SpyCloud · Agentic Access
SpyCloud Agentic Access
x-agentic-access
generated
SpyCloud exposes 69 API operations that an AI agent could call, of which 2 are state-changing ‘acting’ operations. This is a recommended x-agentic-access execution contract — the scope, audience, consequence tier, short-lived token constraints, and escalation each action should carry before it is handed to an autonomous agent.
By consequence: 67 read and 2 write.
Contracts are classified heuristically from the provider’s OpenAPI and refresh on every APIs.io network build; audience is bound per deployment. The model follows Curity’s Access Intelligence (apidays Munich 2026). Browse every provider’s agent contracts at agentic-access.apis.io.
CybersecurityThreat IntelligenceIdentityFraud PreventionAccount TakeoverDark WebBreach DataMalwareAuthenticationSecurity
Operations: 69
Acting: 2
Human-in-the-loop: 0
Method: generated
By consequence
read 67
write 2
Source
Agentic Access
generated: '2026-08-05'
method: generated
source: openapi/spycloud-compromised-credit-card-openapi.yml, openapi/spycloud-consumer-ato-prevention-openapi.yml,
openapi/spycloud-data-partnership-openapi.yml, openapi/spycloud-enterprise-ato-prevention-openapi.yml,
openapi/spycloud-idlink-openapi.yml, openapi/spycloud-investigations-openapi.yml, openapi/spycloud-nist-password-openapi.yml,
openapi/spycloud-prospecting-openapi.yml, openapi/spycloud-session-identity-protection-openapi.yml
description: Recommended x-agentic-access execution contracts, classified heuristically from
the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind
audience per deployment. See research/curity/agentic-governance/.
summary:
operations: 69
by_action_class:
connected: 67
acting: 2
by_consequence:
read: 67
write: 2
human_in_the_loop_required: 0
operations:
- path: /data/cc/bins/{bin}
method: get
operationId: fd-get-credit-cards-by-bin
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /data/cc/bins
method: get
operationId: list-credit-cards
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/emails/{email}
method: get
operationId: cap-get-records-by-email-address
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/ips/{ip}
method: get
operationId: cap-get-records-by-ip-address
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/usernames/{username}
method: get
operationId: get-records-by-usernames
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/catalog/
method: get
operationId: cap-list-all-breach-metadata
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/catalog/{id}
method: get
operationId: get-metadata-for-a-breach
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /check/hashes/credentials/{hash_prefix}
method: get
operationId: cap-zero-knowledge
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/phone-numbers/{phone_number}
method: get
operationId: cap-get-records-by-phone-number
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/domains/{domain}
method: get
operationId: dp-get-records-by-domain
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/emails/{email}
method: get
operationId: dp-records-by-email
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/ips/{ip}
method: get
operationId: dp-get-records-by-ip-address
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/health-insurance-ids/{health_insurance_id}
method: get
operationId: dp-get-records-by-health-insurance-id
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/usernames/{username}
method: get
operationId: dp-get-records-by-username
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/bank-numbers/{bank_number}
method: get
operationId: dp-get-records-by-bank-number
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/cc-numbers/{cc_number}
method: get
operationId: dp-get-records-by-credit-card-number
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/drivers-licenses/{drivers_license}
method: get
operationId: dp-get-records-by-drivers-license
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/national-ids/{national_id}
method: get
operationId: get-records-by-national-id
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/passport-numbers/{passport_number}
method: get
operationId: dp-get-records-by-passport-number
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/catalog/
method: get
operationId: dp-list-all-breach-metadata
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/catalog/{id}
method: get
operationId: dp-get-metadata-for-a-breach
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: //breach/data/passwords/{password}
method: get
operationId: get_breachdatapasswords{password}
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/social-security-numbers/{social_security_number}
method: get
operationId: get-records-by-social-security-number
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/phone-numbers/{phone_number}
method: get
operationId: dp-get-records-by-phone-number
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/domains/{domain}
method: get
operationId: eap-get-records-by-domain
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/emails/{email}
method: get
operationId: eap-get-records-by-email-address
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/ips/{ip}
method: get
operationId: eap-get-records-by-ip-address
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/passwords/{password}
method: get
operationId: eap-get-records-by-password
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/usernames/{username}
method: get
operationId: eap-get-records-by-username
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/watchlist
method: get
operationId: eap-get-all-records-in-watchlist
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/catalog
method: get
operationId: eap-list-all-breach-metadata
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/catalog/{id}
method: get
operationId: eap-get-metadata-for-a-breach
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /watchlist/identifiers
method: get
operationId: eap-list-all-identifiers
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /watchlist/{identifier}
method: get
operationId: eap-get-an-identifier
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /watchlist/create
method: post
operationId: eap-create-an-identifier
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /watchlist/{identifier}/delete
method: delete
operationId: eap-delete-an-identifier
x-agentic-access:
action-class: acting
consequence: write
subject: required
audience: null
token:
max-ttl: 900
escalation:
human-in-the-loop: conditional
triggers:
- abnormal
- high-value
audit: required
- path: /watchlist/{identifier}/verify
method: get
operationId: eap-verify-an-identifier
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /compass/devices
method: get
operationId: eap-list-all-compass-devices
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /compass/data/devices/{infected_machine_id}
method: get
operationId: eap-get-records-for-a-device
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /compass/applications
method: get
operationId: eap-list-all-applications
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /compass/data/applications/{target_application}
method: get
operationId: eap-get-records-for-an-application
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /compass/data
method: get
operationId: eap-get-all-records
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /query/emails/{email}
method: get
operationId: idl-get-records-by-email
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /query/phone-numbers/{phone}
method: get
operationId: idl-get-records-by-phone-number
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /query/usernames/{username}
method: get
operationId: idl-get-records-by-username
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/domains/{domain}
method: get
operationId: inv-get-records-by-domain
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/emails/{email}
method: get
operationId: get-records-by-email-address
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/ips/{ip}
method: get
operationId: inv-get-records-by-ip-address
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/infected-machine-ids/{infected_machine_id}
method: get
operationId: inv-get-records-by-infected-machine-id
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/log-ids/{log_id}
method: get
operationId: inv-get-records-by-log-id
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/passwords/{password}
method: get
operationId: inv-get-records-by-password
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/usernames/{username}
method: get
operationId: inv-get-records-by-username
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/email-usernames/{email_username}
method: get
operationId: inv-get-records-by-email-username
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/phone-numbers/{phone_number}
method: get
operationId: inv-get-records-by-phone-number
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/social-handles/{social_handle}
method: get
operationId: inv-get-records-by-social-handle
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/cc-numbers/{cc_number}
method: get
operationId: inv-get-records-by-credit-card-number
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/drivers-licenses/{drivers_license}
method: get
operationId: inv-get-records-by-drivers-license
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/national-ids/{national_id}
method: get
operationId: inv-get-records-by-national-id
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/passport-numbers/{passport_number}
method: get
operationId: inv-get-records-by-passport-number
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/social-security-numbers/{social_security_number}
method: get
operationId: inv-get-records-by-social-security-number
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/catalog
method: get
operationId: inv-list-all-breach-metadata
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/catalog/{id}
method: get
operationId: inv-get-metadata-for-a-breach
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/bank-numbers/{bank_number}
method: get
operationId: inv-get-records-by-bank-number
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /check/hashes/{hash}
method: get
operationId: nist-check-password-hash
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /stats/domains/{domain}
method: get
operationId: get-stats-for-a-domain
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /stats/emails/{email}
method: get
operationId: prospecting-get-stats-for-an-email
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/data/cookie-domains/{cookie_domain}
method: get
operationId: sip-get-cookies-for-domain
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/catalog
method: get
operationId: sip-list-all-breach-metadata
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none
- path: /breach/catalog/{id}
method: get
operationId: sip-get-metadata-for-a-breach
x-agentic-access:
action-class: connected
consequence: read
subject: optional
token:
max-ttl: 3600
audit: none