Skip to main content

Slate security

Generated from apiome-rest/openapi.yaml (API version 1.204.1) — do not edit by hand. How to authenticate is on the REST API reference.

Tag: slate-security · 19 operations

GET /v1/slate/environments/{environment_id}/security​

Get Security Policy

Return a lane's security policy, its rules and carve-outs, and what it actually enforces.

Operation id: get_security_policy_v1_slate_environments__environment_id__security_get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get security policy.application/json SecurityPolicyResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/security/approvals​

Record Security Approval

Record the approving half of dual control.

The approver is always the authenticated caller — there is no field by which one person can record somebody else's approval, which is the only version of two-person review that means anything. Approving one's own change is refused here as approval-self and again by V188's CHECK (approver_actor_key <> author_actor_key).

Operation id: record_security_approval_v1_slate_environments__environment_id__security_approvals_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for record security approval.

Responses

StatusDescriptionBody
201Successful response for record security approval.application/json SlateSecurityApprovalBody
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/environments/{environment_id}/security/audit​

Get Security Audit

Return a lane's append-only security audit trail, most recent first.

Operation id: get_security_audit_v1_slate_environments__environment_id__security_audit_get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
limitqueryintegernoMaximum number of rows to return.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get security audit.application/json SlateSecurityAuditResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/environments/{environment_id}/security/audit/export​

Export Security Audit

Export a lane's security audit trail as CSV.

Modelled on access_routes.py's exporter, and fixing the two defects that precedent carries.

CSV injection is neutralized. A cell whose first character is =, +, -, @, a tab or a carriage return is prefixed with an apostrophe. An actor display name and a refusal detail are attacker-influenced text, and the existing exporter writes them raw, so opening the evidence in a spreadsheet is a code-execution path.

Nothing is silently truncated. The existing exporter caps at 1000 rows with no signal, which in compliance evidence is a correctness bug rather than a performance choice: an auditor reading a truncated ledger concludes the missing entries never happened. This one reads one row past the cap, and when there are more it emits a final row saying so in words.

Reading the evidence is itself audit-worthy — who exported the record of who disabled the WAF is part of that record — so an export audit row is written before the download begins.

Operation id: export_security_audit_v1_slate_environments__environment_id__security_audit_export_get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
limitqueryintegernoMaximum number of rows to return.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for export security audit.application/json any
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/environments/{environment_id}/security/events​

Get Security Events

Return a lane's security events, most recent first.

The filter names are the designer's dimension ids unchanged, so filtering on screen and filtering in a query cannot mean different things.

Operation id: get_security_events_v1_slate_environments__environment_id__security_events_get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
limitqueryintegernoMaximum number of rows to return.
ruleRefquerystring or nullnoQuery parameter: rule ref.
actionquerystring or nullnoQuery parameter: action.
routequerystring or nullnoQuery parameter: route.
releaseIdquerystring or nullnoQuery parameter: release id.
regionquerystring or nullnoQuery parameter: region.
sourcequerystring or nullnoSource material descriptor (file, URL, paste, or discovery).
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get security events.application/json SecurityEventsResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/environments/{environment_id}/security/events/{event_id}​

Get Security Event

Return one security event with its redacted evidence.

Operation id: get_security_event_v1_slate_environments__environment_id__security_events__event_id__get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
event_idpathstringyesPath parameter identifying the event id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get security event.application/json SecurityEventBody
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/security/exceptions​

Create Security Exception

Open a scoped, expiring carve-out.

An exception is a hole. §29.4 wants them possible; keeping them scoped and bounded is what stops them becoming the policy, so an unbounded or over-long carve-out is refused with no acknowledgement path.

Operation id: create_security_exception_v1_slate_environments__environment_id__security_exceptions_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for create security exception.

Responses

StatusDescriptionBody
201Successful response for create security exception.application/json ExceptionResponse
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/slate/environments/{environment_id}/security/exceptions/{exception_id}​

Remove Security Exception

Close a carve-out early.

Operation id: remove_security_exception_v1_slate_environments__environment_id__security_exceptions__exception_id__delete

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
exception_idpathstringyesPath parameter identifying the exception id segment.
expectedPolicyVersionqueryintegeryesRequired. Query parameter: expected policy version.
dryRunquerybooleannoWhen true, validate without persisting side effects.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for remove security exception.application/json DeleteExceptionResponse
422Validation Errorapplication/json HTTPValidationError

PUT /v1/slate/environments/{environment_id}/security/managed-groups/{group_id}​

Set Security Managed Group

Move one managed WAF group off, or back onto, its catalog default.

off and log are the directions that remove protection, so both require a stated reason — refused here as managed-off-without-reason and again by V188's mode NOT IN ('off','log') OR reason IS NOT NULL.

Operation id: set_security_managed_group_v1_slate_environments__environment_id__security_managed_groups__group_id__put

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
group_idpathstringyesPath parameter identifying the group id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for set security managed group.

Responses

StatusDescriptionBody
200Successful response for set security managed group.application/json SetManagedGroupResponse
422Validation Errorapplication/json HTTPValidationError

PUT /v1/slate/environments/{environment_id}/security/presets​

Set Security Presets

Change a lane's managed tier and its bot, rate and challenge settings.

Turning the managed ruleset off with no stated reason is refused here with a sentence, and again by V188's CHECK. Both are deliberate: the operator should meet the explanation, not a constraint violation, and no future code path should be able to skip the explanation.

Operation id: set_security_presets_v1_slate_environments__environment_id__security_presets_put

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for set security presets.

Responses

StatusDescriptionBody
200Successful response for set security presets.application/json SetPresetsResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/security/rules​

Create Security Rule

Create a custom security rule, refusing an unsafe variant by name.

Operation id: create_security_rule_v1_slate_environments__environment_id__security_rules_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for create security rule.

Responses

StatusDescriptionBody
201Successful response for create security rule.application/json SlateSecurityWriteRuleResponse
422Validation Errorapplication/json HTTPValidationError

PUT /v1/slate/environments/{environment_id}/security/rules/{rule_id}​

Replace Security Rule

Replace a custom security rule, running the same gates as a create.

Operation id: replace_security_rule_v1_slate_environments__environment_id__security_rules__rule_id__put

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
rule_idpathstringyesPath parameter identifying the rule id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for replace security rule.

Responses

StatusDescriptionBody
200Successful response for replace security rule.application/json SlateSecurityWriteRuleResponse
422Validation Errorapplication/json HTTPValidationError

DELETE /v1/slate/environments/{environment_id}/security/rules/{rule_id}​

Remove Security Rule

Remove a custom security rule, keeping its body so the removal can be undone.

Operation id: remove_security_rule_v1_slate_environments__environment_id__security_rules__rule_id__delete

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
rule_idpathstringyesPath parameter identifying the rule id segment.
expectedPolicyVersionqueryintegeryesRequired. Query parameter: expected policy version.
dryRunquerybooleannoWhen true, validate without persisting side effects.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for remove security rule.application/json SlateSecurityDeleteRuleResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/security/rules/{rule_id}/revert​

Revert Security Rule

Restore a rule to a stored revision.

Reverting applies the recorded document rather than reconstructing intent from an audit sentence, which is what makes §29.4's "every rule change can be reverted" a fact about this system rather than a claim about it.

Operation id: revert_security_rule_v1_slate_environments__environment_id__security_rules__rule_id__revert_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
rule_idpathstringyesPath parameter identifying the rule id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for revert security rule.

Responses

StatusDescriptionBody
200Successful response for revert security rule.application/json SlateSecurityWriteRuleResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/environments/{environment_id}/security/rules/{rule_id}/revisions​

Get Security Rule Revisions

Return a rule's revision history, newest first.

Operation id: get_security_rule_revisions_v1_slate_environments__environment_id__security_rules__rule_id__revisions_get

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
rule_idpathstringyesPath parameter identifying the rule id segment.
limitqueryintegernoMaximum number of rows to return.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get security rule revisions.application/json SlateSecurityRevisionsResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/security/rules/{rule_id}/rollout​

Set Security Rule Rollout

Advance or retreat a rule's staged rollout.

This is where dual control actually bites. A rule can be written in simulate freely; the write that makes an enforcing block rule real runs the same :func:app.slate_security.evaluate_security_safety gate as a body edit, so it is refused as enforce-without-simulation, enforce-without-approval, approval-stale or approval-self rather than succeeding because it happened to arrive by a different route.

Operation id: set_security_rule_rollout_v1_slate_environments__environment_id__security_rules__rule_id__rollout_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
rule_idpathstringyesPath parameter identifying the rule id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for set security rule rollout.

Responses

StatusDescriptionBody
200Successful response for set security rule rollout.application/json SlateSecurityWriteRuleResponse
422Validation Errorapplication/json HTTPValidationError

POST /v1/slate/environments/{environment_id}/security/simulate​

Simulate Security Request

Explain what this lane's policy decides for a test request, and why every rule lost.

A read, not a write, unless persist is set. "Which rule blocked this customer" is the question that brings an operator here during an incident, so requiring PUBLISH would put the answer out of reach of exactly the person asking.

Operation id: simulate_security_request_v1_slate_environments__environment_id__security_simulate_post

Parameters

NameInTypeRequiredDescription
environment_idpathstringyesPath parameter identifying the environment id segment.
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Request body (required)

Request body for simulate security request.

Responses

StatusDescriptionBody
200Successful response for simulate security request.application/json SlateSecuritySimulateResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/security/managed-groups​

Get Managed Group Catalog

Return the curated WAF group catalog.

Each group states its false-positive risk and what it will break. A group that cannot say what it will break is a group nobody can safely enable, so the catalog is the answer rather than a list of names.

Operation id: get_managed_group_catalog_v1_slate_security_managed_groups_get

Parameters

NameInTypeRequiredDescription
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get managed group catalog.application/json ManagedGroupsResponse
422Validation Errorapplication/json HTTPValidationError

GET /v1/slate/security/presets​

Get Security Presets

Return every managed tier and safe preset as data.

A preset is its fields, not its name. "Aggressive" is not a mood the system interprets at request time, and an operator choosing it is entitled to read what it will do to their readers before they choose — which is why expectedImpact is a required field on all three families rather than documentation somewhere else.

Operation id: get_security_presets_v1_slate_security_presets_get

Parameters

NameInTypeRequiredDescription
tenantSlugquerystring or nullnoTenant slug. Optional: the Slate routes read tenancy from the credential, so a browser call carrying a session JWT does not need to name a tenant in the URL.
authorizationheaderstring or nullnoJWT bearer token for authenticated access (Authorization: Bearer <token>).
X-API-Keyheaderstring or nullnoTenant-scoped API key used as an alternative to JWT bearer authentication.

Responses

StatusDescriptionBody
200Successful response for get security presets.application/json SecurityPresetsResponse
422Validation Errorapplication/json HTTPValidationError

Schemas used​

CreateExceptionRequest​

Open a scoped, expiring carve-out.

PropertyTypeRequiredDescription
subjectKindenum "managed-group", "rule", "policy"yesWhat the carve-out applies to.
subjectRefstringnoGroup catalog id or rule id.
matcherKindstringnoMatcher Kind.
matcherValuestringyesThe route pattern the exception covers.
expiresAtstringyesWhen it lapses. An exception that cannot lapse is policy.
reasonstringyesWhy it exists.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoDry Run.

DeleteExceptionResponse​

The outcome of closing a carve-out early.

PropertyTypeRequiredDescription
deletedbooleanyesDeleted.
dryRunbooleanyesDry Run.
policyVersionintegeryesPolicy Version.

ExceptionResponse​

The outcome of opening a carve-out.

PropertyTypeRequiredDescription
appliedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
exceptionSecurityExceptionBody or nullnoException.
policyVersionintegeryesThe version after the write.
warningsarray of SecurityWarningBodynoWarnings.

HTTPValidationError​

Validation error response emitted when request data fails schema checks.

PropertyTypeRequiredDescription
detailarray of ValidationErrornoDetail.

ManagedGroupsResponse​

The curated group catalog.

PropertyTypeRequiredDescription
groupsarray of ManagedGroupBodyyesEvery group, in catalog order.

SecurityEventBody​

One security event, with its redacted evidence.

PropertyTypeRequiredDescription
idstringyesStable resource identifier.
atstring or nullnoAt.
sourcestringnoProvenance source for the record (for example human or imported).
ruleKindstringnoRule Kind.
ruleRefstringnoRule Ref.
ruleLabelstringnoRule Label.
routestringnoRoute.
methodstringnoMethod.
releaseIdstring or nullnoRelease ID.
regionstring or nullnoRegion.
actionstringnoAction.
mitigatedbooleannoMitigated.
edgeAttachedbooleannoEdge Attached.
evidencemap of stringnoEvidence.
retainUntilstring or nullnoRetain Until.

SecurityEventsResponse​

A lane's security events.

PropertyTypeRequiredDescription
eventsarray of SecurityEventBodyyesMost recent first.
observedbooleannoFalse: none of these were observed in a request path.
sentencestringnoSentence.

SecurityPolicyResponse​

A lane's complete security policy, and what it actually enforces.

PropertyTypeRequiredDescription
environmentIdstringyesThe lane.
managedRulesetstringyesActive managed tier.
botPresetstringyesActive bot preset.
ratePresetstringyesActive rate preset.
challengeModestringyesoff, managed or always.
presetOverridesobjectnoPreset Overrides.
managedOffReasonstring or nullnoManaged Off Reason.
policyVersionintegeryesOptimistic-concurrency token.
edgeAttachedbooleanyesWhether a delivery tier serves this lane.
edgeProviderstring or nullnoEdge Provider.
enforcementSlateSecurityEnforcementBodynoWhether the policy stops anything.
ddosDdosBodynoDDoS status, or its absence.
groupsarray of ManagedGroupBodyyesThe catalog with this lane's overrides.
rulesarray of SecurityRuleBodyyesCustom rules, in precedence order.
exceptionsarray of SecurityExceptionBodyyesCarve-outs, soonest first.
rulesDigeststringyesDeterminism receipt over the enabled ruleset.
updatedAtstring or nullnoUpdated At.
updatedBystring or nullnoUpdated By.

SecurityPresetsResponse​

Every managed tier and safe preset this control plane offers.

PropertyTypeRequiredDescription
managedRulesetsarray of ManagedRulesetBodyyesThe three managed tiers.
botPresetsarray of BotPresetBodyyesThe four bot presets.
ratePresetsarray of RatePresetBodyyesThe four rate presets.

SetManagedGroupRequest​

Move one managed group off, or back onto, its catalog default.

PropertyTypeRequiredDescription
modestringyesoff, log, challenge or block.
reasonstring or nullnoRequired for off and log, which remove protection.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoDry Run.

SetManagedGroupResponse​

The outcome of a managed-group change.

PropertyTypeRequiredDescription
appliedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
groupManagedGroupBodyyesThe group as it now stands.
policyVersionintegeryesThe version after the change.
enforcementSlateSecurityEnforcementBodynoEnforcement.

SetPresetsRequest​

Change a lane's managed tier and its bot, rate and challenge settings.

PropertyTypeRequiredDescription
managedRulesetstringnooff, core or strict.
botPresetstringnoBot Preset.
ratePresetstringnoRate Preset.
challengeModestringnoChallenge Mode.
overridesobjectnoOverrides.
managedOffReasonstring or nullnoRequired when the managed ruleset is off.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoRun every gate and write nothing.
reasonstringnoWhy; recorded in audit.

SetPresetsResponse​

The outcome of a preset change.

PropertyTypeRequiredDescription
appliedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
managedRulesetstringyesThe tier now in effect, or that would be.
botPresetstringyesThe bot preset now in effect.
ratePresetstringyesThe rate preset now in effect.
policyVersionintegeryesThe version after the change.
enforcementSlateSecurityEnforcementBodynoEnforcement.
warningsarray of SecurityWarningBodynoWarnings.

SlateSecurityApprovalBody​

One recorded approval.

PropertyTypeRequiredDescription
idstringyesStable resource identifier.
subjectKindstringnoSubject Kind.
subjectIdstringnoSubject ID.
digeststringnoDigest.
authorActorNamestringnoAuthor Actor Name.
approverActorNamestringnoApprover Actor Name.
approvedAtstring or nullnoApproved At.
notestring or nullnoNote.

SlateSecurityApprovalRequest​

Record a second person's approval of one exact body.

PropertyTypeRequiredDescription
subjectKindenum "rule", "exception", "policy", "managed-group"yesWhat is being approved.
subjectIdstringyesId of the subject.
digeststringyesThe body that was reviewed, from the write response.
authorActorKeystringyesImmutable identity of whoever proposed it.
authorActorNamestringnoThe proposer's display name.
notestring or nullnoNote.

SlateSecurityAuditResponse​

A lane's security audit trail.

PropertyTypeRequiredDescription
entriesarray of SlateSecurityAuditEntryBodyyesMost recent first.

SlateSecurityDeleteRuleResponse​

The outcome of a rule deletion.

PropertyTypeRequiredDescription
deletedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
policyVersionintegeryesThe version after the write.

SlateSecurityRevertRequest​

Restore a rule to a stored revision.

PropertyTypeRequiredDescription
revisionintegeryesWhich stored revision to apply.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoDry Run.
reasonstringnoReason.

SlateSecurityRevisionsResponse​

A rule's revision history.

PropertyTypeRequiredDescription
revisionsarray of SlateSecurityRevisionBodyyesNewest first.

SlateSecurityRolloutRequest​

Advance or retreat a rule's staged rollout.

PropertyTypeRequiredDescription
rolloutModestringyessimulate or enforce.
rolloutPercentintegeryesShare of traffic, 0 to 100.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoDry Run.
reasonstringnoReason.

SlateSecuritySimulateCommandBody​

A simulation, optionally over a what-if ruleset.

PropertyTypeRequiredDescription
requestSlateSecuritySimulateRequestBodyyesThe test request.
rulesarray of SecurityRuleBody or nullnoWhat-if overlay. When absent, the lane's stored rules are used.
persistbooleannoRecord the outcome as a security event.

SlateSecuritySimulateResponse​

What the policy decides for a test request, and why every other rule did not.

basis, observed, enforced and mitigated are literal defaults no handler assigns. There is no code path able to make this response claim that a request was observed or stopped, which is the structural form of the same guarantee V188 expresses as CHECKs.

PropertyTypeRequiredDescription
actionstringyesallowed, logged, challenged, rate-limited or would-block.
actionReasonstringyesOne sentence naming the outcome and what produced it.
winningRuleKindstringyesWhat decided.
winningRuleRefstring or nullnoWinning Rule Ref.
winningRuleLabelstringyesIts name.
rolloutModestringyesThe rollout mode of whatever decided.
exceptionAppliedmap of string or nullnoException Applied.
consideredarray of SlateSecuritySimulationStepBodyyesEvery rule, and why it did not win.
warningsarray of SecurityWarningBodynoWarnings.
rulesDigeststringyesDeterminism receipt over the evaluated ruleset.
policyVersionintegeryesWhich policy generation answered.
basis"policy-simulation"noThis is an evaluation of recorded policy against a test request, not a replay of an observed request. When a delivery tier lands, 'edge-observed' becomes the second value of this field rather than a change of meaning for the first.
observedbooleannoFalse: no delivery tier reported this request.
enforcedfalsenoFalse: nothing acted on this request.
mitigatedfalsenoFalse: nothing was stopped, because nothing can be.
sentencestringnoWhat all of that means, in words.
eventIdstring or nullnoSet when the outcome was recorded.

SlateSecurityWriteRuleRequest​

Create or replace a custom security rule.

PropertyTypeRequiredDescription
idstring or nullnoRule id, absent before it is written.
ordinalintegernoPrecedence; lower wins.
enabledbooleannoWhether the rule participates.
labelstringnoOperator-facing rule name.
matcherKindstringnoexact, prefix, glob or regex.
matcherValuestringnoThe route pattern.
matcherMethodsarray of stringnoMatcher Methods.
matcherHostsarray of stringnoMatcher Hosts.
conditionsarray of objectnoConditions.
actionstringnoallow, log, challenge, rate-limit or block.
rateRequestsinteger or nullnoRate Requests.
rateWindowSecondsinteger or nullnoRate Window Seconds.
rolloutModestringnosimulate or enforce.
rolloutPercentintegernoRollout Percent.
expiresAtstring or nullnoExpires At.
acknowledgedWarningsarray of stringnoAcknowledged Warnings.
bodyDigeststringnoContent digest of the decisive fields; what an approval names.
revisionintegernoMonotonic revision counter.
expectedPolicyVersionintegeryesThe version the caller read.
dryRunbooleannoValidate without writing.
reasonstringnoWhy; recorded in audit.

SlateSecurityWriteRuleResponse​

The outcome of a rule write.

PropertyTypeRequiredDescription
appliedbooleanyesFalse for a dry run.
dryRunbooleanyesWhether this was a preview.
ruleSecurityRuleBody or nullnoRule.
bodyDigeststringyesWhat an approval of this body must name.
policyVersionintegeryesThe version after the write.
enforcementSlateSecurityEnforcementBodynoEnforcement.
warningsarray of SecurityWarningBodynoWarnings.