Logto Agentic Access
Logto exposes 335 API operations that an AI agent could call, of which 223 are state-changing ‘acting’ operations. This is a recommended x-agentic-access execution contract — the scope, audience, consequence tier, short-lived token constraints, and escalation each action should carry before it is handed to an autonomous agent.
By consequence: 112 read, 212 write, 5 physical, and 6 safety-critical.
6 operations are classed safety-critical and should require human-in-the-loop approval at runtime.
Contracts are classified heuristically from the provider’s OpenAPI and refresh on every APIs.io network build; audience is bound per deployment. The model follows Curity’s Access Intelligence (apidays Munich 2026). Browse every provider’s agent contracts at agentic-access.apis.io.
By consequence
Highest-consequence actions
The physical and safety-critical operations an agent could invoke — the ones that most warrant scoped tokens, tight TTLs, and escalation. Full per-operation contracts are in the source below.
| Method | Path | Consequence | Human-in-loop |
|---|---|---|---|
| DELETE | /api/applications/{id}/users/{userId}/consent-organizations/{organizationId} | safety-critical | required |
| PUT | /api/experience/profile/password | safety-critical | required |
| DELETE | /api/my-account/grants/{grantId} | safety-critical | required |
| DELETE | /api/my-account/sessions/{sessionId} | safety-critical | required |
| DELETE | /api/users/{userId}/grants/{grantId} | safety-critical | required |
| DELETE | /api/users/{userId}/sessions/{sessionId} | safety-critical | required |
| POST | /api/custom-profile-fields/properties/sie-order | physical | conditional |
| POST | /api/experience/verification/mfa-verification-code | physical | conditional |
| POST | /api/experience/verification/verification-code | physical | conditional |
| POST | /api/organization-invitations/{id}/message | physical | conditional |
| POST | /api/verification-codes | physical | conditional |
Source
Agentic Access
generated: '2026-07-15'
method: generated
source: openapi/logto-openapi-original.yml
description: Recommended x-agentic-access execution contracts, classified heuristically from
the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind
audience per deployment. See research/curity/agentic-governance/.
summary:
operations: 335
by_action_class:
connected: 112
acting: 223
by_consequence:
read: 112
write: 212
safety-critical: 6
physical: 5
human_in_the_loop_required: 6
operations:
- path: /api/applications
method: get
operationId: ListApplications
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/applications
method: post
operationId: CreateApplication
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{id}
method: get
operationId: GetApplication
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/applications/{id}
method: patch
operationId: UpdateApplication
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{id}
method: delete
operationId: DeleteApplication
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{applicationId}/custom-data
method: patch
operationId: UpdateApplicationCustomData
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{applicationId}/roles
method: get
operationId: ListApplicationRoles
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/applications/{applicationId}/roles
method: post
operationId: AssignApplicationRoles
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{applicationId}/roles
method: put
operationId: ReplaceApplicationRoles
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{applicationId}/roles/{roleId}
method: delete
operationId: DeleteApplicationRole
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{id}/protected-app-metadata/custom-domains
method: get
operationId: ListApplicationProtectedAppMetadataCustomDomains
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/applications/{id}/protected-app-metadata/custom-domains
method: post
operationId: CreateApplicationProtectedAppMetadataCustomDomain
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{id}/protected-app-metadata/custom-domains/{domain}
method: delete
operationId: DeleteApplicationProtectedAppMetadataCustomDomain
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{id}/organizations
method: get
operationId: ListApplicationOrganizations
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/applications/{id}/legacy-secret
method: delete
operationId: DeleteApplicationLegacySecret
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{id}/secrets
method: get
operationId: ListApplicationSecrets
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/applications/{id}/secrets
method: post
operationId: CreateApplicationSecret
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{id}/secrets/{name}
method: delete
operationId: DeleteApplicationSecret
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{id}/secrets/{name}
method: patch
operationId: UpdateApplicationSecret
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{applicationId}/user-consent-scopes
method: post
operationId: CreateApplicationUserConsentScope
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{applicationId}/user-consent-scopes
method: get
operationId: ListApplicationUserConsentScopes
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/applications/{applicationId}/user-consent-scopes/{scopeType}/{scopeId}
method: delete
operationId: DeleteApplicationUserConsentScope
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{applicationId}/sign-in-experience
method: put
operationId: ReplaceApplicationSignInExperience
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{applicationId}/sign-in-experience
method: get
operationId: GetApplicationSignInExperience
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/applications/{id}/users/{userId}/consent-organizations
method: get
operationId: ListApplicationUserConsentOrganizations
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/applications/{id}/users/{userId}/consent-organizations
method: put
operationId: ReplaceApplicationUserConsentOrganizations
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{id}/users/{userId}/consent-organizations
method: post
operationId: CreateApplicationUserConsentOrganization
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/applications/{id}/users/{userId}/consent-organizations/{organizationId}
method: delete
operationId: DeleteApplicationUserConsentOrganization
x-agentic-access:
action-class: acting
consequence: safety-critical
subject: required
audience: null
token:
max-ttl: 120
exchange: true
purpose-required: true
proof-of-possession: true
escalation:
human-in-the-loop: required
audit: required
scope:
- all
- path: /api/configs/admin-console
method: get
operationId: GetAdminConsoleConfig
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/configs/admin-console
method: patch
operationId: UpdateAdminConsoleConfig
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/configs/oidc/session
method: get
operationId: GetOidcSessionConfig
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/configs/oidc/session
method: patch
operationId: UpdateOidcSessionConfig
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/configs/oidc/{keyType}
method: get
operationId: GetOidcKeys
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/configs/oidc/{keyType}/{keyId}
method: delete
operationId: DeleteOidcKey
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/configs/oidc/{keyType}/rotate
method: post
operationId: RotateOidcKeys
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/configs/jwt-customizer/{tokenTypePath}
method: put
operationId: UpsertJwtCustomizer
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/configs/jwt-customizer/{tokenTypePath}
method: patch
operationId: UpdateJwtCustomizer
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/configs/jwt-customizer/{tokenTypePath}
method: get
operationId: GetJwtCustomizer
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/configs/jwt-customizer/{tokenTypePath}
method: delete
operationId: DeleteJwtCustomizer
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/configs/jwt-customizer
method: get
operationId: ListJwtCustomizers
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/configs/jwt-customizer/test
method: post
operationId: TestJwtCustomizer
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/configs/id-token
method: get
operationId: GetIdTokenConfig
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/configs/id-token
method: put
operationId: UpsertIdTokenConfig
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/connectors
method: post
operationId: CreateConnector
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/connectors
method: get
operationId: ListConnectors
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/connectors/{id}
method: get
operationId: GetConnector
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/connectors/{id}
method: patch
operationId: UpdateConnector
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/connectors/{id}
method: delete
operationId: DeleteConnector
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/connectors/{factoryId}/test
method: post
operationId: CreateConnectorTest
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/connectors/{connectorId}/authorization-uri
method: post
operationId: CreateConnectorAuthorizationUri
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/connector-factories
method: get
operationId: ListConnectorFactories
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/connector-factories/{id}
method: get
operationId: GetConnectorFactory
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/resources
method: get
operationId: ListResources
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/resources
method: post
operationId: CreateResource
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/resources/{id}
method: get
operationId: GetResource
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/resources/{id}
method: patch
operationId: UpdateResource
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/resources/{id}
method: delete
operationId: DeleteResource
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/resources/{id}/is-default
method: patch
operationId: UpdateResourceIsDefault
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/resources/{resourceId}/scopes
method: get
operationId: ListResourceScopes
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/resources/{resourceId}/scopes
method: post
operationId: CreateResourceScope
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/resources/{resourceId}/scopes/{scopeId}
method: patch
operationId: UpdateResourceScope
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/resources/{resourceId}/scopes/{scopeId}
method: delete
operationId: DeleteResourceScope
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/sign-in-exp
method: get
operationId: GetSignInExp
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/sign-in-exp
method: patch
operationId: UpdateSignInExp
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/sign-in-exp/default/check-password
method: post
operationId: CheckPasswordWithDefaultSignInExperience
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/sign-in-exp/default/custom-ui-assets
method: post
operationId: UploadCustomUiAssets
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}
method: get
operationId: GetUser
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/users/{userId}
method: patch
operationId: UpdateUser
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}
method: delete
operationId: DeleteUser
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/custom-data
method: get
operationId: ListUserCustomData
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/users/{userId}/custom-data
method: patch
operationId: UpdateUserCustomData
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/logto-configs
method: get
operationId: ListUserLogtoConfigs
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/users/{userId}/logto-configs
method: patch
operationId: UpdateUserLogtoConfigs
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/profile
method: patch
operationId: UpdateUserProfile
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users
method: post
operationId: CreateUser
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users
method: get
operationId: ListUsers
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/users/{userId}/password
method: patch
operationId: UpdateUserPassword
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/password/verify
method: post
operationId: VerifyUserPassword
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/has-password
method: get
operationId: GetUserHasPassword
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/users/{userId}/is-suspended
method: patch
operationId: UpdateUserIsSuspended
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/roles
method: get
operationId: ListUserRoles
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/users/{userId}/roles
method: post
operationId: AssignUserRoles
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/roles
method: put
operationId: ReplaceUserRoles
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/roles/{roleId}
method: delete
operationId: DeleteUserRole
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/identities/{target}
method: put
operationId: ReplaceUserIdentity
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/identities/{target}
method: delete
operationId: DeleteUserIdentity
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/identities/{target}
method: get
operationId: GetUserIdentity
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/users/{userId}/identities
method: post
operationId: CreateUserIdentity
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/organizations
method: get
operationId: ListUserOrganizations
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/users/{userId}/grants
method: get
operationId: ListUserGrants
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/users/{userId}/grants/{grantId}
method: delete
operationId: DeleteUserGrant
x-agentic-access:
action-class: acting
consequence: safety-critical
subject: required
audience: null
token:
max-ttl: 120
exchange: true
purpose-required: true
proof-of-possession: true
escalation:
human-in-the-loop: required
audit: required
scope:
- all
- path: /api/users/{userId}/mfa-verifications
method: get
operationId: ListUserMfaVerifications
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/users/{userId}/mfa-verifications
method: post
operationId: CreateUserMfaVerification
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/mfa-verifications/{verificationId}
method: delete
operationId: DeleteUserMfaVerification
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
scope:
- all
- path: /api/users/{userId}/personal-access-tokens
method: get
operationId: ListUserPersonalAccessTokens
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
scope:
- all
- path: /api/users/{userId}/personal-access-tokens
method: post
operationId: CreateUserPersonalAccessToken
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
trigg
# --- truncated at 32 KB (111 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/logto/refs/heads/main/agentic-access/logto-agentic-access.yml