get operationId: GetSuperAdmins x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /super-admins/{person_id} method: delete operationId: DeleteSuperAdminsPersonId x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /super-admins/audit-logs method: get operationId: GetSuperAdminsAuditLogs x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none