Akamai API Security Configuration version export API

Get comprehensive details about a security configuration version.

OpenAPI Specification

akamai-api-security-configuration-version-export-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  description: 'Manage your configurations for Kona Site Defender,

    Web Application Protector, and Client Reputation.

    '
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: 'Akamai: Application Security Activation history Configuration version export API'
  version: v1
servers:
- url: https://{hostname}/appsec/v1
tags:
- description: 'Get comprehensive details about a security configuration

    version.'
  name: Configuration version export
paths:
  /export/configs/{configId}/versions/{versionNumber}:
    parameters:
    - description: A unique identifier for each configuration.
      example: '{{configId}}'
      in: path
      name: configId
      required: true
      schema:
        example: 77653
        format: int64
        type: integer
      x-akamai:
        file-path: parameters/config-id-path.yaml
    - description: A unique identifier for each version of a configuration.
      example: '{{versionNumber}}'
      in: path
      name: versionNumber
      required: true
      schema:
        example: 25
        type: integer
      x-akamai:
        file-path: parameters/version-number-path.yaml
    x-akamai:
      file-path: paths/export.yaml
      path-info: /export/configs/{configId}/versions/{versionNumber}
    get:
      description: Returns comprehensive details about a security configuration version. This operation returns more data than [Get configuration version details](https://techdocs.akamai.com/application-security/reference/get-version-number), including Bot Manager protections, rate and security policies, rules, hostnames, and numerous additional settings.
      externalDocs:
        description: See documentation for this operation in Akamai's Application Security API
        url: https://techdocs.akamai.com/application-security/reference/get-export-config-version
      operationId: get-export-config-version
      parameters:
      - description: For customers who manage more than one account, this [runs the operation from another account](https://techdocs.akamai.com/developer/docs/manage-many-accounts-with-one-api-client). The Identity and Access Management API provides a [list of available account switch keys](https://techdocs.akamai.com/iam-api/reference/get-client-account-switch-keys).
        example: '{{accountSwitchKey}}'
        in: query
        name: accountSwitchKey
        required: false
        schema:
          example: 1-5C0YLB:1-8BYUX
          type: string
      responses:
        '200':
          content:
            application/json:
              example:
                advancedOptions:
                  logging:
                    allowSampling: true
                    cookies:
                      type: exclude
                      values:
                      - _updated_By_SoapUI
                      - w
                      - NEW_VAL_ADDED_BY_SoapUI
                    customHeaders:
                      type: only
                      values:
                      - '112'
                      - sdasd
                      - ds
                    standardHeaders:
                      type: only
                  pragmaHeader:
                    action: REMOVE
                    conditionOperator: AND
                    excludeCondition:
                    - header: Expect
                      positiveMatch: true
                      type: requestHeaderValueMatch
                      useHeaders: false
                      value:
                      - dasd
                      valueCase: true
                      valueWildcard: true
                    - positiveMatch: true
                      type: networkList
                      useHeaders: true
                      value:
                      - 62569_AEPUAT1PARTNERSSTRICTWL
                      valueCase: false
                      valueWildcard: false
                    override: true
                  prefetch:
                    allExtensions: false
                    enableAppLayer: true
                    enableRateControls: false
                    extensions:
                    - cgi
                    - jsp
                    - EMPTY_STRING
                    - aspx
                    - php
                    - py
                    - asp
                advancedSettings:
                  userAllowListIdSettings:
                    userAllowListId: 82004_APRE2ENLDONOTDELETE
                  userRiskResponseStrategySettings:
                    traffic:
                      inline:
                        aggressive:
                          threshold: 76
                        cautious:
                          threshold: 0
                        strict:
                          threshold: 51
                      nativeSdkAndroid:
                        aggressive:
                          threshold: 76
                        cautious:
                          threshold: 0
                        strict:
                          threshold: 51
                      nativeSdkIos:
                        aggressive:
                          threshold: 76
                        cautious:
                          threshold: 0
                        strict:
                          threshold: 51
                      standard:
                        aggressive:
                          threshold: 76
                        cautious:
                          threshold: 0
                        strict:
                          threshold: 51
                basedOn: 1
                configId: 48579
                configName: New Security Config
                createDate: '2017-09-08T22:24:41Z'
                createdBy: mrossi
                customRules:
                - conditions:
                  - positiveMatch: true
                    type: requestMethodMatch
                    value:
                    - GET
                  configId: 77653
                  id: 776532
                  name: UXR-715 RE2 Second Test with Flags
                  ruleActivated: false
                  stagingOnly: true
                  structured: true
                  tag:
                  - tagfor
                  - '17.2'
                  version: 1
                - conditions:
                  - positiveMatch: true
                    type: extensionMatch
                    value:
                    - fdf
                    valueCase: true
                    valueWildcard: false
                  configId: 77653
                  description: Test CR
                  id: 600001
                  name: Test CR
                  ruleActivated: false
                  structured: true
                  tag:
                  - Test
                  - Tag
                  version: 1
                - conditions:
                  - name: kids
                    nameCase: true
                    nameWildcard: false
                    positiveMatch: true
                    type: cookieMatch
                    value:
                    - dsds
                    - dasdqw
                    - dsa
                    - dqwd
                    - csqw
                    valueCase: true
                    valueWildcard: true
                  configId: 77653
                  description: Test CR
                  id: 600006
                  name: Test CR
                  ruleActivated: false
                  structured: true
                  tag:
                  - k
                  version: 1
                - conditions:
                  - positiveMatch: true
                    type: pathMatch
                    value:
                    - /login
                  configId: 77653
                  id: 606713
                  name: Test
                  ruleActivated: false
                  structured: true
                  tag:
                  - adsa
                  version: 1
                - conditions:
                  - name: fvfv
                    positiveMatch: true
                    type: argsPostMatch
                    value:
                    - fgbr
                  - name:
                    - test
                    nameWildcard: true
                    positiveMatch: true
                    type: requestHeaderMatch
                    value:
                    - test1
                    valueCase: false
                    valueWildcard: true
                  configId: 77653
                  description: Test CR
                  id: 690265
                  name: Test CR2
                  ruleActivated: false
                  structured: true
                  tag:
                  - ee
                  version: 1
                - configId: 77653
                  id: 667825
                  inspectRequest: false
                  inspectResponse: false
                  metadata: '<match:variable name="MY_SAMPLE_THREAT_DETECTED" result="true" value="execute rule">

                    <match:regex impl="re2" regex="^\d+$" result="false" select="REQUEST_HEADERS:Content-Length" strict-err-check-re2="on" transform="urlDecodeUni">

                    <security:firewall.action>

                    <msg>UXR-715 CRB Metadata testing</msg>

                    <tag>CUSTOM/TEST</tag>

                    <id>667825</id>

                    <deny>%(WAF_CUSTOM_R667825_DENY)</deny>

                    <data>threat indicated from data %(MY_SAMPLE_THREAT_DETECTED)</data>

                    <http-status>403</http-status>

                    </security:firewall.action>

                    </match:regex>

                    </match:variable>'
                  name: UXR-715 RE27890
                  ruleActivated: false
                  structured: false
                  version: 1
                errorHosts:
                - hostname: business.example.com
                  reason: property is not active in either production or staging
                  reasonCode: 400
                - hostname: anotherhostname.example.com
                  reason: You don't have access to this property
                  reasonCode: 403
                matchTargets:
                  apiTargets:
                  - apis:
                    - id: 1041
                      name: hmm test
                    bypassNetworkLists:
                    - id: 1024_AMAZONELASTICCOMPUTECLOU
                      name: Ec2 Akamai Network List
                    - id: 1283_MICROSOFTWINDOWSAZUREDAT
                      name: Azure IP range cloud services
                    effectiveSecurityControls:
                      applyApiConstraints: false
                      applyApplicationLayerControls: false
                      applyNetworkLayerControls: false
                      applyRateControls: true
                      applyReputationControls: false
                      applySlowPostControls: false
                    id: 1362597
                    securityPolicy:
                      policyId: 99e_47293
                    sequence: 6
                    type: api
                  - apis:
                    - id: 1001
                      name: '1001'
                    - id: 1041
                      name: hmm test
                    bypassNetworkLists:
                    - id: 11212_BYPASSURR
                      name: bypass-URR
                    effectiveSecurityControls:
                      applyApiConstraints: true
                      applyApplicationLayerControls: false
                      applyNetworkLayerControls: true
                      applyRateControls: false
                      applyReputationControls: true
                      applySlowPostControls: false
                    id: 1362598
                    securityPolicy:
                      policyId: '4444_44572'
                    sequence: 7
                    type: api
                  websiteTargets:
                  - bypassNetworkLists:
                    - id: 11212_BYPASSURR
                      name: bypass-URR
                    defaultFile: NO_MATCH
                    effectiveSecurityControls:
                      applyApiConstraints: true
                      applyApplicationLayerControls: true
                      applyNetworkLayerControls: false
                      applyRateControls: true
                      applyReputationControls: false
                      applySlowPostControls: false
                    fileExtensions:
                    - jpg
                    filePaths:
                    - /path
                    id: 1362593
                    isNegativeFileExtensionMatch: false
                    isNegativePathMatch: false
                    securityPolicy:
                      policyId: qik3_38800
                    sequence: 1
                    type: website
                  - defaultFile: NO_MATCH
                    effectiveSecurityControls:
                      applyApiConstraints: true
                      applyApplicationLayerControls: true
                      applyNetworkLayerControls: true
                      applyRateControls: true
                      applyReputationControls: true
                      applySlowPostControls: false
                    filePaths:
                    - /images
                    - /image1
                    - /path
                    hostnames:
                    - b2c.div1.akamaniac.com
                    id: 1362594
                    isNegativeFileExtensionMatch: false
                    isNegativePathMatch: false
                    securityPolicy:
                      policyId: qik2_38799
                    sequence: 2
                    type: website
                production:
                  status: Inactive
                ratePolicies:
                - averageThreshold: 3
                  burstThreshold: 2
                  clientIdentifier: ''
                  createDate: '2017-09-08T22:24:42Z'
                  id: 672601
                  matchType: path
                  name: dsafsfdsf
                  pathMatchType: RequestDisabled
                  pathUriPositiveMatch: true
                  queryParameters:
                  - name: dasdasdasd*
                    positiveMatch: true
                    valueInRange: false
                    values:
                    - dasdasdas8*&^
                  requestType: ClientRequest
                  sameActionOnIpv6: true
                  type: BOTMAN
                  updateDate: '2017-09-08T22:24:42Z'
                  useXForwardForHeaders: false
                  used: false
                - additionalMatchOptions:
                  - positiveMatch: true
                    type: NetworkListCondition
                    values:
                    - 25620_REPUTATIONALLOWLIST174
                    - 11212_BYPASSURR
                  - positiveMatch: true
                    type: RequestMethodCondition
                    values:
                    - GET
                    - HTTP_DELETE
                  - positiveMatch: true
                    type: UserAgentCondition
                    values:
                    - MOZILLA
                    - Googlebot
                  - positiveMatch: true
                    type: RequestMethodCondition
                    values:
                    - GET
                    - POST
                    - HEAD
                  - positiveMatch: true
                    type: ResponseStatusCondition
                    values:
                    - '400'
                    - '401'
                    - '402'
                    - '403'
                    - '404'
                    - '405'
                    - '406'
                    - '407'
                    - '408'
                    - '409'
                    - '410'
                    - '500'
                    - '501'
                    - '502'
                    - '503'
                    - '504'
                  averageThreshold: 1000
                  burstThreshold: 10
                  burstWindow: 3
                  clientIdentifier: ip
                  condition:
                    atomicConditions:
                    - className: TlsFingerprintCondition
                      positiveMatch: true
                      value:
                      - a797dc449ef113be
                      - ba51ec8d71259a5b3c92d8787370e2c3
                    - className: ClientReputationCondition
                      name:
                      - DOSATCK
                      - WEBATCK
                      positiveMatch: true
                      sharedIpHandling: BOTH
                      value: 3
                    - className: RequestHeaderCondition
                      name:
                      - Accept
                      - Content-Type
                      nameWildcard: true
                      positiveMatch: true
                      value:
                      - json
                      - xml
                      valueCase: false
                      valueWildcard: true
                    positiveMatch: true
                  createDate: '2017-09-08T22:24:42Z'
                  description: These Shared Resources will be available to all policies within the Security Configuration
                  id: 672607
                  matchType: path
                  name: These Shared Resources will be available to all policies within the Security Configuration
                  pathMatchType: Custom
                  pathUriPositiveMatch: true
                  queryParameters:
                  - name: param1
                    positiveMatch: false
                    valueInRange: true
                    values:
                    - value1
                  requestType: ClientRequest
                  sameActionOnIpv6: true
                  type: WAF
                  updateDate: '2017-09-08T22:24:42Z'
                  useXForwardForHeaders: false
                  used: true
                reputationProfiles:
                - context: SCANTL
                  contextReadable: Scanning Tools
                  enabled: true
                  id: 210588
                  name: Scanning Tools (Low Threat)
                  threshold: 5
                - condition:
                    atomicConditions:
                    - className: RequestHeaderCondition
                      index: 1
                      name:
                      - test*
                      nameWildcard: false
                      positiveMatch: true
                      value:
                      - test*
                      valueCase: false
                      valueWildcard: false
                    - className: RequestHeaderCondition
                      index: 2
                      name:
                      - Head
                      - Header
                      nameWildcard: true
                      positiveMatch: true
                      value:
                      - Header value
                      valueCase: false
                      valueWildcard: true
                    - checkIps: connecting
                      className: NetworkListCondition
                      index: 3
                      positiveMatch: true
                      value:
                      - 14121_IMAGEMANAGERSERVERS
                    - className: RequestCookieCondition
                      index: 4
                      name: cookieName
                      nameCase: false
                      nameWildcard: true
                      positiveMatch: true
                      value:
                      - cookieValue
                      valueCase: false
                      valueWildcard: true
                    - checkIps: connecting
                      className: AsNumberCondition
                      index: 5
                      positiveMatch: true
                      value:
                      - '5'
                    canDelete: false
                    configVersionId: 152889
                    id: 88112456
                    name: Cloned of 87956156 for version 152889
                    positiveMatch: true
                    uuid: SEC_COND_88112456
                    version: 1504909482545
                  context: WEBATCK
                  contextReadable: Web Attackers
                  enabled: false
                  id: 210578
                  name: Web Attackers (Low Threat)
                  threshold: 5
                rulesets:
                - attackGroups:
                  - group: DDOS
                    groupName: Anomaly Score Exceeded for DDoS
                    threshold: 5
                  - group: IN
                    groupName: Anomaly Score Exceeded for Inbound
                    threshold: 30
                  - group: SQL
                    groupName: Anomaly Score Exceeded for SQL Injection
                    threshold: 19
                  - group: TROJAN
                    groupName: Anomaly Score Exceeded for Trojan
                    threshold: 4
                  - group: XSS
                    groupName: Anomaly Score Exceeded for Cross-Site Scripting
                    threshold: 9
                  id: 41
                  releaseDate: '2017-04-21T16:00:38Z'
                  rules:
                  - id: 699989
                    inspectRequestBody: false
                    inspectResponseBody: false
                    ruleVersion: 1
                    score: 5
                    tag: <AKAMAI/PRAGMA_DEFLECTION>
                    title: Akamai-X debug Pragma header detected and removed
                  - id: 699990
                    inspectRequestBody: false
                    inspectResponseBody: false
                    ruleVersion: 1
                    score: 5
                    tag: <AKAMAI/EDGESCAPE_ANONYMOUS_PROXY_v1>
                    title: Detected request from anonymous proxy
                  - attackGroups:
                    - SQL
                    - IN
                    id: 981252
                    inspectRequestBody: true
                    inspectResponseBody: false
                    ruleVersion: 4
                    score: 5
                    tag: <OWASP_CRS/WEB_ATTACK/SQL_INJECTION>
                    title: MySQL Charset Switch and MSSQL DoS Attempts
                  - attackGroups:
                    - IN
                    - DDOS
                    id: 3000060
                    inspectRequestBody: true
                    inspectResponseBody: false
                    ruleVersion: 2
                    score: 1000
                    tag: <AKAMAI/AUTOMATION/MALICIOUS>
                    title: Mirai / Kaiten DDoS Detection - HTTP Attacks
                  - attackGroups:
                    - XSS
                    - IN
                    id: 3000061
                    inspectRequestBody: true
                    inspectResponseBody: false
                    ruleVersion: 1
                    score: 5
                    tag: <AKAMAI/WEB_ATTACK/XSS>
                    title: Referer Header From OpenBugBounty Website - Potential XSS
                  rulesetVersionId: 327550
                  type: Kona
                securityPolicies:
                - attackGroupActions:
                  - action: deny
                    exception:
                      specificHeaderCookieParamXmlOrJsonNames:
                      - names:
                        - '*'
                        selector: REQUEST_HEADERS_NAMES
                        wildcard: true
                      - names:
                        - test
                        selector: REQUEST_HEADERS
                        wildcard: true
                      - names:
                        - connect.sid
                        selector: REQUEST_COOKIES_NAMES
                        wildcard: false
                      - names:
                        - XSRF_TOKEN
                        selector: REQUEST_COOKIES
                        wildcard: true
                      - names:
                        - '*'
                        selector: ARGS_NAMES
                        wildcard: true
                      - names:
                        - value
                        selector: ARGS
                        wildcard: true
                      - names:
                        - '*'
                        selector: JSON_NAMES
                        wildcard: true
                      - names:
                        - val
                        selector: JSON_PAIRS
                        wildcard: true
                      - names:
                        - test
                        selector: XML_PAIRS
                        wildcard: true
                      - selector: REQUEST_PROTOCOL
                        wildcard: true
                      - selector: REQUEST_METHOD
                        wildcard: true
                      - selector: REQUEST_URI
                        wildcard: true
                      - selector: QUERY_STRING
                        wildcard: true
                      - selector: REQUEST_FILENAME
                        wildcard: true
                      - selector: REQUEST_PATH_SEGMENT
                        wildcard: true
                      - selector: REQUEST_BODY
                        wildcard: true
                      - selector: REQBODY_PROCESSOR_ERROR
                        wildcard: true
                      - selector: FILES_NAMES
                        wildcard: true
                    group: SQL
                    rulesetVersionId: 327550
                  - action: deny
                    group: XSS
                    rulesetVersionId: 327550
                  - action: deny
                    group: IN
                    rulesetVersionId: 327550
                  customRuleActions:
                  - action: deny
                    id: 628035
                  - action: alert
                    id: 628037
                  hasRatePolicyWithApiKey: false
                  id: qik2_38799
                  name: Generated Quick Policy - 4/10/17 7:13:18 PM GMT
                  networkLayerControls:
                    accountProtection:
                      generalSettings:
                        accountProtectionEnabled: true
                        originSignalHeaderEnabled: true
                        originUserIdInRequestHeaderEnabled: false
                        usernameInRequestHeaderEnabled: false
                      transactionalEndpoints:
                      - apiEndPointId: 784844
                        operationId: d7cf5676-5e30-4682-aa8d-2f181a139213
                        telemetryTypeStates:
                          inline:
                            ajaxSupportEnabled: false
                            disabledAction: none
                            enabled: true
                          nativeSdk:
                            ajaxSupportEnabled: false
                            disabledAction: none
                            enabled: true
                          standard:
                            ajaxSupportEnabled: false
                            disabledAction: monitor
                            enabled: true
                        traffic:
                          inline:
                            aggressive:
                              action: monitor
                              threshold: 100
                            cautious:
                              action: monitor
                              threshold: 0
                            overrideThresholds: true
                            strict:
                              action: monitor
                              threshold: 51
                          nativeSdkAndroid:
                            aggressive:
                              action: monitor
                              threshold: 100
                            bypassPreSdkVersion: true
                            cautious:
                              action: monitor
                              threshold: 0
                            overrideThresholds: true
                            strict:
                              action: monitor
                              threshold: 51
                          nativeSdkIos:
                            aggressive:
                              action: monitor
                              threshold: 100
                            bypassPreSdkVersion: true
                            cautious:
                              action: monitor
                              threshold: 0
                            overrideThresholds: true
                            strict:
                              action: monitor
                              threshold: 51
                          standard:
                            aggressive:
                              action: monitor
                              threshold: 100
                            cautious:
                              action: monitor
                              threshold: 0
                            overrideThresholds: true
                            strict:
                              action: monitor
                              threshold: 63
                    block: blockSpecificIPGeo
                    geoControls:
                      blockedIPNetworkLists:
                        additional:
                        - AF
                        - AS
                        networkList:
                        - 4389_BLANKLIST
                    ipControls:
                      allowedIPNetworkLists:
                        additional:
                        - 192.0.2.86
                        networkList:
                        - '12801_25000'
                        - '19440_1671'
                      blockedIPNetworkLists:
                        additional:
                        - 192.0.2.1
                        networkList:
                        - 16656_CPISERVERS
                        - 18460_166RELEASETESTING
                    slowPost:
                      action: alert
                      durationThreshold:
                        timeout: 5
                      slowRateThreshold:
                        period: 60
                        rate: 10
                  pragmaHeader:
                    action: REMOVE
                    conditionOperator: AND
                    excludeCondition:
                    - header: Expect
                      positiveMatch: true
                      type: requestHeaderValueMatch
                      useHeaders: false
                      value:
                      - dasd
                      valueCase: true
                      valueWildcard: true
                    - positiveMatch: true
                      type: networkList
                      useHeaders: true
                      value:
                      - 62569_AEPUAT1PARTNERSSTRICTWL
                      valueCase: false
                      valueWildcard: false
                    override: true
                  ratePolicyActions:
                  - id: 0
                    ipv4Action: alert
                    ipv6Action: deny
                  - id: 0
                    ipv4Action: alert
                    ipv6Action: none
                  reputationProfileActions:
                  - action: alert
                    id: 281778
                  - action: deny
                    id: 210588
                  ruleActions:
                  - action: alert
                    id: 960912
                    rulesetVersionId: 327550
                  - action: alert
                    id: 960035
                    rulesetVersionId: 327550
                  - action: alert
                    id: 981300
                    rulesetVersionId: 327550
                  - action: deny
                    id: 3000001
                    rulesetVersionId: 327550
                  - action: alert
                    conditions:
                    - hosts:
                      - www.example.com
                      - '*.example.com'
                      positiveMatch: true
                      type: hostMatch
                    - paths:
                      - /a/d
                      - /test/
                      positiveMatch: false
                      type: pathMatch
                    - caseSensitive: false
                      name: test
                      nameCase: false

# --- truncated at 32 KB (333 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/akamai-api-security/refs/heads/main/openapi/akamai-api-security-configuration-version-export-api-openapi.yml