POST
/v1/deny-diagnostics
Reuses audit request bundle, policy simulation, registry, session, credential binding, connector route, environment, and client-surface projections. The response never includes request/response bodies, prompts, payloads, tokens, or secret material.
object
Admin API request ID for this diagnostics lookup.
string
>= 1 characters
deniedRequestId
Denied runtime request ID. Exactly one of deniedRequestId, auditEventId, or explicitContext is required.
string
>= 1 characters
auditEventId
Audit event ID from search/detail. Exactly one lookup selector is required.
string
>= 1 characters
explicitContext
object
object
targetEnvironmentId required
object
matchedRule
object
Allowed values: allow deny
failingConstraints required
string
Allowed values: none service_account user_delegated agent_scoped workload_mapped
object
Allowed values: submitted under_review approved rejected disabled revoked archived
string
Allowed values: submitted under_review approved rejected disabled archived
allowedEnvironmentIds required
object
actorEnvironmentId required
targetEnvironmentId required
object
Allowed values: approved under_review rejected disabled revoked unknown
Allowed values: approved under_review rejected disabled revoked unknown
serverStatus
string
Allowed values: submitted under_review approved rejected disabled archived
apiSourceStatus
string
Allowed values: submitted under_review approved rejected disabled archived
credentialBinding required
object
string
Allowed values: none service_account user_delegated agent_scoped workload_mapped
Allowed values: approved disabled revoked missing denied unknown
revocationStatus required
Allowed values: none disabled revoked unknown
object
routeAvailabilityReason required
Allowed values: healthy degraded unhealthy unknown
Allowed values: submitted under_review active disabled revoked archived
schemaValidation
object
upstreamAttempted required
tenantId
Tenant scope, derived from auth context in production and explicit in deterministic fixtures.
string
>= 1 characters
environmentId
Environment scope to permission-check and hide cross-scope diagnostics.
string
>= 1 characters
Remediation-ready deny diagnostics bundle with safe metadata only.
object
Allowed values: request_id audit_event_id explicit_context
object
matchedRule
object
Allowed values: allow deny
failingConstraints required
string
Allowed values: none service_account user_delegated agent_scoped workload_mapped
object
Allowed values: submitted under_review approved rejected disabled revoked archived
string
Allowed values: submitted under_review approved rejected disabled archived
allowedEnvironmentIds required
object
actorEnvironmentId required
targetEnvironmentId required
object
Allowed values: approved under_review rejected disabled revoked unknown
Allowed values: approved under_review rejected disabled revoked unknown
serverStatus
string
Allowed values: submitted under_review approved rejected disabled archived
apiSourceStatus
string
Allowed values: submitted under_review approved rejected disabled archived
credentialBinding required
object
string
Allowed values: none service_account user_delegated agent_scoped workload_mapped
Allowed values: approved disabled revoked missing denied unknown
revocationStatus required
Allowed values: none disabled revoked unknown
object
routeAvailabilityReason required
Allowed values: healthy degraded unhealthy unknown
Allowed values: submitted under_review active disabled revoked archived
schemaValidation
object
upstreamAttempted required
suggestedRemediation required
sourceProjections required
Array
>= 1 items
Allowed values: audit_request_bundle policy_simulation credential_binding connector_registry session_registry registry client_surface_registry environment_registry api_adapter
object
Array
Allowed values: deny_diagnostics:read
Request shape, lookup, or safe-metadata validation failed.
object
Allowed values: redacted metadata_only
field
Optional metadata-only field identifier for validation errors.
string
details
Optional metadata-only diagnostic details. Never include secret material, payloads, prompts, raw endpoint URLs, or customer data.
object
key additional properties
Actor lacks tenant/environment permission to read deny diagnostics.
object
Allowed values: redacted metadata_only
field
Optional metadata-only field identifier for validation errors.
string
details
Optional metadata-only diagnostic details. Never include secret material, payloads, prompts, raw endpoint URLs, or customer data.
object
key additional properties
Denied request or audit event was unknown, stale, or outside actor scope.
object
Allowed values: redacted metadata_only
field
Optional metadata-only field identifier for validation errors.
string
details
Optional metadata-only diagnostic details. Never include secret material, payloads, prompts, raw endpoint URLs, or customer data.
object
key additional properties