Skip to main content

Capability Mapper · MAP

What could an AI agent do through this API?

Capability Mapper translates each documented OpenAPI operation into deterministic capability metadata: access type, risk tags, authentication state, permission alternatives, and sensitive-data context.

01Input → output

Turn operations into a capability inventory.

The mapper reuses the canonical OpenAPI operation surface. One capability represents one documented path and HTTP method.

INPUTopenapi.yaml

Paths, methods, security requirements

MAPPERoperation → capability

Deterministic static classification

OUTPUTagent-capabilities 1.0

Terminal + JSON

02Illustrative result

See capability, context, and documented controls together.

This example shows the shape of output, not customer data or runtime proof.

CAPABILITY / EXAMPLE
POST /refunds
accesswrite
risk_tagsfinancial, privileged
auth_statemandatory
permission_alternativesrefunds:write
Illustrative output — not customer data
03Use cases

Answer the tool-access question before wiring the tool.

Use the inventory during agent tool design, AppSec review, API contract review, or as the foundation for Readiness.

01

Agent builders

See which documented actions become potential agent tools.

02

AppSec

Review destructive, privileged, financial, object-access, and sensitive-data tags.

03

API teams

Find missing or unclear security metadata in the contract surface.

Static scope

Documented capability is not runtime authorization.

Documented permission alternatives are descriptive metadata. Capability Mapper does not prove the agent can reach an operation or that the server enforces the declared authorization.

Read the technical trust model →
$99 · ONE-TIME PURCHASE

Map the capability surface first.

Capability Mapper is a one-time Agent Security purchase with the capability_mapper entitlement.