MTN Group Agentic Access
MTN Group exposes 475 API operations that an AI agent could call, of which 246 are state-changing ‘acting’ operations. This is a recommended x-agentic-access execution contract — the scope, audience, consequence tier, short-lived token constraints, and escalation each action should carry before it is handed to an autonomous agent.
By consequence: 229 read, 173 write, 59 physical, and 14 safety-critical.
14 operations are classed safety-critical and should require human-in-the-loop approval at runtime.
Contracts are classified heuristically from the provider’s OpenAPI and refresh on every APIs.io network build; audience is bound per deployment. The model follows Curity’s Access Intelligence (apidays Munich 2026). Browse every provider’s agent contracts at agentic-access.apis.io.
By consequence
Highest-consequence actions
The physical and safety-critical operations an agent could invoke — the ones that most warrant scoped tokens, tight TTLs, and escalation. Full per-operation contracts are in the source below.
| Method | Path | Consequence | Human-in-loop |
|---|---|---|---|
| POST | /bundle/callback/{entitlementType} | safety-critical | required |
| PATCH | /customer/{customerId}/pin | safety-critical | required |
| PATCH | /incident/{id} | safety-critical | required |
| POST | /loans/{id}/advance | safety-critical | required |
| POST | /service | safety-critical | required |
| POST | /service/callback/{countryCode}/{consumer}/{requestType} | safety-critical | required |
| POST | /service/license | safety-critical | required |
| PATCH | /service/license/{id} | safety-critical | required |
| PUT | /service/{id} | safety-critical | required |
| DELETE | /service/{id} | safety-critical | required |
| PATCH | /service/{id} | safety-critical | required |
| PATCH | /sim/admin/suspend/{iccid} | safety-critical | required |
| POST | /troubleTicket | safety-critical | required |
| PATCH | /troubleTicket/{id} | safety-critical | required |
| POST | /adviceReconcile/{merchantId} | physical | conditional |
| POST | /balanceTransfer | physical | conditional |
| POST | /bill/refund | physical | conditional |
| POST | /chat/outboundMessageWithMedia | physical | conditional |
| POST | /consent/{customerId}/generateotp | physical | conditional |
| POST | /customers/{customerId}/score/creditinfo | physical | conditional |
| POST | /customers/{id}/plans/provision | physical | conditional |
| POST | /customers/{senderMsisdn} | physical | conditional |
| POST | /customers/{senderMsisdn} | physical | conditional |
| POST | /customers/{senderMsisdn} | physical | conditional |
| PATCH | /customers/{senderMsisdn} | physical | conditional |
Source
Agentic Access
generated: '2026-07-25'
method: generated
source: openapi/mtn-group-account-decisioning.yml, openapi/mtn-group-account-management-coe.yml,
openapi/mtn-group-advertising-v2.yml, openapi/mtn-group-agent-profile.yml, openapi/mtn-group-ayo-preapproval.yml,
openapi/mtn-group-ayoaccountholderinfo.yml, openapi/mtn-group-balance-management-v1.yml, openapi/mtn-group-bss-tt-oauth-v1.yml,
openapi/mtn-group-callmeback-v1.yml, openapi/mtn-group-callmeback-v2.yml, openapi/mtn-group-communication-management-v1.yml,
openapi/mtn-group-content-push.yml, openapi/mtn-group-customer-account-management-v1.yml,
openapi/mtn-group-customer-billing-token-v1.yml, openapi/mtn-group-customer-data-transfer-ng-prod.yml,
openapi/mtn-group-customer-delivery-booking.yml, openapi/mtn-group-customer-identification-v1.yml,
openapi/mtn-group-customer-kyc-verification.yml, openapi/mtn-group-customer-loyalty-management.yml,
openapi/mtn-group-customer-management-coe-za-preprod.yml, openapi/mtn-group-customer-management.yml,
openapi/mtn-group-customer-pin-management-v2.yml, openapi/mtn-group-customer-promotion.yml,
openapi/mtn-group-customer-survey.yml, openapi/mtn-group-device-swap-v1.yml, openapi/mtn-group-digital-partner-management.yml,
openapi/mtn-group-document-managment.yml, openapi/mtn-group-eec-token-management.yml, openapi/mtn-group-g2m.yml,
openapi/mtn-group-hcm-v1.yml, openapi/mtn-group-insurance.yml, openapi/mtn-group-iot-device-management.yml,
openapi/mtn-group-job-card-management.yml, openapi/mtn-group-kyc-consent.yml, openapi/mtn-group-loans-v2.yml,
openapi/mtn-group-logback-v1.yml, openapi/mtn-group-medallia-sms-v2.yml, openapi/mtn-group-merchant-provisioning-v1.yml,
openapi/mtn-group-mobile-customer-information.yml, openapi/mtn-group-momo-verification.yml,
openapi/mtn-group-mtn-advertising-api-v1.yml, openapi/mtn-group-mtn-customer-bill-management.yml,
openapi/mtn-group-mtn-customer-datatransfer.yml, openapi/mtn-group-mtn-customer-kyc-api-v1-product.yml,
openapi/mtn-group-mtn-customer-loans-api-v1.yml, openapi/mtn-group-mtn-customer-locations-api-v1.yml,
openapi/mtn-group-mtn-customer-plans-api-v2.yml, openapi/mtn-group-mtn-customer-profiles-api-v2-product.yml,
openapi/mtn-group-mtn-customer-score.yml, openapi/mtn-group-mtn-ng-retailer-productivity-tracking-v1.yml,
openapi/mtn-group-mtn-nigeria-customer-datashare.yml, openapi/mtn-group-mtn-nigeria-data-gifting-v1.yml,
openapi/mtn-group-mtn-party-management.yml, openapi/mtn-group-mtn-product-offering-api-v2.yml,
openapi/mtn-group-mtn-product-offering-api-v3.yml, openapi/mtn-group-mtn-sms-api-v1.yml, openapi/mtn-group-mtn-sms-interface.yml,
openapi/mtn-group-mtn-subscription-api-v2.yml, openapi/mtn-group-mtnid-getinfo.yml, openapi/mtn-group-notification-production.yml,
openapi/mtn-group-notification-v2.yml, openapi/mtn-group-oauth-v1.yml, openapi/mtn-group-order-fulfillment.yml,
openapi/mtn-group-payment-methods-management-sa.yml, openapi/mtn-group-payments-v1.yml, openapi/mtn-group-product-catalog-coe.yml,
openapi/mtn-group-product-catalog-management-v1.yml, openapi/mtn-group-product-catalogue-management.yml,
openapi/mtn-group-product-ordering-coe.yml, openapi/mtn-group-provisioning.yml, openapi/mtn-group-rcs-capability.yml,
openapi/mtn-group-rcs-communication.yml, openapi/mtn-group-resource-config-v1.yml, openapi/mtn-group-resource-pool-management.yml,
openapi/mtn-group-risk-management.yml, openapi/mtn-group-rwanda-party-management.yml, openapi/mtn-group-sales-management.yml,
openapi/mtn-group-service-activation-and-configuration.yml, openapi/mtn-group-service-ordering.yml,
openapi/mtn-group-siebel.yml, openapi/mtn-group-sim-management-staging.yml, openapi/mtn-group-sim-swap-verification-v1.yml,
openapi/mtn-group-simverification.yml, openapi/mtn-group-sms-v3-api.yml, openapi/mtn-group-subscriber-details.yml,
openapi/mtn-group-subscriber-management.yml, openapi/mtn-group-subscriber-type.yml, openapi/mtn-group-taxation-v1.yml,
openapi/mtn-group-ticket.yml, openapi/mtn-group-tmf-720-digital-identity-management.yml, openapi/mtn-group-tmf-customer-bill-management.yml,
openapi/mtn-group-tmf-document-management-tmf667.yml, openapi/mtn-group-tmf-loyalty-management-tmf658.yml,
openapi/mtn-group-tmf-party-interaction-tmf683.yml, openapi/mtn-group-tmf-party-management.yml,
openapi/mtn-group-tmf-payment-management-tmf676.yml, openapi/mtn-group-tmf-prepay-balance-management-tmf654.yml,
openapi/mtn-group-tmf-product-catalog-tmf620.yml, openapi/mtn-group-tmf-product-ordering-tmf622.yml,
openapi/mtn-group-tmf-resource-ordering-tmf652.yml, openapi/mtn-group-tmf-resourceinventorymanagement-tmf639.yml,
openapi/mtn-group-tmf-service-activation-tmf678.yml, openapi/mtn-group-tmf-trouble-ticket-tmf621.yml,
openapi/mtn-group-tmf-usage-consumption-tmf677.yml, openapi/mtn-group-tmf-usage-management-tmf635.yml,
openapi/mtn-group-tmf629-customer-management.yml, openapi/mtn-group-tmf633-shopping-cart-management.yml,
openapi/mtn-group-tmf637-product-inventory.yml, openapi/mtn-group-tmf681-communication-management.yml,
openapi/mtn-group-tmf688-event-management.yml, openapi/mtn-group-unified-balance-v1.yml, openapi/mtn-group-usage-consumption.yml,
openapi/mtn-group-usage-management.yml, openapi/mtn-group-ussd.yml, openapi/mtn-group-withdrawals-v1.yml
description: Recommended x-agentic-access execution contracts, classified heuristically from
the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind
audience per deployment. See research/curity/agentic-governance/.
summary:
operations: 475
by_action_class:
acting: 246
connected: 229
by_consequence:
write: 173
read: 229
physical: 59
safety-critical: 14
human_in_the_loop_required: 14
operations:
- path: /account/status
method: post
operationId: changeAccountStatus
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /financialAccount/{id}/transaction
method: get
operationId: listFinancialAccountTransactions
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /financialAccount/{id}/transaction/{tid}
method: get
operationId: getFinancialAccountTransaction
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /financialAccount/{id}/outstandingBalance
method: get
operationId: getFinancialAccountOutstandingBalance
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /financialAccount/{id}/balance
method: get
operationId: getFinancialAccountBalance
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /customers/{customerId}
method: post
operationId: MobileAdService_post_fetchAdverts_customerscustomerId
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /{agentId}
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /{customerId}/agentFlag
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /{agentId}/devices
method: patch
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /{agentId}/tracking/
method: post
operationId: addAppInstallationConfirmationDetails
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /consent/{msisdn}
method: post
operationId: consentValidation
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /consent/preapproval
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /consent/cancelPreapproval
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /consent/{customerId}/generateotp
method: post
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /consent/{customerId}/verifyotp
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /accountholders/{id}
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /accountholders/{id}/validate
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /accountholders/{id}/verify
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /accounts/{recipientPhoneNumber}/topUp
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /oauth2/token
method: post
operationId: auth
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /ayo/v1/callmeback
method: post
operationId: callmebackUsingPOST
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /callmeback/{id}
method: get
operationId: getGeographicLocation and postCallMeBack
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /chat/inboundMessage
method: post
operationId: createInboundMessage
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /chat/outboundMediaUpload/{communicationId}
method: post
operationId: UploadMedia
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /chat/outboundMessageWithMedia
method: post
operationId: Send message with media reference
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /contents/pushes
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /wig/push
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /partyAccount/{id}
method: get
operationId: retrievePartyAccount
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /bill/registerToken
method: post
operationId: Register
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /bill/activateToken
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /bill/deactivateToken
method: put
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /bill/urlCreate
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /bill/debit
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /bill/refund
method: post
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /bill/transactionStatus
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /bill/tokenStatus
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /customers/{senderMsisdn}
method: post
operationId: CustomerTransferService_post_transfer_customerssenderMsisd
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customers/transactionStatus
method: get
operationId: CustomerTransferService_get_transactionStatus_customerstransaction
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /notification
method: post
operationId: CustomerTransferService_post_handleConsentNotification_notification
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /booking/province
method: get
operationId: Province
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /booking/town
method: get
operationId: Town
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /booking/suburb
method: get
operationId: Suburb
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /booking/bookingAvailability
method: get
operationId: Booking Availability
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /booking/externalBooking
method: post
operationId: External Booking
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /booking/getBooking
method: get
operationId: Booking update
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /booking/cancelBooking
method: post
operationId: Cancel Booking
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /booking/findBooking
method: get
operationId: Track Booking
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /booking/updateBooking
method: post
operationId: Update Booking
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customer
method: get
operationId: GetUsage,Roaming,RechargeHistory,CustomerProfileorEligibilitystatusofacustomer,identifiedbyanMSISDN
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /customer
method: post
operationId: QueryCustomerorMerchantData
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customers
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /customers
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customers/{customerId}
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customers/{customerId}
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /customers/{customerId}/kycScore
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customers/{customerId}/nameScore
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customers/{customerId}/addressScore
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customers/{customerId}/biometric/verify
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /biometric-roc/customers/identityStatus
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /loyaltyProgramMember/{memberId}/loyaltyProgramProduct
method: get
operationId: List Products
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /loyaltyProgramMember/{memberId}/loyaltyProgramProduct/{programProductId}
method: get
operationId: Get Product
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /customer
method: post
operationId: createCustomer
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customer/attribute
method: patch
operationId: partially update the attribute of a customer
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customer/{portfolioId}/user
method: post
operationId: to add a user
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /sim/admin/suspend/{iccid}
method: patch
operationId: to disable a sim
x-agentic-access:
action-class: acting
consequence: safety-critical
subject: required
audience: null
token:
max-ttl: 120
exchange: true
purpose-required: true
proof-of-possession: true
escalation:
human-in-the-loop: required
audit: required
- path: /momo/tier0/registration
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /momo/tier0/{id}/link/account
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customer/{customerId}/pin
method: post
operationId: createCutomerPin
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customer/{customerId}/pin
method: get
operationId: validateCutomerPin
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /customer/{customerId}/pin
method: put
operationId: changeCutomerPin
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customer/{customerId}/pin
method: patch
operationId: resetCutomerPin
x-agentic-access:
action-class: acting
consequence: safety-critical
subject: required
audience: null
token:
max-ttl: 120
exchange: true
purpose-required: true
proof-of-possession: true
escalation:
human-in-the-loop: required
audit: required
- path: /customer/{customerId}/pinProfile
method: put
operationId: chanageSecurityQnACutomerPin
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customer/{customerId}/pinProfile
method: get
operationId: getProfileDetails
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /tbd/promo
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /eligibilityCheck/{msisdn}
method: get
operationId: getUserProfile
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /optin
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customers/{customerId}
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /customers/{customerId}
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /customers/surveyOptInByTimeStamp
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /customers/surveyInvitation
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /deviceSwap
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /deviceSwap/{id}
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /partners
method: get
operationId: listOrganization
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /partners
method: post
operationId: createOrganization
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /partners/{id}
method: get
operationId: retrieveOrganization
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /partners/{id}
method: patch
operationId: patchOrganization
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /document/{id}
method: get
operationId: retrieveDocument
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /document/{id}
method: patch
operationId: patchDocument
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /document
method: get
operationId: listDocument
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /document
method: post
operationId: createDocument
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /eecToken/{msisdn}/{accountRef}
method: get
operationId: geteecTokensFromDBUsingGet
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /productOffering/deals
method: get
operationId: getDealsResponseUsingGET
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /employee/leaveBalance
method: get
operationId: getLeave Balance
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/quotation
method: post
operationId: Quotation
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/applicati
# --- truncated at 32 KB (141 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/mtn-group/refs/heads/main/agentic-access/mtn-group-agentic-access.yml