Ordo · Agentic Access

Ordo Agentic Access

x-agentic-access generated

Ordo exposes 54 API operations that an AI agent could call, of which 25 are state-changing ‘acting’ operations. This is a recommended x-agentic-access execution contract — the scope, audience, consequence tier, short-lived token constraints, and escalation each action should carry before it is handed to an autonomous agent.

By consequence: 29 read, 18 write, and 7 physical.

Contracts are classified heuristically from the provider’s OpenAPI and refresh on every APIs.io network build; audience is bound per deployment. The model follows Curity’s Access Intelligence (apidays Munich 2026). Browse every provider’s agent contracts at agentic-access.apis.io.

PaymentsUnited KingdomOpen BankingAccount-to-AccountPayment InitiationVariable Recurring PaymentsRequest to PayReal-Time PaymentsFaster PaymentsPSD2Account Information
Operations: 54 Acting: 25 Human-in-the-loop: 0 Method: generated

By consequence

read 29 write 18 physical 7

Highest-consequence actions

The physical and safety-critical operations an agent could invoke — the ones that most warrant scoped tokens, tight TTLs, and escalation. Full per-operation contracts are in the source below.

MethodPathConsequenceHuman-in-loop
POST /create physical conditional
POST /initiate physical conditional
POST /smartRequests/newSmartRequestBDRLink physical conditional
POST /smartRequests/newSmartRequestMessage physical conditional
POST /smartRequests/withdrawSmartRequestMessage physical conditional
POST /smartRequests/withdrawSmartRequestMessageBDR physical conditional
POST /withdraw physical conditional

Source

Agentic Access

Raw ↑
generated: '2026-07-24'
method: generated
source: openapi/ordo-account-data-client-hosted.yml, openapi/ordo-account-data-ordo-hosted.yml,
  openapi/ordo-recurring-payment-mandates.yml, openapi/ordo-registry-manager.yml, openapi/ordo-single-payments.yml,
  openapi/ordo-smart-request-manager.yml
description: Recommended x-agentic-access execution contracts, classified heuristically from
  the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind
  audience per deployment. See research/curity/agentic-governance/.
summary:
  operations: 54
  by_action_class:
    connected: 29
    acting: 25
  by_consequence:
    read: 29
    write: 18
    physical: 7
  human_in_the_loop_required: 0
operations:
- path: /account/information/institutions
  method: get
  operationId: get-account-information-institutions
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/information/create
  method: post
  operationId: post-account-information-create
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /account/information/data
  method: post
  operationId: post-account-information-data
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /account/information/data
  method: get
  operationId: get-account-information-data-aisdatarequestid-aisdatarequestid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/information/consent/{aisConsentId}
  method: get
  operationId: get-account-information-consent-aisconsentid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/information/consents
  method: get
  operationId: get-account-information-consents
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/information/cancel
  method: post
  operationId: post-account-information-cancel
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /account/information/data/request/{aisDataRequestId}
  method: get
  operationId: get-account-information-data-request-aisdatarequestid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/information/data/requests/{aisConsentId}
  method: get
  operationId: get-account-information-data-requests-aisconsentid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/information/initiate
  method: post
  operationId: post-account-information-clienthostedinitiate
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /account/verification/create
  method: post
  operationId: post-account-verification-create
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /account/verification/initiate
  method: post
  operationId: post-account-verification-clienthostedinitiate
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /account/verification/institutions
  method: get
  operationId: get-account-verification-institutions
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/verification/{avId}
  method: get
  operationId: get-account-verification-avid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/verification/account
  method: get
  operationId: get-account-verification-account
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/verification/account/{avId}
  method: get
  operationId: get-account-verification-account-avid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/information/create
  method: post
  operationId: post-account-information-create
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /account/information/data
  method: post
  operationId: post-account-information-data
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /account/information/data
  method: get
  operationId: get-account-information-data-aisdatarequestid-aisdatarequestid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/information/consent/{aisConsentId}
  method: get
  operationId: get-account-information-consent-aisconsentid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/information/consents
  method: get
  operationId: get-account-information-consents
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/information/cancel
  method: post
  operationId: post-account-information-cancel
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /account/information/data/request/{aisDataRequestId}
  method: get
  operationId: get-account-information-data-request-aisdatarequestid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/information/data/requests/{aisConsentId}
  method: get
  operationId: get-account-information-data-requests-aisconsentid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/verification/create
  method: post
  operationId: post-account-verification-create
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /account/verification/initiate
  method: post
  operationId: post-account-verification-initiate
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /account/verification/institutions
  method: get
  operationId: get-account-verification-institutions
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/verification/{avId}
  method: get
  operationId: get-account-verification-avid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/verification/account
  method: get
  operationId: get-account-verification-account
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /account/verification/account/{avId}
  method: get
  operationId: get-account-verification-account-avid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /VRPMandate/sweeping
  method: post
  operationId: post-vrpmandate
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /VRPMandate/{mandateId}
  method: get
  operationId: get-vrpmandate-mandateid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /VRPMandates
  method: get
  operationId: get-vrpmandates
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /VRPTransaction/{vrpTransactionId}
  method: get
  operationId: get-vrptransaction-vrptransactionid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /VRPTransactions/{vrpMandateId}
  method: get
  operationId: get-vrptransactions-vrpmandateid
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /VRPMandate/nonsweeping
  method: post
  operationId: 63e10df05af59030f7e5fa4b
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /Registry/{billerAccountId}
  method: get
  operationId: GetBillerAccountDetailsAsync
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /Registry/{billerAccountId}
  method: delete
  operationId: DeleteBillerAccountAsync
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /Registry
  method: put
  operationId: PutBillerAccountAsync
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /Registry
  method: post
  operationId: PostBillerAccountAsync
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /Registry
  method: get
  operationId: GetBillerAccountsAsync
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /Registry/BillerAccountId
  method: get
  operationId: GetBillerAccountIdAsync
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /institutions
  method: get
  operationId: get-institutions
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /create
  method: post
  operationId: postsmartrequestbdrasync
  x-agentic-access:
    action-class: acting
    consequence: physical
    subject: required
    audience: null
    token:
      max-ttl: 300
      exchange: true
      purpose-required: true
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /initiate
  method: post
  operationId: post-initiatepayment
  x-agentic-access:
    action-class: acting
    consequence: physical
    subject: required
    audience: null
    token:
      max-ttl: 300
      exchange: true
      purpose-required: true
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /withdraw
  method: post
  operationId: postwithdrawsmartrequestbdrasync
  x-agentic-access:
    action-class: acting
    consequence: physical
    subject: required
    audience: null
    token:
      max-ttl: 300
      exchange: true
      purpose-required: true
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /smartRequests/newSmartRequestBDRLink
  method: post
  operationId: PostSmartRequestBDRAsync
  x-agentic-access:
    action-class: acting
    consequence: physical
    subject: required
    audience: null
    token:
      max-ttl: 300
      exchange: true
      purpose-required: true
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /smartRequests/{smartRequestId}
  method: get
  operationId: GetSmartRequestAsync
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /smartRequests/smartRequestMessages
  method: get
  operationId: GetSmartRequestsAsync
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /smartRequests/withdrawSmartRequestMessageBDR
  method: post
  operationId: PostWithdrawSmartRequestBDRAsync
  x-agentic-access:
    action-class: acting
    consequence: physical
    subject: required
    audience: null
    token:
      max-ttl: 300
      exchange: true
      purpose-required: true
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /smartRequests/newSmartRequestMessage
  method: post
  operationId: PostSmartRequestAsync
  x-agentic-access:
    action-class: acting
    consequence: physical
    subject: required
    audience: null
    token:
      max-ttl: 300
      exchange: true
      purpose-required: true
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /smartRequests/withdrawSmartRequestMessage
  method: post
  operationId: PostWithdrawSmartRequestAsync
  x-agentic-access:
    action-class: acting
    consequence: physical
    subject: required
    audience: null
    token:
      max-ttl: 300
      exchange: true
      purpose-required: true
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /smartRequests/grantExtensionMessage
  method: post
  operationId: PostSmartRequestMessagesGrantDueDateAsync
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /smartRequests/declineExtensionMessage
  method: post
  operationId: PostSmartRequestMessagesDeclineDueDateAsync
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required