Akamai API Security Configuration version export API
Get comprehensive details about a security configuration version.
Get comprehensive details about a security configuration version.
openapi: 3.0.0
info:
description: 'Manage your configurations for Kona Site Defender,
Web Application Protector, and Client Reputation.
'
license:
name: Apache 2.0
url: https://www.apache.org/licenses/LICENSE-2.0.html
title: 'Akamai: Application Security Activation history Configuration version export API'
version: v1
servers:
- url: https://{hostname}/appsec/v1
tags:
- description: 'Get comprehensive details about a security configuration
version.'
name: Configuration version export
paths:
/export/configs/{configId}/versions/{versionNumber}:
parameters:
- description: A unique identifier for each configuration.
example: '{{configId}}'
in: path
name: configId
required: true
schema:
example: 77653
format: int64
type: integer
x-akamai:
file-path: parameters/config-id-path.yaml
- description: A unique identifier for each version of a configuration.
example: '{{versionNumber}}'
in: path
name: versionNumber
required: true
schema:
example: 25
type: integer
x-akamai:
file-path: parameters/version-number-path.yaml
x-akamai:
file-path: paths/export.yaml
path-info: /export/configs/{configId}/versions/{versionNumber}
get:
description: Returns comprehensive details about a security configuration version. This operation returns more data than [Get configuration version details](https://techdocs.akamai.com/application-security/reference/get-version-number), including Bot Manager protections, rate and security policies, rules, hostnames, and numerous additional settings.
externalDocs:
description: See documentation for this operation in Akamai's Application Security API
url: https://techdocs.akamai.com/application-security/reference/get-export-config-version
operationId: get-export-config-version
parameters:
- description: For customers who manage more than one account, this [runs the operation from another account](https://techdocs.akamai.com/developer/docs/manage-many-accounts-with-one-api-client). The Identity and Access Management API provides a [list of available account switch keys](https://techdocs.akamai.com/iam-api/reference/get-client-account-switch-keys).
example: '{{accountSwitchKey}}'
in: query
name: accountSwitchKey
required: false
schema:
example: 1-5C0YLB:1-8BYUX
type: string
responses:
'200':
content:
application/json:
example:
advancedOptions:
logging:
allowSampling: true
cookies:
type: exclude
values:
- _updated_By_SoapUI
- w
- NEW_VAL_ADDED_BY_SoapUI
customHeaders:
type: only
values:
- '112'
- sdasd
- ds
standardHeaders:
type: only
pragmaHeader:
action: REMOVE
conditionOperator: AND
excludeCondition:
- header: Expect
positiveMatch: true
type: requestHeaderValueMatch
useHeaders: false
value:
- dasd
valueCase: true
valueWildcard: true
- positiveMatch: true
type: networkList
useHeaders: true
value:
- 62569_AEPUAT1PARTNERSSTRICTWL
valueCase: false
valueWildcard: false
override: true
prefetch:
allExtensions: false
enableAppLayer: true
enableRateControls: false
extensions:
- cgi
- jsp
- EMPTY_STRING
- aspx
- php
- py
- asp
advancedSettings:
userAllowListIdSettings:
userAllowListId: 82004_APRE2ENLDONOTDELETE
userRiskResponseStrategySettings:
traffic:
inline:
aggressive:
threshold: 76
cautious:
threshold: 0
strict:
threshold: 51
nativeSdkAndroid:
aggressive:
threshold: 76
cautious:
threshold: 0
strict:
threshold: 51
nativeSdkIos:
aggressive:
threshold: 76
cautious:
threshold: 0
strict:
threshold: 51
standard:
aggressive:
threshold: 76
cautious:
threshold: 0
strict:
threshold: 51
basedOn: 1
configId: 48579
configName: New Security Config
createDate: '2017-09-08T22:24:41Z'
createdBy: mrossi
customRules:
- conditions:
- positiveMatch: true
type: requestMethodMatch
value:
- GET
configId: 77653
id: 776532
name: UXR-715 RE2 Second Test with Flags
ruleActivated: false
stagingOnly: true
structured: true
tag:
- tagfor
- '17.2'
version: 1
- conditions:
- positiveMatch: true
type: extensionMatch
value:
- fdf
valueCase: true
valueWildcard: false
configId: 77653
description: Test CR
id: 600001
name: Test CR
ruleActivated: false
structured: true
tag:
- Test
- Tag
version: 1
- conditions:
- name: kids
nameCase: true
nameWildcard: false
positiveMatch: true
type: cookieMatch
value:
- dsds
- dasdqw
- dsa
- dqwd
- csqw
valueCase: true
valueWildcard: true
configId: 77653
description: Test CR
id: 600006
name: Test CR
ruleActivated: false
structured: true
tag:
- k
version: 1
- conditions:
- positiveMatch: true
type: pathMatch
value:
- /login
configId: 77653
id: 606713
name: Test
ruleActivated: false
structured: true
tag:
- adsa
version: 1
- conditions:
- name: fvfv
positiveMatch: true
type: argsPostMatch
value:
- fgbr
- name:
- test
nameWildcard: true
positiveMatch: true
type: requestHeaderMatch
value:
- test1
valueCase: false
valueWildcard: true
configId: 77653
description: Test CR
id: 690265
name: Test CR2
ruleActivated: false
structured: true
tag:
- ee
version: 1
- configId: 77653
id: 667825
inspectRequest: false
inspectResponse: false
metadata: '<match:variable name="MY_SAMPLE_THREAT_DETECTED" result="true" value="execute rule">
<match:regex impl="re2" regex="^\d+$" result="false" select="REQUEST_HEADERS:Content-Length" strict-err-check-re2="on" transform="urlDecodeUni">
<security:firewall.action>
<msg>UXR-715 CRB Metadata testing</msg>
<tag>CUSTOM/TEST</tag>
<id>667825</id>
<deny>%(WAF_CUSTOM_R667825_DENY)</deny>
<data>threat indicated from data %(MY_SAMPLE_THREAT_DETECTED)</data>
<http-status>403</http-status>
</security:firewall.action>
</match:regex>
</match:variable>'
name: UXR-715 RE27890
ruleActivated: false
structured: false
version: 1
errorHosts:
- hostname: business.example.com
reason: property is not active in either production or staging
reasonCode: 400
- hostname: anotherhostname.example.com
reason: You don't have access to this property
reasonCode: 403
matchTargets:
apiTargets:
- apis:
- id: 1041
name: hmm test
bypassNetworkLists:
- id: 1024_AMAZONELASTICCOMPUTECLOU
name: Ec2 Akamai Network List
- id: 1283_MICROSOFTWINDOWSAZUREDAT
name: Azure IP range cloud services
effectiveSecurityControls:
applyApiConstraints: false
applyApplicationLayerControls: false
applyNetworkLayerControls: false
applyRateControls: true
applyReputationControls: false
applySlowPostControls: false
id: 1362597
securityPolicy:
policyId: 99e_47293
sequence: 6
type: api
- apis:
- id: 1001
name: '1001'
- id: 1041
name: hmm test
bypassNetworkLists:
- id: 11212_BYPASSURR
name: bypass-URR
effectiveSecurityControls:
applyApiConstraints: true
applyApplicationLayerControls: false
applyNetworkLayerControls: true
applyRateControls: false
applyReputationControls: true
applySlowPostControls: false
id: 1362598
securityPolicy:
policyId: '4444_44572'
sequence: 7
type: api
websiteTargets:
- bypassNetworkLists:
- id: 11212_BYPASSURR
name: bypass-URR
defaultFile: NO_MATCH
effectiveSecurityControls:
applyApiConstraints: true
applyApplicationLayerControls: true
applyNetworkLayerControls: false
applyRateControls: true
applyReputationControls: false
applySlowPostControls: false
fileExtensions:
- jpg
filePaths:
- /path
id: 1362593
isNegativeFileExtensionMatch: false
isNegativePathMatch: false
securityPolicy:
policyId: qik3_38800
sequence: 1
type: website
- defaultFile: NO_MATCH
effectiveSecurityControls:
applyApiConstraints: true
applyApplicationLayerControls: true
applyNetworkLayerControls: true
applyRateControls: true
applyReputationControls: true
applySlowPostControls: false
filePaths:
- /images
- /image1
- /path
hostnames:
- b2c.div1.akamaniac.com
id: 1362594
isNegativeFileExtensionMatch: false
isNegativePathMatch: false
securityPolicy:
policyId: qik2_38799
sequence: 2
type: website
production:
status: Inactive
ratePolicies:
- averageThreshold: 3
burstThreshold: 2
clientIdentifier: ''
createDate: '2017-09-08T22:24:42Z'
id: 672601
matchType: path
name: dsafsfdsf
pathMatchType: RequestDisabled
pathUriPositiveMatch: true
queryParameters:
- name: dasdasdasd*
positiveMatch: true
valueInRange: false
values:
- dasdasdas8*&^
requestType: ClientRequest
sameActionOnIpv6: true
type: BOTMAN
updateDate: '2017-09-08T22:24:42Z'
useXForwardForHeaders: false
used: false
- additionalMatchOptions:
- positiveMatch: true
type: NetworkListCondition
values:
- 25620_REPUTATIONALLOWLIST174
- 11212_BYPASSURR
- positiveMatch: true
type: RequestMethodCondition
values:
- GET
- HTTP_DELETE
- positiveMatch: true
type: UserAgentCondition
values:
- MOZILLA
- Googlebot
- positiveMatch: true
type: RequestMethodCondition
values:
- GET
- POST
- HEAD
- positiveMatch: true
type: ResponseStatusCondition
values:
- '400'
- '401'
- '402'
- '403'
- '404'
- '405'
- '406'
- '407'
- '408'
- '409'
- '410'
- '500'
- '501'
- '502'
- '503'
- '504'
averageThreshold: 1000
burstThreshold: 10
burstWindow: 3
clientIdentifier: ip
condition:
atomicConditions:
- className: TlsFingerprintCondition
positiveMatch: true
value:
- a797dc449ef113be
- ba51ec8d71259a5b3c92d8787370e2c3
- className: ClientReputationCondition
name:
- DOSATCK
- WEBATCK
positiveMatch: true
sharedIpHandling: BOTH
value: 3
- className: RequestHeaderCondition
name:
- Accept
- Content-Type
nameWildcard: true
positiveMatch: true
value:
- json
- xml
valueCase: false
valueWildcard: true
positiveMatch: true
createDate: '2017-09-08T22:24:42Z'
description: These Shared Resources will be available to all policies within the Security Configuration
id: 672607
matchType: path
name: These Shared Resources will be available to all policies within the Security Configuration
pathMatchType: Custom
pathUriPositiveMatch: true
queryParameters:
- name: param1
positiveMatch: false
valueInRange: true
values:
- value1
requestType: ClientRequest
sameActionOnIpv6: true
type: WAF
updateDate: '2017-09-08T22:24:42Z'
useXForwardForHeaders: false
used: true
reputationProfiles:
- context: SCANTL
contextReadable: Scanning Tools
enabled: true
id: 210588
name: Scanning Tools (Low Threat)
threshold: 5
- condition:
atomicConditions:
- className: RequestHeaderCondition
index: 1
name:
- test*
nameWildcard: false
positiveMatch: true
value:
- test*
valueCase: false
valueWildcard: false
- className: RequestHeaderCondition
index: 2
name:
- Head
- Header
nameWildcard: true
positiveMatch: true
value:
- Header value
valueCase: false
valueWildcard: true
- checkIps: connecting
className: NetworkListCondition
index: 3
positiveMatch: true
value:
- 14121_IMAGEMANAGERSERVERS
- className: RequestCookieCondition
index: 4
name: cookieName
nameCase: false
nameWildcard: true
positiveMatch: true
value:
- cookieValue
valueCase: false
valueWildcard: true
- checkIps: connecting
className: AsNumberCondition
index: 5
positiveMatch: true
value:
- '5'
canDelete: false
configVersionId: 152889
id: 88112456
name: Cloned of 87956156 for version 152889
positiveMatch: true
uuid: SEC_COND_88112456
version: 1504909482545
context: WEBATCK
contextReadable: Web Attackers
enabled: false
id: 210578
name: Web Attackers (Low Threat)
threshold: 5
rulesets:
- attackGroups:
- group: DDOS
groupName: Anomaly Score Exceeded for DDoS
threshold: 5
- group: IN
groupName: Anomaly Score Exceeded for Inbound
threshold: 30
- group: SQL
groupName: Anomaly Score Exceeded for SQL Injection
threshold: 19
- group: TROJAN
groupName: Anomaly Score Exceeded for Trojan
threshold: 4
- group: XSS
groupName: Anomaly Score Exceeded for Cross-Site Scripting
threshold: 9
id: 41
releaseDate: '2017-04-21T16:00:38Z'
rules:
- id: 699989
inspectRequestBody: false
inspectResponseBody: false
ruleVersion: 1
score: 5
tag: <AKAMAI/PRAGMA_DEFLECTION>
title: Akamai-X debug Pragma header detected and removed
- id: 699990
inspectRequestBody: false
inspectResponseBody: false
ruleVersion: 1
score: 5
tag: <AKAMAI/EDGESCAPE_ANONYMOUS_PROXY_v1>
title: Detected request from anonymous proxy
- attackGroups:
- SQL
- IN
id: 981252
inspectRequestBody: true
inspectResponseBody: false
ruleVersion: 4
score: 5
tag: <OWASP_CRS/WEB_ATTACK/SQL_INJECTION>
title: MySQL Charset Switch and MSSQL DoS Attempts
- attackGroups:
- IN
- DDOS
id: 3000060
inspectRequestBody: true
inspectResponseBody: false
ruleVersion: 2
score: 1000
tag: <AKAMAI/AUTOMATION/MALICIOUS>
title: Mirai / Kaiten DDoS Detection - HTTP Attacks
- attackGroups:
- XSS
- IN
id: 3000061
inspectRequestBody: true
inspectResponseBody: false
ruleVersion: 1
score: 5
tag: <AKAMAI/WEB_ATTACK/XSS>
title: Referer Header From OpenBugBounty Website - Potential XSS
rulesetVersionId: 327550
type: Kona
securityPolicies:
- attackGroupActions:
- action: deny
exception:
specificHeaderCookieParamXmlOrJsonNames:
- names:
- '*'
selector: REQUEST_HEADERS_NAMES
wildcard: true
- names:
- test
selector: REQUEST_HEADERS
wildcard: true
- names:
- connect.sid
selector: REQUEST_COOKIES_NAMES
wildcard: false
- names:
- XSRF_TOKEN
selector: REQUEST_COOKIES
wildcard: true
- names:
- '*'
selector: ARGS_NAMES
wildcard: true
- names:
- value
selector: ARGS
wildcard: true
- names:
- '*'
selector: JSON_NAMES
wildcard: true
- names:
- val
selector: JSON_PAIRS
wildcard: true
- names:
- test
selector: XML_PAIRS
wildcard: true
- selector: REQUEST_PROTOCOL
wildcard: true
- selector: REQUEST_METHOD
wildcard: true
- selector: REQUEST_URI
wildcard: true
- selector: QUERY_STRING
wildcard: true
- selector: REQUEST_FILENAME
wildcard: true
- selector: REQUEST_PATH_SEGMENT
wildcard: true
- selector: REQUEST_BODY
wildcard: true
- selector: REQBODY_PROCESSOR_ERROR
wildcard: true
- selector: FILES_NAMES
wildcard: true
group: SQL
rulesetVersionId: 327550
- action: deny
group: XSS
rulesetVersionId: 327550
- action: deny
group: IN
rulesetVersionId: 327550
customRuleActions:
- action: deny
id: 628035
- action: alert
id: 628037
hasRatePolicyWithApiKey: false
id: qik2_38799
name: Generated Quick Policy - 4/10/17 7:13:18 PM GMT
networkLayerControls:
accountProtection:
generalSettings:
accountProtectionEnabled: true
originSignalHeaderEnabled: true
originUserIdInRequestHeaderEnabled: false
usernameInRequestHeaderEnabled: false
transactionalEndpoints:
- apiEndPointId: 784844
operationId: d7cf5676-5e30-4682-aa8d-2f181a139213
telemetryTypeStates:
inline:
ajaxSupportEnabled: false
disabledAction: none
enabled: true
nativeSdk:
ajaxSupportEnabled: false
disabledAction: none
enabled: true
standard:
ajaxSupportEnabled: false
disabledAction: monitor
enabled: true
traffic:
inline:
aggressive:
action: monitor
threshold: 100
cautious:
action: monitor
threshold: 0
overrideThresholds: true
strict:
action: monitor
threshold: 51
nativeSdkAndroid:
aggressive:
action: monitor
threshold: 100
bypassPreSdkVersion: true
cautious:
action: monitor
threshold: 0
overrideThresholds: true
strict:
action: monitor
threshold: 51
nativeSdkIos:
aggressive:
action: monitor
threshold: 100
bypassPreSdkVersion: true
cautious:
action: monitor
threshold: 0
overrideThresholds: true
strict:
action: monitor
threshold: 51
standard:
aggressive:
action: monitor
threshold: 100
cautious:
action: monitor
threshold: 0
overrideThresholds: true
strict:
action: monitor
threshold: 63
block: blockSpecificIPGeo
geoControls:
blockedIPNetworkLists:
additional:
- AF
- AS
networkList:
- 4389_BLANKLIST
ipControls:
allowedIPNetworkLists:
additional:
- 192.0.2.86
networkList:
- '12801_25000'
- '19440_1671'
blockedIPNetworkLists:
additional:
- 192.0.2.1
networkList:
- 16656_CPISERVERS
- 18460_166RELEASETESTING
slowPost:
action: alert
durationThreshold:
timeout: 5
slowRateThreshold:
period: 60
rate: 10
pragmaHeader:
action: REMOVE
conditionOperator: AND
excludeCondition:
- header: Expect
positiveMatch: true
type: requestHeaderValueMatch
useHeaders: false
value:
- dasd
valueCase: true
valueWildcard: true
- positiveMatch: true
type: networkList
useHeaders: true
value:
- 62569_AEPUAT1PARTNERSSTRICTWL
valueCase: false
valueWildcard: false
override: true
ratePolicyActions:
- id: 0
ipv4Action: alert
ipv6Action: deny
- id: 0
ipv4Action: alert
ipv6Action: none
reputationProfileActions:
- action: alert
id: 281778
- action: deny
id: 210588
ruleActions:
- action: alert
id: 960912
rulesetVersionId: 327550
- action: alert
id: 960035
rulesetVersionId: 327550
- action: alert
id: 981300
rulesetVersionId: 327550
- action: deny
id: 3000001
rulesetVersionId: 327550
- action: alert
conditions:
- hosts:
- www.example.com
- '*.example.com'
positiveMatch: true
type: hostMatch
- paths:
- /a/d
- /test/
positiveMatch: false
type: pathMatch
- caseSensitive: false
name: test
nameCase: false
# --- truncated at 32 KB (333 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/akamai-api-security/refs/heads/main/openapi/akamai-api-security-configuration-version-export-api-openapi.yml