APIs.io Engineering Platform Access Groups API

The Access Groups API from APIs.io Engineering Platform — 2 operation(s) for access groups.

Documentation

Specifications

Other Resources

🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-1ab188a6-cc1f-490d-9413-9c6da20918d0?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-0e94f581-cbc1-48e0-b594-1f6b3d07a328?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-4517d93a-e7f7-4dc2-b572-06762bbe14de?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-88f9ddbb-3115-47dc-b6e5-7fc6f1d2a190?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-3a12caae-4945-4df4-8ab9-bb6219ba7a9f?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-863b18f0-c2f2-4e32-a5fa-0d1e6ccf77a9?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-189876d1-f207-49a2-a4bc-5c67ae78cd19?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-c1e74fd9-3f84-4d95-943d-d645d6cb82f7?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-b002164d-6e8a-4b6d-b409-4929476e7818?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-508660fd-30b8-4c9c-aede-8edbac8a514d?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-da35e0ba-f1a9-42fe-a77a-56ff0a47e341?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-1d4df7d0-9c92-4fa8-946f-2110c2b3b48d?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-2af6f54f-d259-46c0-8f86-78856f5885cd?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-cc203f31-e7f6-42ec-ad34-c5c4cde58904?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-f19285da-48dd-4691-bbdf-f7d6bec157a3?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-aa69cacc-4bbf-4724-a1d4-78cdad57fee8?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-a5858f86-04d3-4e15-ae11-b42c7516688b?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-c2052341-766c-43c7-b1dc-ed4985e4606b?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-aa777c90-8271-4809-8eac-3ec39a9a899c?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-4d5957dc-df05-4216-a5fc-d46b3ba811d8?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-28d97617-fdba-46a5-ac3e-40f3d2e0fa57?action=share&creator=35240
🔗
PostmanCollection
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-7429b451-d812-4abc-b497-b763372cf5c5?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-b0eafdd0-adaa-48a2-a855-6a31beb86d83?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-209f34ef-13c1-400c-bca8-fcddb304aff5?action=share&creator=35240
🔗
PostmanCapability
https://api-evangelist.postman.co/workspace/APIs.io-Engineering-Platform/fe320942-e505-4ee8-8b7c-d72eae00d93f/collection/35240-fb2bbbb8-d4cc-48b1-a660-c8e158bfbbea?action=share&creator=35240

OpenAPI Specification

engineering-platform-access-groups-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  version: "1.0.0"
  x-release: v4
  title: APIs.io Engineering Platform Amazon API Gateway 2014 11 13 Access Groups API
  description: <fullname>Amazon API Gateway</fullname> <p>Amazon API Gateway helps developers deliver robust, secure, and scalable mobile and web application back ends. API Gateway allows developers to securely connect mobile and web applications to APIs that run on AWS Lambda, Amazon EC2, or other publicly addressable web services that are hosted outside of AWS.</p>
  x-logo:
    url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png
    backgroundColor: '#FFFFFF'
  termsOfService: https://aws.amazon.com/service-terms/
  contact:
    name: Mike Ralphson
    email: mike.ralphson@gmail.com
    url: https://github.com/mermade/aws2openapi
    x-twitter: PermittedSoc
  license:
    name: Apache 2.0 License
    url: http://www.apache.org/licenses/
  x-providerName: amazonaws.com
  x-serviceName: apigateway
  x-origin:
  - contentType: application/json
    url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/apigateway-2015-07-09.normal.json
    converter:
      url: https://github.com/mermade/aws2openapi
    x-apisguru-driver: external
  x-apiClientRegistration:
    url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
  x-apisguru-categories:
  - cloud
  x-preferred: true
servers:
- url: http://apigateway.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Amazon API Gateway multi-region endpoint
- url: https://apigateway.{region}.amazonaws.com
  variables:
    region:
      description: The AWS region
      enum:
      - us-east-1
      - us-east-2
      - us-west-1
      - us-west-2
      - us-gov-west-1
      - us-gov-east-1
      - ca-central-1
      - eu-north-1
      - eu-west-1
      - eu-west-2
      - eu-west-3
      - eu-central-1
      - eu-south-1
      - af-south-1
      - ap-northeast-1
      - ap-northeast-2
      - ap-northeast-3
      - ap-southeast-1
      - ap-southeast-2
      - ap-east-1
      - ap-south-1
      - sa-east-1
      - me-south-1
      default: us-east-1
  description: The Amazon API Gateway multi-region endpoint
- url: http://apigateway.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Amazon API Gateway endpoint for China (Beijing) and China (Ningxia)
- url: https://apigateway.{region}.amazonaws.com.cn
  variables:
    region:
      description: The AWS region
      enum:
      - cn-north-1
      - cn-northwest-1
      default: cn-north-1
  description: The Amazon API Gateway endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:
- name: Access Groups
paths:
  /accounts/{account_id}/access/groups:
    get:
      description: Lists all Access groups.
      operationId: access-groups-list-access-groups
      parameters:
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: List Access groups response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_schemas-response_collection'
          description: List Access groups response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform List Access groups
      tags:
      - Access Groups
      x-api-token-group:
      - 'Access: Organizations, Identity Providers, and Groups Write'
      - 'Access: Organizations, Identity Providers, and Groups Read'
    post:
      description: Creates a new Access group.
      operationId: access-groups-create-an-access-group
      parameters:
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      requestBody:
        content:
          application/json:
            schema:
              properties:
                exclude:
                  $ref: '#/components/schemas/access_exclude'
                include:
                  $ref: '#/components/schemas/access_include'
                is_default:
                  $ref: '#/components/schemas/access_is_default'
                name:
                  $ref: '#/components/schemas/access_groups_components-schemas-name'
                require:
                  $ref: '#/components/schemas/access_require'
              required:
              - name
              - include
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Create an Access group response failure
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_groups_components-schemas-single_response'
          description: Create an Access group response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Create an Access group
      tags:
      - Access Groups
      x-api-token-group:
      - 'Access: Organizations, Identity Providers, and Groups Write'
  /accounts/{account_id}/access/groups/{group_id}:
    delete:
      description: Deletes an Access group.
      operationId: access-groups-delete-an-access-group
      parameters:
      - in: path
        name: group_id
        required: true
        schema:
          $ref: '#/components/schemas/access_uuid'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Delete an Access group response failure
        '202':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_id_response'
          description: Delete an Access group response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Delete an Access group
      tags:
      - Access Groups
      x-api-token-group:
      - 'Access: Organizations, Identity Providers, and Groups Write'
    get:
      description: Fetches a single Access group.
      operationId: access-groups-get-an-access-group
      parameters:
      - in: path
        name: group_id
        required: true
        schema:
          $ref: '#/components/schemas/access_uuid'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Get an Access group response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_groups_components-schemas-single_response'
          description: Get an Access group response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Get an Access group
      tags:
      - Access Groups
      x-api-token-group:
      - 'Access: Organizations, Identity Providers, and Groups Write'
      - 'Access: Organizations, Identity Providers, and Groups Read'
    put:
      description: Updates a configured Access group.
      operationId: access-groups-update-an-access-group
      parameters:
      - in: path
        name: group_id
        required: true
        schema:
          $ref: '#/components/schemas/access_uuid'
      - in: path
        name: account_id
        required: true
        schema:
          $ref: '#/components/schemas/access_identifier'
      requestBody:
        content:
          application/json:
            schema:
              properties:
                exclude:
                  $ref: '#/components/schemas/access_exclude'
                include:
                  $ref: '#/components/schemas/access_include'
                is_default:
                  $ref: '#/components/schemas/access_is_default'
                name:
                  $ref: '#/components/schemas/access_groups_components-schemas-name'
                require:
                  $ref: '#/components/schemas/access_require'
              required:
              - name
              - include
        required: true
      responses:
        4XX:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_api-response-common-failure'
          description: Update an Access group response failure
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/access_groups_components-schemas-single_response'
          description: Update an Access group response
      security:
      - api_email: []
        api_key: []
      summary: APIs.io Engineering Platform Update an Access group
      tags:
      - Access Groups
      x-api-token-group:
      - 'Access: Organizations, Identity Providers, and Groups Write'
components:
  schemas:
    access_schemas-response_collection:
      allOf:
      - $ref: '#/components/schemas/access_api-response-collection'
      - properties:
          result:
            items:
              $ref: '#/components/schemas/access_groups'
            type: array
    access_any_valid_service_token_rule:
      description: Matches any valid Access Service Token
      properties:
        any_valid_service_token:
          description: An empty object which matches on all service tokens.
          example: {}
          type: object
      required:
      - any_valid_service_token
      title: Any Valid Service Token
      type: object
    access_exclude:
      description: Rules evaluated with a NOT logical operator. To match a policy, a user cannot meet any of the Exclude rules.
      items:
        $ref: '#/components/schemas/access_rule'
      type: array
    access_service_token_rule:
      description: Matches a specific Access Service Token
      properties:
        service_token:
          properties:
            token_id:
              description: The ID of a Service Token.
              example: aa0a4aab-672b-4bdb-bc33-a59f1130a11f
              type: string
          required:
          - token_id
          type: object
      required:
      - service_token
      title: Service Token
      type: object
    access_api-response-collection:
      allOf:
      - $ref: '#/components/schemas/access_api-response-common'
      - properties:
          result_info:
            $ref: '#/components/schemas/access_result_info'
      type: object
    access_rule:
      oneOf:
      - $ref: '#/components/schemas/access_email_rule'
      - $ref: '#/components/schemas/access_email_list_rule'
      - $ref: '#/components/schemas/access_domain_rule'
      - $ref: '#/components/schemas/access_everyone_rule'
      - $ref: '#/components/schemas/access_ip_rule'
      - $ref: '#/components/schemas/access_ip_list_rule'
      - $ref: '#/components/schemas/access_certificate_rule'
      - $ref: '#/components/schemas/access_access_group_rule'
      - $ref: '#/components/schemas/access_azure_group_rule'
      - $ref: '#/components/schemas/access_github_organization_rule'
      - $ref: '#/components/schemas/access_gsuite_group_rule'
      - $ref: '#/components/schemas/access_okta_group_rule'
      - $ref: '#/components/schemas/access_saml_group_rule'
      - $ref: '#/components/schemas/access_service_token_rule'
      - $ref: '#/components/schemas/access_any_valid_service_token_rule'
      - $ref: '#/components/schemas/access_external_evaluation_rule'
      - $ref: '#/components/schemas/access_country_rule'
      - $ref: '#/components/schemas/access_authentication_method_rule'
      - $ref: '#/components/schemas/access_device_posture_rule'
      type: object
    access_uuid:
      description: UUID
      example: f174e90a-fafe-4643-bbbc-4a0ed4fc8415
      maxLength: 36
      type: string
    access_groups:
      properties:
        created_at:
          $ref: '#/components/schemas/access_timestamp'
        exclude:
          $ref: '#/components/schemas/access_exclude'
        id:
          $ref: '#/components/schemas/access_uuid'
        include:
          $ref: '#/components/schemas/access_include'
        is_default:
          $ref: '#/components/schemas/access_require'
        name:
          $ref: '#/components/schemas/access_groups_components-schemas-name'
        require:
          $ref: '#/components/schemas/access_require'
        updated_at:
          $ref: '#/components/schemas/access_timestamp'
      type: object
    access_github_organization_rule:
      description: 'Matches a Github organization.

        Requires a Github identity provider.'
      properties:
        github-organization:
          properties:
            identity_provider_id:
              description: The ID of your Github identity provider.
              example: ea85612a-29c8-46c2-bacb-669d65136971
              type: string
            name:
              description: The name of the organization.
              example: cloudflare
              type: string
          required:
          - name
          - identity_provider_id
          type: object
      required:
      - github-organization
      title: Github organization
      type: object
    access_authentication_method_rule:
      description: Enforce different MFA options
      properties:
        auth_method:
          properties:
            auth_method:
              description: The type of authentication method https://datatracker.ietf.org/doc/html/rfc8176#section-2.
              example: mfa
              type: string
          required:
          - auth_method
          type: object
      required:
      - auth_method
      title: Authentication method
      type: object
    access_is_default:
      description: Whether this is the default group
      type: boolean
    access_identifier:
      description: Identifier
      example: 023e105f4ecef8ad9ca31a8372d0c353
      maxLength: 32
      type: string
    access_saml_group_rule:
      description: 'Matches a SAML group.

        Requires a SAML identity provider.'
      properties:
        saml:
          properties:
            attribute_name:
              description: The name of the SAML attribute.
              example: group
              type: string
            attribute_value:
              description: The SAML attribute value to look for.
              example: devs@cloudflare.com
              type: string
            identity_provider_id:
              description: The ID of your SAML identity provider.
              example: ea85612a-29c8-46c2-bacb-669d65136971
              type: string
          required:
          - attribute_name
          - attribute_value
          - identity_provider_id
          type: object
      required:
      - saml
      title: SAML group
      type: object
    access_access_group_rule:
      description: Matches an Access group.
      properties:
        group:
          properties:
            id:
              description: The ID of a previously created Access group.
              example: aa0a4aab-672b-4bdb-bc33-a59f1130a11f
              type: string
          required:
          - id
          type: object
      required:
      - group
      title: Access groups
      type: object
    access_country_rule:
      description: Matches a specific country
      properties:
        geo:
          properties:
            country_code:
              description: The country code that should be matched.
              example: US
              type: string
          required:
          - country_code
          type: object
      required:
      - geo
      title: Country
      type: object
    access_api-response-common-failure:
      properties:
        errors:
          allOf:
          - $ref: '#/components/schemas/access_messages'
          example:
          - code: 7003
            message: No route for the URI
          minLength: 1
        messages:
          allOf:
          - $ref: '#/components/schemas/access_messages'
          example: []
        result:
          enum:
          - null
          nullable: true
          type: object
        success:
          description: Whether the API call was successful
          enum:
          - false
          example: false
          type: boolean
      required:
      - success
      - errors
      - messages
      - result
      type: object
    access_result_info:
      properties:
        count:
          description: Total number of results for the requested service
          example: 1
          type: number
        page:
          description: Current page within paginated list of results
          example: 1
          type: number
        per_page:
          description: Number of results per page of results
          example: 20
          type: number
        total_count:
          description: Total results available without any search parameters
          example: 2000
          type: number
      type: object
    access_ip_list_rule:
      description: Matches an IP address from a list.
      properties:
        ip_list:
          properties:
            id:
              description: The ID of a previously created IP list.
              example: aa0a4aab-672b-4bdb-bc33-a59f1130a11f
              type: string
          required:
          - id
          type: object
      required:
      - ip_list
      title: IP list
      type: object
    access_ip_rule:
      description: Matches an IP address block.
      properties:
        ip:
          properties:
            ip:
              description: An IPv4 or IPv6 CIDR block.
              example: 2400:cb00:21:10a::/64
              type: string
          required:
          - ip
          type: object
      required:
      - ip
      title: IP ranges
      type: object
    access_gsuite_group_rule:
      description: 'Matches a group in Google Workspace.

        Requires a Google Workspace identity provider.'
      properties:
        gsuite:
          properties:
            email:
              description: The email of the Google Workspace group.
              example: devs@cloudflare.com
              type: string
            identity_provider_id:
              description: The ID of your Google Workspace identity provider.
              example: ea85612a-29c8-46c2-bacb-669d65136971
              type: string
          required:
          - email
          - identity_provider_id
          type: object
      required:
      - gsuite
      title: Google Workspace group
      type: object
    access_okta_group_rule:
      description: 'Matches an Okta group.

        Requires an Okta identity provider.'
      properties:
        okta:
          properties:
            identity_provider_id:
              description: The ID of your Okta identity provider.
              example: ea85612a-29c8-46c2-bacb-669d65136971
              type: string
            name:
              description: The name of the Okta group.
              example: devs
              type: string
          required:
          - name
          - identity_provider_id
          type: object
      required:
      - okta
      title: Okta group
      type: object
    access_api-response-common:
      properties:
        errors:
          $ref: '#/components/schemas/access_messages'
        messages:
          $ref: '#/components/schemas/access_messages'
        success:
          description: Whether the API call was successful
          enum:
          - true
          example: true
          type: boolean
      required:
      - success
      - errors
      - messages
      type: object
    access_domain_rule:
      description: Match an entire email domain.
      properties:
        email_domain:
          properties:
            domain:
              description: The email domain to match.
              example: example.com
              type: string
          required:
          - domain
          type: object
      required:
      - email_domain
      title: Email domain
      type: object
    access_email_rule:
      description: Matches a specific email.
      properties:
        email:
          properties:
            email:
              description: The email of the user.
              example: test@example.com
              format: email
              type: string
          required:
          - email
          type: object
      required:
      - email
      title: Email
      type: object
    access_external_evaluation_rule:
      description: Create Allow or Block policies which evaluate the user based on custom criteria.
      properties:
        external_evaluation:
          properties:
            evaluate_url:
              description: The API endpoint containing your business logic.
              example: https://eval.example.com
              type: string
            keys_url:
              description: The API endpoint containing the key that Access uses to verify that the response came from your API.
              example: https://eval.example.com/keys
              type: string
          required:
          - evaluate_url
          - keys_url
          type: object
      required:
      - external_evaluation
      title: External Evaluation
      type: object
    access_require:
      description: Rules evaluated with an AND logical operator. To match a policy, a user must meet all of the Require rules.
      items:
        $ref: '#/components/schemas/access_rule'
      type: array
    access_messages:
      example: []
      items:
        properties:
          code:
            minimum: 1000
            type: integer
          message:
            type: string
        required:
        - code
        - message
        type: object
        uniqueItems: true
      type: array
    access_device_posture_rule:
      description: Enforces a device posture rule has run successfully
      properties:
        device_posture:
          properties:
            integration_uid:
              description: The ID of a device posture integration.
              example: aa0a4aab-672b-4bdb-bc33-a59f1130a11f
              type: string
          required:
          - integration_uid
          type: object
      required:
      - device_posture
      title: Device Posture
      type: object
    access_id_response:
      allOf:
      - $ref: '#/components/schemas/access_api-response-single'
      - properties:
          result:
            properties:
              id:
                $ref: '#/components/schemas/access_uuid'
            type: object
    access_groups_components-schemas-name:
      description: The name of the Access group.
      example: Allow devs
      type: string
    access_everyone_rule:
      description: Matches everyone.
      properties:
        everyone:
          description: An empty object which matches on all users.
          example: {}
          type: object
      required:
      - everyone
      title: Everyone
      type: object
    access_timestamp:
      example: '2014-01-01T05:20:00.12345Z'
      format: date-time
      type: string
    access_email_list_rule:
      description: Matches an email address from a list.
      properties:
        email_list:
          properties:
            id:
              description: The ID of a previously created email list.
              example: aa0a4aab-672b-4bdb-bc33-a59f1130a11f
              type: string
          required:
          - id
          type: object
      required:
      - email_list
      title: Email list
      type: object
    access_groups_components-schemas-single_response:
      allOf:
      - $ref: '#/components/schemas/access_api-response-single'
      - properties:
          result:
            $ref: '#/components/schemas/access_groups'
    access_azure_group_rule:
      description: 'Matches an Azure group.

        Requires an Azure identity provider.'
      properties:
        azureAD:
          properties:
            id:
              description: The ID of an Azure group.
              example: aa0a4aab-672b-4bdb-bc33-a59f1130a11f
              type: string
            identity_provider_id:
              description: The ID of your Azure identity provider.
              example: ea85612a-29c8-46c2-bacb-669d65136971
              type: string
          required:
          - id
          - identity_provider_id
          type: object
      required:
      - azureAD
      title: Azure group
      type: object
    access_certificate_rule:
      description: Matches any valid client certificate.
      example:
        certificate: {}
      properties:
        certificate:
          example: {}
          type: object
      required:
      - certificate
      title: Valid certificate
      type: object
    access_api-response-single:
      allOf:
      - $ref: '#/components/schemas/access_api-response-common'
      type: object
    access_include:
      description: Rules evaluated with an OR logical operator. A user needs to meet only one of the Include rules.
      items:
        $ref: '#/components/schemas/access_rule'
      type: array
  securitySchemes:
    hmac:
      type: apiKey
      name: Authorization
      in: header
      description: Amazon Signature authorization v4
      x-amazon-apigateway-authtype: awsSigv4
externalDocs:
  description: Amazon Web Services documentation
  url: https://docs.aws.amazon.com/apigateway/
x-hasEquivalentPaths: true