WSO2 Throttling Policies API

The Throttling Policies API from WSO2 — 2 operation(s) for throttling policies.

OpenAPI Specification

wso2-throttling-policies-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: WSO2 API Manager - Admin Advanced Policy (Collection) Advanced Policy (Collection) Throttling Policies API
  description: "This document specifies a **RESTful API** for WSO2 **API Manager** - **Admin Portal**.\nPlease see [full OpenAPI Specification](https://raw.githubusercontent.com/wso2/carbon-apimgt/master/components/apimgt/org.wso2.carbon.apimgt.rest.api.admin.v1/src/main/resources/admin-api.yaml) of the API which is written using [OAS 3.0](http://swagger.io/) specification.\n\n# Authentication\nThe Admin REST API is protected using OAuth2 and access control is achieved through scopes. Before you start invoking\nthe the API you need to obtain an access token with the required scopes. This guide will walk you through the steps\nthat you will need to follow to obtain an access token.\nFirst you need to obtain the consumer key/secret key pair by calling the dynamic client registration (DCR) endpoint. You can add your preferred grant types\nin the payload. A sample payload is shown below.\n```\n  {\n  \"callbackUrl\":\"www.example.com\",\n  \"clientName\":\"rest_api_admin\",\n  \"owner\":\"admin\",\n  \"grantType\":\"client_credentials password refresh_token\",\n  \"saasApp\":true\n  }\n```\nCreate a file (payload.json) with the above sample payload, and use the cURL shown bellow to invoke the DCR endpoint. Authorization header of this should contain the\nbase64 encoded admin username and password.\n**Format of the request**\n```\n  curl -X POST -H \"Authorization: Basic Base64(admin_username:admin_password)\" -H \"Content-Type: application/json\"\n  \\ -d @payload.json https://<host>:<servlet_port>/client-registration/v0.17/register\n```\n**Sample request**\n```\n  curl -X POST -H \"Authorization: Basic YWRtaW46YWRtaW4=\" -H \"Content-Type: application/json\"\n  \\ -d @payload.json https://localhost:9443/client-registration/v0.17/register\n```\nFollowing is a sample response after invoking the above curl.\n```\n{\n\"clientId\": \"fOCi4vNJ59PpHucC2CAYfYuADdMa\",\n\"clientName\": \"rest_api_admin\",\n\"callBackURL\": \"www.example.com\",\n\"clientSecret\": \"a4FwHlq0iCIKVs2MPIIDnepZnYMa\",\n\"isSaasApplication\": true,\n\"appOwner\": \"admin\",\n\"jsonString\": \"{\\\"grant_types\\\":\\\"client_credentials password refresh_token\\\",\\\"redirect_uris\\\":\\\"www.example.com\\\",\\\"client_name\\\":\\\"rest_api_admin\\\"}\",\n\"jsonAppAttribute\": \"{}\",\n\"tokenType\": null\n}\n```\nNote that in a distributed deployment or IS as KM separated environment to invoke RESTful APIs (product APIs), users must generate tokens through API-M Control Plane's token endpoint.\nThe tokens generated using third party key managers, are to manage end-user authentication when accessing APIs.\n\nNext you must use the above client id and secret to obtain the access token.\nWe will be using the password grant type for this, you can use any grant type you desire.\nYou also need to add the proper **scope** when getting the access token. All possible scopes for Admin REST API can be viewed in **OAuth2 Security** section\nof this document and scope for each resource is given in **authorizations** section of resource documentation.\nFollowing is the format of the request if you are using the password grant type.\n```\ncurl -k -d \"grant_type=password&username=<admin_username>&password=<admin_passowrd>&scope=<scopes seperated by space>\"\n\\ -H \"Authorization: Basic base64(cliet_id:client_secret)\"\n\\ https://<host>:<server_port>/oauth2/token\n```\n**Sample request**\n```\ncurl https://localhost:9443/oauth2/token -k \\\n-H \"Authorization: Basic Zk9DaTR2Tko1OVBwSHVjQzJDQVlmWXVBRGRNYTphNEZ3SGxxMGlDSUtWczJNUElJRG5lcFpuWU1h\" \\\n-d \"grant_type=password&username=admin&password=admin&scope=apim:admin apim:tier_view\"\n```\nShown below is a sample response to the above request.\n```\n{\n\"access_token\": \"e79bda48-3406-3178-acce-f6e4dbdcbb12\",\n\"refresh_token\": \"a757795d-e69f-38b8-bd85-9aded677a97c\",\n\"scope\": \"apim:admin apim:tier_view\",\n\"token_type\": \"Bearer\",\n\"expires_in\": 3600\n}\n```\nNow you have a valid access token, which you can use to invoke an API.\nNavigate through the API descriptions to find the required API, obtain an access token as described above and invoke the API with the authentication header.\nIf you use a different authentication mechanism, this process may change.\n\n# Try out in Postman\nIf you want to try-out the embedded postman collection with \"Run in Postman\" option, please follow the guidelines listed below.\n* All of the OAuth2 secured endpoints have been configured with an Authorization Bearer header with a parameterized access token. Before invoking any REST API resource make sure you run the `Register DCR Application` and `Generate Access Token` requests to fetch an access token with all required scopes.\n* Make sure you have an API Manager instance up and running.\n* Update the `basepath` parameter to match the hostname and port of the APIM instance.\n\n[![Run in Postman](https://run.pstmn.io/button.svg)](https://app.getpostman.com/run-collection/32294946-71bea2bc-f808-4208-a4f6-861ede6f0434)\n"
  contact:
    name: WSO2
    url: https://wso2.com/api-manager/
    email: architecture@wso2.com
  license:
    name: Apache 2.0
    url: http://www.apache.org/licenses/LICENSE-2.0.html
  version: v4
servers:
- url: https://apis.wso2.com/api/am/admin/v4
tags:
- name: Throttling Policies
paths:
  /throttling-policies/{policyLevel}:
    get:
      tags:
      - Throttling Policies
      summary: Get All Available Throttling Policies
      description: 'This operation can be used to get all available application or subscription level throttling policies

        '
      parameters:
      - $ref: '#/components/parameters/limit'
      - $ref: '#/components/parameters/offset'
      - $ref: '#/components/parameters/policyLevel'
      - $ref: '#/components/parameters/If-None-Match'
      - $ref: '#/components/parameters/requestedTenant'
      responses:
        200:
          description: 'OK.

            List of throttling policies returned.

            '
          headers:
            ETag:
              description: 'Entity Tag of the response resource.

                Used by caches, or in conditional requests.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ThrottlingPolicyList'
        304:
          description: 'Not Modified.

            Empty body because the client has already the latest version of the requested resource.

            '
          content: {}
        406:
          $ref: '#/components/responses/NotAcceptable'
      security:
      - OAuth2Security: []
      x-code-samples:
      - lang: Curl
        source: curl -k "https://localhost:9443/api/am/devportal/v3/throttling-policies/application"
  /throttling-policies/{policyLevel}/{policyId}:
    get:
      tags:
      - Throttling Policies
      summary: 'Get Details of a Throttling Policy

        '
      description: 'This operation can be used to retrieve details of a single throttling policy by specifying the policy level and policy name.


        `X-WSO2-Tenant` header can be used to retrive throttling policy that belongs to a different tenant domain. If not specified super tenant will be used. If Authorization header is present in the request, the user''s tenant associated with the access token will be used.

        '
      parameters:
      - $ref: '#/components/parameters/policyId'
      - $ref: '#/components/parameters/policyLevel'
      - $ref: '#/components/parameters/requestedTenant'
      - $ref: '#/components/parameters/If-None-Match'
      responses:
        200:
          description: 'OK.

            Throttling Policy returned

            '
          headers:
            ETag:
              description: 'Entity Tag of the response resource.

                Used by caches, or in conditional requests.

                '
              schema:
                type: string
            Last-Modified:
              description: 'Date and time the resource has been modifed the last time.

                Used by caches, or in conditional requests.

                '
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ThrottlingPolicy'
        304:
          description: 'Not Modified.

            Empty body because the client has already the latest version of the requested resource.

            '
          content: {}
        404:
          $ref: '#/components/responses/NotFound'
        406:
          $ref: '#/components/responses/NotAcceptable'
      security:
      - OAuth2Security: []
      x-code-samples:
      - lang: Curl
        source: curl -k "https://localhost:9443/api/am/devportal/v3/throttling-policies/application/10PerMin"
components:
  schemas:
    ThrottlingPolicyPermissionInfo:
      title: Throttling Policy Permission info object with throttling policy permission details
      type: object
      properties:
        type:
          type: string
          enum:
          - allow
          - deny
        roles:
          type: array
          description: roles for this permission
          example:
          - manager
          - developer
          items:
            type: string
    ErrorListItem:
      title: Description of individual errors that may have occurred during a request.
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: string
        message:
          type: string
          description: 'Description about individual errors occurred

            '
    ThrottlingPolicy:
      title: Throttling Policy
      required:
      - name
      - requestCount
      - stopOnQuotaReach
      - tierPlan
      - unitTime
      type: object
      properties:
        name:
          type: string
          example: Platinum
        description:
          type: string
          example: Allows 50 request(s) per minute.
        policyLevel:
          type: string
          example: subscription
          enum:
          - application
          - subscription
        attributes:
          type: object
          additionalProperties:
            type: string
          description: 'Custom attributes added to the throttling policy

            '
          example: {}
        requestCount:
          type: integer
          description: 'Maximum number of requests which can be sent within a provided unit time

            '
          format: int64
          example: 50
        dataUnit:
          description: 'Unit of data allowed to be transfered. Allowed values are "KB", "MB" and "GB"

            '
          type: string
          example: KB
        unitTime:
          type: integer
          format: int64
          example: 60000
        timeUnit:
          type: string
          example: min
        rateLimitCount:
          type: integer
          default: 0
          description: Burst control request count
          example: 10
        rateLimitTimeUnit:
          type: string
          description: Burst control time unit
          example: min
        quotaPolicyType:
          type: string
          description: Default quota limit type
          enum:
          - REQUESTCOUNT
          - BANDWIDTHVOLUME
          example: REQUESTCOUNT
        tierPlan:
          type: string
          description: 'This attribute declares whether this tier is available under commercial or free

            '
          example: FREE
          enum:
          - FREE
          - COMMERCIAL
        stopOnQuotaReach:
          type: boolean
          description: 'If this attribute is set to false, you are capabale of sending requests

            even if the request count exceeded within a unit time

            '
          example: true
        monetizationAttributes:
          $ref: '#/components/schemas/MonetizationInfo'
        throttlingPolicyPermissions:
          $ref: '#/components/schemas/ThrottlingPolicyPermissionInfo'
    Pagination:
      title: Pagination
      type: object
      properties:
        offset:
          type: integer
          example: 0
        limit:
          type: integer
          example: 10
        total:
          type: integer
          example: 1
        next:
          type: string
          description: 'Link to the next subset of resources qualified.

            Empty if no more resources are to be returned.

            '
          example: ''
        previous:
          type: string
          description: 'Link to the previous subset of resources qualified.

            Empty if current subset is the first subset returned.

            '
          example: ''
    Error:
      title: Error object returned with 4XX HTTP status
      required:
      - code
      - message
      type: object
      properties:
        code:
          type: integer
          format: int64
        message:
          type: string
          description: Error message.
        description:
          type: string
          description: 'A detail description about the error message.

            '
        moreInfo:
          type: string
          description: 'Preferably an url with more details about the error.

            '
        error:
          type: array
          description: 'If there are more than one error list them out.

            For example, list out validation errors by each field.

            '
          items:
            $ref: '#/components/schemas/ErrorListItem'
    ThrottlingPolicyList:
      title: Throttling Policy List
      type: object
      properties:
        count:
          type: integer
          description: 'Number of Throttling Policies returned.

            '
          example: 1
        list:
          type: array
          items:
            $ref: '#/components/schemas/ThrottlingPolicy'
        pagination:
          $ref: '#/components/schemas/Pagination'
    MonetizationInfo:
      title: Monetization
      type: object
      properties:
        billingType:
          type: string
          example: fixedPrice
          enum:
          - fixedPrice
          - dynamicRate
        billingCycle:
          type: string
          example: month
        fixedPrice:
          type: string
          example: '10'
        pricePerRequest:
          type: string
          example: '1'
        currencyType:
          type: string
          example: USD
  responses:
    NotAcceptable:
      description: Not Acceptable. The requested media type is not supported.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 406
            message: Not Acceptable
            description: The requested media type is not supported
            moreInfo: ''
            error: []
    NotFound:
      description: Not Found. The specified resource does not exist.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            code: 404
            message: Not Found
            description: The specified resource does not exist
            moreInfo: ''
            error: []
  parameters:
    offset:
      name: offset
      in: query
      description: 'Starting point within the complete list of items qualified.

        '
      schema:
        type: integer
        default: 0
    policyLevel:
      name: policyLevel
      in: path
      description: 'List Application or Subscription type thro.

        '
      required: true
      schema:
        type: string
        enum:
        - application
        - subscription
    If-None-Match:
      name: If-None-Match
      in: header
      description: 'Validator for conditional requests; based on the ETag of the formerly retrieved

        variant of the resourec.

        '
      schema:
        type: string
    policyId:
      name: policyId
      in: path
      description: 'The name of the policy

        '
      required: true
      schema:
        type: string
    limit:
      name: limit
      in: query
      description: 'Maximum size of resource array to return.

        '
      schema:
        type: integer
        default: 25
    requestedTenant:
      name: X-WSO2-Tenant
      in: header
      description: "For cross-tenant invocations, this is used to specify the tenant domain, where the resource need to be\n  retrieved from.\n"
      schema:
        type: string
  securitySchemes:
    OAuth2Security:
      type: oauth2
      flows:
        password:
          tokenUrl: https://localhost:9443/oauth2/token
          scopes:
            openid: Authorize access to user details
            apim:policies_import_export: Export and import policies related operations
            apim:admin: Manage all admin operations
            apim:tier_view: View throttling policies
            apim:tier_manage: Update and delete throttling policies
            apim:admin_tier_view: View throttling policies
            apim:admin_tier_manage: Update and delete throttling policies
            apim:bl_view: View deny policies
            apim:bl_manage: Update and delete deny policies
            apim:mediation_policy_view: View mediation policies
            apim:mediation_policy_create: Create and update mediation policies
            apim:app_owner_change: Retrieve and manage applications
            apim:app_settings_change: Change Application Settings
            apim:app_import_export: Import and export applications related operations
            apim:api_import_export: Import and export APIs related operations
            apim:api_product_import_export: Import and export API Products related operations
            apim:environment_manage: Manage gateway environments
            apim:environment_read: Retrieve gateway environments
            apim:monetization_usage_publish: Retrieve and publish Monetization related usage records
            apim:api_workflow_approve: Manage workflows
            apim:bot_data: Retrieve bot detection data
            apim:tenantInfo: Retrieve tenant related information
            apim:tenant_theme_manage: Manage tenant themes
            apim:admin_operations: Manage API categories and Key Managers related operations
            apim:api_category: Manage API categories
            apim:admin_settings: Retrieve admin settings
            apim:admin_alert_manage: Manage admin alerts
            apim:api_workflow_view: Retrive workflow requests
            apim:scope_manage: Manage system scopes
            apim:role_manage: Manage system roles
            apim:admin_application_view: View Applications
            apim:keymanagers_manage: Manage Key Managers
            apim:api_provider_change: Retrieve and manage applications
            apim:llm_provider_manage: Manage LLM Providers
            apim:gov_policy_read: Retrieve governance policies
            apim:gov_policy_manage: Manage governance policies
            apim:gov_result_read: Retrieve governance results
            apim:gov_rule_read: Retrieve governance rules
            apim:gov_rule_manage: Manage governance rules
            apim:organization_manage: Manage Organizations
            apim:organization_read: Read Organizations