Ordo Agentic Access
Ordo exposes 54 API operations that an AI agent could call, of which 25 are state-changing ‘acting’ operations. This is a recommended x-agentic-access execution contract — the scope, audience, consequence tier, short-lived token constraints, and escalation each action should carry before it is handed to an autonomous agent.
By consequence: 29 read, 18 write, and 7 physical.
Contracts are classified heuristically from the provider’s OpenAPI and refresh on every APIs.io network build; audience is bound per deployment. The model follows Curity’s Access Intelligence (apidays Munich 2026). Browse every provider’s agent contracts at agentic-access.apis.io.
By consequence
Highest-consequence actions
The physical and safety-critical operations an agent could invoke — the ones that most warrant scoped tokens, tight TTLs, and escalation. Full per-operation contracts are in the source below.
| Method | Path | Consequence | Human-in-loop |
|---|---|---|---|
| POST | /create | physical | conditional |
| POST | /initiate | physical | conditional |
| POST | /smartRequests/newSmartRequestBDRLink | physical | conditional |
| POST | /smartRequests/newSmartRequestMessage | physical | conditional |
| POST | /smartRequests/withdrawSmartRequestMessage | physical | conditional |
| POST | /smartRequests/withdrawSmartRequestMessageBDR | physical | conditional |
| POST | /withdraw | physical | conditional |
Source
Agentic Access
generated: '2026-07-24'
method: generated
source: openapi/ordo-account-data-client-hosted.yml, openapi/ordo-account-data-ordo-hosted.yml,
openapi/ordo-recurring-payment-mandates.yml, openapi/ordo-registry-manager.yml, openapi/ordo-single-payments.yml,
openapi/ordo-smart-request-manager.yml
description: Recommended x-agentic-access execution contracts, classified heuristically from
the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind
audience per deployment. See research/curity/agentic-governance/.
summary:
operations: 54
by_action_class:
connected: 29
acting: 25
by_consequence:
read: 29
write: 18
physical: 7
human_in_the_loop_required: 0
operations:
- path: /account/information/institutions
method: get
operationId: get-account-information-institutions
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/information/create
method: post
operationId: post-account-information-create
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /account/information/data
method: post
operationId: post-account-information-data
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /account/information/data
method: get
operationId: get-account-information-data-aisdatarequestid-aisdatarequestid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/information/consent/{aisConsentId}
method: get
operationId: get-account-information-consent-aisconsentid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/information/consents
method: get
operationId: get-account-information-consents
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/information/cancel
method: post
operationId: post-account-information-cancel
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /account/information/data/request/{aisDataRequestId}
method: get
operationId: get-account-information-data-request-aisdatarequestid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/information/data/requests/{aisConsentId}
method: get
operationId: get-account-information-data-requests-aisconsentid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/information/initiate
method: post
operationId: post-account-information-clienthostedinitiate
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /account/verification/create
method: post
operationId: post-account-verification-create
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /account/verification/initiate
method: post
operationId: post-account-verification-clienthostedinitiate
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /account/verification/institutions
method: get
operationId: get-account-verification-institutions
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/verification/{avId}
method: get
operationId: get-account-verification-avid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/verification/account
method: get
operationId: get-account-verification-account
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/verification/account/{avId}
method: get
operationId: get-account-verification-account-avid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/information/create
method: post
operationId: post-account-information-create
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /account/information/data
method: post
operationId: post-account-information-data
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /account/information/data
method: get
operationId: get-account-information-data-aisdatarequestid-aisdatarequestid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/information/consent/{aisConsentId}
method: get
operationId: get-account-information-consent-aisconsentid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/information/consents
method: get
operationId: get-account-information-consents
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/information/cancel
method: post
operationId: post-account-information-cancel
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /account/information/data/request/{aisDataRequestId}
method: get
operationId: get-account-information-data-request-aisdatarequestid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/information/data/requests/{aisConsentId}
method: get
operationId: get-account-information-data-requests-aisconsentid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/verification/create
method: post
operationId: post-account-verification-create
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /account/verification/initiate
method: post
operationId: post-account-verification-initiate
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /account/verification/institutions
method: get
operationId: get-account-verification-institutions
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/verification/{avId}
method: get
operationId: get-account-verification-avid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/verification/account
method: get
operationId: get-account-verification-account
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /account/verification/account/{avId}
method: get
operationId: get-account-verification-account-avid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /VRPMandate/sweeping
method: post
operationId: post-vrpmandate
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /VRPMandate/{mandateId}
method: get
operationId: get-vrpmandate-mandateid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /VRPMandates
method: get
operationId: get-vrpmandates
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /VRPTransaction/{vrpTransactionId}
method: get
operationId: get-vrptransaction-vrptransactionid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /VRPTransactions/{vrpMandateId}
method: get
operationId: get-vrptransactions-vrpmandateid
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /VRPMandate/nonsweeping
method: post
operationId: 63e10df05af59030f7e5fa4b
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /Registry/{billerAccountId}
method: get
operationId: GetBillerAccountDetailsAsync
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /Registry/{billerAccountId}
method: delete
operationId: DeleteBillerAccountAsync
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /Registry
method: put
operationId: PutBillerAccountAsync
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /Registry
method: post
operationId: PostBillerAccountAsync
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /Registry
method: get
operationId: GetBillerAccountsAsync
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /Registry/BillerAccountId
method: get
operationId: GetBillerAccountIdAsync
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /institutions
method: get
operationId: get-institutions
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /create
method: post
operationId: postsmartrequestbdrasync
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /initiate
method: post
operationId: post-initiatepayment
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /withdraw
method: post
operationId: postwithdrawsmartrequestbdrasync
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /smartRequests/newSmartRequestBDRLink
method: post
operationId: PostSmartRequestBDRAsync
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /smartRequests/{smartRequestId}
method: get
operationId: GetSmartRequestAsync
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /smartRequests/smartRequestMessages
method: get
operationId: GetSmartRequestsAsync
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /smartRequests/withdrawSmartRequestMessageBDR
method: post
operationId: PostWithdrawSmartRequestBDRAsync
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /smartRequests/newSmartRequestMessage
method: post
operationId: PostSmartRequestAsync
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /smartRequests/withdrawSmartRequestMessage
method: post
operationId: PostWithdrawSmartRequestAsync
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /smartRequests/grantExtensionMessage
method: post
operationId: PostSmartRequestMessagesGrantDueDateAsync
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /smartRequests/declineExtensionMessage
method: post
operationId: PostSmartRequestMessagesDeclineDueDateAsync
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required