1. Registry
  2. Packages
  3. Incapsula Provider
  4. API Docs
  5. AiApplicationSecurityApplication
Viewing docs for incapsula 3.40.0
published on Tuesday, Sep 15, 2026 by imperva
Viewing docs for incapsula 3.40.0
published on Tuesday, Sep 15, 2026 by imperva

    Provides an Imperva AI Application Security application resource.

    An AI Application Security application represents a protected AI/LLM endpoint. The deployment type (application_type) determines how traffic reaches the application:

    • SDK - traffic is inspected via the Inline Reverse Proxy integrated into your application.
    • API - traffic is inspected via the AI Application Security API.
    • EDGE - traffic is inspected inline at the edge. This type requires a configuration block describing how to extract prompts and responses.

    Example Usage

    SDK Application

    import * as pulumi from "@pulumi/pulumi";
    import * as incapsula from "@pulumi/incapsula";
    
    const sdkApp = new incapsula.AiApplicationSecurityApplication("sdk_app", {
        accountId: 1234567,
        name: "my-sdk-app",
        applicationType: "SDK",
        region: "US",
    });
    
    import pulumi
    import pulumi_incapsula as incapsula
    
    sdk_app = incapsula.AiApplicationSecurityApplication("sdk_app",
        account_id=1234567,
        name="my-sdk-app",
        application_type="SDK",
        region="US")
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-terraform-provider/sdks/go/incapsula/v3/incapsula"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		_, err := incapsula.NewAiApplicationSecurityApplication(ctx, "sdk_app", &incapsula.AiApplicationSecurityApplicationArgs{
    			AccountId:       pulumi.Float64(1234567),
    			Name:            pulumi.String("my-sdk-app"),
    			ApplicationType: pulumi.String("SDK"),
    			Region:          pulumi.String("US"),
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Incapsula = Pulumi.Incapsula;
    
    return await Deployment.RunAsync(() => 
    {
        var sdkApp = new Incapsula.AiApplicationSecurityApplication("sdk_app", new()
        {
            AccountId = 1234567,
            Name = "my-sdk-app",
            ApplicationType = "SDK",
            Region = "US",
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.incapsula.AiApplicationSecurityApplication;
    import com.pulumi.incapsula.AiApplicationSecurityApplicationArgs;
    import java.util.List;
    import java.util.ArrayList;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var sdkApp = new AiApplicationSecurityApplication("sdkApp", AiApplicationSecurityApplicationArgs.builder()
                .accountId(1234567.0)
                .name("my-sdk-app")
                .applicationType("SDK")
                .region("US")
                .build());
    
        }
    }
    
    resources:
      sdkApp:
        type: incapsula:AiApplicationSecurityApplication
        name: sdk_app
        properties:
          accountId: 1.234567e+06
          name: my-sdk-app
          applicationType: SDK
          region: US
    
    Example coming soon!
    

    API Application

    import * as pulumi from "@pulumi/pulumi";
    import * as incapsula from "@pulumi/incapsula";
    
    const apiApp = new incapsula.AiApplicationSecurityApplication("api_app", {
        accountId: 1234567,
        name: "my-api-app",
        applicationType: "API",
        region: "EU",
    });
    
    import pulumi
    import pulumi_incapsula as incapsula
    
    api_app = incapsula.AiApplicationSecurityApplication("api_app",
        account_id=1234567,
        name="my-api-app",
        application_type="API",
        region="EU")
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-terraform-provider/sdks/go/incapsula/v3/incapsula"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		_, err := incapsula.NewAiApplicationSecurityApplication(ctx, "api_app", &incapsula.AiApplicationSecurityApplicationArgs{
    			AccountId:       pulumi.Float64(1234567),
    			Name:            pulumi.String("my-api-app"),
    			ApplicationType: pulumi.String("API"),
    			Region:          pulumi.String("EU"),
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Incapsula = Pulumi.Incapsula;
    
    return await Deployment.RunAsync(() => 
    {
        var apiApp = new Incapsula.AiApplicationSecurityApplication("api_app", new()
        {
            AccountId = 1234567,
            Name = "my-api-app",
            ApplicationType = "API",
            Region = "EU",
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.incapsula.AiApplicationSecurityApplication;
    import com.pulumi.incapsula.AiApplicationSecurityApplicationArgs;
    import java.util.List;
    import java.util.ArrayList;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var apiApp = new AiApplicationSecurityApplication("apiApp", AiApplicationSecurityApplicationArgs.builder()
                .accountId(1234567.0)
                .name("my-api-app")
                .applicationType("API")
                .region("EU")
                .build());
    
        }
    }
    
    resources:
      apiApp:
        type: incapsula:AiApplicationSecurityApplication
        name: api_app
        properties:
          accountId: 1.234567e+06
          name: my-api-app
          applicationType: API
          region: EU
    
    Example coming soon!
    

    EDGE Application

    An EDGE application requires a configuration block:

    import * as pulumi from "@pulumi/pulumi";
    import * as incapsula from "@pulumi/incapsula";
    
    const edgeApp = new incapsula.AiApplicationSecurityApplication("edge_app", {
        accountId: 1234567,
        name: "my-edge-app",
        applicationType: "EDGE",
        region: "US",
        configuration: {
            siteId: 987654,
            path: "/v1/chat/completions",
            contentType: "application/json",
            promptLocation: "$.body",
            blockedResponseStructure: JSON.stringify({
                error: "$BLOCKED_MESSAGE",
            }),
            isStreaming: false,
            request: {
                messagePath: "$.messages",
                contentPath: "$.content",
                rolePath: "$.role",
            },
            response: {
                rolePath: "$.choices.0.message.role",
                contentPath: "$.choices.0.message.content",
                finishReasonPath: "$.choices.0.finish_reason",
                finishReasonValue: "$.stop",
                endOfStreamMarker: "[DONE]",
            },
        },
    });
    
    import pulumi
    import json
    import pulumi_incapsula as incapsula
    
    edge_app = incapsula.AiApplicationSecurityApplication("edge_app",
        account_id=1234567,
        name="my-edge-app",
        application_type="EDGE",
        region="US",
        configuration={
            "site_id": 987654,
            "path": "/v1/chat/completions",
            "content_type": "application/json",
            "prompt_location": "$.body",
            "blocked_response_structure": json.dumps({
                "error": "$BLOCKED_MESSAGE",
            }),
            "is_streaming": False,
            "request": {
                "message_path": "$.messages",
                "content_path": "$.content",
                "role_path": "$.role",
            },
            "response": {
                "role_path": "$.choices.0.message.role",
                "content_path": "$.choices.0.message.content",
                "finish_reason_path": "$.choices.0.finish_reason",
                "finish_reason_value": "$.stop",
                "end_of_stream_marker": "[DONE]",
            },
        })
    
    package main
    
    import (
    	"encoding/json"
    
    	"github.com/pulumi/pulumi-terraform-provider/sdks/go/incapsula/v3/incapsula"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		tmpJSON0, err := json.Marshal(map[string]interface{}{
    			"error": "$BLOCKED_MESSAGE",
    		})
    		if err != nil {
    			return err
    		}
    		json0 := string(tmpJSON0)
    		_, err = incapsula.NewAiApplicationSecurityApplication(ctx, "edge_app", &incapsula.AiApplicationSecurityApplicationArgs{
    			AccountId:       pulumi.Float64(1234567),
    			Name:            pulumi.String("my-edge-app"),
    			ApplicationType: pulumi.String("EDGE"),
    			Region:          pulumi.String("US"),
    			Configuration: &incapsula.AiApplicationSecurityApplicationConfigurationArgs{
    				SiteId:                   pulumi.Float64(987654),
    				Path:                     pulumi.String("/v1/chat/completions"),
    				ContentType:              pulumi.String("application/json"),
    				PromptLocation:           pulumi.String("$.body"),
    				BlockedResponseStructure: pulumi.String(json0),
    				IsStreaming:              pulumi.Bool(false),
    				Request: &incapsula.AiApplicationSecurityApplicationConfigurationRequestArgs{
    					MessagePath: pulumi.String("$.messages"),
    					ContentPath: pulumi.String("$.content"),
    					RolePath:    pulumi.String("$.role"),
    				},
    				Response: &incapsula.AiApplicationSecurityApplicationConfigurationResponseArgs{
    					RolePath:          pulumi.String("$.choices.0.message.role"),
    					ContentPath:       pulumi.String("$.choices.0.message.content"),
    					FinishReasonPath:  pulumi.String("$.choices.0.finish_reason"),
    					FinishReasonValue: pulumi.String("$.stop"),
    					EndOfStreamMarker: pulumi.String("[DONE]"),
    				},
    			},
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using System.Text.Json;
    using Pulumi;
    using Incapsula = Pulumi.Incapsula;
    
    return await Deployment.RunAsync(() => 
    {
        var edgeApp = new Incapsula.AiApplicationSecurityApplication("edge_app", new()
        {
            AccountId = 1234567,
            Name = "my-edge-app",
            ApplicationType = "EDGE",
            Region = "US",
            Configuration = new Incapsula.Inputs.AiApplicationSecurityApplicationConfigurationArgs
            {
                SiteId = 987654,
                Path = "/v1/chat/completions",
                ContentType = "application/json",
                PromptLocation = "$.body",
                BlockedResponseStructure = JsonSerializer.Serialize(new Dictionary<string, object?>
                {
                    ["error"] = "$BLOCKED_MESSAGE",
                }),
                IsStreaming = false,
                Request = new Incapsula.Inputs.AiApplicationSecurityApplicationConfigurationRequestArgs
                {
                    MessagePath = "$.messages",
                    ContentPath = "$.content",
                    RolePath = "$.role",
                },
                Response = new Incapsula.Inputs.AiApplicationSecurityApplicationConfigurationResponseArgs
                {
                    RolePath = "$.choices.0.message.role",
                    ContentPath = "$.choices.0.message.content",
                    FinishReasonPath = "$.choices.0.finish_reason",
                    FinishReasonValue = "$.stop",
                    EndOfStreamMarker = "[DONE]",
                },
            },
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.incapsula.AiApplicationSecurityApplication;
    import com.pulumi.incapsula.AiApplicationSecurityApplicationArgs;
    import com.pulumi.incapsula.inputs.AiApplicationSecurityApplicationConfigurationArgs;
    import com.pulumi.incapsula.inputs.AiApplicationSecurityApplicationConfigurationRequestArgs;
    import com.pulumi.incapsula.inputs.AiApplicationSecurityApplicationConfigurationResponseArgs;
    import static com.pulumi.codegen.internal.Serialization.*;
    import java.util.List;
    import java.util.ArrayList;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var edgeApp = new AiApplicationSecurityApplication("edgeApp", AiApplicationSecurityApplicationArgs.builder()
                .accountId(1234567.0)
                .name("my-edge-app")
                .applicationType("EDGE")
                .region("US")
                .configuration(AiApplicationSecurityApplicationConfigurationArgs.builder()
                    .siteId(987654.0)
                    .path("/v1/chat/completions")
                    .contentType("application/json")
                    .promptLocation("$.body")
                    .blockedResponseStructure(serializeJson(
                        jsonObject(
                            jsonProperty("error", "$BLOCKED_MESSAGE")
                        )))
                    .isStreaming(false)
                    .request(AiApplicationSecurityApplicationConfigurationRequestArgs.builder()
                        .messagePath("$.messages")
                        .contentPath("$.content")
                        .rolePath("$.role")
                        .build())
                    .response(AiApplicationSecurityApplicationConfigurationResponseArgs.builder()
                        .rolePath("$.choices.0.message.role")
                        .contentPath("$.choices.0.message.content")
                        .finishReasonPath("$.choices.0.finish_reason")
                        .finishReasonValue("$.stop")
                        .endOfStreamMarker("[DONE]")
                        .build())
                    .build())
                .build());
    
        }
    }
    
    resources:
      edgeApp:
        type: incapsula:AiApplicationSecurityApplication
        name: edge_app
        properties:
          accountId: 1.234567e+06
          name: my-edge-app
          applicationType: EDGE
          region: US
          configuration:
            siteId: 987654
            path: /v1/chat/completions
            contentType: application/json
            promptLocation: $.body
            blockedResponseStructure:
              fn::toJSON:
                error: $BLOCKED_MESSAGE
            isStreaming: false
            request:
              messagePath: $.messages
              contentPath: $.content
              rolePath: $.role
            response:
              rolePath: $.choices.0.message.role
              contentPath: $.choices.0.message.content
              finishReasonPath: $.choices.0.finish_reason
              finishReasonValue: $.stop
              endOfStreamMarker: '[DONE]'
    
    Example coming soon!
    

    JSONPath required. Every path field in the configuration block (prompt_location, and the request / response *_path fields) must be a valid JSONPath expression starting with $. blocked_response_structure must contain the literal $BLOCKED_MESSAGE placeholder, which the service replaces with the block reason at runtime.

    Create AiApplicationSecurityApplication Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new AiApplicationSecurityApplication(name: string, args: AiApplicationSecurityApplicationArgs, opts?: CustomResourceOptions);
    @overload
    def AiApplicationSecurityApplication(resource_name: str,
                                         args: AiApplicationSecurityApplicationArgs,
                                         opts: Optional[ResourceOptions] = None)
    
    @overload
    def AiApplicationSecurityApplication(resource_name: str,
                                         opts: Optional[ResourceOptions] = None,
                                         application_type: Optional[str] = None,
                                         account_id: Optional[float] = None,
                                         ai_application_security_application_id: Optional[str] = None,
                                         configuration: Optional[AiApplicationSecurityApplicationConfigurationArgs] = None,
                                         name: Optional[str] = None,
                                         region: Optional[str] = None)
    func NewAiApplicationSecurityApplication(ctx *Context, name string, args AiApplicationSecurityApplicationArgs, opts ...ResourceOption) (*AiApplicationSecurityApplication, error)
    public AiApplicationSecurityApplication(string name, AiApplicationSecurityApplicationArgs args, CustomResourceOptions? opts = null)
    public AiApplicationSecurityApplication(String name, AiApplicationSecurityApplicationArgs args)
    public AiApplicationSecurityApplication(String name, AiApplicationSecurityApplicationArgs args, CustomResourceOptions options)
    
    type: incapsula:AiApplicationSecurityApplication
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    
    resource "incapsula_ai_application_security_application" "name" {
        # resource properties
    }

    Parameters

    name string
    The unique name of the resource.
    args AiApplicationSecurityApplicationArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args AiApplicationSecurityApplicationArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args AiApplicationSecurityApplicationArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args AiApplicationSecurityApplicationArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args AiApplicationSecurityApplicationArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    Constructor example

    The following reference example uses placeholder values for all input properties.

    var aiApplicationSecurityApplicationResource = new Incapsula.AiApplicationSecurityApplication("aiApplicationSecurityApplicationResource", new()
    {
        ApplicationType = "string",
        AccountId = 0.0,
        AiApplicationSecurityApplicationId = "string",
        Configuration = new Incapsula.Inputs.AiApplicationSecurityApplicationConfigurationArgs
        {
            BlockedResponseStructure = "string",
            ContentType = "string",
            IsStreaming = false,
            Path = "string",
            PromptLocation = "string",
            Request = new Incapsula.Inputs.AiApplicationSecurityApplicationConfigurationRequestArgs
            {
                ContentPath = "string",
                MessagePath = "string",
                RolePath = "string",
            },
            Response = new Incapsula.Inputs.AiApplicationSecurityApplicationConfigurationResponseArgs
            {
                ContentPath = "string",
                EndOfStreamMarker = "string",
                FinishReasonPath = "string",
                FinishReasonValue = "string",
                RolePath = "string",
            },
            SiteId = 0.0,
        },
        Name = "string",
        Region = "string",
    });
    
    example, err := incapsula.NewAiApplicationSecurityApplication(ctx, "aiApplicationSecurityApplicationResource", &incapsula.AiApplicationSecurityApplicationArgs{
    	ApplicationType:                    pulumi.String("string"),
    	AccountId:                          pulumi.Float64(0),
    	AiApplicationSecurityApplicationId: pulumi.String("string"),
    	Configuration: &incapsula.AiApplicationSecurityApplicationConfigurationArgs{
    		BlockedResponseStructure: pulumi.String("string"),
    		ContentType:              pulumi.String("string"),
    		IsStreaming:              pulumi.Bool(false),
    		Path:                     pulumi.String("string"),
    		PromptLocation:           pulumi.String("string"),
    		Request: &incapsula.AiApplicationSecurityApplicationConfigurationRequestArgs{
    			ContentPath: pulumi.String("string"),
    			MessagePath: pulumi.String("string"),
    			RolePath:    pulumi.String("string"),
    		},
    		Response: &incapsula.AiApplicationSecurityApplicationConfigurationResponseArgs{
    			ContentPath:       pulumi.String("string"),
    			EndOfStreamMarker: pulumi.String("string"),
    			FinishReasonPath:  pulumi.String("string"),
    			FinishReasonValue: pulumi.String("string"),
    			RolePath:          pulumi.String("string"),
    		},
    		SiteId: pulumi.Float64(0),
    	},
    	Name:   pulumi.String("string"),
    	Region: pulumi.String("string"),
    })
    
    resource "incapsula_ai_application_security_application" "aiApplicationSecurityApplicationResource" {
      lifecycle {
        create_before_destroy = true
      }
      application_type                       = "string"
      account_id                             = 0
      ai_application_security_application_id = "string"
      configuration = {
        blocked_response_structure = "string"
        content_type               = "string"
        is_streaming               = false
        path                       = "string"
        prompt_location            = "string"
        request = {
          content_path = "string"
          message_path = "string"
          role_path    = "string"
        }
        response = {
          content_path         = "string"
          end_of_stream_marker = "string"
          finish_reason_path   = "string"
          finish_reason_value  = "string"
          role_path            = "string"
        }
        site_id = 0
      }
      name   = "string"
      region = "string"
    }
    
    var aiApplicationSecurityApplicationResource = new AiApplicationSecurityApplication("aiApplicationSecurityApplicationResource", AiApplicationSecurityApplicationArgs.builder()
        .applicationType("string")
        .accountId(0.0)
        .aiApplicationSecurityApplicationId("string")
        .configuration(AiApplicationSecurityApplicationConfigurationArgs.builder()
            .blockedResponseStructure("string")
            .contentType("string")
            .isStreaming(false)
            .path("string")
            .promptLocation("string")
            .request(AiApplicationSecurityApplicationConfigurationRequestArgs.builder()
                .contentPath("string")
                .messagePath("string")
                .rolePath("string")
                .build())
            .response(AiApplicationSecurityApplicationConfigurationResponseArgs.builder()
                .contentPath("string")
                .endOfStreamMarker("string")
                .finishReasonPath("string")
                .finishReasonValue("string")
                .rolePath("string")
                .build())
            .siteId(0.0)
            .build())
        .name("string")
        .region("string")
        .build());
    
    ai_application_security_application_resource = incapsula.AiApplicationSecurityApplication("aiApplicationSecurityApplicationResource",
        application_type="string",
        account_id=float(0),
        ai_application_security_application_id="string",
        configuration={
            "blocked_response_structure": "string",
            "content_type": "string",
            "is_streaming": False,
            "path": "string",
            "prompt_location": "string",
            "request": {
                "content_path": "string",
                "message_path": "string",
                "role_path": "string",
            },
            "response": {
                "content_path": "string",
                "end_of_stream_marker": "string",
                "finish_reason_path": "string",
                "finish_reason_value": "string",
                "role_path": "string",
            },
            "site_id": float(0),
        },
        name="string",
        region="string")
    
    const aiApplicationSecurityApplicationResource = new incapsula.AiApplicationSecurityApplication("aiApplicationSecurityApplicationResource", {
        applicationType: "string",
        accountId: 0,
        aiApplicationSecurityApplicationId: "string",
        configuration: {
            blockedResponseStructure: "string",
            contentType: "string",
            isStreaming: false,
            path: "string",
            promptLocation: "string",
            request: {
                contentPath: "string",
                messagePath: "string",
                rolePath: "string",
            },
            response: {
                contentPath: "string",
                endOfStreamMarker: "string",
                finishReasonPath: "string",
                finishReasonValue: "string",
                rolePath: "string",
            },
            siteId: 0,
        },
        name: "string",
        region: "string",
    });
    
    type: incapsula:AiApplicationSecurityApplication
    properties:
        accountId: 0
        aiApplicationSecurityApplicationId: string
        applicationType: string
        configuration:
            blockedResponseStructure: string
            contentType: string
            isStreaming: false
            path: string
            promptLocation: string
            request:
                contentPath: string
                messagePath: string
                rolePath: string
            response:
                contentPath: string
                endOfStreamMarker: string
                finishReasonPath: string
                finishReasonValue: string
                rolePath: string
            siteId: 0
        name: string
        region: string
    

    AiApplicationSecurityApplication Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

    The AiApplicationSecurityApplication resource accepts the following input properties:

    ApplicationType string
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    AccountId double
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    AiApplicationSecurityApplicationId string
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    Configuration AiApplicationSecurityApplicationConfiguration
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    Name string
    Name of the AI Application Security application.
    Region string
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
    ApplicationType string
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    AccountId float64
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    AiApplicationSecurityApplicationId string
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    Configuration AiApplicationSecurityApplicationConfigurationArgs
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    Name string
    Name of the AI Application Security application.
    Region string
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
    application_type string
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    account_id number
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    ai_application_security_application_id string
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    configuration object
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    name string
    Name of the AI Application Security application.
    region string
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
    applicationType String
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    accountId Double
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    aiApplicationSecurityApplicationId String
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    configuration AiApplicationSecurityApplicationConfiguration
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    name String
    Name of the AI Application Security application.
    region String
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
    applicationType string
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    accountId number
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    aiApplicationSecurityApplicationId string
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    configuration AiApplicationSecurityApplicationConfiguration
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    name string
    Name of the AI Application Security application.
    region string
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
    application_type str
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    account_id float
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    ai_application_security_application_id str
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    configuration AiApplicationSecurityApplicationConfigurationArgs
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    name str
    Name of the AI Application Security application.
    region str
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
    applicationType String
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    accountId Number
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    aiApplicationSecurityApplicationId String
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    configuration Property Map
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    name String
    Name of the AI Application Security application.
    region String
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.

    Outputs

    All input properties are implicitly available as output properties. Additionally, the AiApplicationSecurityApplication resource produces the following output properties:

    Id string
    The provider-assigned unique ID for this managed resource.
    Id string
    The provider-assigned unique ID for this managed resource.
    id string
    The provider-assigned unique ID for this managed resource.
    id String
    The provider-assigned unique ID for this managed resource.
    id string
    The provider-assigned unique ID for this managed resource.
    id str
    The provider-assigned unique ID for this managed resource.
    id String
    The provider-assigned unique ID for this managed resource.

    Look up Existing AiApplicationSecurityApplication Resource

    Get an existing AiApplicationSecurityApplication resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.

    public static get(name: string, id: Input<ID>, state?: AiApplicationSecurityApplicationState, opts?: CustomResourceOptions): AiApplicationSecurityApplication
    @staticmethod
    def get(resource_name: str,
            id: str,
            opts: Optional[ResourceOptions] = None,
            account_id: Optional[float] = None,
            ai_application_security_application_id: Optional[str] = None,
            application_type: Optional[str] = None,
            configuration: Optional[AiApplicationSecurityApplicationConfigurationArgs] = None,
            name: Optional[str] = None,
            region: Optional[str] = None) -> AiApplicationSecurityApplication
    func GetAiApplicationSecurityApplication(ctx *Context, name string, id IDInput, state *AiApplicationSecurityApplicationState, opts ...ResourceOption) (*AiApplicationSecurityApplication, error)
    public static AiApplicationSecurityApplication Get(string name, Input<string> id, AiApplicationSecurityApplicationState? state, CustomResourceOptions? opts = null)
    public static AiApplicationSecurityApplication get(String name, Output<String> id, AiApplicationSecurityApplicationState state, CustomResourceOptions options)
    resources:  _:    type: incapsula:AiApplicationSecurityApplication    get:      id: ${id}
    import {
      to = incapsula_ai_application_security_application.example
      id = "${id}"
    }
    
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    resource_name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    The following state arguments are supported:
    AccountId double
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    AiApplicationSecurityApplicationId string
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    ApplicationType string
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    Configuration AiApplicationSecurityApplicationConfiguration
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    Name string
    Name of the AI Application Security application.
    Region string
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
    AccountId float64
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    AiApplicationSecurityApplicationId string
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    ApplicationType string
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    Configuration AiApplicationSecurityApplicationConfigurationArgs
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    Name string
    Name of the AI Application Security application.
    Region string
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
    account_id number
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    ai_application_security_application_id string
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    application_type string
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    configuration object
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    name string
    Name of the AI Application Security application.
    region string
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
    accountId Double
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    aiApplicationSecurityApplicationId String
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    applicationType String
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    configuration AiApplicationSecurityApplicationConfiguration
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    name String
    Name of the AI Application Security application.
    region String
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
    accountId number
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    aiApplicationSecurityApplicationId string
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    applicationType string
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    configuration AiApplicationSecurityApplicationConfiguration
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    name string
    Name of the AI Application Security application.
    region string
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
    account_id float
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    ai_application_security_application_id str
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    application_type str
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    configuration AiApplicationSecurityApplicationConfigurationArgs
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    name str
    Name of the AI Application Security application.
    region str
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
    accountId Number
    Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
    aiApplicationSecurityApplicationId String
    UUID of the application. Used as the import key and as application_id on the AI Application Security policy and api-key resources.
    applicationType String
    Deployment type of the application. One of SDK, EDGE, API. Cannot be changed after the resource is created.
    configuration Property Map
    Application configuration block. Required when application_type = "EDGE"; not supported for SDK or API application types. Supports a single block with the following arguments:
    name String
    Name of the AI Application Security application.
    region String
    Data region of the application. One of US, EU, AU, APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.

    Supporting Types

    AiApplicationSecurityApplicationConfiguration, AiApplicationSecurityApplicationConfigurationArgs

    BlockedResponseStructure string
    Response body returned when a request is blocked. Must contain the $BLOCKED_MESSAGE placeholder, which the service substitutes with the block reason at runtime.
    ContentType string
    Content type of the inspected traffic. Default: application/json.
    IsStreaming bool
    Whether the application uses streaming responses. Default: false.
    Path string
    Request path to inspect.
    PromptLocation string
    JSONPath to the prompt within the request payload (must start with $).
    Request AiApplicationSecurityApplicationConfigurationRequest
    Single block describing how to extract fields from requests. All *_path values are JSONPath expressions starting with $:
    Response AiApplicationSecurityApplicationConfigurationResponse
    Single block describing how to extract fields from responses. All *_path values are JSONPath expressions starting with $:
    SiteId double
    Numeric identifier of the site the application is attached to.
    BlockedResponseStructure string
    Response body returned when a request is blocked. Must contain the $BLOCKED_MESSAGE placeholder, which the service substitutes with the block reason at runtime.
    ContentType string
    Content type of the inspected traffic. Default: application/json.
    IsStreaming bool
    Whether the application uses streaming responses. Default: false.
    Path string
    Request path to inspect.
    PromptLocation string
    JSONPath to the prompt within the request payload (must start with $).
    Request AiApplicationSecurityApplicationConfigurationRequest
    Single block describing how to extract fields from requests. All *_path values are JSONPath expressions starting with $:
    Response AiApplicationSecurityApplicationConfigurationResponse
    Single block describing how to extract fields from responses. All *_path values are JSONPath expressions starting with $:
    SiteId float64
    Numeric identifier of the site the application is attached to.
    blocked_response_structure string
    Response body returned when a request is blocked. Must contain the $BLOCKED_MESSAGE placeholder, which the service substitutes with the block reason at runtime.
    content_type string
    Content type of the inspected traffic. Default: application/json.
    is_streaming bool
    Whether the application uses streaming responses. Default: false.
    path string
    Request path to inspect.
    prompt_location string
    JSONPath to the prompt within the request payload (must start with $).
    request object
    Single block describing how to extract fields from requests. All *_path values are JSONPath expressions starting with $:
    response object
    Single block describing how to extract fields from responses. All *_path values are JSONPath expressions starting with $:
    site_id number
    Numeric identifier of the site the application is attached to.
    blockedResponseStructure String
    Response body returned when a request is blocked. Must contain the $BLOCKED_MESSAGE placeholder, which the service substitutes with the block reason at runtime.
    contentType String
    Content type of the inspected traffic. Default: application/json.
    isStreaming Boolean
    Whether the application uses streaming responses. Default: false.
    path String
    Request path to inspect.
    promptLocation String
    JSONPath to the prompt within the request payload (must start with $).
    request AiApplicationSecurityApplicationConfigurationRequest
    Single block describing how to extract fields from requests. All *_path values are JSONPath expressions starting with $:
    response AiApplicationSecurityApplicationConfigurationResponse
    Single block describing how to extract fields from responses. All *_path values are JSONPath expressions starting with $:
    siteId Double
    Numeric identifier of the site the application is attached to.
    blockedResponseStructure string
    Response body returned when a request is blocked. Must contain the $BLOCKED_MESSAGE placeholder, which the service substitutes with the block reason at runtime.
    contentType string
    Content type of the inspected traffic. Default: application/json.
    isStreaming boolean
    Whether the application uses streaming responses. Default: false.
    path string
    Request path to inspect.
    promptLocation string
    JSONPath to the prompt within the request payload (must start with $).
    request AiApplicationSecurityApplicationConfigurationRequest
    Single block describing how to extract fields from requests. All *_path values are JSONPath expressions starting with $:
    response AiApplicationSecurityApplicationConfigurationResponse
    Single block describing how to extract fields from responses. All *_path values are JSONPath expressions starting with $:
    siteId number
    Numeric identifier of the site the application is attached to.
    blocked_response_structure str
    Response body returned when a request is blocked. Must contain the $BLOCKED_MESSAGE placeholder, which the service substitutes with the block reason at runtime.
    content_type str
    Content type of the inspected traffic. Default: application/json.
    is_streaming bool
    Whether the application uses streaming responses. Default: false.
    path str
    Request path to inspect.
    prompt_location str
    JSONPath to the prompt within the request payload (must start with $).
    request AiApplicationSecurityApplicationConfigurationRequest
    Single block describing how to extract fields from requests. All *_path values are JSONPath expressions starting with $:
    response AiApplicationSecurityApplicationConfigurationResponse
    Single block describing how to extract fields from responses. All *_path values are JSONPath expressions starting with $:
    site_id float
    Numeric identifier of the site the application is attached to.
    blockedResponseStructure String
    Response body returned when a request is blocked. Must contain the $BLOCKED_MESSAGE placeholder, which the service substitutes with the block reason at runtime.
    contentType String
    Content type of the inspected traffic. Default: application/json.
    isStreaming Boolean
    Whether the application uses streaming responses. Default: false.
    path String
    Request path to inspect.
    promptLocation String
    JSONPath to the prompt within the request payload (must start with $).
    request Property Map
    Single block describing how to extract fields from requests. All *_path values are JSONPath expressions starting with $:
    response Property Map
    Single block describing how to extract fields from responses. All *_path values are JSONPath expressions starting with $:
    siteId Number
    Numeric identifier of the site the application is attached to.

    AiApplicationSecurityApplicationConfigurationRequest, AiApplicationSecurityApplicationConfigurationRequestArgs

    ContentPath string
    JSONPath to the message content.
    MessagePath string
    JSONPath to the messages array.
    RolePath string
    JSONPath to the message role.
    ContentPath string
    JSONPath to the message content.
    MessagePath string
    JSONPath to the messages array.
    RolePath string
    JSONPath to the message role.
    content_path string
    JSONPath to the message content.
    message_path string
    JSONPath to the messages array.
    role_path string
    JSONPath to the message role.
    contentPath String
    JSONPath to the message content.
    messagePath String
    JSONPath to the messages array.
    rolePath String
    JSONPath to the message role.
    contentPath string
    JSONPath to the message content.
    messagePath string
    JSONPath to the messages array.
    rolePath string
    JSONPath to the message role.
    content_path str
    JSONPath to the message content.
    message_path str
    JSONPath to the messages array.
    role_path str
    JSONPath to the message role.
    contentPath String
    JSONPath to the message content.
    messagePath String
    JSONPath to the messages array.
    rolePath String
    JSONPath to the message role.

    AiApplicationSecurityApplicationConfigurationResponse, AiApplicationSecurityApplicationConfigurationResponseArgs

    ContentPath string
    JSONPath to the response content.
    EndOfStreamMarker string
    Marker that signals the end of the stream.
    FinishReasonPath string
    JSONPath to the finish-reason field.
    FinishReasonValue string
    Value of the finish-reason field that marks completion.
    RolePath string
    JSONPath to the response role.
    ContentPath string
    JSONPath to the response content.
    EndOfStreamMarker string
    Marker that signals the end of the stream.
    FinishReasonPath string
    JSONPath to the finish-reason field.
    FinishReasonValue string
    Value of the finish-reason field that marks completion.
    RolePath string
    JSONPath to the response role.
    content_path string
    JSONPath to the response content.
    end_of_stream_marker string
    Marker that signals the end of the stream.
    finish_reason_path string
    JSONPath to the finish-reason field.
    finish_reason_value string
    Value of the finish-reason field that marks completion.
    role_path string
    JSONPath to the response role.
    contentPath String
    JSONPath to the response content.
    endOfStreamMarker String
    Marker that signals the end of the stream.
    finishReasonPath String
    JSONPath to the finish-reason field.
    finishReasonValue String
    Value of the finish-reason field that marks completion.
    rolePath String
    JSONPath to the response role.
    contentPath string
    JSONPath to the response content.
    endOfStreamMarker string
    Marker that signals the end of the stream.
    finishReasonPath string
    JSONPath to the finish-reason field.
    finishReasonValue string
    Value of the finish-reason field that marks completion.
    rolePath string
    JSONPath to the response role.
    content_path str
    JSONPath to the response content.
    end_of_stream_marker str
    Marker that signals the end of the stream.
    finish_reason_path str
    JSONPath to the finish-reason field.
    finish_reason_value str
    Value of the finish-reason field that marks completion.
    role_path str
    JSONPath to the response role.
    contentPath String
    JSONPath to the response content.
    endOfStreamMarker String
    Marker that signals the end of the stream.
    finishReasonPath String
    JSONPath to the finish-reason field.
    finishReasonValue String
    Value of the finish-reason field that marks completion.
    rolePath String
    JSONPath to the response role.

    Import

    AI Application Security application can be imported using its application_id, optionally prefixed with the account_id:

    $ pulumi import incapsula:index/aiApplicationSecurityApplication:AiApplicationSecurityApplication example 3f2504e0-4f89-41d3-9a0c-0305e82c3301
    
    $ pulumi import incapsula:index/aiApplicationSecurityApplication:AiApplicationSecurityApplication example 1234567/3f2504e0-4f89-41d3-9a0c-0305e82c3301
    

    When the account_id is omitted from the import ID it is taken from the account of the API credentials.

    To learn more about importing existing cloud resources, see Importing resources.

    Package Details

    Repository
    incapsula imperva/terraform-provider-incapsula
    License
    Notes
    This Pulumi package is based on the incapsula Terraform Provider.
    Viewing docs for incapsula 3.40.0
    published on Tuesday, Sep 15, 2026 by imperva

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial