Read API definitions and versions, then change access with approval
Connect Swaggerhub and your agent can read the things you normally open a browser tab for: API and domain versions, the default version, the OpenAPI definition behind a given version, and who currently holds access on a resource. When something needs to change, like granting a team read access before a review, the agent shows the call first and waits for your approval. Authentication is by API key.
44 tools: 35 read, 9 write. Reads answer instantly. Writes require approval by default. Everything is logged.
What a governed Swaggerhub run looks like inside Luumen.
Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.
Read actions answer immediately. Anything that writes — add access control for teams, add access control for users, delete table of contents entry, remove access control for teams, and more — is shown as a plan and requires approval by default, including the 4 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.
You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.
Every call to Swaggerhub — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.
Connect in minutes. Every action scoped, approved, and audited from day one.