generated: '2026-07-15' method: generated source: openapi/token-io-openapi.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 71 by_action_class: connected: 47 acting: 24 by_consequence: read: 47 write: 13 physical: 10 safety-critical: 1 human_in_the_loop_required: 1 operations: - path: /accounts method: get operationId: GatewayService.GetAccounts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId} method: get operationId: GatewayService.GetAccount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account-balance method: get operationId: GatewayService.GetBalances x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/balance method: get operationId: GatewayService.GetBalance x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/standing-orders method: get operationId: GatewayService.GetStandingOrders x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/standing-orders/{standingOrderId} method: get operationId: GatewayService.GetStandingOrder x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/transactions method: get operationId: GatewayService.GetTransactions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /accounts/{accountId}/transaction/{transactionId} method: get operationId: GatewayService.GetTransaction x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /banks method: get operationId: GatewayService.GetBanks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /bank/countries method: get operationId: GatewayService.GetBanksCountries x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /member/sub-tpps method: post operationId: GatewayService.CreateSubTpp x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /member/sub-tpps method: get operationId: GatewayService.RetrieveSubTpps x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /member/sub-tpps/{subTppId} method: get operationId: GatewayService.RetrieveSubTpp x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /member/sub-tpps/{subTppId} method: delete operationId: GatewayService.DeleteSubTpp x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /member/sub-tpps/{subTppId}/children method: get operationId: GatewayService.RetrieveSubTppChildren x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /member/{memberId}/keys method: post operationId: GatewayService.AddMemberKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /member/{memberId}/keys method: get operationId: GatewayService.GetMemberKeys x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /member/{memberId}/keys/{keyId} method: get operationId: GatewayService.GetMemberKey x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /member/{memberId}/keys/{keyId} method: delete operationId: GatewayService.DeleteMemberKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /reports/banks/status method: get operationId: GatewayService.GetBanksStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /reports/banks/{bankId}/status method: get operationId: GatewayService.GetBankStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /token-requests method: post operationId: GatewayService.StoreTokenRequest x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /token-requests/{requestId} method: get operationId: GatewayService.RetrieveTokenRequest x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /token-requests/{tokenRequestId}/result method: get operationId: GatewayService.GetTokenRequestResultWithStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tokens method: get operationId: GatewayService.GetTokens x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tokens/{tokenId} method: get operationId: GatewayService.GetToken x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tokens/{tokenId}/cancel method: put operationId: GatewayService.CancelToken x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /transfers method: post operationId: GatewayService.CreateTransfer x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /transfers method: get operationId: GatewayService.GetTransfers x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /token-requests/{tokenRequestId}/authorization method: post operationId: GatewayService.InitiateBankAuthorization x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /transfers/{transferId} method: get operationId: GatewayService.GetTransfer x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /webhook/config method: put operationId: GatewayService.SetWebhookConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /webhook/config method: get operationId: GatewayService.GetWebhookConfig x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /webhook/config method: delete operationId: GatewayService.DeleteWebhookConfig x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vrp-consents method: post operationId: CreateVrpConsent x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /vrp-consents method: get operationId: GetVrpConsents x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vrp-consents/{id} method: get operationId: GetVrpConsent x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vrp-consents/{id} method: delete operationId: RevokeVrpConsent x-agentic-access: action-class: acting consequence: safety-critical subject: required audience: null token: max-ttl: 120 exchange: true purpose-required: true proof-of-possession: true escalation: human-in-the-loop: required audit: required - path: /vrp-consents/{id}/payments method: get operationId: GetVrpConsentPayments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /vrps/{id}/confirm-funds method: get operationId: ConfirmFunds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /refunds method: post operationId: InitiateRefund x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /refunds method: get operationId: GetRefunds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /refunds/{id} method: get operationId: GetRefund x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /transfers/{id}/refunds method: get operationId: GetTransferRefunds x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /payouts method: post operationId: InitiatePayout x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /payouts method: get operationId: GetPayouts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /payouts/{id} method: get operationId: GetPayout x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v2/banks method: get operationId: GetBanksv2 x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v2/payments method: post operationId: InitiatePayment x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v2/payments method: get operationId: GetPayments x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tokenized-accounts method: post operationId: CreateTokenizedAccount x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /tokenized-accounts/{tokenizedAccountId} method: get operationId: GetTokenizedAccount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /tokenized-accounts/{tokenizedAccountId} method: delete operationId: DeleteTokenizedAccount x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v2/payments/{paymentId} method: get operationId: GetPayment x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v2/payments/{paymentId}/embedded-auth method: post operationId: ProvideEmbeddedFields x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v2/payment-links method: post operationId: CreatePaymentLink x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v2/payment-links method: get operationId: ListPaymentLinks x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v2/payment-links/{paymentLinkId} method: get operationId: GetPaymentLink x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v2/payment-links/{paymentLinkId} method: delete operationId: DeactivatePaymentLink x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /virtual-accounts method: post operationId: GatewayService.CreateVirtualAccount x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /virtual-accounts method: get operationId: GatewayService.GetVirtualAccounts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /virtual-accounts/{accountId} method: get operationId: GatewayService.GetVirtualAccountById x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /virtual-accounts/{accountId}/transactions method: get operationId: GatewayService.GetVirtualAccountTransactions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /virtual-accounts/{accountId}/transactions/{providerPaymentId} method: get operationId: GatewayService.GetVirtualAccountTransaction x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /virtual-accounts/{accountId}/settlement-rule method: post operationId: GatewayService.CreateVirtualAccountSettlementRule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /virtual-accounts/{accountId}/settlement-rules method: get operationId: GatewayService.GetVirtualAccountSettlementRules x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /virtual-accounts/{accountId}/settlement-rules/{settlementRuleId} method: get operationId: GatewayService.GetVirtualAccountSettlementRule x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /virtual-accounts/{accountId}/settlement-rules/{settlementRuleId} method: delete operationId: GatewayService.DeleteVirtualAccountSettlementRule x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /virtual-accounts/{accountId}/settlement-rule-payouts method: get operationId: GatewayService.GetVirtualAccountSettlementPayouts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /qr-code method: get operationId: GetQrCode x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /account-verifications method: post operationId: post-verification x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required