Akamai API Security Match targets API

Manage your match targets, which define which security policy applies to an API, hostname, or path.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/akamai-api-security-match-targets-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

akamai-api-security-match-targets-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  description: 'Manage your configurations for Kona Site Defender,

    Web Application Protector, and Client Reputation.

    '
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: 'Akamai: Application Security Activation history Match targets API'
  version: v1
servers:
- url: https://{hostname}/appsec/v1
tags:
- description: 'Manage your match targets, which define which security policy

    applies to an API, hostname, or path.'
  name: Match targets
paths:
  /configs/{configId}/versions/{versionNumber}/hostname-coverage/match-targets:
    parameters:
    - description: A unique identifier for each configuration.
      example: '{{configId}}'
      in: path
      name: configId
      required: true
      schema:
        example: 77653
        format: int64
        type: integer
      x-akamai:
        file-path: parameters/config-id-path.yaml
    - description: A unique identifier for each version of a configuration.
      example: '{{versionNumber}}'
      in: path
      name: versionNumber
      required: true
      schema:
        example: 25
        type: integer
      x-akamai:
        file-path: parameters/version-number-path.yaml
    x-akamai:
      file-path: paths/config-hostname-coverage-match-targets.yaml
      path-info: /configs/{configId}/versions/{versionNumber}/hostname-coverage/match-targets
    get:
      description: List the API and website match targets that protect a hostname. _Products:_ Kona Site Defender, App & API Protector with the Advanced Security module.
      externalDocs:
        description: See documentation for this operation in Akamai's Application Security API
        url: https://techdocs.akamai.com/application-security/reference/get-coverage-match-targets
      operationId: get-coverage-match-targets
      parameters:
      - description: Get results by hostname.
        example: '{{hostname}}'
        in: query
        name: hostname
        schema:
          example: www.example.com
          type: string
        x-akamai:
          file-path: parameters/search-hostname.yaml
      - description: For customers who manage more than one account, this [runs the operation from another account](https://techdocs.akamai.com/developer/docs/manage-many-accounts-with-one-api-client). The Identity and Access Management API provides a [list of available account switch keys](https://techdocs.akamai.com/iam-api/reference/get-client-account-switch-keys).
        example: '{{accountSwitchKey}}'
        in: query
        name: accountSwitchKey
        required: false
        schema:
          example: 1-5C0YLB:1-8BYUX
          type: string
      responses:
        '200':
          content:
            application/json:
              example:
                matchTargets:
                  apiTargets: []
                  websiteTargets:
                  - bypassNetworkLists:
                    - id: 1410_BYPASSWAFLIST
                      name: shawn - BypassWAFList
                    configId: 75498
                    configVersion: 428
                    defaultFile: NO_MATCH
                    effectiveSecurityControls:
                      applyApplicationLayerControls: true
                      applyBotmanControls: true
                      applyNetworkLayerControls: true
                      applyPageIntegrityControls: false
                      applyRateControls: true
                      applyReputationControls: true
                      applySlowPostControls: true
                    fileExtensions: []
                    filePaths:
                    - /content/tealeaf
                    firewallPolicy:
                      evaluated: false
                      policyId: GRD_4186
                      policyName: Main Street Corporation  USA
                      policySecurityControls:
                        applyApiConstraints: false
                        applyApplicationLayerControls: true
                        applyBotmanControls: true
                        applyNetworkLayerControls: true
                        applyPageIntegrityControls: false
                        applyRateControls: true
                        applyReputationControls: true
                        applySlowPostControls: true
                    hostnames:
                    - www.example.com
                    - m.example.com
                    - m.new.example.com
                    - safety.example.com
                    - static.example.net
                    - failover3.example.com
                    - static.example.com
                    - images.example.com
                    - failover5.example.com
                    - espanol.example.com
                    isNegativeFileExtensionMatch: false
                    isNegativePathMatch: false
                    isTargetSecurityControlsEditable: false
                    logicalId: 1730010
                    sequence: 3
                    targetId: 2555705
                    targetSecurityControls:
                      applyApplicationLayerControls: true
                      applyNetworkLayerControls: true
                      applyPageIntegrityControls: false
                      applyRateControls: true
                      applyReputationControls: true
                      applySlowPostControls: true
                    type: website
              schema:
                additionalProperties: false
                description: Contains the hostname coverage API and website match targets defined in the security configuration version.
                properties:
                  matchTargets:
                    additionalProperties: false
                    description: Contains the API and website match targets defined in the security configuration version.
                    properties:
                      apiTargets:
                        description: The list of `api` match targets.
                        items:
                          additionalProperties: false
                          description: Contains details about a hostname coverage match target.
                          properties:
                            apis:
                              description: The list of API endpoint identifiers and names. This applies only for `api` match targets.
                              items:
                                additionalProperties: false
                                properties:
                                  id:
                                    description: Uniquely identifies the API endpoint.
                                    type: integer
                                  name:
                                    description: The API endpoint name.
                                    type: string
                                required:
                                - id
                                type: object
                              type: array
                            bypassNetworkLists:
                              description: The network lists' identifiers and names in the match target.
                              items:
                                additionalProperties: false
                                properties:
                                  id:
                                    description: Uniquely identifies the network list.
                                    type: string
                                  name:
                                    description: The name you assigned to the network list.
                                    type: string
                                required:
                                - id
                                type: object
                              type: array
                            defaultFile:
                              default: NO_MATCH
                              description: Describes the rule to match on paths. Either `NO_MATCH` not to match on the default file, `BASE_MATCH` to match only requests for top-level hostnames ending in a trailing slash, or `RECURSIVE_MATCH` to match all requests for paths that end in a trailing slash. The default value is `NO_MATCH`.
                              enum:
                              - NO_MATCH
                              - BASE_MATCH
                              - RECURSIVE_MATCH
                              type: string
                            effectiveSecurityControls:
                              additionalProperties: false
                              description: __Read-only__ The security controls to apply. For a security control to be effectively turned on, you must enable it in both the match target and the security policy.
                              properties:
                                applyApiConstraints:
                                  description: Whether you enabled API constraints.
                                  type: boolean
                                applyApplicationLayerControls:
                                  description: Whether you enabled application layer controls.
                                  type: boolean
                                applyBotmanControls:
                                  description: Whether you enabled Bot Manager controls.
                                  type: boolean
                                applyNetworkLayerControls:
                                  description: Whether you enabled network layer controls.
                                  type: boolean
                                applyRateControls:
                                  description: Whether you enabled rate controls.
                                  type: boolean
                                applyReputationControls:
                                  description: Whether you enabled reputation controls.
                                  type: boolean
                                applySlowPostControls:
                                  description: Whether you enabled slow post controls.
                                  type: boolean
                              readOnly: true
                              required:
                              - applyApplicationLayerControls
                              - applyNetworkLayerControls
                              - applyRateControls
                              - applyReputationControls
                              - applyBotmanControls
                              - applyApiConstraints
                              - applySlowPostControls
                              type: object
                              x-akamai:
                                file-path: schemas/security-controls.yaml
                            fileExtensions:
                              description: The list of file extensions to apply the match target to.
                              items:
                                type: string
                              type: array
                            filePaths:
                              description: The list of file paths to apply the match target to.
                              items:
                                type: string
                              type: array
                            hostnames:
                              description: The list of hostnames to protect.
                              items:
                                type: string
                              type: array
                            isNegativeFileExtensionMatch:
                              description: Whether the match target applies when a match is found in the specified `fileExtensions` or when a match isn't found.
                              type: boolean
                            isNegativePathMatch:
                              description: Whether the match target applies when a match is found in the specified `filePaths` or when a match isn't found.
                              type: boolean
                            securityPolicy:
                              additionalProperties: false
                              description: The security policy associated with the match target.
                              properties:
                                policyId:
                                  description: Uniquely identifies the security policy.
                                  type: string
                              required:
                              - policyId
                              type: object
                            sequence:
                              description: The match target's position in the sequence of match targets.
                              type: integer
                            targetId:
                              description: Uniquely identifies the match target.
                              type: integer
                            type:
                              description: The type of match target. Either `website` or `api`.
                              enum:
                              - website
                              - api
                              type: string
                            validations:
                              additionalProperties: false
                              description: __Read-only__ Contains details about warnings, errors, or notices determined by a validation of this resource.
                              properties:
                                errors:
                                  description: The list of errors.
                                  items:
                                    additionalProperties: false
                                    description: Contains feedback on validation.
                                    properties:
                                      detail:
                                        description: The explanation of the error message.
                                        type: string
                                      fieldName:
                                        description: The name of the field causing the validation problem.
                                        type: string
                                      jsonReference:
                                        description: The JSON reference to the field in the resource.
                                        type: string
                                      title:
                                        description: The title for the error.
                                        example: Not Found
                                        type: string
                                      type:
                                        description: The URL for the error type.
                                        example: /appsec/problem-types/INCOMPATIBLE-FIELD
                                        type: string
                                    required:
                                    - title
                                    - type
                                    type: object
                                    x-akamai:
                                      file-path: schemas/validation.yaml
                                  type: array
                                notices:
                                  description: The list of notices.
                                  items:
                                    additionalProperties: false
                                    description: Contains feedback on validation.
                                    properties:
                                      detail:
                                        description: The explanation of the error message.
                                        type: string
                                      fieldName:
                                        description: The name of the field causing the validation problem.
                                        type: string
                                      jsonReference:
                                        description: The JSON reference to the field in the resource.
                                        type: string
                                      title:
                                        description: The title for the error.
                                        example: Not Found
                                        type: string
                                      type:
                                        description: The URL for the error type.
                                        example: /appsec/problem-types/INCOMPATIBLE-FIELD
                                        type: string
                                    required:
                                    - title
                                    - type
                                    type: object
                                    x-akamai:
                                      file-path: schemas/validation.yaml
                                  type: array
                                warnings:
                                  description: The list of warnings.
                                  items:
                                    additionalProperties: false
                                    description: Contains feedback on validation.
                                    properties:
                                      detail:
                                        description: The explanation of the error message.
                                        type: string
                                      fieldName:
                                        description: The name of the field causing the validation problem.
                                        type: string
                                      jsonReference:
                                        description: The JSON reference to the field in the resource.
                                        type: string
                                      title:
                                        description: The title for the error.
                                        example: Not Found
                                        type: string
                                      type:
                                        description: The URL for the error type.
                                        example: /appsec/problem-types/INCOMPATIBLE-FIELD
                                        type: string
                                    required:
                                    - title
                                    - type
                                    type: object
                                    x-akamai:
                                      file-path: schemas/validation.yaml
                                  type: array
                              readOnly: true
                              required:
                              - notices
                              - errors
                              - warnings
                              type: object
                              x-akamai:
                                file-path: schemas/validations.yaml
                          required:
                          - type
                          - securityPolicy
                          type: object
                          x-akamai:
                            file-path: schemas/hostname-coverage-match-target.yaml
                        type: array
                      websiteTargets:
                        description: The list of `website` match targets.
                        items:
                          additionalProperties: false
                          description: Contains details about a hostname coverage match target.
                          properties:
                            apis:
                              description: The list of API endpoint identifiers and names. This applies only for `api` match targets.
                              items:
                                additionalProperties: false
                                properties:
                                  id:
                                    description: Uniquely identifies the API endpoint.
                                    type: integer
                                  name:
                                    description: The API endpoint name.
                                    type: string
                                required:
                                - id
                                type: object
                              type: array
                            bypassNetworkLists:
                              description: The network lists' identifiers and names in the match target.
                              items:
                                additionalProperties: false
                                properties:
                                  id:
                                    description: Uniquely identifies the network list.
                                    type: string
                                  name:
                                    description: The name you assigned to the network list.
                                    type: string
                                required:
                                - id
                                type: object
                              type: array
                            defaultFile:
                              default: NO_MATCH
                              description: Describes the rule to match on paths. Either `NO_MATCH` not to match on the default file, `BASE_MATCH` to match only requests for top-level hostnames ending in a trailing slash, or `RECURSIVE_MATCH` to match all requests for paths that end in a trailing slash. The default value is `NO_MATCH`.
                              enum:
                              - NO_MATCH
                              - BASE_MATCH
                              - RECURSIVE_MATCH
                              type: string
                            effectiveSecurityControls:
                              additionalProperties: false
                              description: __Read-only__ The security controls to apply. For a security control to be effectively turned on, you must enable it in both the match target and the security policy.
                              properties:
                                applyApiConstraints:
                                  description: Whether you enabled API constraints.
                                  type: boolean
                                applyApplicationLayerControls:
                                  description: Whether you enabled application layer controls.
                                  type: boolean
                                applyBotmanControls:
                                  description: Whether you enabled Bot Manager controls.
                                  type: boolean
                                applyNetworkLayerControls:
                                  description: Whether you enabled network layer controls.
                                  type: boolean
                                applyRateControls:
                                  description: Whether you enabled rate controls.
                                  type: boolean
                                applyReputationControls:
                                  description: Whether you enabled reputation controls.
                                  type: boolean
                                applySlowPostControls:
                                  description: Whether you enabled slow post controls.
                                  type: boolean
                              readOnly: true
                              required:
                              - applyApplicationLayerControls
                              - applyNetworkLayerControls
                              - applyRateControls
                              - applyReputationControls
                              - applyBotmanControls
                              - applyApiConstraints
                              - applySlowPostControls
                              type: object
                              x-akamai:
                                file-path: schemas/security-controls.yaml
                            fileExtensions:
                              description: The list of file extensions to apply the match target to.
                              items:
                                type: string
                              type: array
                            filePaths:
                              description: The list of file paths to apply the match target to.
                              items:
                                type: string
                              type: array
                            hostnames:
                              description: The list of hostnames to protect.
                              items:
                                type: string
                              type: array
                            isNegativeFileExtensionMatch:
                              description: Whether the match target applies when a match is found in the specified `fileExtensions` or when a match isn't found.
                              type: boolean
                            isNegativePathMatch:
                              description: Whether the match target applies when a match is found in the specified `filePaths` or when a match isn't found.
                              type: boolean
                            securityPolicy:
                              additionalProperties: false
                              description: The security policy associated with the match target.
                              properties:
                                policyId:
                                  description: Uniquely identifies the security policy.
                                  type: string
                              required:
                              - policyId
                              type: object
                            sequence:
                              description: The match target's position in the sequence of match targets.
                              type: integer
                            targetId:
                              description: Uniquely identifies the match target.
                              type: integer
                            type:
                              description: The type of match target. Either `website` or `api`.
                              enum:
                              - website
                              - api
                              type: string
                            validations:
                              additionalProperties: false
                              description: __Read-only__ Contains details about warnings, errors, or notices determined by a validation of this resource.
                              properties:
                                errors:
                                  description: The list of errors.
                                  items:
                                    additionalProperties: false
                                    description: Contains feedback on validation.
                                    properties:
                                      detail:
                                        description: The explanation of the error message.
                                        type: string
                                      fieldName:
                                        description: The name of the field causing the validation problem.
                                        type: string
                                      jsonReference:
                                        description: The JSON reference to the field in the resource.
                                        type: string
                                      title:
                                        description: The title for the error.
                                        example: Not Found
                                        type: string
                                      type:
                                        description: The URL for the error type.
                                        example: /appsec/problem-types/INCOMPATIBLE-FIELD
                                        type: string
                                    required:
                                    - title
                                    - type
                                    type: object
                                    x-akamai:
                                      file-path: schemas/validation.yaml
                                  type: array
                                notices:
                                  description: The list of notices.
                                  items:
                                    additionalProperties: false
                                    description: Contains feedback on validation.
                                    properties:
                                      detail:
                                        description: The explanation of the error message.
                                        type: string
                                      fieldName:
                                        description: The name of the field causing the validation problem.
                                        type: string
                                      jsonReference:
                                        description: The JSON reference to the field in the resource.
                                        type: string
                                      title:
                                        description: The title for the error.
                                        example: Not Found
                                        type: string
                                      type:
                                        description: The URL for the error type.
                                        example: /appsec/problem-types/INCOMPATIBLE-FIELD
                                        type: string
                                    required:
                                    - title
                                    - type
                                    type: object
                                    x-akamai:
                                      file-path: schemas/validation.yaml
                                  type: array
                                warnings:
                                  description: The list of warnings.
                                  items:
                                    additionalProperties: false
                                    description: Contains feedback on validation.
                                    properties:
                                      detail:
                                        description: The explanation of the error message.
                                        type: string
                                      fieldName:
                                        description: The name of the field causing the validation problem.
                                        type: string
                                      jsonReference:
                                        description: The JSON reference to the field in the resource.
                                        type: string
                                      title:
                                        description: The title for the error.
                                        example: Not Found
                                        type: string
                                      type:
                                        description: The URL for the error type.
                                        example: /appsec/problem-types/INCOMPATIBLE-FIELD
                                        type: string
                                    required:
                                    - title
                                    - type
                                    type: object
                                    x-akamai:
                                      file-path: schemas/validation.yaml
                                  type: array
                              readOnly: true
                        

# --- truncated at 32 KB (184 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/akamai-api-security/refs/heads/main/openapi/akamai-api-security-match-targets-api-openapi.yml