Critical-risk tools in API-Central
42 of the 590 tools in API-Central are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
aos8_execute_migration_rollbackDestructiveaos8_execute_migration_rollback
-
aos8_logoutDestructiveLog out of AOS8/Mobility Conductor and clear the cached session, if any.
-
apstra_delete_connectivity_templateDestructiveDelete one Apstra connectivity template by ID.
-
clear_alertsDestructiveClear one or more alerts by key. Returns the Central async task payload.
-
clearpass_delete_endpointDestructiveDelete a ClearPass endpoint by MAC address.
-
clearpass_delete_guestDestructiveDelete a ClearPass guest account by username or ID.
-
delete_aaa_profileDestructiveDelete an AAA profile by name.
-
delete_auth_profileDestructiveDelete a Central NAC authentication profile by UUID.
-
delete_auth_serverDestructiveDelete a RADIUS/auth server profile by name.
-
delete_authz_policyDestructiveDelete a CNAC authz policy by ID.
-
delete_config_assignmentDestructivedelete_config_assignment
-
delete_device_groupsDestructiveBulk-delete device groups by scope ID list.
-
delete_device_notesDestructiveClear notes on a device by serial number (sets notes to an empty string).
-
delete_glp_role_assignmentDestructiveDelete an RBAC role assignment by ID.
-
delete_glp_scope_groupDestructiveDelete an RBAC scope group by ID.
-
delete_glp_scope_group_scopesDestructivedelete_glp_scope_group_scopes
-
delete_gw_policyDestructiveDelete a GW security policy by name.
-
delete_mac_registrationDestructiveDelete a MAC registration by ID.
-
delete_mpsk_registrationDestructiveDelete a Named MPSK registration by ID.
-
delete_network_profileDestructiveDelete a network-config library profile by name. See get_network_profile for profile_type.
-
delete_notification_ruleDestructiveDelete a notification rule by ID. UNCONFIRMED endpoint shape — see module note above.
-
delete_overlay_ssidDestructivedelete_overlay_ssid
-
delete_reportDestructivedelete_report
-
delete_report_runDestructivedelete_report_run
-
delete_roleDestructivedelete_role
-
delete_role_aclDestructiveDelete a role ACL policy by name. Must precede delete_role.
-
delete_server_groupDestructiveDelete an auth server group by name.
-
delete_site_collections_bulkDestructivedelete_site_collections_bulk
-
delete_sites_bulkDestructivedelete_sites_bulk
-
delete_static_tagDestructiveDelete a static classification tag by UUID.
-
delete_underlay_ssidDestructiveDelete an underlay SSID and its scope-map.
-
delete_visitorDestructiveDelete a visitor account by ID.
-
delete_vsf_templateDestructivedelete_vsf_template
-
delete_webhookDestructiveDelete a webhook by ID.
-
disassociate_glp_userDestructiveRemove (disassociate) a user from the GLP workspace.
-
edgeconnect_delete_address_groupDestructiveDelete an EdgeConnect ACL address group by name with write guards.
-
edgeconnect_delete_service_groupDestructiveDelete an EdgeConnect ACL service group by name with write guards.
-
gateway_haltDestructiveHalt an Aruba gateway (POST .../halt). Requires elicited confirmation — this stops
-
glp_archive_deviceDestructiveglp_archive_device
-
mist_delete_wlanDestructiveDelete one Mist site WLAN.
-
uxi_delete_agentDestructiveDelete/decommission a UXI agent by ID; requires read-write access.
-
uxi_delete_groupDestructiveDelete a UXI group by ID; requires read-write access.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.