2026/09/29 - AWS Security Agent - 1 new 6 updated api methods
Changes Adds support for Azure DevOps and Bitbucket Data Center integration providers.
Creates an integration's webhook, or rotates the HMAC signing secret of an existing one. The secret is returned only once, in this response, and cannot be retrieved again.
See also: AWS API Documentation
Request Syntax
client.update_integration(
integrationId='string',
webhookAction='CREATE_IF_ABSENT'|'ROTATE'
)
string
[REQUIRED]
The ID of the integration whose webhook you want to create or rotate.
string
[REQUIRED]
The action to perform on the integration's webhook.
dict
Response Syntax
{
'integrationId': 'string',
'webhookUrl': 'string',
'secret': 'string'
}
Response Structure
(dict) --
Output for the UpdateIntegration operation.
integrationId (string) --
The ID of the integration.
webhookUrl (string) --
The payload URL to configure on your provider instance. Returned when a webhook is created; unchanged by a rotate.
secret (string) --
The HMAC signing secret for the webhook. Returned only once, in this response; it is never returned again.
{'input': {'azureDevOps': {'code': 'string',
'organizationName': 'string',
'state': 'string'},
'bitbucketDataCenter': {'code': 'string',
'state': 'string',
'targetUrl': 'string'}},
'provider': {'AZURE_DEVOPS'}}
Creates a new integration with a third-party provider, such as GitHub, for code review and remediation.
See also: AWS API Documentation
Request Syntax
client.create_integration(
provider='GITHUB'|'GITLAB'|'BITBUCKET'|'CONFLUENCE'|'AZURE_DEVOPS',
input={
'github': {
'code': 'string',
'state': 'string',
'organizationName': 'string',
'targetUrl': 'string',
'installationId': 'string'
},
'gitlab': {
'accessToken': 'string',
'targetUrl': 'string',
'tokenType': 'PERSONAL'|'GROUP',
'groupId': 'string'
},
'bitbucket': {
'installationId': 'string',
'workspace': 'string',
'code': 'string',
'state': 'string'
},
'confluence': {
'installationId': 'string',
'code': 'string',
'state': 'string',
'siteUrl': 'string'
},
'azureDevOps': {
'code': 'string',
'state': 'string',
'organizationName': 'string'
},
'bitbucketDataCenter': {
'targetUrl': 'string',
'code': 'string',
'state': 'string'
}
},
integrationDisplayName='string',
kmsKeyId='string',
tags={
'string': 'string'
},
privateConnectionName='string'
)
string
[REQUIRED]
The integration provider.
dict
[REQUIRED]
The provider-specific input required to create the integration.
github (dict) --
The GitHub-specific input for creating an integration.
code (string) -- [REQUIRED]
The OAuth authorization code received from GitHub.
state (string) -- [REQUIRED]
The CSRF state token for validating the OAuth flow.
organizationName (string) --
The name of the GitHub organization to integrate with.
targetUrl (string) --
The HTTPS URL of a self-hosted GitHub Enterprise Server instance. Omit this value for GitHub.com.
installationId (string) --
The installation identifier provided by GitHub Enterprise Server on the install callback. Required for GitHub Enterprise Server integrations and ignored for GitHub.com.
gitlab (dict) --
The configuration for a GitLab integration.
accessToken (string) -- [REQUIRED]
The GitLab access token used to authenticate. This can be a personal access token or a group access token.
targetUrl (string) --
The HTTPS URL of a self-managed GitLab instance. Omit this value for GitLab SaaS (gitlab.com).
tokenType (string) -- [REQUIRED]
The type of GitLab access token provided in accessToken.
groupId (string) --
The identifier of the GitLab group. Required when tokenType is group and ignored for personal tokens.
bitbucket (dict) --
The configuration for a Bitbucket integration.
installationId (string) -- [REQUIRED]
The Atlassian installation identifier, available from the Atlassian administration console.
workspace (string) -- [REQUIRED]
The Bitbucket workspace slug that identifies the workspace to integrate, for example acme-corp.
code (string) -- [REQUIRED]
The OAuth 2.0 authorization code returned from the consent redirect.
state (string) -- [REQUIRED]
The CSRF state token echoed back from the OAuth redirect.
confluence (dict) --
The configuration for a Confluence integration.
installationId (string) -- [REQUIRED]
The Atlassian installation identifier, available from the Atlassian administration console.
code (string) -- [REQUIRED]
The OAuth 2.0 authorization code returned from the consent redirect.
state (string) -- [REQUIRED]
The CSRF state token echoed back from the OAuth redirect.
siteUrl (string) -- [REQUIRED]
The Confluence Cloud site URL, for example https://mysite.atlassian.net.
azureDevOps (dict) --
The Azure DevOps-specific input for creating an integration.
code (string) -- [REQUIRED]
The OAuth 2.0 authorization code returned to your redirect URL after the connection is authorized.
state (string) -- [REQUIRED]
The CSRF state value returned by InitiateProviderRegistration and echoed back on the authorization redirect.
organizationName (string) -- [REQUIRED]
The name of the Azure DevOps organization to connect, for example my-org.
bitbucketDataCenter (dict) --
The Bitbucket Data Center-specific input for creating an integration.
targetUrl (string) -- [REQUIRED]
The HTTPS URL of your Bitbucket Data Center instance, for example https://bitbucket.example.com.
code (string) -- [REQUIRED]
The OAuth 2.0 authorization code returned to your redirect URL after the connection is authorized.
state (string) -- [REQUIRED]
The CSRF state value returned by InitiateProviderRegistration and echoed back on the authorization redirect.
string
[REQUIRED]
The display name for the integration.
string
The identifier of the AWS KMS key to use for encrypting data associated with the integration.
dict
The tags to associate with the integration.
(string) --
Key for a resource tag.
(string) --
Value for a resource tag.
string
The name of an active private connection used to reach a self-hosted provider instance over private networking. Specify this when the instance is not publicly reachable.
dict
Response Syntax
{
'integrationId': 'string'
}
Response Structure
(dict) --
integrationId (string) --
The unique identifier of the created integration.
{'provider': {'AZURE_DEVOPS'}, 'webhookUrl': 'string'}
Retrieves information about an integration.
See also: AWS API Documentation
Request Syntax
client.get_integration(
integrationId='string'
)
string
[REQUIRED]
The unique identifier of the integration to retrieve.
dict
Response Syntax
{
'integrationId': 'string',
'installationId': 'string',
'provider': 'GITHUB'|'GITLAB'|'BITBUCKET'|'CONFLUENCE'|'AZURE_DEVOPS',
'providerType': 'SOURCE_CODE'|'DOCUMENTATION',
'displayName': 'string',
'kmsKeyId': 'string',
'targetUrl': 'string',
'webhookUrl': 'string',
'privateConnectionName': 'string'
}
Response Structure
(dict) --
integrationId (string) --
The unique identifier of the integration.
installationId (string) --
The installation identifier from the integration provider.
provider (string) --
The integration provider.
providerType (string) --
The type of the integration provider.
displayName (string) --
The display name of the integration.
kmsKeyId (string) --
The identifier of the AWS KMS key used to encrypt data associated with the integration.
targetUrl (string) --
The HTTPS URL of the customer self-hosted instance, such as a GitHub Enterprise Server or self-managed GitLab instance. This value is absent for SaaS integrations.
webhookUrl (string) --
The payload URL of the integration's webhook, once it has been created. The signing secret is never returned on a read.
privateConnectionName (string) --
The name of the private connection used to reach the integration's self-hosted instance over private networking, if one is configured.
{'clientId': 'string',
'clientSecret': 'string',
'organizationName': 'string',
'provider': {'AZURE_DEVOPS'},
'targetUrl': 'string'}
Initiates the OAuth registration flow with a third-party provider. Returns a redirect URL and CSRF state token for completing the authorization.
See also: AWS API Documentation
Request Syntax
client.initiate_provider_registration(
provider='GITHUB'|'GITLAB'|'BITBUCKET'|'CONFLUENCE'|'AZURE_DEVOPS',
targetUrl='string',
organizationName='string',
clientId='string',
clientSecret='string'
)
string
[REQUIRED]
The provider to initiate registration with.
string
The HTTPS URL of a self-managed provider instance. Omit for SaaS providers.
string
The name of the organization to connect.
string
The client ID of the OAuth application registered on your self-managed provider instance.
string
The client secret of the OAuth application registered on your self-managed provider instance.
dict
Response Syntax
{
'redirectTo': 'string',
'csrfState': 'string'
}
Response Structure
(dict) --
redirectTo (string) --
The URL to redirect the user to for completing the OAuth authorization.
csrfState (string) --
The CSRF state token to use when completing the OAuth flow.
{'integratedResourceSummaries': {'capabilities': {'azureDevOps': {'leaveComments': 'boolean',
'remediateCode': 'boolean'}},
'resource': {'azureDevOpsRepository': {'accessType': 'PRIVATE '
'| '
'PUBLIC',
'name': 'string',
'organization': 'string',
'project': 'string',
'projectId': 'string',
'providerResourceId': 'string'}}}}
Lists the integrated resources for an agent space, optionally filtered by integration or resource type.
See also: AWS API Documentation
Request Syntax
client.list_integrated_resources(
agentSpaceId='string',
integrationId='string',
resourceType='CODE_REPOSITORY'|'DOCUMENT',
nextToken='string',
maxResults=123
)
string
[REQUIRED]
The unique identifier of the agent space to list integrated resources for.
string
The unique identifier of the integration to filter by.
string
The type of resource to filter by.
string
A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.
integer
The maximum number of results to return in a single call.
dict
Response Syntax
{
'integratedResourceSummaries': [
{
'integrationId': 'string',
'resource': {
'githubRepository': {
'name': 'string',
'providerResourceId': 'string',
'owner': 'string',
'accessType': 'PRIVATE'|'PUBLIC'
},
'gitlabRepository': {
'name': 'string',
'providerResourceId': 'string',
'namespace': 'string',
'accessType': 'PRIVATE'|'PUBLIC'
},
'bitbucketRepository': {
'name': 'string',
'providerResourceId': 'string',
'workspace': 'string',
'accessType': 'PRIVATE'|'PUBLIC'
},
'confluenceDocument': {
'name': 'string',
'providerResourceId': 'string',
'spaceKey': 'string',
'pageId': 'string',
'title': 'string',
'spaceTitle': 'string'
},
'azureDevOpsRepository': {
'name': 'string',
'providerResourceId': 'string',
'organization': 'string',
'project': 'string',
'projectId': 'string',
'accessType': 'PRIVATE'|'PUBLIC'
}
},
'capabilities': {
'github': {
'leaveComments': True|False,
'remediateCode': True|False
},
'gitlab': {
'leaveComments': True|False,
'remediateCode': True|False
},
'bitbucket': {
'leaveComments': True|False,
'remediateCode': True|False
},
'confluence': {
'fetchDocument': True|False,
'createDocument': True|False,
'updateDocument': True|False
},
'azureDevOps': {
'leaveComments': True|False,
'remediateCode': True|False
}
}
},
],
'nextToken': 'string'
}
Response Structure
(dict) --
integratedResourceSummaries (list) --
The list of integrated resource summaries.
(dict) --
Contains summary information about an integrated resource.
integrationId (string) --
The unique identifier of the integration that provides access to the resource.
resource (dict) --
The metadata for the integrated resource.
githubRepository (dict) --
The GitHub repository metadata.
name (string) --
The name of the GitHub repository.
providerResourceId (string) --
The provider-specific resource identifier for the GitHub repository.
owner (string) --
The owner of the GitHub repository.
accessType (string) --
The access type of the GitHub repository. Valid values are PRIVATE and PUBLIC.
gitlabRepository (dict) --
Metadata for an integrated GitLab repository.
name (string) --
Name of the resource e.g. repository name, etc.
providerResourceId (string) --
Provider Id of the resource e.g. GitHub repository id, etc.
namespace (string) --
The namespace (group or user path) that owns the project.
accessType (string) --
Defines the visibility level of provider resources. PRIVATE indicates restricted access, while PUBLIC indicates open access.
bitbucketRepository (dict) --
Metadata for an integrated Bitbucket repository.
name (string) --
Name of the resource e.g. repository name, etc.
providerResourceId (string) --
Provider Id of the resource e.g. GitHub repository id, etc.
workspace (string) --
The workspace slug that owns the repository.
accessType (string) --
Defines the visibility level of provider resources. PRIVATE indicates restricted access, while PUBLIC indicates open access.
confluenceDocument (dict) --
Metadata for an integrated Confluence document.
name (string) --
Name of the resource e.g. repository name, etc.
providerResourceId (string) --
Provider Id of the resource e.g. GitHub repository id, etc.
spaceKey (string) --
The Confluence space key containing the document.
pageId (string) --
The Confluence page identifier.
title (string) --
The display title of the Confluence page.
spaceTitle (string) --
The display title of the Confluence space.
azureDevOpsRepository (dict) --
The Azure DevOps repository metadata.
name (string) --
Name of the resource e.g. repository name, etc.
providerResourceId (string) --
Provider Id of the resource e.g. GitHub repository id, etc.
organization (string) --
The name of the Azure DevOps organization that owns the repository.
project (string) --
The name of the Azure DevOps project that contains the repository.
projectId (string) --
The GUID of the Azure DevOps project that contains the repository.
accessType (string) --
Defines the visibility level of provider resources. PRIVATE indicates restricted access, while PUBLIC indicates open access.
capabilities (dict) --
The capabilities enabled for the integrated resource.
github (dict) --
The GitHub-specific resource capabilities.
leaveComments (boolean) --
Indicates whether the integration can leave comments on pull requests.
remediateCode (boolean) --
Indicates whether the integration can create code remediation pull requests.
gitlab (dict) --
Capabilities for an integrated GitLab repository.
leaveComments (boolean) --
Whether to post code review comments on merge request discussions.
remediateCode (boolean) --
Whether to create merge requests with automated fixes.
bitbucket (dict) --
Capabilities for an integrated Bitbucket repository.
leaveComments (boolean) --
Whether to post code review comments on pull requests.
remediateCode (boolean) --
Whether to create pull requests with automated fixes.
confluence (dict) --
Capabilities for an integrated Confluence space.
fetchDocument (boolean) --
Whether to fetch documents from this space.
createDocument (boolean) --
Whether to create documents in this space.
updateDocument (boolean) --
Whether to update documents in this space.
azureDevOps (dict) --
The Azure DevOps-specific resource capabilities.
leaveComments (boolean) --
Whether to post code review comments on pull requests.
remediateCode (boolean) --
Whether to create pull requests with automated fixes.
nextToken (string) --
A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.
{'filter': {'provider': {'AZURE_DEVOPS'}}}
Response {'integrationSummaries': {'provider': {'AZURE_DEVOPS'}, 'webhookUrl': 'string'}}
Lists the integrations in your account, optionally filtered by provider or provider type.
See also: AWS API Documentation
Request Syntax
client.list_integrations(
filter={
'provider': 'GITHUB'|'GITLAB'|'BITBUCKET'|'CONFLUENCE'|'AZURE_DEVOPS',
'providerType': 'SOURCE_CODE'|'DOCUMENTATION'
},
nextToken='string',
maxResults=123
)
dict
A filter to apply to the list of integrations.
provider (string) --
Filter integrations by provider.
providerType (string) --
Filter integrations by provider type.
string
A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.
integer
The maximum number of results to return in a single call.
dict
Response Syntax
{
'integrationSummaries': [
{
'integrationId': 'string',
'installationId': 'string',
'provider': 'GITHUB'|'GITLAB'|'BITBUCKET'|'CONFLUENCE'|'AZURE_DEVOPS',
'providerType': 'SOURCE_CODE'|'DOCUMENTATION',
'displayName': 'string',
'targetUrl': 'string',
'webhookUrl': 'string',
'privateConnectionName': 'string'
},
],
'nextToken': 'string'
}
Response Structure
(dict) --
integrationSummaries (list) --
The list of integration summaries.
(dict) --
Contains summary information about an integration.
integrationId (string) --
The unique identifier of the integration.
installationId (string) --
The installation identifier from the integration provider.
provider (string) --
The integration provider.
providerType (string) --
The type of the integration provider.
displayName (string) --
The display name of the integration.
targetUrl (string) --
The HTTPS URL of the customer self-hosted instance, such as a GitHub Enterprise Server or self-managed GitLab instance. This value is absent for SaaS integrations.
webhookUrl (string) --
The payload URL of the integration's webhook, once it has been created. The signing secret is never returned on a read.
privateConnectionName (string) --
The name of the private connection used to reach the integration's self-hosted instance over private networking, if one is configured.
nextToken (string) --
A token to use for paginating results that are returned in the response. Set the value of this parameter to null for the first request. For subsequent calls, use the nextToken value returned from the previous request.
{'items': {'capabilities': {'azureDevOps': {'leaveComments': 'boolean',
'remediateCode': 'boolean'}},
'resource': {'azureDevOpsRepository': {'name': 'string',
'organization': 'string',
'project': 'string'}}}}
Updates the integrated resources for an agent space, including their capabilities.
See also: AWS API Documentation
Request Syntax
client.update_integrated_resources(
agentSpaceId='string',
integrationId='string',
items=[
{
'resource': {
'githubRepository': {
'name': 'string',
'owner': 'string'
},
'gitlabRepository': {
'name': 'string',
'namespace': 'string'
},
'bitbucketRepository': {
'name': 'string',
'workspace': 'string'
},
'confluenceDocument': {
'name': 'string',
'spaceKey': 'string',
'pageId': 'string',
'title': 'string',
'spaceTitle': 'string'
},
'azureDevOpsRepository': {
'name': 'string',
'organization': 'string',
'project': 'string'
}
},
'capabilities': {
'github': {
'leaveComments': True|False,
'remediateCode': True|False
},
'gitlab': {
'leaveComments': True|False,
'remediateCode': True|False
},
'bitbucket': {
'leaveComments': True|False,
'remediateCode': True|False
},
'confluence': {
'fetchDocument': True|False,
'createDocument': True|False,
'updateDocument': True|False
},
'azureDevOps': {
'leaveComments': True|False,
'remediateCode': True|False
}
}
},
]
)
string
[REQUIRED]
The unique identifier of the agent space.
string
[REQUIRED]
The unique identifier of the integration.
list
[REQUIRED]
The list of integrated resource items to update.
(dict) --
Represents an input item for updating integrated resources, including the resource and its capabilities.
resource (dict) -- [REQUIRED]
The integrated resource to update.
githubRepository (dict) --
The GitHub repository resource information.
name (string) -- [REQUIRED]
The name of the GitHub repository.
owner (string) -- [REQUIRED]
The owner of the GitHub repository.
gitlabRepository (dict) --
A GitLab repository integrated as a resource.
name (string) -- [REQUIRED]
Name of the resource e.g. repository name, etc.
namespace (string) -- [REQUIRED]
The namespace (group or user path) that owns the project.
bitbucketRepository (dict) --
A Bitbucket repository integrated as a resource.
name (string) -- [REQUIRED]
Name of the resource e.g. repository name, etc.
workspace (string) -- [REQUIRED]
The workspace slug that owns the repository.
confluenceDocument (dict) --
A Confluence document (page) integrated as a resource.
name (string) -- [REQUIRED]
Name of the resource e.g. repository name, etc.
spaceKey (string) -- [REQUIRED]
The Confluence space key containing the document.
pageId (string) -- [REQUIRED]
The Confluence page identifier.
title (string) --
The display title of the Confluence page.
spaceTitle (string) --
The display title of the Confluence space.
azureDevOpsRepository (dict) --
The Azure DevOps repository resource information.
name (string) -- [REQUIRED]
Name of the resource e.g. repository name, etc.
organization (string) -- [REQUIRED]
The name of the Azure DevOps organization that owns the repository.
project (string) --
The name of the Azure DevOps project that contains the repository.
capabilities (dict) --
The capabilities to enable for the integrated resource.
github (dict) --
The GitHub-specific resource capabilities.
leaveComments (boolean) --
Indicates whether the integration can leave comments on pull requests.
remediateCode (boolean) --
Indicates whether the integration can create code remediation pull requests.
gitlab (dict) --
Capabilities for an integrated GitLab repository.
leaveComments (boolean) --
Whether to post code review comments on merge request discussions.
remediateCode (boolean) --
Whether to create merge requests with automated fixes.
bitbucket (dict) --
Capabilities for an integrated Bitbucket repository.
leaveComments (boolean) --
Whether to post code review comments on pull requests.
remediateCode (boolean) --
Whether to create pull requests with automated fixes.
confluence (dict) --
Capabilities for an integrated Confluence space.
fetchDocument (boolean) --
Whether to fetch documents from this space.
createDocument (boolean) --
Whether to create documents in this space.
updateDocument (boolean) --
Whether to update documents in this space.
azureDevOps (dict) --
The Azure DevOps-specific resource capabilities.
leaveComments (boolean) --
Whether to post code review comments on pull requests.
remediateCode (boolean) --
Whether to create pull requests with automated fixes.
dict
Response Syntax
{}
Response Structure
(dict) --