Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

APIs.io Engineering Platform Zone-Level Access Policies API

The Zone-Level Access Policies API from APIs.io Engineering Platform — 2 operation(s) for zone-level access policies.

This API exposes 5 operations across 2 paths, and defines 45 schemas. It is described by OpenAPI 3.0.0, at version 2015-07-09.

Requests are made against 4 base URLs: http://apigateway.{region}.amazonaws.com, https://apigateway.{region}.amazonaws.com, http://apigateway.{region}.amazonaws.com.cn, https://apigateway.{region}.amazonaws.com.cn.

5 operations 2 paths 45 schemas 1 DELETE2 GET1 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.0.0
API Version
2015-07-09
Base URL
https://{bucketname}.s3.amazonaws.com
Authentication
API Key
Terms of Service
Resource Areas
1

Authentication & Security 1

APIs.io Engineering Platform Zone-Level Access Policies API declares 1 security scheme for authenticating requests. An API key is passed in the header as Authorization (hmac). By default, every request must be authenticated.

  • hmac — Amazon Signature authorization v4

Paths & Operations 5

Across 2 paths, the API surfaces 5 operations — 1 DELETE, 2 GET, 1 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Zone-Level Access Policies 5
GET
/zones/{zone_id}/access/apps/{app_id}/policies
APIs.io Engineering Platform List Access policies
zone-level-access-policies-list-access-policies 2 params → 4XX200
POST
/zones/{zone_id}/access/apps/{app_id}/policies
APIs.io Engineering Platform Create an Access policy
zone-level-access-policies-create-an-access-policy 2 params body → 4XX201
DELETE
/zones/{zone_id}/access/apps/{app_id}/policies/{policy_id}
APIs.io Engineering Platform Delete an Access policy
zone-level-access-policies-delete-an-access-policy 3 params → 4XX202
GET
/zones/{zone_id}/access/apps/{app_id}/policies/{policy_id}
APIs.io Engineering Platform Get an Access policy
zone-level-access-policies-get-an-access-policy 3 params → 4XX200
PUT
/zones/{zone_id}/access/apps/{app_id}/policies/{policy_id}
APIs.io Engineering Platform Update an Access policy
zone-level-access-policies-update-an-access-policy 3 params body → 4XX200

Schemas 45

The contract defines 45 schemas that model the data the API accepts and returns. The most detailed are access_policies (14 properties), access_api-response-common-failure (4 properties), access_result_info (4 properties), access_schemas-approval_group (3 properties). Each schema is shown below with its type and property counts.

access_schemas-approval_group
object
A group of email addresses that can approve a temporary authentication request.
3 properties 1 required
access_schemas-require
array
Rules evaluated with an AND logical operator. To match the policy, a user must meet all of the Require rules.
access_any_valid_service_token_rule
object
Matches any valid Access Service Token
1 property 1 required
access_service_token_rule
object
Matches a specific Access Service Token
1 property 1 required
access_api-response-collection
object
access_policies_components-schemas-name
string
The name of the Access policy.
access_rule
object
access_uuid
string
UUID
access_github_organization_rule
object
Matches a Github organization. Requires a Github identity provider.
1 property 1 required
access_authentication_method_rule
object
Enforce different MFA options
1 property 1 required
access_schemas-approval_groups
array
Administrators who can approve a temporary authentication request.
access_identifier
string
Identifier
access_saml_group_rule
object
Matches a SAML group. Requires a SAML identity provider.
1 property 1 required
access_access_group_rule
object
Matches an Access group.
1 property 1 required
access_policies
object
14 properties
access_country_rule
object
Matches a specific country
1 property 1 required
access_result_info
object
4 properties
access_api-response-common-failure
object
4 properties 4 required
access_ip_list_rule
object
Matches an IP address from a list.
1 property 1 required
access_approval_required
boolean
Requires the user to request access from an administrator at the start of each session.
access_ip_rule
object
Matches an IP address block.
1 property 1 required
access_purpose_justification_required
boolean
Require users to enter a justification when they log in to the application.
access_gsuite_group_rule
object
Matches a group in Google Workspace. Requires a Google Workspace identity provider.
1 property 1 required
access_okta_group_rule
object
Matches an Okta group. Requires an Okta identity provider.
1 property 1 required
access_api-response-common
object
3 properties 3 required
access_domain_rule
object
Match an entire email domain.
1 property 1 required
access_email_rule
object
Matches a specific email.
1 property 1 required
access_external_evaluation_rule
object
Create Allow or Block policies which evaluate the user based on custom criteria.
1 property 1 required
access_messages
array
access_device_posture_rule
object
Enforces a device posture rule has run successfully
1 property 1 required
access_schemas-exclude
array
Rules evaluated with a NOT logical operator. To match the policy, a user cannot meet any of the Exclude rules.
access_decision
string
The action Access will take if a user matches this policy.
access_id_response
access_timestamp
string
access_everyone_rule
object
Matches everyone.
1 property 1 required
access_policies_components-schemas-response_collection
access_policies_components-schemas-single_response
access_email_list_rule
object
Matches an email address from a list.
1 property 1 required
access_schemas-isolation_required
boolean
Require this application to be served in an isolated browser for users matching this policy.
access_purpose_justification_prompt
string
A custom message that will appear on the purpose justification screen.
access_azure_group_rule
object
Matches an Azure group. Requires an Azure identity provider.
1 property 1 required
access_certificate_rule
object
Matches any valid client certificate.
1 property 1 required
access_schemas-precedence
integer
The order of execution for this policy. Must be unique for each policy.
access_api-response-single
object
access_include
array
Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

engineering-platform-zone-level-access-policies-api-openapi.yml Raw ↑