Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

APIs.io Engineering Platform Access Policy Tester API

The Access Policy Tester API from APIs.io Engineering Platform — 3 operation(s) for access policy tester.

This API exposes 3 operations across 3 paths, and defines 56 schemas. It is described by OpenAPI 3.0.0, at version 2015-07-09.

Requests are made against 4 base URLs: http://apigateway.{region}.amazonaws.com, https://apigateway.{region}.amazonaws.com, http://apigateway.{region}.amazonaws.com.cn, https://apigateway.{region}.amazonaws.com.cn.

3 operations 3 paths 56 schemas 2 GET1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.0
API Version
2015-07-09
Base URL
https://{bucketname}.s3.amazonaws.com
Authentication
API Key
Terms of Service
Resource Areas
1

Authentication & Security 1

APIs.io Engineering Platform Access Policy Tester API declares 1 security scheme for authenticating requests. An API key is passed in the header as Authorization (hmac). By default, every request must be authenticated.

  • hmac — Amazon Signature authorization v4

Paths & Operations 3

Across 3 paths, the API surfaces 3 operations — 2 GET, 1 POST. Each is listed below with its method, path, parameters, and response codes.

Access Policy Tester 3
POST
/accounts/{account_id}/access/policy-tests
APIs.io Engineering Platform Start Access policy test
access-policy-tests 1 param body → 200400
GET
/accounts/{account_id}/access/policy-tests/{policy_test_id}
APIs.io Engineering Platform Get the current status of a given Access policy test
access-policy-tests-get-an-update 2 params → 200400
GET
/accounts/{account_id}/access/policy-tests/{policy_test_id}/users
APIs.io Engineering Platform Get an Access policy test users page
access-policy-tests-get-a-user-page 2 params → 200400

Schemas 56

The contract defines 56 schemas that model the data the API accepts and returns. The most detailed are access_policy_resp (14 properties), access_policy_update_resp (9 properties), access_api-response-common-failure (4 properties), access_policy_users (4 properties). Each schema is shown below with its type and property counts.

access_approval_groups
array
Administrators who can approve a temporary authentication request.
access_schemas-require
array
Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.
access_any_valid_service_token_rule
object
Matches any valid Access Service Token
1 property 1 required
access_update_status
string
The status of the policy test.
access_percent_users_processed
integer
The percentage of users processed so far (of the entire user base).
access_service_token_rule
object
Matches a specific Access Service Token
1 property 1 required
access_policy_components-schemas-name
string
The name of the Access policy.
access_policy_users_resp
array
Page of processed users.
access_policy_update_resp
object
9 properties
access_uuid
string
UUID
access_rule
object
access_users_blocked
integer
The number of (processed) users blocked based on policy evaluation results.
access_authentication_method_rule
object
Enforce different MFA options
1 property 1 required
access_github_organization_rule
object
Matches a Github organization. Requires a Github identity provider.
1 property 1 required
access_email
string
The email of the user.
access_identifier
string
Identifier
access_status
string
The status of the policy test request.
access_saml_group_rule
object
Matches a SAML group. Requires a SAML identity provider.
1 property 1 required
access_access_group_rule
object
Matches an Access group.
1 property 1 required
access_country_rule
object
Matches a specific country
1 property 1 required
access_api-response-common-failure
object
4 properties 4 required
access_policy_users
object
4 properties
access_ip_list_rule
object
Matches an IP address from a list.
1 property 1 required
access_percent_blocked
integer
The percentage of (processed) users blocked based on policy evaluation results.
access_policy_resp
object
14 properties
access_approval_required
boolean
Requires the user to request access from an administrator at the start of each session.
access_ip_rule
object
Matches an IP address block.
1 property 1 required
access_purpose_justification_required
boolean
Require users to enter a justification when they log in to the application.
access_gsuite_group_rule
object
Matches a group in Google Workspace. Requires a Google Workspace identity provider.
1 property 1 required
access_isolation_required
boolean
Require this application to be served in an isolated browser for users matching this policy. 'Client Web Isolation' must be on for the account in order to use…
access_pages_processed
integer
The number of pages of (processed) users.
access_total_users
integer
The total number of users in the user base.
access_policy_init_resp
object
2 properties
access_okta_group_rule
object
Matches an Okta group. Requires an Okta identity provider.
1 property 1 required
access_percent_approved
integer
The percentage of (processed) users approved based on policy evaluation results.
access_email_rule
object
Matches a specific email.
1 property 1 required
access_external_evaluation_rule
object
Create Allow or Block policies which evaluate the user based on custom criteria.
1 property 1 required
access_domain_rule
object
Match an entire email domain.
1 property 1 required
access_components-schemas-session_duration
string
The amount of time that tokens issued for the application will be valid. Must be in the format 300ms or 2h45m. Valid time units are: ns, us (or µs), ms, s, m,…
access_users_approved
integer
The number of (processed) users approved based on policy evaluation results.
access_messages
array
access_device_posture_rule
object
Enforces a device posture rule has run successfully
1 property 1 required
access_schemas-exclude
array
Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.
access_users_components-schemas-name
string
The name of the user.
access_policy_test_id
string
The UUID of the policy test.
access_decision
string
The action Access will take if a user matches this policy.
access_timestamp
string
access_everyone_rule
object
Matches everyone.
1 property 1 required
access_email_list_rule
object
Matches an email address from a list.
1 property 1 required
access_approval_group
object
A group of email addresses that can approve a temporary authentication request.
3 properties 1 required
access_user_result
string
Policy evaluation result for an individual user.
access_purpose_justification_prompt
string
A custom message that will appear on the purpose justification screen.
access_azure_group_rule
object
Matches an Azure group. Requires an Azure identity provider.
1 property 1 required
access_certificate_rule
object
Matches any valid client certificate.
1 property 1 required
access_schemas-uuid
string
The UUID of the policy
access_include
array
Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

engineering-platform-access-policy-tester-api-openapi.yml Raw ↑