---
title: "Query Vulnerabilities Metrics"
url: "https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8/operations/query-vulnerabilities-metrics"
---

> Full API specification: https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8.md

# Query Vulnerabilities Metrics

`POST` `/metrics/vulnerabilities`

Operation ID: `query-vulnerabilities-metrics`

Post a query to the endpoint to retrieve aggregated vulnerabilities metrics. Data can be requested to group by any 2 dimensions and can include any number of filter conditions.

## Request body (required)

Content types: `application/json`

## Responses

- `200` - The result of a vulnerabilities metrics query. Contains the aggregated data along with metadata about the query.
- `400` - Bad Request
- `401` - Unauthorized
- `403` - Forbidden

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Konnect Service Catalog
  version: 1.3.0
servers:
  - url: https://us.api.konghq.com/v1
    description: United-States Production region
  - url: https://eu.api.konghq.com/v1
    description: Europe Production region
  - url: https://au.api.konghq.com/v1
    description: Australia Production region
  - url: https://me.api.konghq.com/v1
    description: Middle-East Production region
  - url: https://in.api.konghq.com/v1
    description: India Production region
  - url: https://sg.api.konghq.com/v1
    description: Singapore Production region
paths:
  /metrics/vulnerabilities:
    post:
      x-unstable: true
      x-internal: true
      summary: Query Vulnerabilities Metrics
      operationId: query-vulnerabilities-metrics
      description: >
        Post a query to the endpoint to retrieve aggregated vulnerabilities
        metrics.

        Data can be requested to group by any 2 dimensions and can include any
        number of filter conditions.
      requestBody:
        $ref: "#/components/requestBodies/QueryVulnerabilitiesMetricsRequest"
      responses:
        "200":
          $ref: "#/components/responses/VulnerabilitiesMetricsQueryResponse"
        "400":
          $ref: "#/components/responses/BadRequest"
        "401":
          $ref: "#/components/responses/Unauthorized"
        "403":
          $ref: "#/components/responses/Forbidden"
      tags:
        - Vulnerabilities
security:
  - konnectAccessToken: []
  - personalAccessToken: []
  - systemAccountAccessToken: []
components:
  requestBodies:
    QueryVulnerabilitiesMetricsRequest:
      required: true
      content:
        application/json:
          schema:
            $ref: "#/components/schemas/VulnerabilitiesMetricsQuery"
  responses:
    VulnerabilitiesMetricsQueryResponse:
      description: |
        The result of a vulnerabilities metrics query.
        Contains the aggregated data along with metadata about the query.
      content:
        application/json:
          schema:
            type: object
            required:
              - data
              - meta
            properties:
              data:
                readOnly: true
                type: array
                items:
                  $ref: "#/components/schemas/VulnerabilitiesMetricsQueryResult"
              meta:
                $ref: "#/components/schemas/VulnerabilitiesMetricsResponseMetadata"
    BadRequest:
      description: Bad Request
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/BadRequestError"
    Unauthorized:
      description: Unauthorized
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/UnauthorizedError"
          examples:
            UnauthorizedExample:
              $ref: "#/components/examples/UnauthorizedExample"
    Forbidden:
      description: Forbidden
      content:
        application/problem+json:
          schema:
            $ref: "#/components/schemas/ForbiddenError"
          examples:
            UnauthorizedExample:
              $ref: "#/components/examples/ForbiddenExample"
  schemas:
    VulnerabilitiesMetricsQuery:
      type: object
      description: A query against vulnerability metrics.
      additionalProperties: false
      required:
        - metrics
        - dimensions
        - filters
        - time_range
      properties:
        metrics:
          type: array
          minItems: 1
          maxItems: 1
          description: List of aggregated metrics to collect across the requested time span.
          items:
            type: string
            enum:
              - vulnerability_count
        dimensions:
          type: array
          description: The list of dimensions to group by.
          maxItems: 2
          example:
            - service
            - state
          items:
            type: string
            enum:
              - time
              - service
              - severity
              - state
              - type
              - source
              - environment
              - region
        filters:
          type: array
          description: A list of filters to apply to the query.
          items:
            oneOf:
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByService"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterBySeverity"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByState"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByType"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterBySource"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByEnvironment"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByRegion"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByCVE"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByPackageName"
              - $ref: "#/components/schemas/VulnerabilitiesMetricsFilterByScanAttributes"
        granularity:
          type: string
          description: >
            Force time grouping into buckets of the specified duration. Only has
            an effect if `time` is in the `dimensions` list.


            The granularity of the result may be coarser than requested.

            The exact result granularity will be reported in the response
            `meta.granularity_ms` field.


            If granularity is not specified and `time` is in the `dimensions`
            list, a default will be chosen based on the time range requested.


            Different relative times support different granularities:
              - 1d  => daily
              - 7d  => daily, weekly
              - 3w  => daily, weekly
              - 30d => daily, weekly
              - 3mo => daily, weekly
              - 1y  => daily, weekly

            For special time ranges:
              - current_week, previous_week   => daily
              - current_month, previous_month => daily, weekly

            For absolute time ranges, daily will be used.
          enum:
            - daily
            - weekly
        time_range:
          description: The time range to query.
          oneOf:
            - $ref: "#/components/schemas/VulnerabilityMetricsRelativeTimeRange"
            - $ref: "#/components/schemas/VulnerabilityMetricsAbsoluteTimeRange"
          discriminator:
            propertyName: type
            mapping:
              relative: "#/components/schemas/VulnerabilityMetricsRelativeTimeRange"
              absolute: "#/components/schemas/VulnerabilityMetricsAbsoluteTimeRange"
    VulnerabilitiesMetricsQueryResult:
      type: object
      description: A query result with metrics grouped by the dimensions specified in
        the query, at a particular time.
      required:
        - timestamp
        - event
      properties:
        timestamp:
          type: string
          format: date-time
          example: 2025-04-01T07:20:50.000Z
          description: >
            Timestamp corresponding to the aggregated metric data in the `event`
            object.

            RFC-3339 format with a "T" character separating date from time
            within the field value.
        event:
          $ref: "#/components/schemas/VulnerabilitiesMetricsQueryResultEvent"
    VulnerabilitiesMetricsResponseMetadata:
      type: object
      description: |
        Metadata about the query response. This includes:
          - The start and end times of the query
          - The granularity of the result
          - Whether the result was truncated
          - The limit of the result
          - The `query_id`
      required:
        - start
        - start_ms
        - end
        - end_ms
        - display
        - metric_names
        - metric_units
        - granularity_ms
        - truncated
        - limit
        - query_id
      properties:
        start:
          type: string
          format: date-time
          description: Start of the query time range in RFC-3339 format.
          example: 2025-03-30T07:20:50Z
        start_ms:
          type: number
          description: Start of the query time range in epoch format with millisecond
            precision.
          example: 1743319250000
        end:
          type: string
          format: date-time
          description: End of the query time range in RFC-3339 format.
          example: 2025-03-30T08:20:50Z
        end_ms:
          type: number
          description: End of the query time range in epoch format with millisecond
            precision.
          example: 1743322850000
        metric_names:
          type: array
          description: List of vulnerability metric names included in the result.
          items:
            type: string
            enum:
              - vulnerability_count
        metric_units:
          type: object
          description: >
            A mapping of metric names to their associated human-friendly display
            unit.

            The keys are the metric names, and the values are the units.
          properties:
            vulnerability_count:
              type: string
              enum:
                - count
        granularity_ms:
          type: number
          description: |
            The number of milliseconds per interval in a time series.
        truncated:
          type: boolean
          description: >
            Set to `true`` when the limit of cardinarlity is hit.

            For queries with 2 dimensions, the limit truncates the first
            dimension, and then groups all other groupings for the second
            dimension.


            Example: limit of 2 for `service` and `region` would return 2
            services maximum, and 2 regions + ____OTHER____.

            The ____OTHER___ is representative of all other regions.
        limit:
          type: number
          description: The applied cardinality limit.
        query_id:
          type: string
          description: An ID that can be used to reference the query.
          example: e2a6c0ce-3a90-4b6b-b9bf-cf6428d30ffe
        display:
          type: object
          description: >
            Instructs how to interpret identifiers in the query result.

            The structure consists of: dimension -> ID -> entity metadata.

            Since entity names within Konnect may overlap, ids are returned and
            used for exact grouping.

            This blob may be used to join and display results in a more
            human-friendly manner.

            Since IDs represent entities in the system at all points in time,
            historical data will still exist even if an entity is deleted.

            These such entities are marked with the `deleted: true` value.

            Another special case is the `____OTHER____` entity.

            When the limit of cardinality is reached for a second dimension, the
            system will group all other entities into the ____OTHER____
            grouping.

            This prevents returning an overwhelming number of long tail
            entities.
          properties:
            service:
              type: object
              additionalProperties:
                $ref: "#/components/schemas/MetricDimensionDisplayEntry"
            severity:
              type: object
              additionalProperties:
                $ref: "#/components/schemas/MetricDimensionDisplayEntry"
            state:
              type: object
              additionalProperties:
                $ref: "#/components/schemas/MetricDimensionDisplayEntry"
            type:
              type: object
              additionalProperties:
                $ref: "#/components/schemas/MetricDimensionDisplayEntry"
            source:
              type: object
              additionalProperties:
                $ref: "#/components/schemas/MetricDimensionDisplayEntry"
            environment:
              type: object
              additionalProperties:
                $ref: "#/components/schemas/MetricDimensionDisplayEntry"
            region:
              type: object
              additionalProperties:
                $ref: "#/components/schemas/MetricDimensionDisplayEntry"
          example:
            service:
              3a564a6a-1952-4181-89f0-a1cadc70123d:
                id: 3a564a6a-1952-4181-89f0-a1cadc70123d
                name: Pricing Svc
                deleted: false
              58620e4e-27f4-42eb-9776-402ec319c665:
                id: 58620e4e-27f4-42eb-9776-402ec319c665
                name: Billing Svc
                deleted: true
            state:
              open:
                id: open
                name: Open
                deleted: false
              fixed:
                id: fixed
                name: Fixed
                deleted: false
              dismissed:
                id: dismissed
                name: Dismissed
                deleted: false
    BadRequestError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          required:
            - invalid_parameters
          properties:
            invalid_parameters:
              $ref: "#/components/schemas/InvalidParameters"
    UnauthorizedError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 401
            title:
              example: Unauthorized
            type:
              example: https://httpstatuses.com/401
            instance:
              example: kong:trace:1234567890
            detail:
              example: Invalid credentials
    ForbiddenError:
      allOf:
        - $ref: "#/components/schemas/BaseError"
        - type: object
          properties:
            status:
              example: 403
            title:
              example: Forbidden
            type:
              example: https://httpstatuses.com/403
            instance:
              example: kong:trace:1234567890
            detail:
              example: Forbidden
    VulnerabilitiesMetricsFilterByService:
      type: object
      required:
        - operator
        - value
        - field
      properties:
        operator:
          $ref: "#/components/schemas/MetricsFilterInOperator"
        value:
          type: array
          items:
            type: string
            format: uuid
        field:
          type: string
          enum:
            - service
      description: Filters a metrics query by `service`.
    VulnerabilitiesMetricsFilterBySeverity:
      type: object
      description: Filters a metrics query by `severity`.
      required:
        - field
        - operator
        - value
      properties:
        field:
          type: string
          enum:
            - severity
        operator:
          $ref: "#/components/schemas/MetricsFilterInOperator"
        value:
          type: array
          items:
            $ref: "#/components/schemas/VulnerabilitySeverity"
    VulnerabilitiesMetricsFilterByState:
      type: object
      description: Filters a metrics query by `state`.
      required:
        - field
        - operator
        - value
      properties:
        field:
          type: string
          enum:
            - state
        operator:
          $ref: "#/components/schemas/MetricsFilterInOperator"
        value:
          type: array
          items:
            $ref: "#/components/schemas/VulnerabilityState"
    VulnerabilitiesMetricsFilterByType:
      type: object
      description: Filters a metrics query by `type`.
      required:
        - field
        - operator
        - value
      properties:
        field:
          type: string
          enum:
            - type
        operator:
          $ref: "#/components/schemas/MetricsFilterInOperator"
        value:
          type: array
          items:
            $ref: "#/components/schemas/VulnerabilityType"
    VulnerabilitiesMetricsFilterBySource:
      type: object
      description: Filters a metrics query by `source`.
      required:
        - field
        - operator
        - value
      properties:
        field:
          type: string
          enum:
            - source
        operator:
          $ref: "#/components/schemas/MetricsFilterInOperator"
        value:
          type: array
          items:
            type: string
            example: trivy
    VulnerabilitiesMetricsFilterByEnvironment:
      description: Filters a metrics query by `environment`.
      allOf:
        - type: object
          required:
            - field
          properties:
            field:
              type: string
              enum:
                - environment
        - oneOf:
            - $ref: "#/components/schemas/EmptyValueMetricsFilter"
            - type: object
              required:
                - operator
                - value
              properties:
                operator:
                  $ref: "#/components/schemas/MetricsFilterInOperator"
                value:
                  type: array
                  items:
                    type: string
                    example: prod
    VulnerabilitiesMetricsFilterByRegion:
      description: Filters a metrics query by `region`.
      allOf:
        - type: object
          required:
            - field
          properties:
            field:
              type: string
              enum:
                - region
        - oneOf:
            - $ref: "#/components/schemas/EmptyValueMetricsFilter"
            - type: object
              required:
                - operator
                - value
              properties:
                operator:
                  $ref: "#/components/schemas/MetricsFilterInOperator"
                value:
                  type: array
                  items:
                    type: string
                    example: us-east-1
    VulnerabilitiesMetricsFilterByCVE:
      description: Filters a metrics query by `cve_id`.
      allOf:
        - type: object
          required:
            - field
          properties:
            field:
              type: string
              enum:
                - cve_id
        - oneOf:
            - $ref: "#/components/schemas/EmptyValueMetricsFilter"
            - type: object
              required:
                - operator
                - value
              properties:
                operator:
                  $ref: "#/components/schemas/MetricsFilterInOperator"
                value:
                  type: array
                  items:
                    type: string
                    example: CVE-2025-1000
    VulnerabilitiesMetricsFilterByPackageName:
      description: Filters a metrics query by `package.name`.
      allOf:
        - type: object
          required:
            - field
          properties:
            field:
              type: string
              enum:
                - package.name
        - oneOf:
            - $ref: "#/components/schemas/EmptyValueMetricsFilter"
            - type: object
              required:
                - operator
                - value
              properties:
                operator:
                  $ref: "#/components/schemas/MetricsFilterInOperator"
                value:
                  type: array
                  items:
                    type: string
                    example: log4j
    VulnerabilitiesMetricsFilterByScanAttributes:
      description: >
        Filters a metrics query by `scan_attributes` properties.

        Dot-notation off of `scan_attributes` is used to specify the property to
        filter by.


        Example: `scan_attributes.image_tag`.
      allOf:
        - type: object
          required:
            - field
          properties:
            field:
              type: string
              pattern: ^scan_attributes\.[^.\s]+$
        - oneOf:
            - $ref: "#/components/schemas/EmptyValueMetricsFilter"
            - $ref: "#/components/schemas/StringValueMetricsFilter"
            - $ref: "#/components/schemas/NumericValueMetricsFilter"
      example:
        field: scan_attributes.image_version
        operator: in
        value:
          - 2.0.7
    VulnerabilityMetricsRelativeTimeRange:
      type: object
      description: >
        A duration representing a relative-to-now span of time.

        The start time is floored to the requested granularity.

        The exact start and end timestamps are returned in the result query in
        the meta.start and meta.end fields.

        Example:
          7d from now, with 1day granularity initiated at 2024-01-08T17:11:00+05:00 will query for the time range from 2024-01-01T00:00:00+05:00 to 2024-01-08T17:11:00+05:00.
      additionalProperties: false
      required:
        - type
        - time_range
      properties:
        tz:
          type: string
          description: >
            Time zone in IANA Time Zone Database format (e.g.,
            'America/New_York', 'Europe/London', 'Etc/UTC').

            Optional, defaults to UTC when unspecified.
          default: Etc/UTC
          example: America/Chicago
        type:
          type: string
          enum:
            - relative
        time_range:
          oneOf:
            - title: RelativeDayTimeRange
              type: string
              pattern: ^([1-9]|[1-9][0-9]|1[0-9]{2}|2[0-9]{2}|3[0-5][0-9]|36[0-5])d$
              default: 30d
            - title: RelativeWeekTimeRange
              type: string
              pattern: ^([1-9]|[1-4][0-9]|5[0-2])w$
            - title: RelativeMonthTimeRange
              type: string
              pattern: ^([1-9]|1[0-2])mo$
            - title: RelativeYearTimeRange
              type: string
              enum:
                - 1y
            - title: RelativeReservedRange
              type: string
              enum:
                - current_week
                - current_month
                - previous_week
                - previous_month
    VulnerabilityMetricsAbsoluteTimeRange:
      type: object
      description: A duration representing an exact start and end time.
      additionalProperties: false
      required:
        - type
        - start
        - end
      properties:
        tz:
          type: string
          description: >
            Time zone in IANA Time Zone Database format (e.g.,
            'America/New_York', 'Europe/London', 'Etc/UTC').

            Optional, defaults to UTC when unspecified.
          default: Etc/UTC
          example: America/Chicago
        type:
          type: string
          enum:
            - absolute
        start:
          format: date-time
          type: string
          description: Start of the query time range in RFC-3339 format.
          example: 2025-03-30T07:20:50Z
        end:
          format: date-time
          type: string
          description: Start of the query time range in RFC-3339 format.
          example: 2025-06-30T08:20:50Z
    VulnerabilitiesMetricsQueryResultEvent:
      oneOf:
        - $ref: "#/components/schemas/VulnerabilityCountMetricEvent"
      description: Payload containing the aggregated metric data and associated
        dimensions included in the query.
    MetricDimensionDisplayEntry:
      type: object
      required:
        - id
        - name
      properties:
        id:
          type: string
        name:
          type: string
        deleted:
          type: boolean
        is_other_group:
          type: boolean
    BaseError:
      type: object
      title: Error
      description: standard error
      required:
        - status
        - title
        - instance
        - detail
      properties:
        status:
          type: integer
          description: >
            The HTTP status code of the error. Useful when passing the response

            body to child properties in a frontend UI. Must be returned as an
            integer.
          readOnly: true
        title:
          type: string
          description: |
            A short, human-readable summary of the problem. It should not
            change between occurences of a problem, except for localization.
            Should be provided as "Sentence case" for direct use in the UI.
          readOnly: true
        type:
          type: string
          description: The error type.
          readOnly: true
        instance:
          type: string
          description: |
            Used to return the correlation ID back to the user, in the format
            kong:trace:<correlation_id>. This helps us find the relevant logs
            when a customer reports an issue.
          readOnly: true
        detail:
          type: string
          description: >
            A human readable explanation specific to this occurence of the
            problem.

            This field may contain request/entity data to help the user
            understand

            what went wrong. Enclose variable values in square brackets. Should
            be

            provided as "Sentence case" for direct use in the UI.
          readOnly: true
    InvalidParameters:
      type: array
      nullable: false
      uniqueItems: true
      minItems: 1
      description: invalid parameters
      items:
        oneOf:
          - $ref: "#/components/schemas/InvalidParameterStandard"
          - $ref: "#/components/schemas/InvalidParameterMinimumLength"
          - $ref: "#/components/schemas/InvalidParameterMaximumLength"
          - $ref: "#/components/schemas/InvalidParameterChoiceItem"
          - $ref: "#/components/schemas/InvalidParameterDependentItem"
    MetricsFilterInOperator:
      type: string
      description: |
        The type of filter to apply.
          - `in` filters will limit results to only the specified values
          - `not_in` filters will exclude the specified values
      enum:
        - in
        - not_in
    VulnerabilitySeverity:
      type: string
      enum:
        - low
        - medium
        - high
        - critical
      example: low
    VulnerabilityState:
      type: string
      enum:
        - open
        - fixed
        - dismissed
      example: dismissed
    VulnerabilityType:
      type: string
      enum:
        - container_image
        - library
      readOnly: true
      example: container_image
    EmptyValueMetricsFilter:
      type: object
      required:
        - operator
      properties:
        operator:
          $ref: "#/components/schemas/MetricsFilterEmptyOperator"
    StringValueMetricsFilter:
      type: object
      required:
        - operator
        - value
      properties:
        operator:
          $ref: "#/components/schemas/MetricsFilterInOperator"
        value:
          type: array
          items:
            type: string
    NumericValueMetricsFilter:
      type: object
      required:
        - operator
        - value
      properties:
        operator:
          $ref: "#/components/schemas/MetricsFilterNumericOperator"
        value:
          type: number
    VulnerabilityCountMetricEvent:
      type: object
      description: Payload containing the aggregated vulnerability count metric data
        and associated dimensions included in the query.
      properties:
        service:
          type: string
          format: uuid
        severity:
          $ref: "#/components/schemas/VulnerabilitySeverity"
        state:
          $ref: "#/components/schemas/VulnerabilityState"
        type:
          $ref: "#/components/schemas/VulnerabilityType"
        source:
          type: string
          example: trivy
        environment:
          type: string
          example: prod
        region:
          type: string
          example: us-east-1
        vulnerability_count:
          type: number
          format: int32
      required:
        - vulnerability_count
      example:
        vulnerability_count: 58
        state: open
        service: 7f9fd312-a987-4628-b4c5-bb4f4fddd5f7
    InvalidParameterStandard:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          $ref: "#/components/schemas/InvalidRules"
        source:
          type: string
          example: body
        reason:
          type: string
          example: is a required field
          readOnly: true
      required:
        - field
        - reason
    InvalidParameterMinimumLength:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: false
          enum:
            - min_length
            - min_digits
            - min_lowercase
            - min_uppercase
            - min_symbols
            - min_items
            - min
        minimum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must have at least 8 characters
          readOnly: true
      required:
        - field
        - reason
        - rule
        - minimum
    InvalidParameterMaximumLength:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: false
          enum:
            - max_length
            - max_items
            - max
        maximum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must not have more than 8 characters
          readOnly: true
      required:
        - field
        - reason
        - rule
        - maximum
    InvalidParameterChoiceItem:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: false
          enum:
            - enum
        reason:
          type: string
          example: is a required field
          readOnly: true
        choices:
          type: array
          uniqueItems: true
          readOnly: true
          nullable: false
          minItems: 1
          items: {}
        source:
          type: string
          example: body
      required:
        - field
        - reason
        - rule
        - choices
    InvalidParameterDependentItem:
      type: object
      additionalProperties: false
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          readOnly: true
          nullable: true
          enum:
            - dependent_fields
        reason:
          type: string
          example: is a required field
          readOnly: true
        dependents:
          type: array
          uniqueItems: true
          nullable: true
          items: {}
          readOnly: true
        source:
          type: string
          example: body
      required:
        - field
        - rule
        - reason
        - dependents
    MetricsFilterEmptyOperator:
      type: string
      description: |
        The type of filter to apply.
        Empty values are `null` or undefined.
      enum:
        - empty
        - not_empty
    MetricsFilterNumericOperator:
      type: string
      description: The type of filter to apply to numeric field values.
      enum:
        - =
        - "!="
        - <
        - ">"
        - <=
        - ">="
    InvalidRules:
      description: invalid parameters rules
      type: string
      readOnly: true
      nullable: true
      enum:
        - required
        - is_array
        - is_base64
        - is_boolean
        - is_date_time
        - is_integer
        - is_null
        - is_number
        - is_object
        - is_string
        - is_uuid
        - is_fqdn
        - is_arn
        - unknown_property
        - missing_reference
        - is_label
        - matches_regex
        - invalid
        - is_supported_network_availability_zone_list
        - is_supported_network_cidr_block
        - is_supported_provider_region
        - type
  examples:
    UnauthorizedExample:
      value:
        status: 401
        title: Unauthorized
        instance: kong:trace:8347343766220159418
        detail: Unauthorized
    ForbiddenExample:
      value:
        status: 403
        title: Forbidden
        instance: kong:trace:2723154947768991354
        detail: You do not have permission to perform this action
  securitySchemes:
    konnectAccessToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        The Konnect access token is meant to be used by the Konnect dashboard
        and the decK CLI authenticate with.
    personalAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: >
        The personal access token is meant to be used as an alternative to
        basic-auth when accessing Konnect via APIs.

        You can generate a Personal Access Token (PAT) from the [personal access
        token page](https://cloud.konghq.com/global/account/tokens/) in the
        Konnect dashboard.

        The PAT token must be passed in the header of a request, for example:

        `curl -X GET 'https://global.api.konghq.com/v2/users/' --header
        'Authorization: Bearer kpat_xgfT...'`
    systemAccountAccessToken:
      type: http
      scheme: bearer
      bearerFormat: Token
      description: >
        The system account access token is meant for automations and
        integrations that are not directly associated with a human identity.

        You can generate a system account Access Token by creating a system
        account and then obtaining a system account access token for that
        account.

        The access token must be passed in the header of a request, for example:

        `curl -X GET 'https://global.api.konghq.com/v2/users/' --header
        'Authorization: Bearer spat_i2Ej...'`
```
