OWASP ZAP · Agentic Access

OWASP ZAP Agentic Access

x-agentic-access generated

OWASP ZAP exposes 735 API operations that an AI agent could call, of which 0 are state-changing ‘acting’ operations. This is a recommended x-agentic-access execution contract — the scope, audience, consequence tier, short-lived token constraints, and escalation each action should carry before it is handed to an autonomous agent.

By consequence: 735 read.

Contracts are classified heuristically from the provider’s OpenAPI and refresh on every APIs.io network build; audience is bound per deployment. The model follows Curity’s Access Intelligence (apidays Munich 2026). Browse every provider’s agent contracts at agentic-access.apis.io.

Security TestingApplication SecurityVulnerability ScanningTestingOpen Source
Operations: 735 Acting: 0 Human-in-the-loop: 0 Method: generated

By consequence

read 735

Source

Agentic Access

Raw ↑
generated: '2026-07-15'
method: generated
source: openapi/owasp-zap-openapi.yml
description: Recommended x-agentic-access execution contracts, classified heuristically from
  the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind
  audience per deployment. See research/curity/agentic-governance/.
summary:
  operations: 735
  by_action_class:
    connected: 735
  by_consequence:
    read: 735
  human_in_the_loop_required: 0
operations:
- path: /JSON/accessControl/action/scan/
  method: get
  operationId: accessControlActionScan
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/accessControl/action/writeHTMLreport/
  method: get
  operationId: accessControlActionWriteHTMLreport
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/accessControl/view/getScanProgress/
  method: get
  operationId: accessControlViewGetScanProgress
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/accessControl/view/getScanStatus/
  method: get
  operationId: accessControlViewGetScanStatus
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/acsrf/action/addOptionToken/
  method: get
  operationId: acsrfActionAddOptionToken
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/acsrf/action/removeOptionToken/
  method: get
  operationId: acsrfActionRemoveOptionToken
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/acsrf/action/setOptionPartialMatchingEnabled/
  method: get
  operationId: acsrfActionSetOptionPartialMatchingEnabled
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /OTHER/acsrf/other/genForm/
  method: get
  operationId: acsrfOtherGenForm
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/acsrf/view/optionPartialMatchingEnabled/
  method: get
  operationId: acsrfViewOptionPartialMatchingEnabled
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/acsrf/view/optionTokensNames/
  method: get
  operationId: acsrfViewOptionTokensNames
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/addAllowedResource/
  method: get
  operationId: ajaxSpiderActionAddAllowedResource
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/addExcludedElement/
  method: get
  operationId: ajaxSpiderActionAddExcludedElement
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/modifyExcludedElement/
  method: get
  operationId: ajaxSpiderActionModifyExcludedElement
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/removeAllowedResource/
  method: get
  operationId: ajaxSpiderActionRemoveAllowedResource
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/removeExcludedElement/
  method: get
  operationId: ajaxSpiderActionRemoveExcludedElement
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/scan/
  method: get
  operationId: ajaxSpiderActionScan
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/scanAsUser/
  method: get
  operationId: ajaxSpiderActionScanAsUser
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setEnabledAllowedResource/
  method: get
  operationId: ajaxSpiderActionSetEnabledAllowedResource
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionBrowserId/
  method: get
  operationId: ajaxSpiderActionSetOptionBrowserId
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionClickDefaultElems/
  method: get
  operationId: ajaxSpiderActionSetOptionClickDefaultElems
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionClickElemsOnce/
  method: get
  operationId: ajaxSpiderActionSetOptionClickElemsOnce
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionEnableExtensions/
  method: get
  operationId: ajaxSpiderActionSetOptionEnableExtensions
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionEventWait/
  method: get
  operationId: ajaxSpiderActionSetOptionEventWait
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionLogoutAvoidance/
  method: get
  operationId: ajaxSpiderActionSetOptionLogoutAvoidance
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionMaxCrawlDepth/
  method: get
  operationId: ajaxSpiderActionSetOptionMaxCrawlDepth
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionMaxCrawlStates/
  method: get
  operationId: ajaxSpiderActionSetOptionMaxCrawlStates
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionMaxDuration/
  method: get
  operationId: ajaxSpiderActionSetOptionMaxDuration
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionNumberOfBrowsers/
  method: get
  operationId: ajaxSpiderActionSetOptionNumberOfBrowsers
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionRandomInputs/
  method: get
  operationId: ajaxSpiderActionSetOptionRandomInputs
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionReloadWait/
  method: get
  operationId: ajaxSpiderActionSetOptionReloadWait
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/setOptionScopeCheck/
  method: get
  operationId: ajaxSpiderActionSetOptionScopeCheck
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/action/stop/
  method: get
  operationId: ajaxSpiderActionStop
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/allowedResources/
  method: get
  operationId: ajaxSpiderViewAllowedResources
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/excludedElements/
  method: get
  operationId: ajaxSpiderViewExcludedElements
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/fullResults/
  method: get
  operationId: ajaxSpiderViewFullResults
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/numberOfResults/
  method: get
  operationId: ajaxSpiderViewNumberOfResults
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionBrowserId/
  method: get
  operationId: ajaxSpiderViewOptionBrowserId
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionClickDefaultElems/
  method: get
  operationId: ajaxSpiderViewOptionClickDefaultElems
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionClickElemsOnce/
  method: get
  operationId: ajaxSpiderViewOptionClickElemsOnce
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionEnableExtensions/
  method: get
  operationId: ajaxSpiderViewOptionEnableExtensions
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionEventWait/
  method: get
  operationId: ajaxSpiderViewOptionEventWait
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionLogoutAvoidance/
  method: get
  operationId: ajaxSpiderViewOptionLogoutAvoidance
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionMaxCrawlDepth/
  method: get
  operationId: ajaxSpiderViewOptionMaxCrawlDepth
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionMaxCrawlStates/
  method: get
  operationId: ajaxSpiderViewOptionMaxCrawlStates
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionMaxDuration/
  method: get
  operationId: ajaxSpiderViewOptionMaxDuration
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionNumberOfBrowsers/
  method: get
  operationId: ajaxSpiderViewOptionNumberOfBrowsers
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionRandomInputs/
  method: get
  operationId: ajaxSpiderViewOptionRandomInputs
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionReloadWait/
  method: get
  operationId: ajaxSpiderViewOptionReloadWait
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/optionScopeCheck/
  method: get
  operationId: ajaxSpiderViewOptionScopeCheck
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/results/
  method: get
  operationId: ajaxSpiderViewResults
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ajaxSpider/view/status/
  method: get
  operationId: ajaxSpiderViewStatus
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/action/addAlert/
  method: get
  operationId: alertActionAddAlert
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/action/deleteAlert/
  method: get
  operationId: alertActionDeleteAlert
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/action/deleteAlerts/
  method: get
  operationId: alertActionDeleteAlerts
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/action/deleteAllAlerts/
  method: get
  operationId: alertActionDeleteAllAlerts
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/action/updateAlert/
  method: get
  operationId: alertActionUpdateAlert
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/action/updateAlertsConfidence/
  method: get
  operationId: alertActionUpdateAlertsConfidence
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/action/updateAlertsRisk/
  method: get
  operationId: alertActionUpdateAlertsRisk
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/view/alert/
  method: get
  operationId: alertViewAlert
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/view/alertCountsByRisk/
  method: get
  operationId: alertViewAlertCountsByRisk
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/view/alerts/
  method: get
  operationId: alertViewAlerts
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/view/alertsByRisk/
  method: get
  operationId: alertViewAlertsByRisk
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/view/alertsSummary/
  method: get
  operationId: alertViewAlertsSummary
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alert/view/numberOfAlerts/
  method: get
  operationId: alertViewNumberOfAlerts
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alertFilter/action/addAlertFilter/
  method: get
  operationId: alertFilterActionAddAlertFilter
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alertFilter/action/addGlobalAlertFilter/
  method: get
  operationId: alertFilterActionAddGlobalAlertFilter
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alertFilter/action/applyAll/
  method: get
  operationId: alertFilterActionApplyAll
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alertFilter/action/applyContext/
  method: get
  operationId: alertFilterActionApplyContext
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alertFilter/action/applyGlobal/
  method: get
  operationId: alertFilterActionApplyGlobal
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alertFilter/action/removeAlertFilter/
  method: get
  operationId: alertFilterActionRemoveAlertFilter
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alertFilter/action/removeGlobalAlertFilter/
  method: get
  operationId: alertFilterActionRemoveGlobalAlertFilter
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alertFilter/action/testAll/
  method: get
  operationId: alertFilterActionTestAll
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alertFilter/action/testContext/
  method: get
  operationId: alertFilterActionTestContext
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alertFilter/action/testGlobal/
  method: get
  operationId: alertFilterActionTestGlobal
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alertFilter/view/alertFilterList/
  method: get
  operationId: alertFilterViewAlertFilterList
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/alertFilter/view/globalAlertFilterList/
  method: get
  operationId: alertFilterViewGlobalAlertFilterList
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/addExcludedParam/
  method: get
  operationId: ascanActionAddExcludedParam
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/addScanPolicy/
  method: get
  operationId: ascanActionAddScanPolicy
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/clearExcludedFromScan/
  method: get
  operationId: ascanActionClearExcludedFromScan
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/disableAllScanners/
  method: get
  operationId: ascanActionDisableAllScanners
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/disableScanners/
  method: get
  operationId: ascanActionDisableScanners
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/enableAllScanners/
  method: get
  operationId: ascanActionEnableAllScanners
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/enableScanners/
  method: get
  operationId: ascanActionEnableScanners
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/excludeFromScan/
  method: get
  operationId: ascanActionExcludeFromScan
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/importScanPolicy/
  method: get
  operationId: ascanActionImportScanPolicy
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/modifyExcludedParam/
  method: get
  operationId: ascanActionModifyExcludedParam
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/pause/
  method: get
  operationId: ascanActionPause
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/pauseAllScans/
  method: get
  operationId: ascanActionPauseAllScans
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/removeAllScans/
  method: get
  operationId: ascanActionRemoveAllScans
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/removeExcludedParam/
  method: get
  operationId: ascanActionRemoveExcludedParam
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/removeScan/
  method: get
  operationId: ascanActionRemoveScan
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/removeScanPolicy/
  method: get
  operationId: ascanActionRemoveScanPolicy
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/resume/
  method: get
  operationId: ascanActionResume
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/resumeAllScans/
  method: get
  operationId: ascanActionResumeAllScans
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/scan/
  method: get
  operationId: ascanActionScan
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/scanAsUser/
  method: get
  operationId: ascanActionScanAsUser
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setEnabledPolicies/
  method: get
  operationId: ascanActionSetEnabledPolicies
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionAddQueryParam/
  method: get
  operationId: ascanActionSetOptionAddQueryParam
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionAllowAttackOnStart/
  method: get
  operationId: ascanActionSetOptionAllowAttackOnStart
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionAttackPolicy/
  method: get
  operationId: ascanActionSetOptionAttackPolicy
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionDefaultPolicy/
  method: get
  operationId: ascanActionSetOptionDefaultPolicy
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionDelayInMs/
  method: get
  operationId: ascanActionSetOptionDelayInMs
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionEncodeCookieValues/
  method: get
  operationId: ascanActionSetOptionEncodeCookieValues
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionHandleAntiCSRFTokens/
  method: get
  operationId: ascanActionSetOptionHandleAntiCSRFTokens
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionHostPerScan/
  method: get
  operationId: ascanActionSetOptionHostPerScan
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionInjectPluginIdInHeader/
  method: get
  operationId: ascanActionSetOptionInjectPluginIdInHeader
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionMaxAlertsPerRule/
  method: get
  operationId: ascanActionSetOptionMaxAlertsPerRule
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionMaxChartTimeInMins/
  method: get
  operationId: ascanActionSetOptionMaxChartTimeInMins
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionMaxResultsToList/
  method: get
  operationId: ascanActionSetOptionMaxResultsToList
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionMaxRuleDurationInMins/
  method: get
  operationId: ascanActionSetOptionMaxRuleDurationInMins
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionMaxScanDurationInMins/
  method: get
  operationId: ascanActionSetOptionMaxScanDurationInMins
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionMaxScansInUI/
  method: get
  operationId: ascanActionSetOptionMaxScansInUI
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionPromptInAttackMode/
  method: get
  operationId: ascanActionSetOptionPromptInAttackMode
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionPromptToClearFinishedScans/
  method: get
  operationId: ascanActionSetOptionPromptToClearFinishedScans
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionRescanInAttackMode/
  method: get
  operationId: ascanActionSetOptionRescanInAttackMode
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionScanHeadersAllRequests/
  method: get
  operationId: ascanActionSetOptionScanHeadersAllRequests
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionScanNullJsonValues/
  method: get
  operationId: ascanActionSetOptionScanNullJsonValues
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionShowAdvancedDialog/
  method: get
  operationId: ascanActionSetOptionShowAdvancedDialog
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionTargetParamsEnabledRPC/
  method: get
  operationId: ascanActionSetOptionTargetParamsEnabledRPC
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionTargetParamsInjectable/
  method: get
  operationId: ascanActionSetOptionTargetParamsInjectable
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setOptionThreadPerHost/
  method: get
  operationId: ascanActionSetOptionThreadPerHost
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setPolicyAlertThreshold/
  method: get
  operationId: ascanActionSetPolicyAlertThreshold
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setPolicyAttackStrength/
  method: get
  operationId: ascanActionSetPolicyAttackStrength
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setScannerAlertThreshold/
  method: get
  operationId: ascanActionSetScannerAlertThreshold
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/setScannerAttackStrength/
  method: get
  operationId: ascanActionSetScannerAttackStrength
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/skipScanner/
  method: get
  operationId: ascanActionSkipScanner
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/stop/
  method: get
  operationId: ascanActionStop
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/stopAllScans/
  method: get
  operationId: ascanActionStopAllScans
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/action/updateScanPolicy/
  method: get
  operationId: ascanActionUpdateScanPolicy
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/view/alertsIds/
  method: get
  operationId: ascanViewAlertsIds
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /JSON/ascan/v

# --- truncated at 32 KB (176 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/owasp-zap/refs/heads/main/agentic-access/owasp-zap-agentic-access.yml