generated: '2026-07-15' method: generated source: openapi/zuplo-openapi.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 45 by_action_class: acting: 26 connected: 19 by_consequence: write: 23 read: 19 physical: 3 human_in_the_loop_required: 0 operations: - path: /mcp/docs method: post operationId: MCPService_post x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /openapi method: get operationId: openApi x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/audit-logs method: get operationId: AuditLogsService_list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/custom-domains method: get operationId: CustomDomainsService_list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/custom-domains method: post operationId: CustomDomainsService_create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/custom-domains method: patch operationId: CustomDomainsService_update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/custom-domains method: delete operationId: CustomDomainsService_delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets method: get operationId: ApiKeyBucketsService_list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/key-buckets method: post operationId: ApiKeyBucketsService_create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets/{bucketName} method: get operationId: ApiKeyBucketsService_read x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/key-buckets/{bucketName} method: patch operationId: ApiKeyBucketsService_update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets/{bucketName} method: delete operationId: ApiKeyBucketsService_delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers method: get operationId: ApiKeyConsumersService_list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers method: post operationId: ApiKeyConsumersService_create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName} method: get operationId: ApiKeyConsumersService_read x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName} method: patch operationId: ApiKeyConsumersService_update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName} method: delete operationId: ApiKeyConsumersService_delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName}/keys method: get operationId: ApiKeyKeysService_list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName}/keys method: post operationId: ApiKeyKeysService_create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName}/keys/$bulk method: post operationId: ApiKeyKeysService_bulkCreate x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName}/keys/{keyId} method: get operationId: ApiKeyKeysService_get x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName}/keys/{keyId} method: patch operationId: ApiKeyKeysService_update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName}/keys/{keyId} method: delete operationId: ApiKeyKeysService_delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName}/managers method: get operationId: ApiKeyConsumerManagers_list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName}/managers method: post operationId: ApiKeyConsumerManagers_create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName}/managers/{managerId} method: delete operationId: ApiKeyConsumerManagers_delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/key-buckets/{bucketName}/consumers/{consumerName}/roll-key method: post operationId: ApiKeyConsumersService_rollKey x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/projects/{projectName}/branches/{branchName}/variables method: post operationId: VariablesService_create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/projects/{projectName}/branches/{branchName}/variables/{variableName} method: patch operationId: VariablesService_update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/projects/{projectName}/deployment-status/{statusId} method: get operationId: V1_deploymentStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/projects/{projectName}/deployments method: get operationId: DeploymentsService_list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/tunnels method: get operationId: TunnelService_list x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/tunnels method: post operationId: TunnelService_create x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/tunnels/{tunnelId} method: get operationId: TunnelService_read x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/tunnels/{tunnelId} method: delete operationId: TunnelService_delete x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/tunnels/{tunnelId}/$rotate-token method: post operationId: TunnelService_update x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/tunnels/{tunnelId}/provisioning-operations/{operationId} method: get operationId: TunneledServicesService_getProvisioningStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/tunnels/{tunnelId}/services-configuration method: get operationId: TunneledServicesService_getServiceConfiguration x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/accounts/{accountName}/tunnels/{tunnelId}/services-configuration method: put operationId: TunneledServicesService_putServiceConfiguration x-agentic-access: action-class: acting consequence: write subject: required audience: null token: max-ttl: 900 escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/accounts/{accountName}/tunnels/{tunnelId}/teardown-operations/{operationId} method: get operationId: TunnelService_getProvisioningStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/deployments/sources method: post operationId: DeployService_sources x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/deployments/{deploymentName} method: get operationId: DeploymentsService_read x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /v1/deployments/{deploymentName} method: delete operationId: DeploymentsService_delete x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/deployments/{deploymentName}/deploy method: post operationId: DeployService_redeploy x-agentic-access: action-class: acting consequence: physical subject: required audience: null token: max-ttl: 300 exchange: true purpose-required: true escalation: human-in-the-loop: conditional triggers: - abnormal - high-value audit: required - path: /v1/who-am-i method: get operationId: V1_whoAmI x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none