PingCAP Agentic Access
PingCAP exposes 192 API operations that an AI agent could call, of which 93 are state-changing ‘acting’ operations. This is a recommended x-agentic-access execution contract — the scope, audience, consequence tier, short-lived token constraints, and escalation each action should carry before it is handed to an autonomous agent.
By consequence: 99 read, 85 write, 3 physical, and 5 safety-critical.
5 operations are classed safety-critical and should require human-in-the-loop approval at runtime.
Contracts are classified heuristically from the provider’s OpenAPI and refresh on every APIs.io network build; audience is bound per deployment. The model follows Curity’s Access Intelligence (apidays Munich 2026). Browse every provider’s agent contracts at agentic-access.apis.io.
By consequence
Highest-consequence actions
The physical and safety-critical operations an agent could invoke — the ones that most warrant scoped tokens, tight TTLs, and escalation. Full per-operation contracts are in the source below.
| Method | Path | Consequence | Human-in-loop |
|---|---|---|---|
| POST | /api/v1/sources/{source-name}/disable | safety-critical | required |
| POST | /api/v1/sources/{source-name}/relay/disable | safety-critical | required |
| POST | /api/v1/tasks/{task-name}/stop | safety-critical | required |
| POST | /clusters/{clusterId}/branches/{branchId}:reset | safety-critical | required |
| POST | /clusters/{clusterId}:resetRootPassword | safety-critical | required |
| POST | /api/v1/sources/{source-name}/transfer | physical | conditional |
| POST | /members/{user_id}/resendInvitation | physical | conditional |
| POST | /v1beta1/dataApps/{dataAppId}/deployments | physical | conditional |
Source
Agentic Access
generated: '2026-08-02'
method: generated
source: openapi/pingcap-ossinsight-public-api-openapi-original.yaml, openapi/pingcap-tidb-cloud-billing-v1beta1-openapi-original.json,
openapi/pingcap-tidb-cloud-data-service-v1beta1-openapi-original.json, openapi/pingcap-tidb-cloud-dedicated-v1beta1-openapi-original.json,
openapi/pingcap-tidb-cloud-iam-v1beta1-openapi-original.json, openapi/pingcap-tidb-cloud-starter-essential-v1beta1-openapi-original.json,
openapi/pingcap-tidb-cloud-v1beta-openapi-original.json, openapi/pingcap-tidb-cloud-zero-v1alpha1-openapi-original.json,
openapi/pingcap-tidb-dm-openapi-original.yaml
description: Recommended x-agentic-access execution contracts, classified heuristically from
the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind
audience per deployment. See research/curity/agentic-governance/.
summary:
operations: 192
by_action_class:
connected: 99
acting: 93
by_consequence:
read: 99
write: 85
physical: 3
safety-critical: 5
human_in_the_loop_required: 5
operations:
- path: /collections/
method: get
operationId: list-collections
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /collections/hot/
method: get
operationId: list-hot-collections
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /trends/repos/
method: get
operationId: list-trending-repos
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /collections/{collection_id}/ranking_by_issues/
method: get
operationId: collection-repo-ranking-by-issues
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /collections/{collection_id}/ranking_by_prs/
method: get
operationId: collection-repo-ranking-by-prs
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /collections/{collection_id}/ranking_by_stars/
method: get
operationId: collection-repo-ranking-by-stars
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /collections/{collection_id}/repos/
method: get
operationId: list-repos-of-collection
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /repos/{owner}/{repo}/issue_creators/
method: get
operationId: list-issue-creators
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /repos/{owner}/{repo}/pull_request_creators/
method: get
operationId: list-pull-request-creators
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /repos/{owner}/{repo}/issue_creators/countries/
method: get
operationId: list-countries-of-issue-creators
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /repos/{owner}/{repo}/issue_creators/history/
method: get
operationId: issue-creators-history
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /repos/{owner}/{repo}/issue_creators/organizations/
method: get
operationId: list-organizations-of-issue-creators
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /repos/{owner}/{repo}/stargazers/countries/
method: get
operationId: list-countries-of-stargazers
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /repos/{owner}/{repo}/stargazers/history/
method: get
operationId: stargazers-history
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /repos/{owner}/{repo}/stargazers/organizations/
method: get
operationId: list-organizations-of-stargazers
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /repos/{owner}/{repo}/pull_request_creators/countries/
method: get
operationId: list-countries-of-pr-creators
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /repos/{owner}/{repo}/pull_request_creators/history/
method: get
operationId: pull-request-creators-history
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /repos/{owner}/{repo}/pull_request_creators/organizations/
method: get
operationId: list-organizations-of-pr-creators
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /bills/{billedMonth}
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /billsCostExplorer
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /billsCostExplorer/args
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /billsDetails/{billedMonth}
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps
method: get
operationId: DataApp_ListDataApps
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps
method: post
operationId: DataApp_CreateDataApp
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{dataAppId}/systemEndpointConfig
method: get
operationId: DataAppsService_GetSystemEndpointConfig
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps/{dataAppId}/systemEndpointConfig
method: patch
operationId: DataAppsService_UpdateSystemEndpointConfig
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{dataAppId}/chat2querySettings
method: get
operationId: DataApp_GetChat2QuerySettings
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps/{dataAppId}/chat2querySettings
method: patch
operationId: DataApp_UpdateChat2QuerySettings
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{dataAppId}
method: patch
operationId: DataApp_UpdateDataApp
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{dataAppId}
method: get
operationId: DataApp_GetDataApp
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps/{dataAppId}
method: delete
operationId: DataApp_DeleteDataApp
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{dataAppId}/dataSources
method: get
operationId: DataSource_ListDataSources
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps/{dataAppId}/dataSources
method: post
operationId: DataSource_CreateDataSource
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{dataAppId}/dataSources/{clusterId}
method: get
operationId: DataSource_GetDataSource
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps/{dataAppId}/dataSources/{clusterId}
method: delete
operationId: DataSource_DeleteDataSource
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{dataAppId}/endpoints
method: get
operationId: Endpoint_ListEndpoints
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps/{dataAppId}/endpoints
method: post
operationId: Endpoint_CreateEndpoint
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{endpoint.name}
method: patch
operationId: Endpoint_UpdateEndpoint
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{endpoint.name}
method: get
operationId: Endpoint_GetEndpoint
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps/{endpoint.name}
method: delete
operationId: Endpoint_DeleteEndpoint
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/{endpoint.name}/test
method: post
operationId: Endpoint_TestEndpoint
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{dataAppId}/apiKeys
method: get
operationId: APIKey_ListApiKeys
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps/{dataAppId}/apiKeys
method: post
operationId: APIKey_CreateApiKey
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{dataAppId}/apiKeys/{apiKeyId}
method: patch
operationId: APIKey_UpdateApiKey
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{dataAppId}/apiKeys/{apiKeyId}
method: get
operationId: APIKey_GetApiKey
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps/{dataAppId}/apiKeys/{apiKeyId}
method: delete
operationId: APIKey_DeleteApiKey
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{dataAppId}/deployments
method: get
operationId: Deployment_ListDeployments
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps/{dataAppId}/deployments
method: post
operationId: Deployment_CreateDeployment
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1beta1/dataApps/{dataAppId}/deployments/{deploymentId}
method: get
operationId: Deployment_GetDeployment
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1beta1/dataApps/{dataAppId}/apiSpec
method: get
operationId: APISpecification_GetApiSpec
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters
method: get
operationId: ClusterService_ListClusters
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters
method: post
operationId: ClusterService_CreateCluster
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}
method: get
operationId: ClusterService_GetCluster
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}
method: delete
operationId: ClusterService_DeleteCluster
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}
method: patch
operationId: ClusterService_UpdateCluster
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}:pauseCluster
method: post
operationId: ClusterService_PauseCluster
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}:resumeCluster
method: post
operationId: ClusterService_ResumeCluster
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}:resetRootPassword
method: post
operationId: ClusterService_ResetRootPassword
x-agentic-access:
action-class: acting
consequence: safety-critical
subject: required
audience: null
token:
max-ttl: 120
exchange: true
purpose-required: true
proof-of-possession: true
escalation:
human-in-the-loop: required
audit: required
- path: /clusters:showNodeQuota
method: get
operationId: ClusterService_ShowNodeQuota
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}/logRedactionPolicy
method: get
operationId: ClusterService_GetLogRedactionPolicy
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /regions
method: get
operationId: RegionService_ListRegions
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /regions/{regionId}
method: get
operationId: RegionService_GetRegion
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /regions:showCloudProviders
method: get
operationId: RegionService_ShowCloudProviders
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /regions/{regionId}/nodeSpecs
method: get
operationId: RegionService_ListNodeSpecs
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /regions/{regionId}/componentTypes/{componentType}/nodeSpecs/{nodeSpecKey}
method: get
operationId: RegionService_GetNodeSpec
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}/tidbNodeGroups/{tidbNodeGroupId}/privateLinkService
method: get
operationId: PrivateEndpointConnectionService_GetPrivateLinkService
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}/tidbNodeGroups/{tidbNodeGroupId}/privateEndpointConnections
method: get
operationId: PrivateEndpointConnectionService_ListPrivateEndpointConnections
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}/tidbNodeGroups/{tidbNodeGroupId}/privateEndpointConnections
method: post
operationId: PrivateEndpointConnectionService_CreatePrivateEndpointConnection
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}/tidbNodeGroups/{tidbNodeGroupId}/privateEndpointConnections/{privateEndpointConnectionId}
method: get
operationId: PrivateEndpointConnectionService_GetPrivateEndpointConnection
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}/tidbNodeGroups/{tidbNodeGroupId}/privateEndpointConnections/{privateEndpointConnectionId}
method: delete
operationId: PrivateEndpointConnectionService_DeletePrivateEndpointConnection
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}/imports
method: get
operationId: ListImports
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}/imports
method: post
operationId: CreateImport
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}/imports/{importId}
method: get
operationId: GetImport
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}/imports/{importId}:cancel
method: post
operationId: CancelImport
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}/integrations
method: get
operationId: IntegrationService_ListIntegrations
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}/integrations
method: post
operationId: IntegrationService_CreateIntegration
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}/integrations/{id}
method: delete
operationId: IntegrationService_DeleteIntegration
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /changefeedRCUs
method: get
operationId: ListChangefeedRCUs
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /changefeeds
method: get
operationId: ListChangefeeds
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /changefeeds
method: post
operationId: CreateChangefeed
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /changefeeds/{changefeedId}
method: get
operationId: GetChangefeed
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /changefeeds/{changefeedId}
method: delete
operationId: DeleteChangefeed
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /changefeeds/{changefeedId}:editDownstreamConfig
method: post
operationId: EditChangefeedDownstreamConfig
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /changefeeds/{changefeedId}:pause
method: post
operationId: PauseChangefeed
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /changefeeds/{changefeedId}:resume
method: post
operationId: ResumeChangefeed
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /changefeeds/{changefeedId}:scale
method: post
operationId: ScaleChangefeed
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /apikeys
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /apikeys
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /apikeys/{accessKey}
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /apikeys/{accessKey}
method: delete
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /apikeys/{accessKey}
method: patch
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /auditLogs
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /members
method: get
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /members
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /members/batchUpdate
method: post
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /members/{user_id}
method: delete
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /members/{user_id}
method: patch
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /members/{user_id}/resendInvitation
method: post
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters
method: get
operationId: ClusterService_ListClusters
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters
method: post
operationId: ClusterService_CreateCluster
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}
method: get
operationId: ClusterService_GetCluster
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}
method: delete
operationId: ClusterService_DeleteCluster
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{cluster.clusterId}
method: patch
operationId: ClusterService_PartialUpdateCluster
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /regions
method: get
operationId: ClusterService_ListRegions
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}/branches
method: get
operationId: BranchService_ListBranches
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}/branches
method: post
operationId: BranchService_CreateBranch
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}/branches/{branchId}
method: get
operationId: BranchService_GetBranch
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /clusters/{clusterId}/branches/{branchId}
method: delete
operationId: BranchService_DeleteBranch
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /clusters/{clusterId}/branches/{branchId}:reset
method: post
operationId: BranchService_ResetBranch
x-agentic-access:
action-class: acting
consequence: safety-critical
subject: required
audience: null
token:
max-ttl: 120
exchange: true
purpose-required: true
proof-of-possession: true
escalation:
human-in-the-loop: required
audit: required
- path: /clusters/{clust
# --- truncated at 32 KB (57 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/pingcap/refs/heads/main/agentic-access/pingcap-agentic-access.yml