AWS Security Agent

2026/09/29 - AWS Security Agent - 1 new6 updated api methods

Changes  Adds support for Azure DevOps and Bitbucket Data Center integration providers.

UpdateIntegration (new) Link ¶

Creates an integration's webhook, or rotates the HMAC signing secret of an existing one. The secret is returned only once, in this response, and cannot be retrieved again.

See also: AWS API Documentation

Request Syntax

client.update_integration(
    integrationId='string',
    webhookAction='CREATE_IF_ABSENT'|'ROTATE'
)
type integrationId:

string

param integrationId:

[REQUIRED]

The ID of the integration whose webhook you want to create or rotate.

type webhookAction:

string

param webhookAction:

[REQUIRED]

The action to perform on the integration's webhook.

rtype:

dict

returns:

Response Syntax

{
    'integrationId': 'string',
    'webhookUrl': 'string',
    'secret': 'string'
}

Response Structure

  • (dict) --

    Output for the UpdateIntegration operation.

    • integrationId (string) --

      The ID of the integration.

    • webhookUrl (string) --

      The payload URL to configure on your provider instance. Returned when a webhook is created; unchanged by a rotate.

    • secret (string) --

      The HMAC signing secret for the webhook. Returned only once, in this response; it is never returned again.

CreateIntegration (updated) Link ¶
Changes (request)
{'input': {'azureDevOps': {'code': 'string',
                           'organizationName': 'string',
                           'state': 'string'},
           'bitbucketDataCenter': {'code': 'string',
                                   'state': 'string',
                                   'targetUrl': 'string'}},
 'provider': {'AZURE_DEVOPS'}}

Creates a new integration with a third-party provider, such as GitHub, for code review and remediation.

See also: AWS API Documentation

Request Syntax

client.create_integration(
    provider='GITHUB'|'GITLAB'|'BITBUCKET'|'CONFLUENCE'|'AZURE_DEVOPS',
    input={
        'github': {
            'code': 'string',
            'state': 'string',
            'organizationName': 'string',
            'targetUrl': 'string',
            'installationId': 'string'
        },
        'gitlab': {
            'accessToken': 'string',
            'targetUrl': 'string',
            'tokenType': 'PERSONAL'|'GROUP',
            'groupId': 'string'
        },
        'bitbucket': {
            'installationId': 'string',
            'workspace': 'string',
            'code': 'string',
            'state': 'string'
        },
        'confluence': {
            'installationId': 'string',
            'code': 'string',
            'state': 'string',
            'siteUrl': 'string'
        },
        'azureDevOps': {
            'code': 'string',
            'state': 'string',
            'organizationName': 'string'
        },
        'bitbucketDataCenter': {
            'targetUrl': 'string',
            'code': 'string',
            'state': 'string'
        }
    },
    integrationDisplayName='string',
    kmsKeyId='string',
    tags={
        'string': 'string'
    },
    privateConnectionName='string'
)
type provider:

string

param provider:

[REQUIRED]

The integration provider.

type input:

dict

param input:

[REQUIRED]

The provider-specific input required to create the integration.

  • github (dict) --

    The GitHub-specific input for creating an integration.

    • code (string) -- [REQUIRED]

      The OAuth authorization code received from GitHub.

    • state (string) -- [REQUIRED]

      The CSRF state token for validating the OAuth flow.

    • organizationName (string) --

      The name of the GitHub organization to integrate with.

    • targetUrl (string) --

      The HTTPS URL of a self-hosted GitHub Enterprise Server instance. Omit this value for GitHub.com.

    • installationId (string) --

      The installation identifier provided by GitHub Enterprise Server on the install callback. Required for GitHub Enterprise Server integrations and ignored for GitHub.com.

  • gitlab (dict) --

    The configuration for a GitLab integration.

    • accessToken (string) -- [REQUIRED]

      The GitLab access token used to authenticate. This can be a personal access token or a group access token.

    • targetUrl (string) --

      The HTTPS URL of a self-managed GitLab instance. Omit this value for GitLab SaaS (gitlab.com).

    • tokenType (string) -- [REQUIRED]

      The type of GitLab access token provided in accessToken.

    • groupId (string) --

      The identifier of the GitLab group. Required when tokenType is group and ignored for personal tokens.

  • bitbucket (dict) --

    The configuration for a Bitbucket integration.

    • installationId (string) -- [REQUIRED]

      The Atlassian installation identifier, available from the Atlassian administration console.

    • workspace (string) -- [REQUIRED]

      The Bitbucket workspace slug that identifies the workspace to integrate, for example acme-corp.

    • code (string) -- [REQUIRED]

      The OAuth 2.0 authorization code returned from the consent redirect.

    • state (string) -- [REQUIRED]

      The CSRF state token echoed back from the OAuth redirect.

  • confluence (dict) --

    The configuration for a Confluence integration.

    • installationId (string) -- [REQUIRED]

      The Atlassian installation identifier, available from the Atlassian administration console.

    • code (string) -- [REQUIRED]

      The OAuth 2.0 authorization code returned from the consent redirect.

    • state (string) -- [REQUIRED]

      The CSRF state token echoed back from the OAuth redirect.

    • siteUrl (string) -- [REQUIRED]

      The Confluence Cloud site URL, for example https://mysite.atlassian.net.

  • azureDevOps (dict) --

    The Azure DevOps-specific input for creating an integration.

    • code (string) -- [REQUIRED]

      The OAuth 2.0 authorization code returned to your redirect URL after the connection is authorized.

    • state (string) -- [REQUIRED]

      The CSRF state value returned by InitiateProviderRegistration and echoed back on the authorization redirect.

    • organizationName (string) -- [REQUIRED]

      The name of the Azure DevOps organization to connect, for example my-org.

  • bitbucketDataCenter (dict) --

    The Bitbucket Data Center-specific input for creating an integration.

    • targetUrl (string) -- [REQUIRED]

      The HTTPS URL of your Bitbucket Data Center instance, for example https://bitbucket.example.com.

    • code (string) -- [REQUIRED]

      The OAuth 2.0 authorization code returned to your redirect URL after the connection is authorized.

    • state (string) -- [REQUIRED]

      The CSRF state value returned by InitiateProviderRegistration and echoed back on the authorization redirect.

type integrationDisplayName:

string

param integrationDisplayName:

[REQUIRED]

The display name for the integration.

type kmsKeyId:

string

param kmsKeyId:

The identifier of the AWS KMS key to use for encrypting data associated with the integration.

type tags:

dict

param tags:

The tags to associate with the integration.

  • (string) --

    Key for a resource tag.

    • (string) --

      Value for a resource tag.

type privateConnectionName:

string

param privateConnectionName:

The name of an active private connection used to reach a self-hosted provider instance over private networking. Specify this when the instance is not publicly reachable.

rtype:

dict

returns:

Response Syntax

{
    'integrationId': 'string'
}

Response Structure

  • (dict) --

    • integrationId (string) --

      The unique identifier of the created integration.

GetIntegration (updated) Link ¶
Changes (response)
{'provider': {'AZURE_DEVOPS'}, 'webhookUrl': 'string'}

Retrieves information about an integration.

See also: AWS API Documentation

Request Syntax

client.get_integration(
    integrationId='string'
)
type integrationId:

string

param integrationId:

[REQUIRED]

The unique identifier of the integration to retrieve.

rtype:

dict

returns:

Response Syntax

{
    'integrationId': 'string',
    'installationId': 'string',
    'provider': 'GITHUB'|'GITLAB'|'BITBUCKET'|'CONFLUENCE'|'AZURE_DEVOPS',
    'providerType': 'SOURCE_CODE'|'DOCUMENTATION',
    'displayName': 'string',
    'kmsKeyId': 'string',
    'targetUrl': 'string',
    'webhookUrl': 'string',
    'privateConnectionName': 'string'
}

Response Structure

  • (dict) --

    • integrationId (string) --

      The unique identifier of the integration.

    • installationId (string) --

      The installation identifier from the integration provider.

    • provider (string) --

      The integration provider.

    • providerType (string) --

      The type of the integration provider.

    • displayName (string) --

      The display name of the integration.

    • kmsKeyId (string) --

      The identifier of the AWS KMS key used to encrypt data associated with the integration.

    • targetUrl (string) --

      The HTTPS URL of the customer self-hosted instance, such as a GitHub Enterprise Server or self-managed GitLab instance. This value is absent for SaaS integrations.

    • webhookUrl (string) --

      The payload URL of the integration's webhook, once it has been created. The signing secret is never returned on a read.

    • privateConnectionName (string) --

      The name of the private connection used to reach the integration's self-hosted instance over private networking, if one is configured.

InitiateProviderRegistration (updated) Link ¶
Changes (request)
{'clientId': 'string',
 'clientSecret': 'string',
 'organizationName': 'string',
 'provider': {'AZURE_DEVOPS'},
 'targetUrl': 'string'}

Initiates the OAuth registration flow with a third-party provider. Returns a redirect URL and CSRF state token for completing the authorization.

See also: AWS API Documentation

Request Syntax

client.initiate_provider_registration(
    provider='GITHUB'|'GITLAB'|'BITBUCKET'|'CONFLUENCE'|'AZURE_DEVOPS',
    targetUrl='string',
    organizationName='string',
    clientId='string',
    clientSecret='string'
)
type provider:

string

param provider:

[REQUIRED]

The provider to initiate registration with.

type targetUrl:

string

param targetUrl:

The HTTPS URL of a self-managed provider instance. Omit for SaaS providers.

type organizationName:

string

param organizationName:

The name of the organization to connect.

type clientId:

string

param clientId:

The client ID of the OAuth application registered on your self-managed provider instance.

type clientSecret:

string

param clientSecret:

The client secret of the OAuth application registered on your self-managed provider instance.

rtype:

dict

returns:

Response Syntax

{
    'redirectTo': 'string',
    'csrfState': 'string'
}

Response Structure

  • (dict) --

    • redirectTo (string) --

      The URL to redirect the user to for completing the OAuth authorization.

    • csrfState (string) --

      The CSRF state token to use when completing the OAuth flow.

ListIntegratedResources (updated) Link ¶
Changes (response)
{'integratedResourceSummaries': {'capabilities': {'azureDevOps': {'leaveComments': 'boolean',
                                                                  'remediateCode': 'boolean'}},
                                 'resource': {'azureDevOpsRepository': {'accessType': 'PRIVATE '
                                                                                      '| '
                                                                                      'PUBLIC',
                                                                        'name': 'string',
                                                                        'organization': 'string',
                                                                        'project': 'string',
                                                                        'projectId': 'string',
                                                                        'providerResourceId': 'string'}}}}

Lists the integrated resources for an agent space, optionally filtered by integration or resource type.

See also: AWS API Documentation

Request Syntax

client.list_integrated_resources(
    agentSpaceId='string',
    integrationId='string',
    resourceType='CODE_REPOSITORY'|'DOCUMENT',
    nextToken='string',
    maxResults=123
)
type agentSpaceId:

string

param agentSpaceId:

[REQUIRED]

The unique identifier of the agent space to list integrated resources for.

type integrationId:

string

param integrationId:

The unique identifier of the integration to filter by.

type resourceType:

string

param resourceType:

The type of resource to filter by.

type nextToken:

string

param nextToken:

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

type maxResults:

integer

param maxResults:

The maximum number of results to return in a single call.

rtype:

dict

returns:

Response Syntax

{
    'integratedResourceSummaries': [
        {
            'integrationId': 'string',
            'resource': {
                'githubRepository': {
                    'name': 'string',
                    'providerResourceId': 'string',
                    'owner': 'string',
                    'accessType': 'PRIVATE'|'PUBLIC'
                },
                'gitlabRepository': {
                    'name': 'string',
                    'providerResourceId': 'string',
                    'namespace': 'string',
                    'accessType': 'PRIVATE'|'PUBLIC'
                },
                'bitbucketRepository': {
                    'name': 'string',
                    'providerResourceId': 'string',
                    'workspace': 'string',
                    'accessType': 'PRIVATE'|'PUBLIC'
                },
                'confluenceDocument': {
                    'name': 'string',
                    'providerResourceId': 'string',
                    'spaceKey': 'string',
                    'pageId': 'string',
                    'title': 'string',
                    'spaceTitle': 'string'
                },
                'azureDevOpsRepository': {
                    'name': 'string',
                    'providerResourceId': 'string',
                    'organization': 'string',
                    'project': 'string',
                    'projectId': 'string',
                    'accessType': 'PRIVATE'|'PUBLIC'
                }
            },
            'capabilities': {
                'github': {
                    'leaveComments': True|False,
                    'remediateCode': True|False
                },
                'gitlab': {
                    'leaveComments': True|False,
                    'remediateCode': True|False
                },
                'bitbucket': {
                    'leaveComments': True|False,
                    'remediateCode': True|False
                },
                'confluence': {
                    'fetchDocument': True|False,
                    'createDocument': True|False,
                    'updateDocument': True|False
                },
                'azureDevOps': {
                    'leaveComments': True|False,
                    'remediateCode': True|False
                }
            }
        },
    ],
    'nextToken': 'string'
}

Response Structure

  • (dict) --

    • integratedResourceSummaries (list) --

      The list of integrated resource summaries.

      • (dict) --

        Contains summary information about an integrated resource.

        • integrationId (string) --

          The unique identifier of the integration that provides access to the resource.

        • resource (dict) --

          The metadata for the integrated resource.

          • githubRepository (dict) --

            The GitHub repository metadata.

            • name (string) --

              The name of the GitHub repository.

            • providerResourceId (string) --

              The provider-specific resource identifier for the GitHub repository.

            • owner (string) --

              The owner of the GitHub repository.

            • accessType (string) --

              The access type of the GitHub repository. Valid values are PRIVATE and PUBLIC.

          • gitlabRepository (dict) --

            Metadata for an integrated GitLab repository.

            • name (string) --

              Name of the resource e.g. repository name, etc.

            • providerResourceId (string) --

              Provider Id of the resource e.g. GitHub repository id, etc.

            • namespace (string) --

              The namespace (group or user path) that owns the project.

            • accessType (string) --

              Defines the visibility level of provider resources. PRIVATE indicates restricted access, while PUBLIC indicates open access.

          • bitbucketRepository (dict) --

            Metadata for an integrated Bitbucket repository.

            • name (string) --

              Name of the resource e.g. repository name, etc.

            • providerResourceId (string) --

              Provider Id of the resource e.g. GitHub repository id, etc.

            • workspace (string) --

              The workspace slug that owns the repository.

            • accessType (string) --

              Defines the visibility level of provider resources. PRIVATE indicates restricted access, while PUBLIC indicates open access.

          • confluenceDocument (dict) --

            Metadata for an integrated Confluence document.

            • name (string) --

              Name of the resource e.g. repository name, etc.

            • providerResourceId (string) --

              Provider Id of the resource e.g. GitHub repository id, etc.

            • spaceKey (string) --

              The Confluence space key containing the document.

            • pageId (string) --

              The Confluence page identifier.

            • title (string) --

              The display title of the Confluence page.

            • spaceTitle (string) --

              The display title of the Confluence space.

          • azureDevOpsRepository (dict) --

            The Azure DevOps repository metadata.

            • name (string) --

              Name of the resource e.g. repository name, etc.

            • providerResourceId (string) --

              Provider Id of the resource e.g. GitHub repository id, etc.

            • organization (string) --

              The name of the Azure DevOps organization that owns the repository.

            • project (string) --

              The name of the Azure DevOps project that contains the repository.

            • projectId (string) --

              The GUID of the Azure DevOps project that contains the repository.

            • accessType (string) --

              Defines the visibility level of provider resources. PRIVATE indicates restricted access, while PUBLIC indicates open access.

        • capabilities (dict) --

          The capabilities enabled for the integrated resource.

          • github (dict) --

            The GitHub-specific resource capabilities.

            • leaveComments (boolean) --

              Indicates whether the integration can leave comments on pull requests.

            • remediateCode (boolean) --

              Indicates whether the integration can create code remediation pull requests.

          • gitlab (dict) --

            Capabilities for an integrated GitLab repository.

            • leaveComments (boolean) --

              Whether to post code review comments on merge request discussions.

            • remediateCode (boolean) --

              Whether to create merge requests with automated fixes.

          • bitbucket (dict) --

            Capabilities for an integrated Bitbucket repository.

            • leaveComments (boolean) --

              Whether to post code review comments on pull requests.

            • remediateCode (boolean) --

              Whether to create pull requests with automated fixes.

          • confluence (dict) --

            Capabilities for an integrated Confluence space.

            • fetchDocument (boolean) --

              Whether to fetch documents from this space.

            • createDocument (boolean) --

              Whether to create documents in this space.

            • updateDocument (boolean) --

              Whether to update documents in this space.

          • azureDevOps (dict) --

            The Azure DevOps-specific resource capabilities.

            • leaveComments (boolean) --

              Whether to post code review comments on pull requests.

            • remediateCode (boolean) --

              Whether to create pull requests with automated fixes.

    • nextToken (string) --

      A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

ListIntegrations (updated) Link ¶
Changes (request, response)
Request
{'filter': {'provider': {'AZURE_DEVOPS'}}}
Response
{'integrationSummaries': {'provider': {'AZURE_DEVOPS'}, 'webhookUrl': 'string'}}

Lists the integrations in your account, optionally filtered by provider or provider type.

See also: AWS API Documentation

Request Syntax

client.list_integrations(
    filter={
        'provider': 'GITHUB'|'GITLAB'|'BITBUCKET'|'CONFLUENCE'|'AZURE_DEVOPS',
        'providerType': 'SOURCE_CODE'|'DOCUMENTATION'
    },
    nextToken='string',
    maxResults=123
)
type filter:

dict

param filter:

A filter to apply to the list of integrations.

  • provider (string) --

    Filter integrations by provider.

  • providerType (string) --

    Filter integrations by provider type.

type nextToken:

string

param nextToken:

A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

type maxResults:

integer

param maxResults:

The maximum number of results to return in a single call.

rtype:

dict

returns:

Response Syntax

{
    'integrationSummaries': [
        {
            'integrationId': 'string',
            'installationId': 'string',
            'provider': 'GITHUB'|'GITLAB'|'BITBUCKET'|'CONFLUENCE'|'AZURE_DEVOPS',
            'providerType': 'SOURCE_CODE'|'DOCUMENTATION',
            'displayName': 'string',
            'targetUrl': 'string',
            'webhookUrl': 'string',
            'privateConnectionName': 'string'
        },
    ],
    'nextToken': 'string'
}

Response Structure

  • (dict) --

    • integrationSummaries (list) --

      The list of integration summaries.

      • (dict) --

        Contains summary information about an integration.

        • integrationId (string) --

          The unique identifier of the integration.

        • installationId (string) --

          The installation identifier from the integration provider.

        • provider (string) --

          The integration provider.

        • providerType (string) --

          The type of the integration provider.

        • displayName (string) --

          The display name of the integration.

        • targetUrl (string) --

          The HTTPS URL of the customer self-hosted instance, such as a GitHub Enterprise Server or self-managed GitLab instance. This value is absent for SaaS integrations.

        • webhookUrl (string) --

          The payload URL of the integration's webhook, once it has been created. The signing secret is never returned on a read.

        • privateConnectionName (string) --

          The name of the private connection used to reach the integration's self-hosted instance over private networking, if one is configured.

    • nextToken (string) --

      A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.

UpdateIntegratedResources (updated) Link ¶
Changes (request)
{'items': {'capabilities': {'azureDevOps': {'leaveComments': 'boolean',
                                            'remediateCode': 'boolean'}},
           'resource': {'azureDevOpsRepository': {'name': 'string',
                                                  'organization': 'string',
                                                  'project': 'string'}}}}

Updates the integrated resources for an agent space, including their capabilities.

See also: AWS API Documentation

Request Syntax

client.update_integrated_resources(
    agentSpaceId='string',
    integrationId='string',
    items=[
        {
            'resource': {
                'githubRepository': {
                    'name': 'string',
                    'owner': 'string'
                },
                'gitlabRepository': {
                    'name': 'string',
                    'namespace': 'string'
                },
                'bitbucketRepository': {
                    'name': 'string',
                    'workspace': 'string'
                },
                'confluenceDocument': {
                    'name': 'string',
                    'spaceKey': 'string',
                    'pageId': 'string',
                    'title': 'string',
                    'spaceTitle': 'string'
                },
                'azureDevOpsRepository': {
                    'name': 'string',
                    'organization': 'string',
                    'project': 'string'
                }
            },
            'capabilities': {
                'github': {
                    'leaveComments': True|False,
                    'remediateCode': True|False
                },
                'gitlab': {
                    'leaveComments': True|False,
                    'remediateCode': True|False
                },
                'bitbucket': {
                    'leaveComments': True|False,
                    'remediateCode': True|False
                },
                'confluence': {
                    'fetchDocument': True|False,
                    'createDocument': True|False,
                    'updateDocument': True|False
                },
                'azureDevOps': {
                    'leaveComments': True|False,
                    'remediateCode': True|False
                }
            }
        },
    ]
)
type agentSpaceId:

string

param agentSpaceId:

[REQUIRED]

The unique identifier of the agent space.

type integrationId:

string

param integrationId:

[REQUIRED]

The unique identifier of the integration.

type items:

list

param items:

[REQUIRED]

The list of integrated resource items to update.

  • (dict) --

    Represents an input item for updating integrated resources, including the resource and its capabilities.

    • resource (dict) -- [REQUIRED]

      The integrated resource to update.

      • githubRepository (dict) --

        The GitHub repository resource information.

        • name (string) -- [REQUIRED]

          The name of the GitHub repository.

        • owner (string) -- [REQUIRED]

          The owner of the GitHub repository.

      • gitlabRepository (dict) --

        A GitLab repository integrated as a resource.

        • name (string) -- [REQUIRED]

          Name of the resource e.g. repository name, etc.

        • namespace (string) -- [REQUIRED]

          The namespace (group or user path) that owns the project.

      • bitbucketRepository (dict) --

        A Bitbucket repository integrated as a resource.

        • name (string) -- [REQUIRED]

          Name of the resource e.g. repository name, etc.

        • workspace (string) -- [REQUIRED]

          The workspace slug that owns the repository.

      • confluenceDocument (dict) --

        A Confluence document (page) integrated as a resource.

        • name (string) -- [REQUIRED]

          Name of the resource e.g. repository name, etc.

        • spaceKey (string) -- [REQUIRED]

          The Confluence space key containing the document.

        • pageId (string) -- [REQUIRED]

          The Confluence page identifier.

        • title (string) --

          The display title of the Confluence page.

        • spaceTitle (string) --

          The display title of the Confluence space.

      • azureDevOpsRepository (dict) --

        The Azure DevOps repository resource information.

        • name (string) -- [REQUIRED]

          Name of the resource e.g. repository name, etc.

        • organization (string) -- [REQUIRED]

          The name of the Azure DevOps organization that owns the repository.

        • project (string) --

          The name of the Azure DevOps project that contains the repository.

    • capabilities (dict) --

      The capabilities to enable for the integrated resource.

      • github (dict) --

        The GitHub-specific resource capabilities.

        • leaveComments (boolean) --

          Indicates whether the integration can leave comments on pull requests.

        • remediateCode (boolean) --

          Indicates whether the integration can create code remediation pull requests.

      • gitlab (dict) --

        Capabilities for an integrated GitLab repository.

        • leaveComments (boolean) --

          Whether to post code review comments on merge request discussions.

        • remediateCode (boolean) --

          Whether to create merge requests with automated fixes.

      • bitbucket (dict) --

        Capabilities for an integrated Bitbucket repository.

        • leaveComments (boolean) --

          Whether to post code review comments on pull requests.

        • remediateCode (boolean) --

          Whether to create pull requests with automated fixes.

      • confluence (dict) --

        Capabilities for an integrated Confluence space.

        • fetchDocument (boolean) --

          Whether to fetch documents from this space.

        • createDocument (boolean) --

          Whether to create documents in this space.

        • updateDocument (boolean) --

          Whether to update documents in this space.

      • azureDevOps (dict) --

        The Azure DevOps-specific resource capabilities.

        • leaveComments (boolean) --

          Whether to post code review comments on pull requests.

        • remediateCode (boolean) --

          Whether to create pull requests with automated fixes.

rtype:

dict

returns:

Response Syntax

{}

Response Structure

  • (dict) --