Akamai API Security Security policy: Conditions and exceptions API

Manage the attack groups and rules that you're currently evaluating for your security policies.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/akamai-api-security-security-policy-conditions-and-exceptions-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

akamai-api-security-security-policy-conditions-and-exceptions-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  description: 'Manage your configurations for Kona Site Defender,

    Web Application Protector, and Client Reputation.

    '
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: 'Akamai: Application Security Activation history Security policy: Conditions and exceptions API'
  version: v1
servers:
- url: https://{hostname}/appsec/v1
tags:
- description: 'Manage the attack groups and rules that you''re currently evaluating

    for your security policies.'
  name: 'Security policy: Conditions and exceptions'
paths:
  /configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/eval-groups/{attackGroupId}/condition-exception:
    parameters:
    - description: A unique identifier for each configuration.
      example: '{{configId}}'
      in: path
      name: configId
      required: true
      schema:
        example: 77653
        format: int64
        type: integer
      x-akamai:
        file-path: parameters/config-id-path.yaml
    - description: A unique identifier for each version of a configuration.
      example: '{{versionNumber}}'
      in: path
      name: versionNumber
      required: true
      schema:
        example: 25
        type: integer
      x-akamai:
        file-path: parameters/version-number-path.yaml
    - description: A unique identifier for a security policy.
      example: '{{policyId}}'
      in: path
      name: policyId
      required: true
      schema:
        example: boBF_19288
        type: string
      x-akamai:
        file-path: parameters/policy-id-path.yaml
    - description: A unique identifier for each attack group.
      example: '{{attackGroupId}}'
      in: path
      name: attackGroupId
      required: true
      schema:
        example: CMD
        type: string
      x-akamai:
        file-path: parameters/attack-group-id-path.yaml
    x-akamai:
      file-path: paths/policy-eval-group-condition-exception.yaml
      path-info: /configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/eval-groups/{attackGroupId}/condition-exception
    get:
      description: List an attack group's exceptions. _Products:_ All.
      externalDocs:
        description: See documentation for this operation in Akamai's Application Security API
        url: https://techdocs.akamai.com/application-security/reference/get-eval-group-condition-exception
      operationId: get-eval-group-condition-exception
      parameters:
      - description: For customers who manage more than one account, this [runs the operation from another account](https://techdocs.akamai.com/developer/docs/manage-many-accounts-with-one-api-client). The Identity and Access Management API provides a [list of available account switch keys](https://techdocs.akamai.com/iam-api/reference/get-client-account-switch-keys).
        example: '{{accountSwitchKey}}'
        in: query
        name: accountSwitchKey
        required: false
        schema:
          example: 1-5C0YLB:1-8BYUX
          type: string
      responses:
        '200':
          content:
            application/json:
              example:
                advancedExceptions:
                  conditionOperator: AND
                  conditions:
                  - filenames:
                    - '*.aspx'
                    - '*.js'
                    positiveMatch: true
                    type: filenameMatch
                  - paths:
                    - /catalog
                    positiveMatch: true
                    type: pathMatch
                  - clientLists:
                    - 88330_TESTIP1
                    positiveMatch: true
                    type: clientListMatch
                    useHeaders: true
                  headerCookieOrParamValues:
                  - valueWildcard: true
                    values:
                    - header1
                    - cookie1
                    - param1
                  specificHeaderCookieOrParamNameValue:
                  - namesValues:
                    - names:
                      - header1
                      values:
                      - value1
                    selector: REQUEST_HEADERS
                    wildcard: true
                  - namesValues:
                    - names:
                      - param-name
                      values:
                      - param-value
                    selector: ARGS
                    wildcard: true
                  - namesValues:
                    - names:
                      - json-param1
                      values:
                      - json-value1
                    selector: JSON_PAIRS
                    wildcard: true
                  - namesValues:
                    - names:
                      - cookie-name
                      values:
                      - cookie1
                    selector: REQUEST_COOKIES
                    wildcard: true
                  specificHeaderCookieParamXmlOrJsonNames:
                  - criteria:
                    - hostnames:
                      - www.host.com
                      paths:
                      - /*
                    selector: REQUEST_HEADERS_NAMES
                    wildcard: true
                  - criteria:
                    - hostnames:
                      - ALL
                      names:
                      - header1
                      paths:
                      - /orders
                    names:
                    - header2
                    selector: REQUEST_HEADERS
                    wildcard: false
                  - criteria:
                    - hostnames:
                      - ALL
                      paths:
                      - /*
                    selector: ARGS_NAMES
                    wildcard: true
                  - names:
                    - param-name
                    selector: ARGS
                    wildcard: true
                  - names:
                    - '*'
                    selector: JSON_NAMES
                    wildcard: true
                  - names:
                    - json1
                    selector: JSON_PAIRS
                    wildcard: true
                  - names:
                    - connect.sid
                    selector: REQUEST_COOKIES_NAMES
                    wildcard: false
                  - names:
                    - cookie1
                    - cookie2
                    selector: REQUEST_COOKIES
                    wildcard: true
                  - selector: REQUEST_BODY
                    wildcard: true
                  - selector: REQBODY_PROCESSOR_ERROR
                    wildcard: true
                  - selector: FILES_NAMES
                    wildcard: true
                  - selector: REQUEST_PROTOCOL
                    wildcard: true
                  - selector: REQUEST_METHOD
                    wildcard: true
                  - selector: REQUEST_URI
                    wildcard: true
                  - selector: QUERY_STRING
                    wildcard: true
                  - selector: REQUEST_FILENAME
                    wildcard: true
                  - selector: REQUEST_PATH_SEGMENT
                    wildcard: true
              schema:
                additionalProperties: false
                description: The GET Response JSON for conditions and exceptions.
                properties:
                  advancedExceptions:
                    additionalProperties: false
                    description: Describes the advanced exception members that allow you to conditionally exclude requests from inspection. This is only available for attack groups and when the advanced exception feature is enabled.
                    properties:
                      conditionOperator:
                        description: Use `OR` to match any condition, or `AND` to match on all conditions.
                        enum:
                        - OR
                        - AND
                        type: string
                      conditions:
                        description: The list of match conditions.
                        items:
                          additionalProperties: false
                          description: Describes what conditions can be set for an action to occur.
                          properties:
                            caseSensitive:
                              description: Whether to consider the case-sensitivity of the provided query parameter `value`. This only applies to the `uriQueryMatch` condition `type`.
                              type: boolean
                            clientLists:
                              description: The clientLists that trigger the condition. This only applies to the `clientListMatch` condition `type`.
                              items:
                                type: string
                              minItems: 0
                              type: array
                            extensions:
                              description: The file extensions that trigger the condition. This only applies to the `extensionMatch` condition `type`.
                              items:
                                type: string
                              type: array
                            filenames:
                              description: The filenames that trigger the condition. This only applies to the `filenameMatch` condition `type`.
                              items:
                                type: string
                              type: array
                            header:
                              description: The HTTP header that triggers the condition. This only applies to the `requestHeaderMatch` condition `type`.
                              type: string
                            hosts:
                              description: The hostnames that trigger the condition. This only applies to the `hostMatch` condition `type`.
                              items:
                                type: string
                              type: array
                            ips:
                              description: The IPs that trigger the condition. This only applies to the `ipMatch` condition `type`.
                              items:
                                type: string
                              type: array
                            methods:
                              description: The HTTP request methods that trigger the condition. The possible values are `GET`, `POST`, `HEAD`, `PUT`, `DELETE`, `OPTIONS`, `TRACE`, `CONNECT` and `PATCH`. This only applies to the `requestMethodMatch` condition `type`.
                              items:
                                enum:
                                - GET
                                - POST
                                - HEAD
                                - PUT
                                - DELETE
                                - OPTIONS
                                - TRACE
                                - CONNECT
                                - PATCH
                                type: string
                              type: array
                            name:
                              description: The query parameter name that triggers the condition. This only applies to the `uriQueryMatch` condition `type`.
                              type: string
                            nameCase:
                              description: Whether to consider the case-sensitivity of the provided query parameter `name`. This only applies to the `uriQueryMatch` condition `type`.
                              type: boolean
                            paths:
                              description: The paths that trigger the condition. This only applies to the  `pathMatch` condition `type`.
                              items:
                                type: string
                              type: array
                            positiveMatch:
                              description: Whether the condition should trigger on a match (`true`) or a lack of match (`false`).
                              type: boolean
                            type:
                              description: The condition type to match on. See [Export condition type values](https://techdocs.akamai.com/application-security/reference/etval).
                              enum:
                              - hostMatch
                              - pathMatch
                              - filenameMatch
                              - extensionMatch
                              - uriQueryMatch
                              - ipMatch
                              - requestMethodMatch
                              - requestHeaderMatch
                              - clientListMatch
                              type: string
                            useHeaders:
                              description: Whether the condition should include `X-Forwarded-For` (XFF) header. This applies to the `ipMatch` and `clientListMatch` condition `type`.
                              type: boolean
                            value:
                              description: The query parameter value if the condition `type` is `uriQueryMatch` and header value if the condition `type` is `requestHeaderMatch`. This only applies when the condition `type` is `uriQueryMatch` or `requestHeaderMatch`.
                              type: string
                            valueCase:
                              description: Whether to consider the case-sensitivity of the provided header `value`. This only applies to the `requestHeaderMatch` condition `type`.
                              type: boolean
                            valueWildcard:
                              description: Whether the provided header `value` is a wildcard. This only applies to the `requestHeaderMatch` condition `type`.
                              type: boolean
                            wildcard:
                              description: Whether the provided query parameter `value` is a wildcard. This only applies to the `uriQueryMatch` condition `type`.
                              type: boolean
                          required:
                          - type
                          - positiveMatch
                          type: object
                          x-akamai:
                            file-path: schemas/condition.yaml
                        type: array
                      headerCookieOrParamValues:
                        description: The list of excepted values in headers, cookies, or query parameters.
                        items:
                          additionalProperties: false
                          properties:
                            criteria:
                              description: A list of criteria to limit the scope of this exception.
                              items:
                                additionalProperties: false
                                description: The hostname and path criteria to limit the scope of exception.
                                properties:
                                  hostnames:
                                    description: The list of excepted hostnames.
                                    items:
                                      type: string
                                    type: array
                                  names:
                                    description: The list of excepted names.
                                    items:
                                      type: string
                                    type: array
                                  paths:
                                    description: The list of excepted paths.
                                    items:
                                      type: string
                                    type: array
                                  values:
                                    description: The list of excepted values.
                                    items:
                                      type: string
                                    type: array
                                required:
                                - paths
                                - names
                                - values
                                type: object
                                x-akamai:
                                  file-path: schemas/criteria.yaml
                              type: array
                            valueWildcard:
                              default: false
                              description: Whether the provided header `name` is a wildcard.
                              type: boolean
                            values:
                              description: The list of request attribute names.
                              items:
                                type: string
                              type: array
                          required:
                          - values
                          type: object
                        type: array
                      specificHeaderCookieOrParamNameValue:
                        description: Contains details about the excepted name-value pairs in a request.
                        items:
                          additionalProperties: false
                          properties:
                            criteria:
                              description: A list of criteria to limit the scope of this exception.
                              items:
                                additionalProperties: false
                                description: The hostname and path criteria to limit the scope of exception.
                                properties:
                                  hostnames:
                                    description: The list of excepted hostnames.
                                    items:
                                      type: string
                                    type: array
                                  names:
                                    description: The list of excepted names.
                                    items:
                                      type: string
                                    type: array
                                  paths:
                                    description: The list of excepted paths.
                                    items:
                                      type: string
                                    type: array
                                  values:
                                    description: The list of excepted values.
                                    items:
                                      type: string
                                    type: array
                                required:
                                - paths
                                - names
                                - values
                                type: object
                                x-akamai:
                                  file-path: schemas/criteria.yaml
                              type: array
                            namesValues:
                              description: A list of name-value pairs to except.
                              items:
                                additionalProperties: false
                                properties:
                                  names:
                                    description: The list of request attribute names.
                                    items:
                                      type: string
                                    type: array
                                  values:
                                    description: The list of request attribute values.
                                    items:
                                      type: string
                                    type: array
                                required:
                                - names
                                type: object
                              type: array
                            selector:
                              description: The request attribute to exclude from inspection. See [Exception selector values](https://techdocs.akamai.com/application-security/reference/exception-selector-values).
                              enum:
                              - REQUEST_COOKIES
                              - JSON_PAIRS
                              - XML_PAIRS
                              - ARGS
                              - REQUEST_HEADERS
                              type: string
                            wildcard:
                              default: false
                              description: Whether the provided header `name` is a wildcard.
                              type: boolean
                          required:
                          - namesValues
                          - selector
                          type: object
                        type: array
                      specificHeaderCookieParamXmlOrJsonNames:
                        description: Describes the advanced exception members that allow you to conditionally exclude requests from inspection. This is only available for attack groups and when the advanced exception feature is enabled.
                        items:
                          additionalProperties: false
                          properties:
                            criteria:
                              description: A list of criteria to limit the scope of this exception.
                              items:
                                additionalProperties: false
                                description: The hostname and path criteria to limit the scope of exception.
                                properties:
                                  hostnames:
                                    description: The list of excepted hostnames.
                                    items:
                                      type: string
                                    type: array
                                  names:
                                    description: The list of excepted names.
                                    items:
                                      type: string
                                    type: array
                                  paths:
                                    description: The list of excepted paths.
                                    items:
                                      type: string
                                    type: array
                                  values:
                                    description: The list of excepted values.
                                    items:
                                      type: string
                                    type: array
                                required:
                                - paths
                                - names
                                - values
                                type: object
                                x-akamai:
                                  file-path: schemas/criteria.yaml
                              type: array
                            names:
                              description: The list of request attribute names.
                              items:
                                type: string
                              type: array
                            selector:
                              description: The request attribute to exclude from inspection. See [Exception selector values](https://techdocs.akamai.com/application-security/reference/exception-selector-values).
                              enum:
                              - ARGS_NAMES
                              - ARGS
                              - REQUEST_HEADERS_NAMES
                              - REQUEST_HEADERS
                              - REQUEST_COOKIES_NAMES
                              - REQUEST_COOKIES
                              - JSON_NAMES
                              - JSON_PAIRS
                              - XML_PAIRS
                              - REQUEST_PROTOCOL
                              - REQUEST_METHOD
                              - REQUEST_URI
                              - QUERY_STRING
                              - REQUEST_FILENAME
                              - REQUEST_PATH_SEGMENT
                              - REQUEST_BODY
                              - REQBODY_PROCESSOR_ERROR
                              - FILES_NAMES
                              type: string
                            wildcard:
                              default: false
                              description: Whether the provided header `name` is a wildcard.
                              type: boolean
                          required:
                          - selector
                          type: object
                        type: array
                    type: object
                    x-akamai:
                      file-path: schemas/advanced-exception.yaml
                  conditions:
                    description: The conditions list for a rule.
                    items:
                      additionalProperties: false
                      description: Describes what conditions can be set for an action to occur.
                      properties:
                        caseSensitive:
                          description: Whether to consider the case-sensitivity of the provided query parameter `value`. This only applies to the `uriQueryMatch` condition `type`.
                          type: boolean
                        clientLists:
                          description: The clientLists that trigger the condition. This only applies to the `clientListMatch` condition `type`.
                          items:
                            type: string
                          minItems: 0
                          type: array
                        extensions:
                          description: The file extensions that trigger the condition. This only applies to the `extensionMatch` condition `type`.
                          items:
                            type: string
                          type: array
                        filenames:
                          description: The filenames that trigger the condition. This only applies to the `filenameMatch` condition `type`.
                          items:
                            type: string
                          type: array
                        header:
                          description: The HTTP header that triggers the condition. This only applies to the `requestHeaderMatch` condition `type`.
                          type: string
                        hosts:
                          description: The hostnames that trigger the condition. This only applies to the `hostMatch` condition `type`.
                          items:
                            type: string
                          type: array
                        ips:
                          description: The IPs that trigger the condition. This only applies to the `ipMatch` condition `type`.
                          items:
                            type: string
                          type: array
                        methods:
                          description: The HTTP request methods that trigger the condition. The possible values are `GET`, `POST`, `HEAD`, `PUT`, `DELETE`, `OPTIONS`, `TRACE`, `CONNECT` and `PATCH`. This only applies to the `requestMethodMatch` condition `type`.
                          items:
                            enum:
                            - GET
                            - POST
                            - HEAD
                            - PUT
                            - DELETE
                            - OPTIONS
                            - TRACE
                            - CONNECT
                            - PATCH
                            type: string
                          type: array
                        name:
                          description: The query parameter name that triggers the condition. This only applies to the `uriQueryMatch` condition `type`.
                          type: string
                        nameCase:
                          description: Whether to consider the case-sensitivity of the provided query parameter `name`. This only applies to the `uriQueryMatch` condition `type`.
                          type: boolean
                        paths:
                          description: The paths that trigger the condition. This only applies to the  `pathMatch` condition `type`.
                          items:
                            type: string
                          type: array
                        positiveMatch:
                          description: Whether the condition should trigger on a match (`true`) or a lack of match (`false`).
                          type: boolean
                        type:
                          description: The condition type to match on. See [Export condition type values](https://techdocs.akamai.com/application-security/reference/etval).
                          enum:
                          - hostMatch
                          - pathMatch
                          - filenameMatch
                          - extensionMatch
                          - uriQueryMatch
                          - ipMatch
                          - requestMethodMatch
                          - requestHeaderMatch
                          - clientListMatch
                          type: string
                        useHeaders:
                          description: Whether the condition should include `X-Forwarded-For` (XFF) header. This applies to the `ipMatch` and `clientListMatch` condition `type`.
                          type: boolean
                        value:
                          description: The query parameter value if the condition `type` is `uriQueryMatch` and header value if the condition `type` is `requestHeaderMatch`. This only applies when the condition `type` is `uriQueryMatch` or `requestHeaderMatch`.
                          type: string
                        valueCase:
                          description: Whether to consider the case-sensitivity of the provided header `value`. This only applies to the `requestHeaderMatch` condition `type`.
                          type: boolean
                        valueWildcard:
                          description: Whether the provided header `value` is a wildcard. This only applies to the `requestHeaderMatch` condition `type`.
                          type: boolean
                        wildcard:
                          description: Whether the provided query parameter `value` is a wildcard. This only applies to the `uriQueryMatch` condition `type`.
                          type: boolean
                      required:
                      - type
                      - positiveMatch
                      type: object
                      x-akamai:
                        file-path: schemas/condition.yaml
                    type: array
                  exception:
                    additionalProperties: false
                    description: Describes the exception members that allow you to conditionally exclude requests from inspection.
                    properties:
                      anyHeaderCookieOrParam:
                        description: The list of request attributes to treat as rule or attack group exceptions. The possible values are `REQUEST_COOKIES`, `JSON_PAIRS` for a JSON parameter, `XML_PAIRS` for an XML parameter, `ARGS` for a request parameter, and `REQUEST_HEADERS` for a request header. Use this option if you can't get an exhaustive list of elements to exclude or the list is too large. You can exclude several attributes.
                        items:
                          enum:
                          - REQUEST_COOKIES
                          - JSON_PAIRS
                          - XML_PAIRS
                          - ARGS
                          - REQUEST_HEADERS
                          type: string
                        type: array
                      headerCookieOrParamValues:
                

# --- truncated at 32 KB (227 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/akamai-api-security/refs/heads/main/openapi/akamai-api-security-security-policy-conditions-and-exceptions-api-openapi.yml