APIs.io Engineering Platform Access Applications API

The Access Applications API from APIs.io Engineering Platform — 4 operation(s) for access applications.

Documentation

Specifications

Other Resources

🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-1ab188a6-cc1f-490d-9413-9c6da20918d0?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-0e94f581-cbc1-48e0-b594-1f6b3d07a328?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-4517d93a-e7f7-4dc2-b572-06762bbe14de?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-88f9ddbb-3115-47dc-b6e5-7fc6f1d2a190?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-3a12caae-4945-4df4-8ab9-bb6219ba7a9f?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-863b18f0-c2f2-4e32-a5fa-0d1e6ccf77a9?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-189876d1-f207-49a2-a4bc-5c67ae78cd19?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-c1e74fd9-3f84-4d95-943d-d645d6cb82f7?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-b002164d-6e8a-4b6d-b409-4929476e7818?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-508660fd-30b8-4c9c-aede-8edbac8a514d?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-da35e0ba-f1a9-42fe-a77a-56ff0a47e341?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-1d4df7d0-9c92-4fa8-946f-2110c2b3b48d?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-2af6f54f-d259-46c0-8f86-78856f5885cd?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-cc203f31-e7f6-42ec-ad34-c5c4cde58904?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-f19285da-48dd-4691-bbdf-f7d6bec157a3?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-aa69cacc-4bbf-4724-a1d4-78cdad57fee8?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-a5858f86-04d3-4e15-ae11-b42c7516688b?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-c2052341-766c-43c7-b1dc-ed4985e4606b?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-aa777c90-8271-4809-8eac-3ec39a9a899c?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-4d5957dc-df05-4216-a5fc-d46b3ba811d8?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-28d97617-fdba-46a5-ac3e-40f3d2e0fa57?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-7429b451-d812-4abc-b497-b763372cf5c5?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-b0eafdd0-adaa-48a2-a855-6a31beb86d83?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-209f34ef-13c1-400c-bca8-fcddb304aff5?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-fb2bbbb8-d4cc-48b1-a660-c8e158bfbbea?action=share&creator=35240

OpenAPI Specification

engineering-platform-access-applications-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  version: "1.0.0"
  x-release: v4
  title: APIs.io Engineering Platform Amazon API Gateway 2014 11 13 Access Applications API
  description: <fullname>Amazon API Gateway</fullname> <p>Amazon API Gateway helps developers deliver robust, secure, and scalable mobile and web application back ends. API Gateway allows developers to securely connect mobile and web applications to APIs that run on AWS Lambda, Amazon EC2, or other publicly addressable web services that are hosted outside of AWS.</p>
  x-logo:
    url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png
    backgroundColor: '#FFFFFF'
  termsOfService: https://aws.amazon.com/service-terms/
  contact:
    name: Mike Ralphson
    email: mike.ralphson@gmail.com
    url: https://github.com/mermade/aws2openapi
    x-twitter: PermittedSoc
  license:
    name: Apache 2.0 License
    url: http://www.apache.org/licenses/
  x-providerName: amazonaws.com
  x-serviceName: apigateway
  x-origin:
  - contentType: application/json
    url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/apigateway-2015-07-09.normal.json
    converter:
      url: https://github.com/mermade/aws2openapi
    x-apisguru-driver: external
  x-apiClientRegistration:
    url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
  x-apisguru-categories:
  - cloud
  x-preferred: true
servers:
- url: http://apigateway.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Amazon API Gateway multi-region endpoint
- url: https://apigateway.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Amazon API Gateway multi-region endpoint
- url: http://apigateway.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Amazon API Gateway endpoint for China (Beijing) and China (Ningxia)
- url: https://apigateway.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Amazon API Gateway endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:
- name: Access Applications
paths:
  /accounts/{account_id}/access/apps:
    get:
      description: Lists all Access applications in an account.
      operationId: access-applications-list-access-applications
      parameters:
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: List Access applications response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_apps_components-schemas-response_collection'
          description: List Access applications response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform List Access applications
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Revoke'
      - 'Access: Apps and Policies Write'
      - 'Access: Apps and Policies Read'
    post:
      description: Adds a new application to Access.
      operationId: access-applications-add-an-application
      parameters:
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/access_app_request'
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Add an Access application response failure
        '201':
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/access_apps_components-schemas-single_response'
                - properties:
                    result:
                      $ref: '#/components/schemas/access_app_response'
          description: Add an Access application response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Add an Access application
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
  /accounts/{account_id}/access/apps/{app_id}:
    delete:
      description: Deletes an application from Access.
      operationId: access-applications-delete-an-access-application
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Delete an Access application response failure
        '202':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_id_response'
          description: Delete an Access application response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Delete an Access application
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
    get:
      description: Fetches information about an Access application.
      operationId: access-applications-get-an-access-application
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Get an Access application response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_apps_components-schemas-single_response'
          description: Get an Access application response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Get an Access application
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
      - 'Access: Apps and Policies Read'
    put:
      description: Updates an Access application.
      operationId: access-applications-update-an-access-application
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/access_app_request'
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Update an Access application response failure
        '200':
          content:
            application/json:
              schema:
                allOf:
                - $ref: '#/components/schemas/access_apps_components-schemas-single_response'
                - properties:
                    result:
                      $ref: '#/components/schemas/access_app_response'
          description: Update an Access application response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Update an Access application
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
  /accounts/{account_id}/access/apps/{app_id}/revoke_tokens:
    post:
      description: Revokes all tokens issued for an application.
      operationId: access-applications-revoke-service-tokens
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Revoke application tokens response failure
        '202':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_schemas-empty_response'
          description: Revoke application tokens response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Revoke application tokens
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Revoke'
      - 'Access: Apps and Policies Write'
  /accounts/{account_id}/access/apps/{app_id}/user_policy_checks:
    get:
      description: Tests if a specific user has permission to access an application.
      operationId: access-applications-test-access-policies
      parameters:
      - in: path
        name: app_id
        required: true
        schema:
          $ref: '#/components/schemas/access_app_id'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Test Access policies response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_policy_check_response'
          description: Test Access policies response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Test Access policies
      tags:
      - Access Applications
      x-api-token-group:
      - 'Access: Apps and Policies Write'
      - 'Access: Apps and Policies Read'
components:
  schemas:
    access_approval_groups:
      description: Administrators who can approve a temporary authentication request.
      example:
      - approvals_needed: 1
        email_addresses:
        - test1@cloudflare.com
        - test2@cloudflare.com
      - approvals_needed: 3
        email_list_uuid: 597147a1-976b-4ef2-9af0-81d5d007fc34
      items:
        $ref: '#/components/schemas/access_approval_group'
      type: array
    access_schemas-session_duration:
      default: 24h
      description: 'The amount of time that tokens issued for this application will be valid. Must be in the format `300ms` or `2h45m`. Valid time units are: ns, us (or µs), ms, s, m, h.'
      example: 24h
      type: string
    access_service_token_rule:
      description: Matches a specific Access Service Token
      properties:
        service_token:
          properties:
            token_id:
              description: The ID of a Service Token.
              example: aa0a4aab-672b-4bdb-bc33-a59f1130a11f
              type: string
          required:
          - token_id
          type: object
      required:
      - service_token
      title: Service Token
      type: object
    access_api-response-collection:
      allOf:
      - $ref: '#/components/schemas/access_api-response-common'
      - properties:
          result_info:
            $ref: '#/components/schemas/access_result_info'
      type: object
    access_policy_components-schemas-name:
      description: The name of the Access policy.
      example: Allow devs
      type: string
    access_vnc_props:
      allOf:
      - $ref: '#/components/schemas/access_self_hosted_props'
      - properties:
          type:
            description: The application type.
            example: vnc
            type: string
    access_identifier:
      description: Identifier
      example: 023e105f4ecef8ad9ca31a8372d0c353
      maxLength: 32
      type: string
    access_allowed_origins:
      description: Allowed origins.
      example:
      - https://example.com
      items:
        type: string
      type: array
    access_approval_required:
      default: false
      description: Requires the user to request access from an administrator at the start of each session.
      example: true
      type: boolean
    access_allow_all_origins:
      description: Allows all origins.
      type: boolean
    access_schemas-empty_response:
      allOf:
      - properties:
          result:
            nullable: true
            type: object
          success:
            enum:
            - true
            - false
            example: true
            type: boolean
    access_app_launcher_props:
      allOf:
      - $ref: '#/components/schemas/access_feature_app_props'
      - properties:
          domain:
            example: authdomain.cloudflareaccess.com
            readOnly: true
          name:
            default: App Launcher
            example: App Launcher
            readOnly: true
          type:
            description: The application type.
            example: app_launcher
            type: string
    access_app_launcher_visible:
      default: true
      description: Displays the application in the App Launcher.
      example: true
      type: boolean
    access_email_rule:
      description: Matches a specific email.
      properties:
        email:
          properties:
            email:
              description: The email of the user.
              example: test@example.com
              format: email
              type: string
          required:
          - email
          type: object
      required:
      - email
      title: Email
      type: object
    access_external_evaluation_rule:
      description: Create Allow or Block policies which evaluate the user based on custom criteria.
      properties:
        external_evaluation:
          properties:
            evaluate_url:
              description: The API endpoint containing your business logic.
              example: https://eval.example.com
              type: string
            keys_url:
              description: The API endpoint containing the key that Access uses to verify that the response came from your API.
              example: https://eval.example.com/keys
              type: string
          required:
          - evaluate_url
          - keys_url
          type: object
      required:
      - external_evaluation
      title: External Evaluation
      type: object
    access_app_response:
      anyOf:
      - allOf:
        - $ref: '#/components/schemas/access_basic_app_response_props'
        - $ref: '#/components/schemas/access_self_hosted_props'
        - $ref: '#/components/schemas/access_app_resp_embedded_policies'
        title: Self Hosted Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_basic_app_response_props'
        - $ref: '#/components/schemas/access_saas_props'
        - $ref: '#/components/schemas/access_app_resp_embedded_policies'
        title: SaaS Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_basic_app_response_props'
        - $ref: '#/components/schemas/access_ssh_props'
        - $ref: '#/components/schemas/access_app_resp_embedded_policies'
        title: Browser SSH Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_basic_app_response_props'
        - $ref: '#/components/schemas/access_vnc_props'
        - $ref: '#/components/schemas/access_app_resp_embedded_policies'
        title: Browser VNC Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_basic_app_response_props'
        - $ref: '#/components/schemas/access_app_launcher_props'
        - $ref: '#/components/schemas/access_app_resp_embedded_policies'
        title: App Launcher Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_basic_app_response_props'
        - $ref: '#/components/schemas/access_warp_props'
        - $ref: '#/components/schemas/access_app_resp_embedded_policies'
        title: Device Enrollment Permissions Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_basic_app_response_props'
        - $ref: '#/components/schemas/access_biso_props'
        - $ref: '#/components/schemas/access_app_resp_embedded_policies'
        title: Browser Isolation Permissions Application
        type: object
      - allOf:
        - $ref: '#/components/schemas/access_basic_app_response_props'
        - $ref: '#/components/schemas/access_bookmark_props'
        title: Bookmark application
        type: object
    access_footer_links:
      description: The links in the App Launcher footer.
      example:
      - name: Cloudflare's Privacy Policy
        url: https://www.cloudflare.com/privacypolicy/
      items:
        properties:
          name:
            description: The hypertext in the footer link.
            example: Cloudflare's Privacy Policy
            type: string
          url:
            description: the hyperlink in the footer link.
            example: https://www.cloudflare.com/privacypolicy/
            type: string
        required:
        - name
        - url
        type: object
      type: array
    access_landing_page_design:
      description: The design of the App Launcher landing page shown to users when they log in.
      properties:
        button_color:
          $ref: '#/components/schemas/access_button_color'
        button_text_color:
          $ref: '#/components/schemas/access_button_text_color'
        image_url:
          $ref: '#/components/schemas/access_image_url'
        message:
          $ref: '#/components/schemas/access_message'
        title:
          $ref: '#/components/schemas/access_title'
      type: object
    access_scim_config_authentication_http_basic:
      description: Attributes for configuring HTTP Basic authentication scheme for SCIM provisioning to an application.
      properties:
        password:
          description: Password used to authenticate with the remote SCIM service.
          type: string
        scheme:
          description: The authentication scheme to use when making SCIM requests to this application.
          enum:
          - httpbasic
          type: string
        user:
          description: User name used to authenticate with the remote SCIM service.
          type: string
      required:
      - scheme
      - user
      - password
      title: HTTP Basic
      type: object
    access_scim_config_authentication_oauth_bearer_token:
      description: Attributes for configuring OAuth Bearer Token authentication scheme for SCIM provisioning to an application.
      properties:
        scheme:
          description: The authentication scheme to use when making SCIM requests to this application.
          enum:
          - oauthbearertoken
          type: string
        token:
          description: Token used to authenticate with the remote SCIM service.
          type: string
      required:
      - scheme
      - token
      title: OAuth Bearer Token
      type: object
    access_self_hosted_props:
      properties:
        allow_authenticate_via_warp:
          $ref: '#/components/schemas/access_schemas-allow_authenticate_via_warp'
        allowed_idps:
          $ref: '#/components/schemas/access_allowed_idps'
        app_launcher_visible:
          $ref: '#/components/schemas/access_app_launcher_visible'
        auto_redirect_to_identity:
          $ref: '#/components/schemas/access_schemas-auto_redirect_to_identity'
        cors_headers:
          $ref: '#/components/schemas/access_cors_headers'
        custom_deny_message:
          $ref: '#/components/schemas/access_custom_deny_message'
        custom_deny_url:
          $ref: '#/components/schemas/access_custom_deny_url'
        custom_non_identity_deny_url:
          $ref: '#/components/schemas/access_custom_non_identity_deny_url'
        custom_pages:
          $ref: '#/components/schemas/access_schemas-custom_pages'
        domain:
          $ref: '#/components/schemas/access_domain'
        enable_binding_cookie:
          $ref: '#/components/schemas/access_enable_binding_cookie'
        http_only_cookie_attribute:
          $ref: '#/components/schemas/access_http_only_cookie_attribute'
        logo_url:
          $ref: '#/components/schemas/access_logo_url'
        name:
          $ref: '#/components/schemas/access_apps_components-schemas-name'
        options_preflight_bypass:
          $ref: '#/components/schemas/access_options_preflight_bypass'
        path_cookie_attribute:
          $ref: '#/components/schemas/access_path_cookie_attribute'
        same_site_cookie_attribute:
          $ref: '#/components/schemas/access_same_site_cookie_attribute'
        self_hosted_domains:
          $ref: '#/components/schemas/access_self_hosted_domains'
        service_auth_401_redirect:
          $ref: '#/components/schemas/access_service_auth_401_redirect'
        session_duration:
          $ref: '#/components/schemas/access_schemas-session_duration'
        skip_interstitial:
          $ref: '#/components/schemas/access_skip_interstitial'
        tags:
          $ref: '#/components/schemas/access_tags'
        type:
          description: The application type.
          example: self_hosted
          type: string
      required:
      - type
      - domain
      title: Self Hosted Application
      type: object
    access_timestamp:
      example: '2014-01-01T05:20:00.12345Z'
      format: date-time
      type: string
    access_message:
      description: The message shown on the landing page.
      example: Log in below to reach your applications behind Access.
      type: string
    access_cors_headers:
      properties:
        allow_all_headers:
          $ref: '#/components/schemas/access_allow_all_headers'
        allow_all_methods:
          $ref: '#/components/schemas/access_allow_all_methods'
        allow_all_origins:
          $ref: '#/components/schemas/access_allow_all_origins'
        allow_credentials:
          $ref: '#/components/schemas/access_allow_credentials'
        allowed_headers:
          $ref: '#/components/schemas/access_allowed_headers'
        allowed_methods:
          $ref: '#/components/schemas/access_allowed_methods'
        allowed_origins:
          $ref: '#/components/schemas/access_allowed_origins'
        max_age:
          $ref: '#/components/schemas/access_max_age'
      type: object
    access_same_site_cookie_attribute:
      description: Sets the SameSite cookie setting, which provides increased security against CSRF attacks.
      example: strict
      type: string
    access_app_req_embedded_scim_config:
      properties:
        scim_config:
          $ref: '#/components/schemas/access_scim_config'
      type: object
    access_button_color:
      description: The background color of the log in button on the landing page.
      example: '#ff0000'
      type: string
    access_ssh_props:
      allOf:
      - $ref: '#/components/schemas/access_self_hosted_props'
      - properties:
          type:
            description: The application type.
            example: ssh
            type: string
    access_button_text_color:
      description: The color of the text in the log in button on the landing page.
      example: '#ff0000'
      type: string
    access_purpose_justification_prompt:
      description: A custom message that will appear on the purpose justification screen.
      example: Please enter a justification for entering this protected domain.
      type: string
    access_basic_app_response_props:
      properties:
        aud:
          $ref: '#/components/schemas/access_schemas-aud'
        created_at:
          $ref: '#/components/schemas/access_timestamp'
        id:
          $ref: '#/components/schemas/access_uuid'
        scim_config:
          $ref: '#/components/schemas/access_scim_config'
        updated_at:
          $ref: '#/components/schemas/access_timestamp'
      type: object
    access_app_resp_embedded_policies:
      description: The policies that will apply to the application.
      properties:
        policies:
          items:
            $ref: '#/components/schemas/access_app_policy_response'
          type: array
      type: object
    access_include:
      description: Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.
      items:
        $ref: '#/components/schemas/access_rule'
      type: array
    access_app_req_embedded_policies:
      properties:
        policies:
          description: The policies that will apply to the application, in ascending order of precedence. Items can reference existing policies or create new policies exclusive to the application.
          items:
            oneOf:
            - $ref: '#/components/schemas/access_app_policy_link'
            - allOf:
              - description: A policy UID to link to this application.
              - $ref: '#/components/schemas/access_schemas-uuid'
            - allOf:
              - type: object
              - description: An application-scoped policy JSON. If the policy does not yet exist, it will be created.
                properties:
                  id:
                    $ref: '#/components/schemas/access_schemas-uuid'
              - $ref: '#/components/schemas/access_app_policy_request'
          type: array
      type: object
    access_any_valid_service_token_rule:
      description: Matches any valid Access Service Token
      properties:
        any_valid_service_token:
          description: An empty object which matches on all service tokens.
          example: {}
          type: object
      required:
      - any_valid_service_token
      title: Any Valid Service Token
      type: object
    access_rule:
      oneOf:
      - $ref: '#/components/schemas/access_email_rule'
      - $ref: '#/components/schemas/access_email_list_rule'
      - $ref: '#/components/schemas/access_domain_rule'
      - $ref: '#/components/schemas/access_everyone_rule'
      - $ref: '#/components/schemas/access_ip_rule'
      - $ref: '#/components/schemas/access_ip_list_rule'
      - $ref: '#/components/schemas/access_certificate_rule'
      - $ref: '#/components/schemas/access_access_group_rule'
      - $ref: '#/components/schemas/access_azure_group_rule'
      - $ref: '#/components/schemas/access_github_organization_rule'
      - $ref: '#/components/schemas/access_gsuite_group_rule'
      - $ref: '#/components/schemas/access_okta_group_rule'
      - $ref: '#/components/schemas/access_saml_group_rule'
      - $ref: '#/components/schemas/access_service_token_rule'
      - $ref: '#/components/schemas/access_any_valid_service_token_rule'
      - $ref: '#/components/schemas/access_external_evaluation_rule'
      - $ref: '#/components/schemas/access_country_rule'
      - $ref: '#/components/schemas/access_authentication_method_rule'
      - $ref: '#/components/schemas/access_device_posture_rule'
      type: object
    access_github_organization_rule:
      description: 'Matches a Github organization.

        Requires a Github identity provider.'
      properties:
        github-organization:
          properties:
            identity_provider_id:
              description: The ID of your Github identity provider.
              example: ea85612a-29c8-46c2-bacb-669d65136971
              type: string
            name:
              description: The name of the organization.
              example: cloudflare
              type: string
          required:
          - name
          - identity_provider_id
          type: object
      required:
      - github-organization
      title: Github organization
      type: object
    access_app_policy_response:
      allOf:
      - $ref: '#/components/schemas/access_policy_resp'
      properties:
        precedence:
          $ref: '#/components/schemas/access_precedence'
      type: object
    access_custom_non_identity_deny_url:
      description: The custom URL a user is redirected to when they are denied access to the application when failing non-identity rules.
      type: string
    access_custom_deny_message:
      description: The custom error message shown to a user when they are denied access to the application.
      type: string
    access_app_policy_link:
      description: A JSON that links a reusable policy to an application.
      properties:
        id:
          $ref: '#/components/schemas/access_schemas-uuid'
        precedence:
          $ref: '#/components/schemas/access_precedence'
      type: object
    access_api-response-common-failure:
      properties:
        errors:
          allOf:
          - $ref: '#/components/schemas/access_messages'
          example:
          - code: 7003
            message: No route for the URI
          minLength: 1
        messages:
          allOf:
          - $ref: '#/components/schemas/access_messages'
          example: []
        result:
          enum:
          - null
          nullable: true
          type: object
        success:
          description: Whether the API call was successful
          enum:
          - false
          example: false
          type: boolean
      required:
      - success
      - errors
      - messages
      - result
      type: object
    access_ip_list_rule:
      description: Matches an IP address from a list.
      properties:
        ip_list:
          properties:
            id:
              description: The ID of a previously created IP list.
              example: aa0a4aab-672b-4bdb-bc33-a59f1130a11f
              type: string
          required:
          - id
          type: object
      required:
      - ip_list
      title: IP list
      type: object
    access_scim_config_authentication_oauth2:
      description: Attributes for configuring OAuth 2 authentication scheme for SCIM provisioning to an application.
      properties:
        authorization_url:
          description: URL used to generate the auth code used during token generation.
          type: string
        client_id:
          description: Client ID used to authenticate when generating a token for authenticating with the remote SCIM service.
          type: string
        client_secret:
          description: Secret used to authenticate when generating a token for authenticating with the remove SCIM service.
          type: string
        scheme:
          description: The authentication scheme to use when making SCIM requests to this application.
          enum:
          - oauth2


# --- truncated at 32 KB (73 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/apis-io-engineering-platform/refs/heads/main/openapi/engineering-platform-access-applications-api-openapi.yml