Skip to content

Opens an emergency window.

POST
/v1/m/governance/breakglass
curl --request POST \
--url https://example.com/v1/m/governance/breakglass \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "expires_in_seconds": 1, "match_action": "example", "reason": "example" }'

Opens an emergency window. Admin-tier; a REAL human only (a system token has no stable identity for the review SoD to key on); justification required; time-boxed; blocked while any prior grant is unreviewed (the forced-post-review backpressure: you cannot stack emergencies over an unexamined one).

X-Olivares-Tenant
string format: uuid

Target tenant id; required when the principal can act in more than one tenant.

Media type application/json
object
expires_in_seconds
Any of:

Values at or below zero, null, and omission select the 3600-second default.

integer format: int64
<= 86400
match_action
Any of:

Empty or * covers every action; otherwise exact match or one trailing * prefix wildcard; capped at 128 bytes.

string
reason
required

Mandatory justification, trimmed and capped at 4096 bytes.

string
/.*\S.*/
Example generated
{
"expires_in_seconds": 1,
"match_action": "example",
"reason": "example"
}

OK

Media type application/json
object
Example generated
{}

Bad request

Media type application/json
object
Example generated
{}

Unauthenticated

Media type application/json
object
Example generated
{}

Forbidden

Media type application/json
object
Example generated
{}

Not found

Media type application/json
object
Example generated
{}

Conflict / setup required

Media type application/json
object
Example generated
{}

Rate limited

Media type application/json
object
Example generated
{}