APIs.io Engineering Platform Access Application-Scoped Policies API is one of 471 APIs that APIs.io Engineering Platform publishes on the APIs.io network, described by a machine-readable OpenAPI specification.
Tagged areas include Access Application-Scoped Policies. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.
This API exposes
5 operations
across 2 paths,
and defines 50 schemas.
It is described by OpenAPI 3.2.0, at version 4.0.0.
Requests are made against the base URL https://{bucketname}.s3.amazonaws.com.
5 operations2 paths50 schemas1 DELETE2 GET1 POST1 PUT
Metadata
The identity and technical contract details declared by the specification.
APIs.io Engineering Platform Access Application-Scoped Policies API declares
4 security schemes
for authenticating requests.
An API key is passed in the header as X-Auth-Email (api_email).
An API key is passed in the header as X-Auth-Key (api_key).
It accepts HTTP bearer tokens (api_token).
An API key is passed in the header as X-Auth-User-Service-Key (user_service_key).
Paths & Operations 5
Across 2 paths, the API surfaces 5 operations — 1 DELETE, 2 GET, 1 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.
The contract defines 50 schemas that model the data the API accepts and returns. The most detailed are access_policy_resp (14 properties), access_policy_req (11 properties), access_api-response-common-failure (4 properties), access_result_info (4 properties). Each schema is shown below with its type and property counts.
access_isolation_required
boolean
Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use…
access_id_response
access_policy_components-schemas-name
string
The name of the Access policy.
access_gsuite_group_rule
object
Matches a group in Google Workspace. Requires a Google Workspace identity provider.
1 property1 required
access_timestamp
string
access_api-response-collection
object
access_approval_required
boolean
Requires the user to request access from an administrator at the start of each session.
access_uuid
string
UUID
access_decision
string
The action Access will take if a user matches this policy.
access_approval_groups
array
Administrators who can approve a temporary authentication request.
A custom message that will appear on the purpose justification screen.
access_rule
object
access_messages
array
access_result_info
object
4 properties
access_everyone_rule
object
Matches everyone.
1 property1 required
access_precedence
integer
The order of execution for this policy. Must be unique for each policy within an app.
access_api-response-common
object
3 properties3 required
access_access_group_rule
object
Matches an Access group.
1 property1 required
access_certificate_rule
object
Matches any valid client certificate.
1 property1 required
access_service_token_rule
object
Matches a specific Access Service Token
1 property1 required
access_include
array
Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.
access_azure_group_rule
object
Matches an Azure group. Requires an Azure identity provider.
1 property1 required
access_email_rule
object
Matches a specific email.
1 property1 required
access_purpose_justification_required
boolean
Require users to enter a justification when they log in to the application.
access_schemas-exclude
array
Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.
access_components-schemas-session_duration
string
The amount of time that tokens issued for the application will be valid. Must be in the format 300ms or 2h45m. Valid time units are: ns, us (or µs), ms, s, m,…
access_country_rule
object
Matches a specific country
1 property1 required
access_approval_group
object
A group of email addresses that can approve a temporary authentication request.
3 properties1 required
access_authentication_method_rule
object
Enforce different MFA options
1 property1 required
access_external_evaluation_rule
object
Create Allow or Block policies which evaluate the user based on custom criteria.
1 property1 required
access_app_policy_response
object
1 property
access_app_policy_request
access_okta_group_rule
object
Matches an Okta group. Requires an Okta identity provider.
1 property1 required
access_github_organization_rule
object
Matches a Github organization. Requires a Github identity provider.
1 property1 required
access_schemas-uuid
string
The UUID of the policy
access_saml_group_rule
object
Matches a SAML group. Requires a SAML identity provider.
1 property1 required
access_policy_resp
object
14 properties
access_domain_rule
object
Match an entire email domain.
1 property1 required
access_any_valid_service_token_rule
object
Matches any valid Access Service Token
1 property1 required
access_api-response-single
object
Specification
The full machine-readable OpenAPI contract behind this narrative.
Every API here is available over the API and to AI agents over MCP. APIs is not yet its own endpoint on the v1 API. Reach this content through network search and the tag graph, or the MCP server below.
Installs https://mcp.apievangelist.com/mcp in Claude, Cursor, VS Code and the rest — one button, every client.
MCP tools for apis
4 tools reach this content
search_api_evangelistSearch every content type across the network at once.
find_relatedThe shared-tag relevance graph — what else covers this.
get_tagEverything one tag labels, across all content types.
guide_topicPRO — a curated bundle for a topic: area, guidance, rules, papers, stories, services.
A second provider on the same verified email joins the account you already have.
Your account
ⓘWhere this information came from
This is an independent, third-party profile of APIs.io Engineering Platform Access Application-Scoped Policies API, published by
API Evangelist. We do not operate, host, resell, or
support these APIs, and we are not affiliated with or endorsed by the company unless stated above.
Everything here is built from publicly available information — the company's own site,
developer portal, documentation, public repositories, and the specifications it publishes for public use.
Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's
public API artifacts, scored against a published rubric. They are not certifications,
endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and
you do not need to justify the request. A removed company is recorded as unrated, never scored
zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy → On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.