Akamai API Security Security policy: Conditions and exceptions API
Manage the attack groups and rules that you're currently evaluating for your security policies.
Manage the attack groups and rules that you're currently evaluating for your security policies.
openapi: 3.0.0
info:
description: 'Manage your configurations for Kona Site Defender,
Web Application Protector, and Client Reputation.
'
license:
name: Apache 2.0
url: https://www.apache.org/licenses/LICENSE-2.0.html
title: 'Akamai: Application Security Activation history Security policy: Conditions and exceptions API'
version: v1
servers:
- url: https://{hostname}/appsec/v1
tags:
- description: 'Manage the attack groups and rules that you''re currently evaluating
for your security policies.'
name: 'Security policy: Conditions and exceptions'
paths:
/configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/eval-groups/{attackGroupId}/condition-exception:
parameters:
- description: A unique identifier for each configuration.
example: '{{configId}}'
in: path
name: configId
required: true
schema:
example: 77653
format: int64
type: integer
x-akamai:
file-path: parameters/config-id-path.yaml
- description: A unique identifier for each version of a configuration.
example: '{{versionNumber}}'
in: path
name: versionNumber
required: true
schema:
example: 25
type: integer
x-akamai:
file-path: parameters/version-number-path.yaml
- description: A unique identifier for a security policy.
example: '{{policyId}}'
in: path
name: policyId
required: true
schema:
example: boBF_19288
type: string
x-akamai:
file-path: parameters/policy-id-path.yaml
- description: A unique identifier for each attack group.
example: '{{attackGroupId}}'
in: path
name: attackGroupId
required: true
schema:
example: CMD
type: string
x-akamai:
file-path: parameters/attack-group-id-path.yaml
x-akamai:
file-path: paths/policy-eval-group-condition-exception.yaml
path-info: /configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/eval-groups/{attackGroupId}/condition-exception
get:
description: List an attack group's exceptions. _Products:_ All.
externalDocs:
description: See documentation for this operation in Akamai's Application Security API
url: https://techdocs.akamai.com/application-security/reference/get-eval-group-condition-exception
operationId: get-eval-group-condition-exception
parameters:
- description: For customers who manage more than one account, this [runs the operation from another account](https://techdocs.akamai.com/developer/docs/manage-many-accounts-with-one-api-client). The Identity and Access Management API provides a [list of available account switch keys](https://techdocs.akamai.com/iam-api/reference/get-client-account-switch-keys).
example: '{{accountSwitchKey}}'
in: query
name: accountSwitchKey
required: false
schema:
example: 1-5C0YLB:1-8BYUX
type: string
responses:
'200':
content:
application/json:
example:
advancedExceptions:
conditionOperator: AND
conditions:
- filenames:
- '*.aspx'
- '*.js'
positiveMatch: true
type: filenameMatch
- paths:
- /catalog
positiveMatch: true
type: pathMatch
- clientLists:
- 88330_TESTIP1
positiveMatch: true
type: clientListMatch
useHeaders: true
headerCookieOrParamValues:
- valueWildcard: true
values:
- header1
- cookie1
- param1
specificHeaderCookieOrParamNameValue:
- namesValues:
- names:
- header1
values:
- value1
selector: REQUEST_HEADERS
wildcard: true
- namesValues:
- names:
- param-name
values:
- param-value
selector: ARGS
wildcard: true
- namesValues:
- names:
- json-param1
values:
- json-value1
selector: JSON_PAIRS
wildcard: true
- namesValues:
- names:
- cookie-name
values:
- cookie1
selector: REQUEST_COOKIES
wildcard: true
specificHeaderCookieParamXmlOrJsonNames:
- criteria:
- hostnames:
- www.host.com
paths:
- /*
selector: REQUEST_HEADERS_NAMES
wildcard: true
- criteria:
- hostnames:
- ALL
names:
- header1
paths:
- /orders
names:
- header2
selector: REQUEST_HEADERS
wildcard: false
- criteria:
- hostnames:
- ALL
paths:
- /*
selector: ARGS_NAMES
wildcard: true
- names:
- param-name
selector: ARGS
wildcard: true
- names:
- '*'
selector: JSON_NAMES
wildcard: true
- names:
- json1
selector: JSON_PAIRS
wildcard: true
- names:
- connect.sid
selector: REQUEST_COOKIES_NAMES
wildcard: false
- names:
- cookie1
- cookie2
selector: REQUEST_COOKIES
wildcard: true
- selector: REQUEST_BODY
wildcard: true
- selector: REQBODY_PROCESSOR_ERROR
wildcard: true
- selector: FILES_NAMES
wildcard: true
- selector: REQUEST_PROTOCOL
wildcard: true
- selector: REQUEST_METHOD
wildcard: true
- selector: REQUEST_URI
wildcard: true
- selector: QUERY_STRING
wildcard: true
- selector: REQUEST_FILENAME
wildcard: true
- selector: REQUEST_PATH_SEGMENT
wildcard: true
schema:
additionalProperties: false
description: The GET Response JSON for conditions and exceptions.
properties:
advancedExceptions:
additionalProperties: false
description: Describes the advanced exception members that allow you to conditionally exclude requests from inspection. This is only available for attack groups and when the advanced exception feature is enabled.
properties:
conditionOperator:
description: Use `OR` to match any condition, or `AND` to match on all conditions.
enum:
- OR
- AND
type: string
conditions:
description: The list of match conditions.
items:
additionalProperties: false
description: Describes what conditions can be set for an action to occur.
properties:
caseSensitive:
description: Whether to consider the case-sensitivity of the provided query parameter `value`. This only applies to the `uriQueryMatch` condition `type`.
type: boolean
clientLists:
description: The clientLists that trigger the condition. This only applies to the `clientListMatch` condition `type`.
items:
type: string
minItems: 0
type: array
extensions:
description: The file extensions that trigger the condition. This only applies to the `extensionMatch` condition `type`.
items:
type: string
type: array
filenames:
description: The filenames that trigger the condition. This only applies to the `filenameMatch` condition `type`.
items:
type: string
type: array
header:
description: The HTTP header that triggers the condition. This only applies to the `requestHeaderMatch` condition `type`.
type: string
hosts:
description: The hostnames that trigger the condition. This only applies to the `hostMatch` condition `type`.
items:
type: string
type: array
ips:
description: The IPs that trigger the condition. This only applies to the `ipMatch` condition `type`.
items:
type: string
type: array
methods:
description: The HTTP request methods that trigger the condition. The possible values are `GET`, `POST`, `HEAD`, `PUT`, `DELETE`, `OPTIONS`, `TRACE`, `CONNECT` and `PATCH`. This only applies to the `requestMethodMatch` condition `type`.
items:
enum:
- GET
- POST
- HEAD
- PUT
- DELETE
- OPTIONS
- TRACE
- CONNECT
- PATCH
type: string
type: array
name:
description: The query parameter name that triggers the condition. This only applies to the `uriQueryMatch` condition `type`.
type: string
nameCase:
description: Whether to consider the case-sensitivity of the provided query parameter `name`. This only applies to the `uriQueryMatch` condition `type`.
type: boolean
paths:
description: The paths that trigger the condition. This only applies to the `pathMatch` condition `type`.
items:
type: string
type: array
positiveMatch:
description: Whether the condition should trigger on a match (`true`) or a lack of match (`false`).
type: boolean
type:
description: The condition type to match on. See [Export condition type values](https://techdocs.akamai.com/application-security/reference/etval).
enum:
- hostMatch
- pathMatch
- filenameMatch
- extensionMatch
- uriQueryMatch
- ipMatch
- requestMethodMatch
- requestHeaderMatch
- clientListMatch
type: string
useHeaders:
description: Whether the condition should include `X-Forwarded-For` (XFF) header. This applies to the `ipMatch` and `clientListMatch` condition `type`.
type: boolean
value:
description: The query parameter value if the condition `type` is `uriQueryMatch` and header value if the condition `type` is `requestHeaderMatch`. This only applies when the condition `type` is `uriQueryMatch` or `requestHeaderMatch`.
type: string
valueCase:
description: Whether to consider the case-sensitivity of the provided header `value`. This only applies to the `requestHeaderMatch` condition `type`.
type: boolean
valueWildcard:
description: Whether the provided header `value` is a wildcard. This only applies to the `requestHeaderMatch` condition `type`.
type: boolean
wildcard:
description: Whether the provided query parameter `value` is a wildcard. This only applies to the `uriQueryMatch` condition `type`.
type: boolean
required:
- type
- positiveMatch
type: object
x-akamai:
file-path: schemas/condition.yaml
type: array
headerCookieOrParamValues:
description: The list of excepted values in headers, cookies, or query parameters.
items:
additionalProperties: false
properties:
criteria:
description: A list of criteria to limit the scope of this exception.
items:
additionalProperties: false
description: The hostname and path criteria to limit the scope of exception.
properties:
hostnames:
description: The list of excepted hostnames.
items:
type: string
type: array
names:
description: The list of excepted names.
items:
type: string
type: array
paths:
description: The list of excepted paths.
items:
type: string
type: array
values:
description: The list of excepted values.
items:
type: string
type: array
required:
- paths
- names
- values
type: object
x-akamai:
file-path: schemas/criteria.yaml
type: array
valueWildcard:
default: false
description: Whether the provided header `name` is a wildcard.
type: boolean
values:
description: The list of request attribute names.
items:
type: string
type: array
required:
- values
type: object
type: array
specificHeaderCookieOrParamNameValue:
description: Contains details about the excepted name-value pairs in a request.
items:
additionalProperties: false
properties:
criteria:
description: A list of criteria to limit the scope of this exception.
items:
additionalProperties: false
description: The hostname and path criteria to limit the scope of exception.
properties:
hostnames:
description: The list of excepted hostnames.
items:
type: string
type: array
names:
description: The list of excepted names.
items:
type: string
type: array
paths:
description: The list of excepted paths.
items:
type: string
type: array
values:
description: The list of excepted values.
items:
type: string
type: array
required:
- paths
- names
- values
type: object
x-akamai:
file-path: schemas/criteria.yaml
type: array
namesValues:
description: A list of name-value pairs to except.
items:
additionalProperties: false
properties:
names:
description: The list of request attribute names.
items:
type: string
type: array
values:
description: The list of request attribute values.
items:
type: string
type: array
required:
- names
type: object
type: array
selector:
description: The request attribute to exclude from inspection. See [Exception selector values](https://techdocs.akamai.com/application-security/reference/exception-selector-values).
enum:
- REQUEST_COOKIES
- JSON_PAIRS
- XML_PAIRS
- ARGS
- REQUEST_HEADERS
type: string
wildcard:
default: false
description: Whether the provided header `name` is a wildcard.
type: boolean
required:
- namesValues
- selector
type: object
type: array
specificHeaderCookieParamXmlOrJsonNames:
description: Describes the advanced exception members that allow you to conditionally exclude requests from inspection. This is only available for attack groups and when the advanced exception feature is enabled.
items:
additionalProperties: false
properties:
criteria:
description: A list of criteria to limit the scope of this exception.
items:
additionalProperties: false
description: The hostname and path criteria to limit the scope of exception.
properties:
hostnames:
description: The list of excepted hostnames.
items:
type: string
type: array
names:
description: The list of excepted names.
items:
type: string
type: array
paths:
description: The list of excepted paths.
items:
type: string
type: array
values:
description: The list of excepted values.
items:
type: string
type: array
required:
- paths
- names
- values
type: object
x-akamai:
file-path: schemas/criteria.yaml
type: array
names:
description: The list of request attribute names.
items:
type: string
type: array
selector:
description: The request attribute to exclude from inspection. See [Exception selector values](https://techdocs.akamai.com/application-security/reference/exception-selector-values).
enum:
- ARGS_NAMES
- ARGS
- REQUEST_HEADERS_NAMES
- REQUEST_HEADERS
- REQUEST_COOKIES_NAMES
- REQUEST_COOKIES
- JSON_NAMES
- JSON_PAIRS
- XML_PAIRS
- REQUEST_PROTOCOL
- REQUEST_METHOD
- REQUEST_URI
- QUERY_STRING
- REQUEST_FILENAME
- REQUEST_PATH_SEGMENT
- REQUEST_BODY
- REQBODY_PROCESSOR_ERROR
- FILES_NAMES
type: string
wildcard:
default: false
description: Whether the provided header `name` is a wildcard.
type: boolean
required:
- selector
type: object
type: array
type: object
x-akamai:
file-path: schemas/advanced-exception.yaml
conditions:
description: The conditions list for a rule.
items:
additionalProperties: false
description: Describes what conditions can be set for an action to occur.
properties:
caseSensitive:
description: Whether to consider the case-sensitivity of the provided query parameter `value`. This only applies to the `uriQueryMatch` condition `type`.
type: boolean
clientLists:
description: The clientLists that trigger the condition. This only applies to the `clientListMatch` condition `type`.
items:
type: string
minItems: 0
type: array
extensions:
description: The file extensions that trigger the condition. This only applies to the `extensionMatch` condition `type`.
items:
type: string
type: array
filenames:
description: The filenames that trigger the condition. This only applies to the `filenameMatch` condition `type`.
items:
type: string
type: array
header:
description: The HTTP header that triggers the condition. This only applies to the `requestHeaderMatch` condition `type`.
type: string
hosts:
description: The hostnames that trigger the condition. This only applies to the `hostMatch` condition `type`.
items:
type: string
type: array
ips:
description: The IPs that trigger the condition. This only applies to the `ipMatch` condition `type`.
items:
type: string
type: array
methods:
description: The HTTP request methods that trigger the condition. The possible values are `GET`, `POST`, `HEAD`, `PUT`, `DELETE`, `OPTIONS`, `TRACE`, `CONNECT` and `PATCH`. This only applies to the `requestMethodMatch` condition `type`.
items:
enum:
- GET
- POST
- HEAD
- PUT
- DELETE
- OPTIONS
- TRACE
- CONNECT
- PATCH
type: string
type: array
name:
description: The query parameter name that triggers the condition. This only applies to the `uriQueryMatch` condition `type`.
type: string
nameCase:
description: Whether to consider the case-sensitivity of the provided query parameter `name`. This only applies to the `uriQueryMatch` condition `type`.
type: boolean
paths:
description: The paths that trigger the condition. This only applies to the `pathMatch` condition `type`.
items:
type: string
type: array
positiveMatch:
description: Whether the condition should trigger on a match (`true`) or a lack of match (`false`).
type: boolean
type:
description: The condition type to match on. See [Export condition type values](https://techdocs.akamai.com/application-security/reference/etval).
enum:
- hostMatch
- pathMatch
- filenameMatch
- extensionMatch
- uriQueryMatch
- ipMatch
- requestMethodMatch
- requestHeaderMatch
- clientListMatch
type: string
useHeaders:
description: Whether the condition should include `X-Forwarded-For` (XFF) header. This applies to the `ipMatch` and `clientListMatch` condition `type`.
type: boolean
value:
description: The query parameter value if the condition `type` is `uriQueryMatch` and header value if the condition `type` is `requestHeaderMatch`. This only applies when the condition `type` is `uriQueryMatch` or `requestHeaderMatch`.
type: string
valueCase:
description: Whether to consider the case-sensitivity of the provided header `value`. This only applies to the `requestHeaderMatch` condition `type`.
type: boolean
valueWildcard:
description: Whether the provided header `value` is a wildcard. This only applies to the `requestHeaderMatch` condition `type`.
type: boolean
wildcard:
description: Whether the provided query parameter `value` is a wildcard. This only applies to the `uriQueryMatch` condition `type`.
type: boolean
required:
- type
- positiveMatch
type: object
x-akamai:
file-path: schemas/condition.yaml
type: array
exception:
additionalProperties: false
description: Describes the exception members that allow you to conditionally exclude requests from inspection.
properties:
anyHeaderCookieOrParam:
description: The list of request attributes to treat as rule or attack group exceptions. The possible values are `REQUEST_COOKIES`, `JSON_PAIRS` for a JSON parameter, `XML_PAIRS` for an XML parameter, `ARGS` for a request parameter, and `REQUEST_HEADERS` for a request header. Use this option if you can't get an exhaustive list of elements to exclude or the list is too large. You can exclude several attributes.
items:
enum:
- REQUEST_COOKIES
- JSON_PAIRS
- XML_PAIRS
- ARGS
- REQUEST_HEADERS
type: string
type: array
headerCookieOrParamValues:
# --- truncated at 32 KB (227 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/akamai-api-security/refs/heads/main/openapi/akamai-api-security-security-policy-conditions-and-exceptions-api-openapi.yml