Rainforest Agentic Access
Rainforest exposes 82 API operations that an AI agent could call, of which 53 are state-changing ‘acting’ operations. This is a recommended x-agentic-access execution contract — the scope, audience, consequence tier, short-lived token constraints, and escalation each action should carry before it is handed to an autonomous agent.
By consequence: 29 read, 28 write, 24 physical, and 1 safety-critical.
1 operation are classed safety-critical and should require human-in-the-loop approval at runtime.
Contracts are classified heuristically from the provider’s OpenAPI and refresh on every APIs.io network build; audience is bound per deployment. The model follows Curity’s Access Intelligence (apidays Munich 2026). Browse every provider’s agent contracts at agentic-access.apis.io.
By consequence
Highest-consequence actions
The physical and safety-critical operations an agent could invoke — the ones that most warrant scoped tokens, tight TTLs, and escalation. Full per-operation contracts are in the source below.
| Method | Path | Consequence | Human-in-loop |
|---|---|---|---|
| POST | /v1/api_keys/{api_key_id}/disable | safety-critical | required |
| POST | /v1/chargebacks/{chargeback_id}/accept | physical | conditional |
| PATCH | /v1/chargebacks/{chargeback_id}/evidence/{chargeback_evidence_id} | physical | conditional |
| PATCH | /v1/chargebacks/{chargeback_id}/metadata | physical | conditional |
| POST | /v1/chargebacks/{chargeback_id}/simulate | physical | conditional |
| POST | /v1/chargebacks/{chargeback_id}/submit | physical | conditional |
| POST | /v1/deposit_method_configs | physical | conditional |
| POST | /v1/deposit_methods | physical | conditional |
| POST | /v1/deposit_methods/{deposit_method_id}/payin | physical | conditional |
| POST | /v1/deposits/{deposit_id}/simulate | physical | conditional |
| POST | /v1/device_registrations/{device_registration_id}/payment_method | physical | conditional |
| POST | /v1/merchants/{merchant_id}/simulate_deposit | physical | conditional |
| POST | /v1/payins/{payin_id}/simulate_chargeback | physical | conditional |
| POST | /v1/payins/{payin_id}/void_or_refund | physical | conditional |
| POST | /v1/payment_method_configs | physical | conditional |
| POST | /v1/payment_method_domains | physical | conditional |
| DELETE | /v1/payment_method_domains/{payment_method_domain_id} | physical | conditional |
| POST | /v1/payment_method_domains/{payment_method_domain_id}/verify | physical | conditional |
| POST | /v1/payment_methods | physical | conditional |
| PATCH | /v1/payment_methods/{payment_method_id} | physical | conditional |
| POST | /v1/payment_methods/{payment_method_id}/deactivate | physical | conditional |
| POST | /v1/payment_methods/{payment_method_id}/forward | physical | conditional |
| POST | /v1/payment_methods/{payment_method_id}/payin | physical | conditional |
| PATCH | /v1/refunds/{refund_id}/metadata | physical | conditional |
| POST | /v1/refunds/{refund_id}/void | physical | conditional |
Source
Agentic Access
generated: '2026-07-20'
method: generated
source: openapi/rainforest-authentication-openapi.yaml, openapi/rainforest-deposits-openapi.yaml,
openapi/rainforest-file_uploads-openapi.yaml, openapi/rainforest-forward_requests-openapi.yaml,
openapi/rainforest-health-openapi.yaml, openapi/rainforest-merchants-openapi.yaml, openapi/rainforest-payments-openapi.yaml
description: Recommended x-agentic-access execution contracts, classified heuristically from
the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind
audience per deployment. See research/curity/agentic-governance/.
summary:
operations: 82
by_action_class:
acting: 53
connected: 29
by_consequence:
write: 28
read: 29
safety-critical: 1
physical: 24
human_in_the_loop_required: 1
operations:
- path: /v1/api_keys
method: post
operationId: create_api_key
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/api_keys
method: get
operationId: list_api_keys
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/api_keys/{api_key_id}
method: get
operationId: get_api_key
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/api_keys/{api_key_id}
method: delete
operationId: delete_api_key
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/api_keys/{api_key_id}/disable
method: post
operationId: disable_api_key
x-agentic-access:
action-class: acting
consequence: safety-critical
subject: required
audience: null
token:
max-ttl: 120
exchange: true
purpose-required: true
proof-of-possession: true
escalation:
human-in-the-loop: required
audit: required
- path: /v1/api_keys/{api_key_id}/enable
method: post
operationId: enable_api_key
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/sessions
method: post
operationId: create_session
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/sessions
method: delete
operationId: delete_session
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/deposits
method: get
operationId: list_deposits
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/deposits/{deposit_id}
method: get
operationId: get_deposit
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/deposits/{deposit_id}/activity
method: get
operationId: get_deposit_activity
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/deposits/{deposit_id}/simulate
method: post
operationId: simulate_deposit_status
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/merchants/{merchant_id}/simulate_deposit
method: post
operationId: simulate_merchant_deposit
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/deposit_method_configs
method: post
operationId: create_deposit_method_config
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/deposit_methods/{deposit_method_id}
method: get
operationId: get_deposit_method
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/deposit_methods/{deposit_method_id}/payin
method: post
operationId: create_deposit_method_payin
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/deposit_methods
method: post
operationId: create_deposit_method
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/file_upload_configs
method: post
operationId: create_file_upload_config
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/file_upload_configs/{file_upload_config_id}
method: get
operationId: get_file_upload_config
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/file_uploads/{file_upload_id}
method: get
operationId: get_file_upload
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/payment_methods/{payment_method_id}/forward
method: post
operationId: forward_payment_method
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /health
method: get
operationId: get_health
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/billing_profiles
method: post
operationId: create_billing_profile
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/billing_profiles
method: get
operationId: list_billing_profiles
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/billing_profiles/{billing_profile_id}
method: get
operationId: get_billing_profile
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/billing_profiles/{billing_profile_id}/deactivate
method: post
operationId: deactivate_billing_profile
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/merchants/{merchant_id}/applications
method: get
operationId: list_merchant_applications
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/merchants/{merchant_id}/applications/{merchant_application_id}
method: get
operationId: get_merchant_application
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/merchants/{merchant_id}/applications/{merchant_application_id}
method: patch
operationId: update_merchant_application
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/merchants/{merchant_id}/applications/{merchant_application_id}/verify
method: post
operationId: verify_merchant_application
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/merchants/{merchant_id}/applications/{merchant_application_id}/submit
method: post
operationId: submit_merchant_application
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/merchants/{merchant_id}/applications/{merchant_application_id}/simulate
method: post
operationId: simulate_merchant_application
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/merchants
method: post
operationId: create_merchant
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/merchants
method: get
operationId: list_merchants
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/merchants/{merchant_id}
method: get
operationId: get_merchant
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/merchants/{merchant_id}
method: patch
operationId: update_merchant
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/merchants/{merchant_id}/cancel
method: post
operationId: cancel_merchant
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/merchants/{merchant_id}/update_billing_profile
method: post
operationId: update_merchant_billing_profile
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/ach_returns/{ach_return_id}
method: get
operationId: get_ach_return
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/ach_returns/{ach_return_id}/metadata
method: patch
operationId: update_ach_return_metadata
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/bin_lookup
method: post
operationId: create_bin_lookup
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/chargebacks/{chargeback_id}
method: get
operationId: get_chargeback
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/chargebacks/{chargeback_id}/accept
method: post
operationId: accept_chargeback
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/chargebacks/{chargeback_id}/submit
method: post
operationId: submit_chargeback
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/chargebacks/{chargeback_id}/evidence/{chargeback_evidence_id}
method: patch
operationId: update_chargeback_evidence
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/chargebacks/{chargeback_id}/metadata
method: patch
operationId: update_chargeback_metadata
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payins/{payin_id}/simulate_chargeback
method: post
operationId: simulate_payin_chargeback
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/chargebacks/{chargeback_id}/simulate
method: post
operationId: simulate_chargeback
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/device_registrations
method: post
operationId: create_device_registration
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/device_registrations
method: get
operationId: list_device_registrations
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/device_registrations/{device_registration_id}
method: get
operationId: get_device_registration
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/device_registrations/{device_registration_id}
method: delete
operationId: delete_device_registration
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/device_registrations/{device_registration_id}/payin
method: post
operationId: create_device_payin
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/device_registrations/{device_registration_id}/payment_method
method: post
operationId: create_device_payment_method
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/device_registrations/{device_registration_id}/cancel
method: post
operationId: cancel_device_presented
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/device_registrations/{device_registration_id}/simulate
method: post
operationId: simulate_on_device
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payin_configs
method: post
operationId: create_payin_config
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payin_configs/{payin_config_id}
method: get
operationId: get_payin_config
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/payins
method: get
operationId: list_payins
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/payins
method: post
operationId: create_payin
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payins/{payin_id}
method: get
operationId: get_payin
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/payins/{payin_id}/metadata
method: patch
operationId: update_payin_metadata
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payins/{payin_id}/capture
method: post
operationId: capture_payin
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payins/{payin_id}/void_or_refund
method: post
operationId: void_or_refund_payin
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payins/{payin_id}/simulate_ach_return
method: post
operationId: simulate_payin_ach_return
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payment_method_domains
method: get
operationId: list_payment_method_domains
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/payment_method_domains
method: post
operationId: create_payment_method_domain
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payment_method_domains/{payment_method_domain_id}
method: get
operationId: get_payment_method_domain
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/payment_method_domains/{payment_method_domain_id}
method: delete
operationId: delete_payment_method_domain
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payment_method_domains/{payment_method_domain_id}/verify
method: post
operationId: verify_payment_method_domain
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payment_method_configs
method: post
operationId: create_payment_method_config
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payment_method_configs/{payment_method_config_id}
method: get
operationId: get_payment_method_config
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/payment_methods
method: get
operationId: list_payment_methods
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/payment_methods
method: post
operationId: create_payment_method
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payment_methods/{payment_method_id}
method: get
operationId: get_payment_method
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/payment_methods/{payment_method_id}
method: patch
operationId: update_payment_method
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payment_methods/{payment_method_id}/payin
method: post
operationId: create_payment_method_payin
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payment_methods/{payment_method_id}/deactivate
method: post
operationId: deactivate_payment_method
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/payments
method: get
operationId: list_payments
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/refunds/{refund_id}
method: get
operationId: get_refund
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /v1/refunds/{refund_id}/metadata
method: patch
operationId: update_refund_metadata
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /v1/refunds/{refund_id}/void
method: post
operationId: void_refund
x-agentic-access:
action-class: acting
consequence: physical
subject: required
audience: null
token:
max-ttl: 300
exchange: true
purpose-required: true
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required