Ping Identity · Agentic Access

Ping Identity Agentic Access

x-agentic-access generated

Ping Identity exposes 54 API operations that an AI agent could call, of which 29 are state-changing ‘acting’ operations. This is a recommended x-agentic-access execution contract — the scope, audience, consequence tier, short-lived token constraints, and escalation each action should carry before it is handed to an autonomous agent.

By consequence: 25 read, 28 write, and 1 physical.

Contracts are classified heuristically from the provider’s OpenAPI and refresh on every APIs.io network build; audience is bound per deployment. The model follows Curity’s Access Intelligence (apidays Munich 2026). Browse every provider’s agent contracts at agentic-access.apis.io.

IdentityAuthenticationAuthorizationSSOMFA
Operations: 54 Acting: 29 Human-in-the-loop: 0 Method: generated

By consequence

read 25 write 28 physical 1

Highest-consequence actions

The physical and safety-critical operations an agent could invoke — the ones that most warrant scoped tokens, tight TTLs, and escalation. Full per-operation contracts are in the source below.

MethodPathConsequenceHuman-in-loop
POST /environments/{environmentID}/flows/{flowID}#deploy+json physical conditional

Source

Agentic Access

Raw ↑
generated: '2026-07-15'
method: generated
source: openapi/ping-identity-openapi.yaml
description: Recommended x-agentic-access execution contracts, classified heuristically from
  the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind
  audience per deployment. See research/curity/agentic-governance/.
summary:
  operations: 54
  by_action_class:
    connected: 25
    acting: 29
  by_consequence:
    read: 25
    write: 28
    physical: 1
  human_in_the_loop_required: 0
operations:
- path: /environments
  method: get
  operationId: getEnvironments
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments
  method: post
  operationId: createEnvironment
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}
  method: get
  operationId: getEnvironmentById
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}
  method: put
  operationId: replaceEnvironmentById
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}
  method: delete
  operationId: deleteEnvironmentById
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/billOfMaterials
  method: get
  operationId: getBillOfMaterialsByEnvironmentId
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/billOfMaterials
  method: put
  operationId: replaceBillOfMaterialsByEnvironmentId
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/connectorInstances
  method: get
  operationId: getConnectorInstances
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/connectorInstances
  method: post
  operationId: createConnectorInstance
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/connectorInstances/{connectorInstanceID}
  method: get
  operationId: getConnectorInstanceById
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/connectorInstances/{connectorInstanceID}
  method: post
  operationId: createConnectorInstanceById
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/connectorInstances/{connectorInstanceID}
  method: put
  operationId: replaceConnectorInstanceById
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/connectorInstances/{connectorInstanceID}
  method: delete
  operationId: deleteConnectorInstanceById
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/connectors
  method: get
  operationId: getConnectors
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/connectors/{connectorID}
  method: get
  operationId: getConnectorById
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/connectors/{connectorID}/details
  method: get
  operationId: getDetailsByConnectorId
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/davinciApplications
  method: get
  operationId: getDavinciApplications
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/davinciApplications
  method: post
  operationId: createDavinciApplication
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}
  method: get
  operationId: getDavinciApplicationById
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}
  method: put
  operationId: replaceDavinciApplicationById
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}
  method: delete
  operationId: deleteDavinciApplicationById
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/flowPolicies
  method: get
  operationId: getFlowPoliciesByDavinciApplicationId
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/flowPolicies
  method: post
  operationId: createFlowPolicyByDavinciApplicationId
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/flowPolicies/{flowPolicyID}
  method: get
  operationId: getFlowPolicyByIdUsingDavinciApplicationId
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/flowPolicies/{flowPolicyID}
  method: put
  operationId: replaceFlowPolicyByIdUsingDavinciApplicationId
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/flowPolicies/{flowPolicyID}
  method: delete
  operationId: deleteFlowPolicyByIdUsingDavinciApplicationId
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/flowPolicies/{flowPolicyID}/events
  method: get
  operationId: getEventsByDavinciApplicationIdAndFlowPolicyId
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/key
  method: post
  operationId: rotateKeyByDavinciApplicationId
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/davinciApplications/{davinciApplicationID}/secret
  method: post
  operationId: rotateSecretByDavinciApplicationId
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/flowPolicies/{flowPolicyID}
  method: get
  operationId: getFlowPolicyById
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/flows
  method: get
  operationId: getFlows
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/flows
  method: post
  operationId: createFlow
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/flows/{flowID}
  method: get
  operationId: getFlowById
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/flows/{flowID}
  method: put
  operationId: replaceFlowById
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/flows/{flowID}
  method: delete
  operationId: deleteFlowById
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/flows/{flowID}#clone+json
  method: post
  operationId: cloneFlowByIdAsCloneJson
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/flows/{flowID}#deploy+json
  method: post
  operationId: deployFlowByIdAsDeployJson
  x-agentic-access:
    action-class: acting
    consequence: physical
    subject: required
    audience: null
    token:
      max-ttl: 300
      exchange: true
      purpose-required: true
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/flows/{flowID}#validate+json
  method: post
  operationId: validateFlowByIdAsValidateJson
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/flows/{flowID}/enabled
  method: put
  operationId: updateEnabledByFlowId
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/flows/{flowID}/versions
  method: get
  operationId: getVersionsByFlowId
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/flows/{flowID}/versions/{versionID}
  method: get
  operationId: getVersionByIdUsingFlowId
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/flows/{flowID}/versions/{versionID}
  method: delete
  operationId: deleteVersionByIdUsingFlowId
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/flows/{flowID}/versions/{versionID}/alias
  method: put
  operationId: replaceAliasByFlowIdAndVersionId
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/flows/{flowID}/versions/{versionID}/details
  method: get
  operationId: getDetailsByFlowIdAndVersionId
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/snapshots
  method: post
  operationId: createSnapshot
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/snapshots/{snapshotID}
  method: get
  operationId: getSnapshotById
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/snapshots/{snapshotID}/versions
  method: get
  operationId: getVersionsBySnapshotId
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/snapshots/{snapshotID}/versions/{versionID}
  method: get
  operationId: getVersionByIdUsingSnapshotId
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/totalIdentities
  method: get
  operationId: getTotalIdentities
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/variables
  method: get
  operationId: getVariables
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/variables
  method: post
  operationId: createVariable
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/variables/{variableID}
  method: get
  operationId: getVariableById
  x-agentic-access:
    action-class: connected
    consequence: read
    subject: optional
    token:
      max-ttl: 3600
    audit: none
- path: /environments/{environmentID}/variables/{variableID}
  method: put
  operationId: replaceVariableById
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required
- path: /environments/{environmentID}/variables/{variableID}
  method: delete
  operationId: deleteVariableById
  x-agentic-access:
    action-class: acting
    consequence: write
    subject: required
    audience: null
    token:
      max-ttl: 900
    escalation:
      human-in-the-loop: conditional
      triggers:
      - abnormal
      - high-value
    audit: required