Akamai API Security Security policy: Evaluation penalty box API

Manage the penalty box settings that you're evaluating for your security policies.

OpenAPI Specification

akamai-api-security-security-policy-evaluation-penalty-box-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  description: 'Manage your configurations for Kona Site Defender,

    Web Application Protector, and Client Reputation.

    '
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: 'Akamai: Application Security Activation history Security policy: Evaluation penalty box API'
  version: v1
servers:
- url: https://{hostname}/appsec/v1
tags:
- description: 'Manage the penalty box settings that you''re evaluating for your

    security policies.'
  name: 'Security policy: Evaluation penalty box'
paths:
  /configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/eval-penalty-box:
    parameters:
    - description: A unique identifier for each configuration.
      example: '{{configId}}'
      in: path
      name: configId
      required: true
      schema:
        example: 77653
        format: int64
        type: integer
      x-akamai:
        file-path: parameters/config-id-path.yaml
    - description: A unique identifier for each version of a configuration.
      example: '{{versionNumber}}'
      in: path
      name: versionNumber
      required: true
      schema:
        example: 25
        type: integer
      x-akamai:
        file-path: parameters/version-number-path.yaml
    - description: A unique identifier for a security policy.
      example: '{{policyId}}'
      in: path
      name: policyId
      required: true
      schema:
        example: boBF_19288
        type: string
      x-akamai:
        file-path: parameters/policy-id-path.yaml
    x-akamai:
      file-path: paths/policy-eval-penalty-box.yaml
      path-info: /configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/eval-penalty-box
    get:
      description: __Beta__ Returns the penalty box settings for a security policy in evaluation mode. When the penalty box is enabled for a policy, clients that trigger a Web Application Firewall deny action are placed in the penalty box. There, the action you select for penalty box (either `alert` or `deny`) continues to apply to any requests from that client for the next 10 minutes. _Products:_ All.
      externalDocs:
        description: See documentation for this operation in Akamai's Application Security API
        url: https://techdocs.akamai.com/application-security/reference/get-eval-policy-penalty-box
      operationId: get-eval-policy-penalty-box
      parameters:
      - description: For customers who manage more than one account, this [runs the operation from another account](https://techdocs.akamai.com/developer/docs/manage-many-accounts-with-one-api-client). The Identity and Access Management API provides a [list of available account switch keys](https://techdocs.akamai.com/iam-api/reference/get-client-account-switch-keys).
        example: '{{accountSwitchKey}}'
        in: query
        name: accountSwitchKey
        required: false
        schema:
          example: 1-5C0YLB:1-8BYUX
          type: string
      responses:
        '200':
          content:
            application/json:
              example:
                action: alert
                penaltyBoxProtection: true
              schema:
                additionalProperties: false
                description: Contains action settings for penalty box protection.
                properties:
                  action:
                    oneOf:
                    - description: 'The action to take when penalty box protection is triggered: `alert` to record the trigger event, `abort` to block the request, or `none` to take no action. Ignored if `penaltyBoxProtection` is set to `false`.'
                      enum:
                      - alert
                      - abort
                      - none
                      title: action
                      type: string
                    - description: 'The custom deny action to take when penalty box protection is triggered: `deny_custom_{custom_deny_id}` to execute a custom deny action. Ignored if `penaltyBoxProtection` is set to `false`.'
                      pattern: deny_custom_{\d+}
                      title: custom action
                      type: string
                  penaltyBoxProtection:
                    description: Specifies whether penalty box protection is enabled for the security policy. When set to `true` the `action` occurs if triggered by a request.
                    type: boolean
                required:
                - penaltyBoxProtection
                - action
                type: object
                x-akamai:
                  file-path: schemas/penalty-box.yaml
          description: Successfully retrieved penalty box protection settings for a security policy in evaluation mode.
        '400':
          content:
            application/json:
              example:
                detail: The request could not be understood by the server due to malformed syntax.
                instance: https://problems.luna.akamaiapis.net/appsec/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                status: 400
                title: Bad Request
                type: https://problems.luna.akamaiapis.net/appsec/error-types/BAD-REQUEST
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Invalid](https://techdocs.akamai.com/application-security/reference/400). Client error, such as invalid or malformed input.'
          x-akamai:
            file-path: errors/400-client-read-errors.yaml
        '404':
          content:
            application/problem+json:
              example:
                detail: The requested resource is not found
                instance: https://problems.luna.akamaiapis.net/appsec/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                status: 404
                title: Not Found
                type: https://problems.luna.akamaiapis.net/appsec/error-types/NOT-FOUND
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Not found](https://techdocs.akamai.com/application-security/reference/404). The named security policy doesn''t exist, doesn''t carry application layer controls, or no rule with this ID is available for use in this policy.'
          x-akamai:
            file-path: errors/404-client-read-errors.yaml
        '500':
          content:
            application/problem+json:
              example:
                detail: Internal Server Error
                instance: 12ab3c45-789d-01ef-2gh3-ijk4l56m78no
                status: 500
                title: Internal Server Error
                type: internal_server_error
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Internal server error](https://techdocs.akamai.com/application-security/reference/500). Something went wrong on our side. Try again in a few minutes, and contact support if the error persists.'
          x-akamai:
            file-path: errors/500-server-errors.yaml
      summary: Akamai API Security Get the Penalty Box for a Policy in Evaluation Mode
      tags:
      - 'Security policy: Evaluation penalty box'
      x-akamai:
        status: BETA
    put:
      description: '__Beta__ Update the penalty box settings for a security policy in evaluation mode. If set to `true`, you can choose to `deny` requests coming from a client in the penalty box, or trigger an `alert` instead. Products: All.'
      externalDocs:
        description: See documentation for this operation in Akamai's Application Security API
        url: https://techdocs.akamai.com/application-security/reference/put-eval-policy-penalty-box
      operationId: put-eval-policy-penalty-box
      parameters:
      - description: For customers who manage more than one account, this [runs the operation from another account](https://techdocs.akamai.com/developer/docs/manage-many-accounts-with-one-api-client). The Identity and Access Management API provides a [list of available account switch keys](https://techdocs.akamai.com/iam-api/reference/get-client-account-switch-keys).
        example: '{{accountSwitchKey}}'
        in: query
        name: accountSwitchKey
        required: false
        schema:
          example: 1-5C0YLB:1-8BYUX
          type: string
      requestBody:
        content:
          application/json:
            example:
              action: alert
              penaltyBoxProtection: true
            schema:
              additionalProperties: false
              description: Contains action settings for penalty box protection.
              properties:
                action:
                  example: '{{action}}'
                  oneOf:
                  - description: 'The action to take when penalty box protection is triggered: `alert` to record the trigger event, `abort` to block the request, or `none` to take no action. Ignored if `penaltyBoxProtection` is set to `false`.'
                    enum:
                    - alert
                    - abort
                    - none
                    title: action
                    type: string
                  - description: 'The custom deny action to take when penalty box protection is triggered: `deny_custom_{custom_deny_id}` to execute a custom deny action. Ignored if `penaltyBoxProtection` is set to `false`.'
                    pattern: deny_custom_{\d+}
                    title: custom action
                    type: string
                penaltyBoxProtection:
                  description: Specifies whether penalty box protection is enabled for the security policy. When set to `true` the `action` occurs if triggered by a request.
                  example: '{{penaltyBoxProtection}}'
                  type: boolean
              required:
              - penaltyBoxProtection
              - action
              type: object
              x-akamai:
                file-path: schemas/penalty-box.yaml
        required: true
      responses:
        '200':
          content:
            application/json:
              example:
                action: alert
                penaltyBoxProtection: true
              schema:
                additionalProperties: false
                description: Contains action settings for penalty box protection.
                properties:
                  action:
                    oneOf:
                    - description: 'The action to take when penalty box protection is triggered: `alert` to record the trigger event, `abort` to block the request, or `none` to take no action. Ignored if `penaltyBoxProtection` is set to `false`.'
                      enum:
                      - alert
                      - abort
                      - none
                      title: action
                      type: string
                    - description: 'The custom deny action to take when penalty box protection is triggered: `deny_custom_{custom_deny_id}` to execute a custom deny action. Ignored if `penaltyBoxProtection` is set to `false`.'
                      pattern: deny_custom_{\d+}
                      title: custom action
                      type: string
                  penaltyBoxProtection:
                    description: Specifies whether penalty box protection is enabled for the security policy. When set to `true` the `action` occurs if triggered by a request.
                    type: boolean
                required:
                - penaltyBoxProtection
                - action
                type: object
                x-akamai:
                  file-path: schemas/penalty-box.yaml
          description: Successfully updated penalty box protection settings for a security policy in evaluation mode.
        '400':
          content:
            application/json:
              example:
                detail: The request could not be understood by the server due to malformed syntax.
                instance: https://problems.luna.akamaiapis.net/appsec/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                status: 400
                title: Bad Request
                type: https://problems.luna.akamaiapis.net/appsec/error-types/BAD-REQUEST
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Invalid](https://techdocs.akamai.com/application-security/reference/400). Client error, such as invalid or malformed input.'
          x-akamai:
            file-path: errors/400-client-read-errors.yaml
        '403':
          content:
            application/problem+json:
              example:
                detail: You do not have the necessary access to perform this operation or the requested resource cannot be modified
                instance: https://problems.luna.akamaiapis.net/appsec/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                status: 403
                title: Forbidden
                type: https://problems.luna.akamaiapis.net/appsec-resource/error-types/ACCESS-DENIED
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Forbidden](https://techdocs.akamai.com/application-security/reference/403). You don''t have permission to write to this resource.'
          x-akamai:
            file-path: errors/403-client-write-errors.yaml
        '404':
          content:
            application/problem+json:
              example:
                detail: The requested resource is not found
                instance: https://problems.luna.akamaiapis.net/appsec/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                status: 404
                title: Not Found
                type: https://problems.luna.akamaiapis.net/appsec/error-types/NOT-FOUND
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Not found](https://techdocs.akamai.com/application-security/reference/404). The named security policy doesn''t exist, doesn''t carry application layer controls, or no rule with this ID is available for use in this policy.'
          x-akamai:
            file-path: errors/404-client-read-errors.yaml
        '500':
          content:
            application/problem+json:
              example:
                detail: Internal Server Error
                instance: 12ab3c45-789d-01ef-2gh3-ijk4l56m78no
                status: 500
                title: Internal Server Error
                type: internal_server_error
              schema:
                additionalProperties: true
                description: Details the errors you can receive.
                properties:
                  detail:
                    description: The detailed error message.
                    type: string
                  fieldErrors:
                    additionalProperties:
                      description: Fields that provide additional details about the problem.
                      type: string
                    description: Pointers to fields for which invalid input was provided, whose values are messages detailing the reason this input was invalid for this field.
                    type: object
                  instance:
                    description: The non-referenceable URI that indicates the error instance.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-instances/d54686b5-21cb-4ab7-a8d6-a92282cf1749
                    type: string
                  status:
                    description: The HTTP status code.
                    example: 404
                    type: integer
                  title:
                    description: The error title.
                    example: Not Found
                    type: string
                  type:
                    description: The URL for the error type.
                    example: https://problems.luna.akamaiapis.net/api-definitions/error-types/NOT-FOUND
                    type: string
                required:
                - title
                - type
                - detail
                - instance
                - status
                type: object
                x-akamai:
                  file-path: schemas/problem-details.yaml
          description: '[Internal server error](https://techdocs.akamai.com/application-security/reference/500). Something went wrong on our side. Try again in a few minutes, and contact support if the error persists.'
          x-akamai:
            file-path: errors/500-server-errors.yaml
      summary: Akamai API Security Modify the Evaluation Penalty Box
      tags:
      - 'Security policy: Evaluation penalty box'
      x-akamai:
        status: BETA
externalDocs:
  description: See documentation for Akamai's Application Security API
  url: https://techdocs.akamai.com/application-security/reference
x-readme:
  samples-languages:
  - curl
  - python
  - node