Akamai API Security Protections API

Manage various security policy protections. These settings enable or disable each protection on your policy. However, you set the protections themselves in their corresponding operations available in this API.

OpenAPI Specification

akamai-api-security-protections-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  description: 'Manage your configurations for Kona Site Defender,

    Web Application Protector, and Client Reputation.

    '
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: 'Akamai: Application Security Activation history Protections API'
  version: v1
servers:
- url: https://{hostname}/appsec/v1
tags:
- description: 'Manage various security policy protections.  These settings

    enable or disable each protection on your policy.  However, you

    set the protections themselves in their corresponding operations

    available in this API.'
  name: Protections
paths:
  /configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/protections:
    parameters:
    - description: A unique identifier for each configuration.
      example: '{{configId}}'
      in: path
      name: configId
      required: true
      schema:
        example: 77653
        format: int64
        type: integer
      x-akamai:
        file-path: parameters/config-id-path.yaml
    - description: A unique identifier for each version of a configuration.
      example: '{{versionNumber}}'
      in: path
      name: versionNumber
      required: true
      schema:
        example: 25
        type: integer
      x-akamai:
        file-path: parameters/version-number-path.yaml
    - description: A unique identifier for a security policy.
      example: '{{policyId}}'
      in: path
      name: policyId
      required: true
      schema:
        example: boBF_19288
        type: string
      x-akamai:
        file-path: parameters/policy-id-path.yaml
    x-akamai:
      file-path: paths/policy-protections.yaml
      path-info: /configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/protections
    get:
      description: Get the protections and whether they are enabled or disabled in a security policy. _Products:_ All.
      externalDocs:
        description: See documentation for this operation in Akamai's Application Security API
        url: https://techdocs.akamai.com/application-security/reference/get-policy-protections
      operationId: get-policy-protections
      parameters:
      - description: For customers who manage more than one account, this [runs the operation from another account](https://techdocs.akamai.com/developer/docs/manage-many-accounts-with-one-api-client). The Identity and Access Management API provides a [list of available account switch keys](https://techdocs.akamai.com/iam-api/reference/get-client-account-switch-keys).
        example: '{{accountSwitchKey}}'
        in: query
        name: accountSwitchKey
        required: false
        schema:
          example: 1-5C0YLB:1-8BYUX
          type: string
      responses:
        '200':
          content:
            application/json:
              example:
                applyApiConstraints: true
                applyApplicationLayerControls: true
                applyMalwareControls: true
                applyNetworkLayerControls: true
                applyRateControls: true
                applyReputationControls: true
                applySlowPostControls: true
              schema:
                additionalProperties: false
                description: These settings enable or disable each protection on your policy. However, you set the protections themselves in their corresponding operations available in this API.
                properties:
                  applyApiConstraints:
                    description: When enabled, this protection responds to triggers with a specified action.
                    type: boolean
                  applyApplicationLayerControls:
                    description: When enabled, your security policy applies the Web Application Firewall controls to your traffic.
                    type: boolean
                  applyCpcControls:
                    default: false
                    description: When enabled, your security policy applies Client-Side Protection & Compliance controls to your match target.
                    type: boolean
                  applyMalwareControls:
                    description: When enabled, your security policy applies file malware scanning controls to your traffic.
                    type: boolean
                  applyNetworkLayerControls:
                    description: When enabled, your security policy applies the network layer control settings to your traffic.
                    type: boolean
                  applyRateControls:
                    description: When enabled, your security policy applies the rate control settings to your traffic. Rate controls monitor and flag traffic too fast to be from a human.
                    type: boolean
                  applyReputationControls:
                    description: When enabled, your security policy applies the reputation profile settings to your traffic. Reputation profile analyses IP addresses based on their prior interactions with Akamai customers, then alerts on or blocks potentially malicious IP addresses from issuing requests.
                    type: boolean
                  applySlowPostControls:
                    description: When enabled, your security policy applies slow POST controls to your traffic.
                    type: boolean
                type: object
                x-akamai:
                  file-path: schemas/security-policy-protections.yaml
          description: Successfully retrieved the security policy protections.
        '400':
          content:
            application/json:
              example:
                detail: The request could not be understood by the server due to malformed syntax.
                instance: https://problems.luna.akamaiapis.net/appsec/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                status: 400
                title: Bad Request
                type: https://problems.luna.akamaiapis.net/appsec/error-types/BAD-REQUEST
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Invalid](https://techdocs.akamai.com/application-security/reference/400). Client error, such as invalid or malformed input.'
          x-akamai:
            file-path: errors/400-client-read-errors.yaml
        '404':
          content:
            application/problem+json:
              example:
                detail: The requested resource is not found
                instance: https://problems.luna.akamaiapis.net/appsec/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                status: 404
                title: Not Found
                type: https://problems.luna.akamaiapis.net/appsec/error-types/NOT-FOUND
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Not found](https://techdocs.akamai.com/application-security/reference/404). The named security policy doesn''t exist, doesn''t carry application layer controls, or no rule with this ID is available for use in this policy.'
          x-akamai:
            file-path: errors/404-client-read-errors.yaml
        '500':
          content:
            application/problem+json:
              example:
                detail: Internal Server Error
                instance: 12ab3c45-789d-01ef-2gh3-ijk4l56m78no
                status: 500
                title: Internal Server Error
                type: internal_server_error
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Internal server error](https://techdocs.akamai.com/application-security/reference/500). Something went wrong on our side. Try again in a few minutes, and contact support if the error persists.'
          x-akamai:
            file-path: errors/500-server-errors.yaml
      summary: Akamai API Security Get Protections
      tags:
      - Protections
    put:
      description: Update the security policy protections. This applies a set of protections that you can enable individually. _Products:_ All.
      externalDocs:
        description: See documentation for this operation in Akamai's Application Security API
        url: https://techdocs.akamai.com/application-security/reference/put-policy-protections
      operationId: put-policy-protections
      parameters:
      - description: For customers who manage more than one account, this [runs the operation from another account](https://techdocs.akamai.com/developer/docs/manage-many-accounts-with-one-api-client). The Identity and Access Management API provides a [list of available account switch keys](https://techdocs.akamai.com/iam-api/reference/get-client-account-switch-keys).
        example: '{{accountSwitchKey}}'
        in: query
        name: accountSwitchKey
        required: false
        schema:
          example: 1-5C0YLB:1-8BYUX
          type: string
      requestBody:
        content:
          application/json:
            example:
              applyApiConstraints: true
              applyApplicationLayerControls: true
              applyMalwareControls: true
              applyNetworkLayerControls: true
              applyRateControls: true
              applyReputationControls: true
              applySlowPostControls: true
            schema:
              additionalProperties: false
              description: These settings enable or disable each protection on your policy. However, you set the protections themselves in their corresponding operations available in this API.
              properties:
                applyApiConstraints:
                  description: When enabled, this protection responds to triggers with a specified action.
                  example: '{{applyApiConstraints}}'
                  type: boolean
                applyApplicationLayerControls:
                  description: When enabled, your security policy applies the Web Application Firewall controls to your traffic.
                  example: '{{applyApplicationLayerControls}}'
                  type: boolean
                applyCpcControls:
                  default: false
                  description: When enabled, your security policy applies Client-Side Protection & Compliance controls to your match target.
                  example: '{{applyCpcControls}}'
                  type: boolean
                applyMalwareControls:
                  description: When enabled, your security policy applies file malware scanning controls to your traffic.
                  example: '{{applyMalwareControls}}'
                  type: boolean
                applyNetworkLayerControls:
                  description: When enabled, your security policy applies the network layer control settings to your traffic.
                  example: '{{applyNetworkLayerControls}}'
                  type: boolean
                applyRateControls:
                  description: When enabled, your security policy applies the rate control settings to your traffic. Rate controls monitor and flag traffic too fast to be from a human.
                  example: '{{applyRateControls}}'
                  type: boolean
                applyReputationControls:
                  description: When enabled, your security policy applies the reputation profile settings to your traffic. Reputation profile analyses IP addresses based on their prior interactions with Akamai customers, then alerts on or blocks potentially malicious IP addresses from issuing requests.
                  example: '{{applyReputationControls}}'
                  type: boolean
                applySlowPostControls:
                  description: When enabled, your security policy applies slow POST controls to your traffic.
                  example: '{{applySlowPostControls}}'
                  type: boolean
              type: object
              x-akamai:
                file-path: schemas/security-policy-protections.yaml
        required: true
      responses:
        '200':
          content:
            application/json:
              example:
                applyApiConstraints: true
                applyApplicationLayerControls: true
                applyMalwareControls: true
                applyNetworkLayerControls: true
                applyRateControls: true
                applyReputationControls: true
                applySlowPostControls: true
              schema:
                additionalProperties: false
                description: These settings enable or disable each protection on your policy. However, you set the protections themselves in their corresponding operations available in this API.
                properties:
                  applyApiConstraints:
                    description: When enabled, this protection responds to triggers with a specified action.
                    type: boolean
                  applyApplicationLayerControls:
                    description: When enabled, your security policy applies the Web Application Firewall controls to your traffic.
                    type: boolean
                  applyCpcControls:
                    default: false
                    description: When enabled, your security policy applies Client-Side Protection & Compliance controls to your match target.
                    type: boolean
                  applyMalwareControls:
                    description: When enabled, your security policy applies file malware scanning controls to your traffic.
                    type: boolean
                  applyNetworkLayerControls:
                    description: When enabled, your security policy applies the network layer control settings to your traffic.
                    type: boolean
                  applyRateControls:
                    description: When enabled, your security policy applies the rate control settings to your traffic. Rate controls monitor and flag traffic too fast to be from a human.
                    type: boolean
                  applyReputationControls:
                    description: When enabled, your security policy applies the reputation profile settings to your traffic. Reputation profile analyses IP addresses based on their prior interactions with Akamai customers, then alerts on or blocks potentially malicious IP addresses from issuing requests.
                    type: boolean
                  applySlowPostControls:
                    description: When enabled, your security policy applies slow POST controls to your traffic.
                    type: boolean
                type: object
                x-akamai:
                  file-path: schemas/security-policy-protections.yaml
          description: Successfully updated the security policy protections.
        '400':
          content:
            application/json:
              example:
                detail: The request could not be understood by the server due to malformed syntax.
                instance: https://problems.luna.akamaiapis.net/appsec/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                status: 400
                title: Bad Request
                type: https://problems.luna.akamaiapis.net/appsec/error-types/BAD-REQUEST
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Invalid](https://techdocs.akamai.com/application-security/reference/400). Client error, such as invalid or malformed input.'
          x-akamai:
            file-path: errors/400-client-read-errors.yaml
        '403':
          content:
            application/problem+json:
              example:
                detail: You do not have the necessary access to perform this operation or the requested resource cannot be modified
                instance: https://problems.luna.akamaiapis.net/appsec/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                status: 403
                title: Forbidden
                type: https://problems.luna.akamaiapis.net/appsec-resource/error-types/ACCESS-DENIED
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Forbidden](https://techdocs.akamai.com/application-security/reference/403). You don''t have permission to write to this resource.'
          x-akamai:
            file-path: errors/403-client-write-errors.yaml
        '404':
          content:
            application/problem+json:
              example:
                detail: The requested resource is not found
                instance: https://problems.luna.akamaiapis.net/appsec/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                status: 404
                title: Not Found
                type: https://problems.luna.akamaiapis.net/appsec/error-types/NOT-FOUND
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Not found](https://techdocs.akamai.com/application-security/reference/404). The named security policy doesn''t exist, doesn''t carry application layer controls, or no rule with this ID is available for use in this policy.'
          x-akamai:
            file-path: errors/404-client-read-errors.yaml
        '500':
          content:
            application/problem+json:
              example:
                detail: Internal Server Error
                instance: 12ab3c45-789d-01ef-2gh3-ijk4l56m78no
                status: 500
                title: Internal Server Error
                type: internal_server_error
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Internal server error](https://techdocs.akamai.com/application-security/reference/500). Something went wrong on our side. Try again in a few minutes, and contact support if the error persists.'
          x-akamai:
            file-path: errors/500-server-errors.yaml
      summary: Akamai API Security Modify Protections
      tags:
      - Protections
externalDocs:
  description: See documentation for Akamai's Application Security API
  url: https://techdocs.akamai.com/application-security/reference
x-readme:
  samples-languages:
  - curl
  - python
  - node