This API exposes
5 operations
across 2 paths,
and defines 45 schemas.
It is described by OpenAPI 3.0.0, at version 2015-07-09.
Requests are made against 4 base URLs: http://apigateway.{region}.amazonaws.com, https://apigateway.{region}.amazonaws.com, http://apigateway.{region}.amazonaws.com.cn, https://apigateway.{region}.amazonaws.com.cn.
5 operations2 paths45 schemas1 DELETE2 GET1 POST1 PUT
Metadata
The identity and technical contract details declared by the specification.
APIs.io Engineering Platform Zone-Level Access Policies API declares
1 security scheme
for authenticating requests.
An API key is passed in the header as Authorization (hmac).
By default, every request must be authenticated.
hmac — Amazon Signature authorization v4
Paths & Operations 5
Across 2 paths, the API surfaces 5 operations — 1 DELETE, 2 GET, 1 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.
The contract defines 45 schemas that model the data the API accepts and returns. The most detailed are access_policies (14 properties), access_api-response-common-failure (4 properties), access_result_info (4 properties), access_schemas-approval_group (3 properties). Each schema is shown below with its type and property counts.
access_schemas-approval_group
object
A group of email addresses that can approve a temporary authentication request.
3 properties1 required
access_schemas-require
array
Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.
access_any_valid_service_token_rule
object
Matches any valid Access Service Token
1 property1 required
access_service_token_rule
object
Matches a specific Access Service Token
1 property1 required
access_api-response-collection
object
access_policies_components-schemas-name
string
The name of the Access policy.
access_rule
object
access_uuid
string
UUID
access_github_organization_rule
object
Matches a Github organization. Requires a Github identity provider.
1 property1 required
access_authentication_method_rule
object
Enforce different MFA options
1 property1 required
access_schemas-approval_groups
array
Administrators who can approve a temporary authentication request.
access_identifier
string
Identifier
access_saml_group_rule
object
Matches a SAML group. Requires a SAML identity provider.
1 property1 required
access_access_group_rule
object
Matches an Access group.
1 property1 required
access_policies
object
14 properties
access_country_rule
object
Matches a specific country
1 property1 required
access_result_info
object
4 properties
access_api-response-common-failure
object
4 properties4 required
access_ip_list_rule
object
Matches an IP address from a list.
1 property1 required
access_approval_required
boolean
Requires the user to request access from an administrator at the start of each session.
access_ip_rule
object
Matches an IP address block.
1 property1 required
access_purpose_justification_required
boolean
Require users to enter a justification when they log in to the application.
access_gsuite_group_rule
object
Matches a group in Google Workspace. Requires a Google Workspace identity provider.
1 property1 required
access_okta_group_rule
object
Matches an Okta group. Requires an Okta identity provider.
1 property1 required
access_api-response-common
object
3 properties3 required
access_domain_rule
object
Match an entire email domain.
1 property1 required
access_email_rule
object
Matches a specific email.
1 property1 required
access_external_evaluation_rule
object
Create Allow or Block policies which evaluate the user based on custom criteria.
1 property1 required
access_messages
array
access_device_posture_rule
object
Enforces a device posture rule has run successfully
1 property1 required
access_schemas-exclude
array
Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.
access_decision
string
The action Access will take if a user matches this policy.