diff --git a/modules/ai-security-for-apps/pom.xml b/modules/ai-security-for-apps/pom.xml
new file mode 100644
index 000000000..6c079b5a0
--- /dev/null
+++ b/modules/ai-security-for-apps/pom.xml
@@ -0,0 +1,63 @@
+
+ 4.0.0
+
+
+ networking
+ com.ibm.cloud
+ 99-SNAPSHOT
+ ../..
+
+
+ ai-security-for-apps
+
+ Cloud Internet Services AI Security for Apps
+ jar
+
+
+
+ com.ibm.cloud
+ sdk-core
+
+
+ networking-common
+ ${project.groupId}
+
+
+ networking-common
+ ${project.groupId}
+ test-jar
+ tests
+ test
+
+
+ org.testng
+ testng
+ test
+
+
+ com.squareup.okhttp3
+ mockwebserver
+ test
+
+
+ org.powermock
+ powermock-api-mockito2
+ test
+
+
+ org.powermock
+ powermock-module-testng
+ test
+
+
+
+
+
+ IBM Cloud DevX SDK Development
+ devxsdk@us.ibm.com
+ https://www.ibm.com/
+
+
+
+
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/AiSecurityForApps.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/AiSecurityForApps.java
new file mode 100644
index 000000000..fde587d34
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/AiSecurityForApps.java
@@ -0,0 +1,617 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+/*
+ * IBM OpenAPI SDK Code Generator Version: 3.117.0-7f07c563-20260915-094553
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1;
+
+import com.google.gson.JsonObject;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.AiSecuritySettingsResp;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.ApiGatewayDiscoveryResp;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.ApiGatewayOperationItemResp;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.ApiGatewayOperationsLabelsResp;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.ApiGatewayOperationsResp;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.ApiGatewaySchemasResp;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.CreateApiGatewayOperationItemOptions;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.CreateZoneApiGatewayOperationOptions;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.DeleteZoneApiGatewayOperationOptions;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.DiscoveryOperationsListResp;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.DiscoveryOperationsPatchResp;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.GetAiSecuritySettingsOptions;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.GetApiGatewayDiscoveryOptions;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.GetApiGatewaySchemasOptions;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.GetZoneApiGatewayOperationOptions;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.ListApiGatewayDiscoveryOperationsOptions;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.ReplaceZoneAiSecuritySettingsOptions;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.UpdateApiGatewayOperationLabelsOptions;
+import com.ibm.cloud.networking.ai_security_for_apps.v1.model.UpdateZoneApiGatewayDiscoveryOperationOptions;
+import com.ibm.cloud.networking.common.SdkCommon;
+import com.ibm.cloud.sdk.core.http.RequestBuilder;
+import com.ibm.cloud.sdk.core.http.ResponseConverter;
+import com.ibm.cloud.sdk.core.http.ServiceCall;
+import com.ibm.cloud.sdk.core.security.Authenticator;
+import com.ibm.cloud.sdk.core.security.ConfigBasedAuthenticatorFactory;
+import com.ibm.cloud.sdk.core.service.BaseService;
+import com.ibm.cloud.sdk.core.util.RequestUtils;
+import com.ibm.cloud.sdk.core.util.ResponseConverterUtils;
+import java.util.HashMap;
+import java.util.Map;
+import java.util.Map.Entry;
+
+/**
+ * AI Security for Apps.
+ *
+ * API Version: 1.0.0
+ */
+public class AiSecurityForApps extends BaseService {
+
+ /**
+ * Default service name used when configuring the `AiSecurityForApps` client.
+ */
+ public static final String DEFAULT_SERVICE_NAME = "ai_security_for_apps";
+
+ /**
+ * Default service endpoint URL.
+ */
+ public static final String DEFAULT_SERVICE_URL = "https://api.cis.cloud.ibm.com";
+
+ private String crn;
+
+ private String zoneIdentifier;
+
+ /**
+ * Class method which constructs an instance of the `AiSecurityForApps` client.
+ * The default service name is used to configure the client instance.
+ *
+ * @param crn Full url-encoded CRN of the service instance.
+ * @param zoneIdentifier Zone identifier to identify the zone.
+ * @return an instance of the `AiSecurityForApps` client using external configuration
+ */
+ public static AiSecurityForApps newInstance(String crn, String zoneIdentifier) {
+ return newInstance(crn, zoneIdentifier, DEFAULT_SERVICE_NAME);
+ }
+
+ /**
+ * Class method which constructs an instance of the `AiSecurityForApps` client.
+ * The specified service name is used to configure the client instance.
+ *
+ * @param crn Full url-encoded CRN of the service instance.
+ * @param zoneIdentifier Zone identifier to identify the zone.
+ * @param serviceName the service name to be used when configuring the client instance
+ * @return an instance of the `AiSecurityForApps` client using external configuration
+ */
+ public static AiSecurityForApps newInstance(String crn, String zoneIdentifier, String serviceName) {
+ Authenticator authenticator = ConfigBasedAuthenticatorFactory.getAuthenticator(serviceName);
+ AiSecurityForApps service = new AiSecurityForApps(crn, zoneIdentifier, serviceName, authenticator);
+ service.configureService(serviceName);
+ return service;
+ }
+
+ /**
+ * Constructs an instance of the `AiSecurityForApps` client.
+ * The specified service name and authenticator are used to configure the client instance.
+ *
+ * @param crn Full url-encoded CRN of the service instance.
+ * @param zoneIdentifier Zone identifier to identify the zone.
+ * @param serviceName the service name to be used when configuring the client instance
+ * @param authenticator the {@link Authenticator} instance to be configured for this client
+ */
+ public AiSecurityForApps(String crn, String zoneIdentifier, String serviceName, Authenticator authenticator) {
+ super(serviceName, authenticator);
+ setServiceUrl(DEFAULT_SERVICE_URL);
+ setCrn(crn);
+ setZoneIdentifier(zoneIdentifier);
+ }
+
+ /**
+ * Gets the crn.
+ *
+ * Full url-encoded CRN of the service instance.
+ *
+ * @return the crn
+ */
+ public String getCrn() {
+ return this.crn;
+ }
+
+ /**
+ * Sets the crn.
+ *
+ * @param crn the new crn
+ */
+ public void setCrn(final String crn) {
+ com.ibm.cloud.sdk.core.util.Validator.notEmpty(crn, "crn cannot be empty.");
+ this.crn = crn;
+ }
+
+ /**
+ * Gets the zoneIdentifier.
+ *
+ * Zone identifier to identify the zone.
+ *
+ * @return the zoneIdentifier
+ */
+ public String getZoneIdentifier() {
+ return this.zoneIdentifier;
+ }
+
+ /**
+ * Sets the zoneIdentifier.
+ *
+ * @param zoneIdentifier the new zoneIdentifier
+ */
+ public void setZoneIdentifier(final String zoneIdentifier) {
+ com.ibm.cloud.sdk.core.util.Validator.notEmpty(zoneIdentifier, "zoneIdentifier cannot be empty.");
+ this.zoneIdentifier = zoneIdentifier;
+ }
+
+ /**
+ * Get AI Security for Apps settings.
+ *
+ * Get AI Security for Apps enabled/disabled setting for a given zone.
+ *
+ * @param getAiSecuritySettingsOptions the {@link GetAiSecuritySettingsOptions} containing the options for the call
+ * @return a {@link ServiceCall} with a result of type {@link AiSecuritySettingsResp}
+ */
+ public ServiceCall getAiSecuritySettings(GetAiSecuritySettingsOptions getAiSecuritySettingsOptions) {
+ Map pathParamsMap = new HashMap();
+ pathParamsMap.put("crn", this.crn);
+ pathParamsMap.put("zone_identifier", this.zoneIdentifier);
+ RequestBuilder builder = RequestBuilder.get(RequestBuilder.resolveRequestUrl(getServiceUrl(), "/v1/{crn}/zones/{zone_identifier}/ai_security/settings", pathParamsMap));
+ Map sdkHeaders = SdkCommon.getSdkHeaders("ai_security_for_apps", "v1", "getAiSecuritySettings");
+ for (Entry header : sdkHeaders.entrySet()) {
+ builder.header(header.getKey(), header.getValue());
+ }
+ builder.header("Accept", "application/json");
+ ResponseConverter responseConverter =
+ ResponseConverterUtils.getValue(new com.google.gson.reflect.TypeToken() { }.getType());
+ return createServiceCall(builder.build(), responseConverter);
+ }
+
+ /**
+ * Get AI Security for Apps settings.
+ *
+ * Get AI Security for Apps enabled/disabled setting for a given zone.
+ *
+ * @return a {@link ServiceCall} with a result of type {@link AiSecuritySettingsResp}
+ */
+ public ServiceCall getAiSecuritySettings() {
+ return getAiSecuritySettings(null);
+ }
+
+ /**
+ * Update AI Security for Apps settings.
+ *
+ * Enable or disable AI Security for Apps for a given zone.
+ *
+ * @param replaceZoneAiSecuritySettingsOptions the {@link ReplaceZoneAiSecuritySettingsOptions} containing the options for the call
+ * @return a {@link ServiceCall} with a result of type {@link AiSecuritySettingsResp}
+ */
+ public ServiceCall replaceZoneAiSecuritySettings(ReplaceZoneAiSecuritySettingsOptions replaceZoneAiSecuritySettingsOptions) {
+ boolean skipBody = false;
+ if (replaceZoneAiSecuritySettingsOptions == null) {
+ replaceZoneAiSecuritySettingsOptions = new ReplaceZoneAiSecuritySettingsOptions.Builder().build();
+ skipBody = true;
+ }
+ Map pathParamsMap = new HashMap();
+ pathParamsMap.put("crn", this.crn);
+ pathParamsMap.put("zone_identifier", this.zoneIdentifier);
+ RequestBuilder builder = RequestBuilder.put(RequestBuilder.resolveRequestUrl(getServiceUrl(), "/v1/{crn}/zones/{zone_identifier}/ai_security/settings", pathParamsMap));
+ Map sdkHeaders = SdkCommon.getSdkHeaders("ai_security_for_apps", "v1", "replaceZoneAiSecuritySettings");
+ for (Entry header : sdkHeaders.entrySet()) {
+ builder.header(header.getKey(), header.getValue());
+ }
+ builder.header("Accept", "application/json");
+ if (!skipBody) {
+ final JsonObject contentJson = new JsonObject();
+ if (replaceZoneAiSecuritySettingsOptions.enabled() != null) {
+ contentJson.addProperty("enabled", replaceZoneAiSecuritySettingsOptions.enabled());
+ }
+ builder.bodyJson(contentJson);
+ }
+ ResponseConverter responseConverter =
+ ResponseConverterUtils.getValue(new com.google.gson.reflect.TypeToken() { }.getType());
+ return createServiceCall(builder.build(), responseConverter);
+ }
+
+ /**
+ * Update AI Security for Apps settings.
+ *
+ * Enable or disable AI Security for Apps for a given zone.
+ *
+ * @return a {@link ServiceCall} with a result of type {@link AiSecuritySettingsResp}
+ */
+ public ServiceCall replaceZoneAiSecuritySettings() {
+ return replaceZoneAiSecuritySettings(null);
+ }
+
+ /**
+ * Get API Gateway discovery.
+ *
+ * Retrieve discovered operations for a zone rendered as OpenAPI schemas. Use this to identify AI-powered endpoints,
+ * save them to Endpoint Management, and label them to enable AI Security for Apps scanning.
+ *
+ * @param getApiGatewayDiscoveryOptions the {@link GetApiGatewayDiscoveryOptions} containing the options for the call
+ * @return a {@link ServiceCall} with a result of type {@link ApiGatewayDiscoveryResp}
+ */
+ public ServiceCall getApiGatewayDiscovery(GetApiGatewayDiscoveryOptions getApiGatewayDiscoveryOptions) {
+ Map pathParamsMap = new HashMap();
+ pathParamsMap.put("crn", this.crn);
+ pathParamsMap.put("zone_identifier", this.zoneIdentifier);
+ RequestBuilder builder = RequestBuilder.get(RequestBuilder.resolveRequestUrl(getServiceUrl(), "/v1/{crn}/zones/{zone_identifier}/api_gateway/discovery", pathParamsMap));
+ Map sdkHeaders = SdkCommon.getSdkHeaders("ai_security_for_apps", "v1", "getApiGatewayDiscovery");
+ for (Entry header : sdkHeaders.entrySet()) {
+ builder.header(header.getKey(), header.getValue());
+ }
+ builder.header("Accept", "application/json");
+ ResponseConverter responseConverter =
+ ResponseConverterUtils.getValue(new com.google.gson.reflect.TypeToken() { }.getType());
+ return createServiceCall(builder.build(), responseConverter);
+ }
+
+ /**
+ * Get API Gateway discovery.
+ *
+ * Retrieve discovered operations for a zone rendered as OpenAPI schemas. Use this to identify AI-powered endpoints,
+ * save them to Endpoint Management, and label them to enable AI Security for Apps scanning.
+ *
+ * @return a {@link ServiceCall} with a result of type {@link ApiGatewayDiscoveryResp}
+ */
+ public ServiceCall getApiGatewayDiscovery() {
+ return getApiGatewayDiscovery(null);
+ }
+
+ /**
+ * List API Gateway discovery operations.
+ *
+ * Retrieve the most up-to-date list of discovered operations for a zone.
+ *
+ * @param listApiGatewayDiscoveryOperationsOptions the {@link ListApiGatewayDiscoveryOperationsOptions} containing the options for the call
+ * @return a {@link ServiceCall} with a result of type {@link DiscoveryOperationsListResp}
+ */
+ public ServiceCall listApiGatewayDiscoveryOperations(ListApiGatewayDiscoveryOperationsOptions listApiGatewayDiscoveryOperationsOptions) {
+ if (listApiGatewayDiscoveryOperationsOptions == null) {
+ listApiGatewayDiscoveryOperationsOptions = new ListApiGatewayDiscoveryOperationsOptions.Builder().build();
+ }
+ Map pathParamsMap = new HashMap();
+ pathParamsMap.put("crn", this.crn);
+ pathParamsMap.put("zone_identifier", this.zoneIdentifier);
+ RequestBuilder builder = RequestBuilder.get(RequestBuilder.resolveRequestUrl(getServiceUrl(), "/v1/{crn}/zones/{zone_identifier}/api_gateway/discovery/operations", pathParamsMap));
+ Map sdkHeaders = SdkCommon.getSdkHeaders("ai_security_for_apps", "v1", "listApiGatewayDiscoveryOperations");
+ for (Entry header : sdkHeaders.entrySet()) {
+ builder.header(header.getKey(), header.getValue());
+ }
+ builder.header("Accept", "application/json");
+ if (listApiGatewayDiscoveryOperationsOptions.diff() != null) {
+ builder.query("diff", String.valueOf(listApiGatewayDiscoveryOperationsOptions.diff()));
+ }
+ if (listApiGatewayDiscoveryOperationsOptions.direction() != null) {
+ builder.query("direction", String.valueOf(listApiGatewayDiscoveryOperationsOptions.direction()));
+ }
+ if (listApiGatewayDiscoveryOperationsOptions.endpoint() != null) {
+ builder.query("endpoint", String.valueOf(listApiGatewayDiscoveryOperationsOptions.endpoint()));
+ }
+ if (listApiGatewayDiscoveryOperationsOptions.host() != null) {
+ builder.query("host", RequestUtils.join(listApiGatewayDiscoveryOperationsOptions.host(), ","));
+ }
+ if (listApiGatewayDiscoveryOperationsOptions.method() != null) {
+ builder.query("method", RequestUtils.join(listApiGatewayDiscoveryOperationsOptions.method(), ","));
+ }
+ if (listApiGatewayDiscoveryOperationsOptions.order() != null) {
+ builder.query("order", String.valueOf(listApiGatewayDiscoveryOperationsOptions.order()));
+ }
+ if (listApiGatewayDiscoveryOperationsOptions.origin() != null) {
+ builder.query("origin", String.valueOf(listApiGatewayDiscoveryOperationsOptions.origin()));
+ }
+ if (listApiGatewayDiscoveryOperationsOptions.state() != null) {
+ builder.query("state", String.valueOf(listApiGatewayDiscoveryOperationsOptions.state()));
+ }
+ if (listApiGatewayDiscoveryOperationsOptions.page() != null) {
+ builder.query("page", String.valueOf(listApiGatewayDiscoveryOperationsOptions.page()));
+ }
+ if (listApiGatewayDiscoveryOperationsOptions.perPage() != null) {
+ builder.query("per_page", String.valueOf(listApiGatewayDiscoveryOperationsOptions.perPage()));
+ }
+ ResponseConverter responseConverter =
+ ResponseConverterUtils.getValue(new com.google.gson.reflect.TypeToken() { }.getType());
+ return createServiceCall(builder.build(), responseConverter);
+ }
+
+ /**
+ * List API Gateway discovery operations.
+ *
+ * Retrieve the most up-to-date list of discovered operations for a zone.
+ *
+ * @return a {@link ServiceCall} with a result of type {@link DiscoveryOperationsListResp}
+ */
+ public ServiceCall listApiGatewayDiscoveryOperations() {
+ return listApiGatewayDiscoveryOperations(null);
+ }
+
+ /**
+ * Bulk update discovered operation states.
+ *
+ * Bulk update the state of one or more discovered operations. Use to mark operations as saved (promoting to Endpoint
+ * Management) or ignored.
+ *
+ * @param updateZoneApiGatewayDiscoveryOperationOptions the {@link UpdateZoneApiGatewayDiscoveryOperationOptions} containing the options for the call
+ * @return a {@link ServiceCall} with a result of type {@link DiscoveryOperationsPatchResp}
+ */
+ public ServiceCall updateZoneApiGatewayDiscoveryOperation(UpdateZoneApiGatewayDiscoveryOperationOptions updateZoneApiGatewayDiscoveryOperationOptions) {
+ if (updateZoneApiGatewayDiscoveryOperationOptions == null) {
+ updateZoneApiGatewayDiscoveryOperationOptions = new UpdateZoneApiGatewayDiscoveryOperationOptions.Builder().build();
+ }
+ Map pathParamsMap = new HashMap();
+ pathParamsMap.put("crn", this.crn);
+ pathParamsMap.put("zone_identifier", this.zoneIdentifier);
+ RequestBuilder builder = RequestBuilder.patch(RequestBuilder.resolveRequestUrl(getServiceUrl(), "/v1/{crn}/zones/{zone_identifier}/api_gateway/discovery/operations", pathParamsMap));
+ Map sdkHeaders = SdkCommon.getSdkHeaders("ai_security_for_apps", "v1", "updateZoneApiGatewayDiscoveryOperation");
+ for (Entry header : sdkHeaders.entrySet()) {
+ builder.header(header.getKey(), header.getValue());
+ }
+ builder.header("Accept", "application/json");
+ if (updateZoneApiGatewayDiscoveryOperationOptions.requestBody() != null) {
+ builder.bodyContent(com.ibm.cloud.sdk.core.util.GsonSingleton.getGsonWithoutPrettyPrinting().toJson(updateZoneApiGatewayDiscoveryOperationOptions.requestBody()), "application/json");
+ }
+ ResponseConverter responseConverter =
+ ResponseConverterUtils.getValue(new com.google.gson.reflect.TypeToken() { }.getType());
+ return createServiceCall(builder.build(), responseConverter);
+ }
+
+ /**
+ * Bulk update discovered operation states.
+ *
+ * Bulk update the state of one or more discovered operations. Use to mark operations as saved (promoting to Endpoint
+ * Management) or ignored.
+ *
+ * @return a {@link ServiceCall} with a result of type {@link DiscoveryOperationsPatchResp}
+ */
+ public ServiceCall updateZoneApiGatewayDiscoveryOperation() {
+ return updateZoneApiGatewayDiscoveryOperation(null);
+ }
+
+ /**
+ * Create API Gateway operations in bulk.
+ *
+ * Create API Gateway operations in bulk for a zone, saving them to Endpoint Management.
+ *
+ * @param createZoneApiGatewayOperationOptions the {@link CreateZoneApiGatewayOperationOptions} containing the options for the call
+ * @return a {@link ServiceCall} with a result of type {@link ApiGatewayOperationsResp}
+ */
+ public ServiceCall createZoneApiGatewayOperation(CreateZoneApiGatewayOperationOptions createZoneApiGatewayOperationOptions) {
+ if (createZoneApiGatewayOperationOptions == null) {
+ createZoneApiGatewayOperationOptions = new CreateZoneApiGatewayOperationOptions.Builder().build();
+ }
+ Map pathParamsMap = new HashMap();
+ pathParamsMap.put("crn", this.crn);
+ pathParamsMap.put("zone_identifier", this.zoneIdentifier);
+ RequestBuilder builder = RequestBuilder.post(RequestBuilder.resolveRequestUrl(getServiceUrl(), "/v1/{crn}/zones/{zone_identifier}/api_gateway/operations", pathParamsMap));
+ Map sdkHeaders = SdkCommon.getSdkHeaders("ai_security_for_apps", "v1", "createZoneApiGatewayOperation");
+ for (Entry header : sdkHeaders.entrySet()) {
+ builder.header(header.getKey(), header.getValue());
+ }
+ builder.header("Accept", "application/json");
+ if (createZoneApiGatewayOperationOptions.apiGatewayOperation() != null) {
+ builder.bodyContent(com.ibm.cloud.sdk.core.util.GsonSingleton.getGsonWithoutPrettyPrinting().toJson(createZoneApiGatewayOperationOptions.apiGatewayOperation()), "application/json");
+ }
+ ResponseConverter responseConverter =
+ ResponseConverterUtils.getValue(new com.google.gson.reflect.TypeToken() { }.getType());
+ return createServiceCall(builder.build(), responseConverter);
+ }
+
+ /**
+ * Create API Gateway operations in bulk.
+ *
+ * Create API Gateway operations in bulk for a zone, saving them to Endpoint Management.
+ *
+ * @return a {@link ServiceCall} with a result of type {@link ApiGatewayOperationsResp}
+ */
+ public ServiceCall createZoneApiGatewayOperation() {
+ return createZoneApiGatewayOperation(null);
+ }
+
+ /**
+ * Create a single API Gateway operation.
+ *
+ * Create a single API Gateway operation for a zone, saving it to Endpoint Management.
+ *
+ * @param createApiGatewayOperationItemOptions the {@link CreateApiGatewayOperationItemOptions} containing the options for the call
+ * @return a {@link ServiceCall} with a result of type {@link ApiGatewayOperationItemResp}
+ */
+ public ServiceCall createApiGatewayOperationItem(CreateApiGatewayOperationItemOptions createApiGatewayOperationItemOptions) {
+ boolean skipBody = false;
+ if (createApiGatewayOperationItemOptions == null) {
+ createApiGatewayOperationItemOptions = new CreateApiGatewayOperationItemOptions.Builder().build();
+ skipBody = true;
+ }
+ Map pathParamsMap = new HashMap();
+ pathParamsMap.put("crn", this.crn);
+ pathParamsMap.put("zone_identifier", this.zoneIdentifier);
+ RequestBuilder builder = RequestBuilder.post(RequestBuilder.resolveRequestUrl(getServiceUrl(), "/v1/{crn}/zones/{zone_identifier}/api_gateway/operations/item", pathParamsMap));
+ Map sdkHeaders = SdkCommon.getSdkHeaders("ai_security_for_apps", "v1", "createApiGatewayOperationItem");
+ for (Entry header : sdkHeaders.entrySet()) {
+ builder.header(header.getKey(), header.getValue());
+ }
+ builder.header("Accept", "application/json");
+ if (!skipBody) {
+ final JsonObject contentJson = new JsonObject();
+ if (createApiGatewayOperationItemOptions.method() != null) {
+ contentJson.addProperty("method", createApiGatewayOperationItemOptions.method());
+ }
+ if (createApiGatewayOperationItemOptions.host() != null) {
+ contentJson.addProperty("host", createApiGatewayOperationItemOptions.host());
+ }
+ if (createApiGatewayOperationItemOptions.endpoint() != null) {
+ contentJson.addProperty("endpoint", createApiGatewayOperationItemOptions.endpoint());
+ }
+ builder.bodyJson(contentJson);
+ }
+ ResponseConverter responseConverter =
+ ResponseConverterUtils.getValue(new com.google.gson.reflect.TypeToken() { }.getType());
+ return createServiceCall(builder.build(), responseConverter);
+ }
+
+ /**
+ * Create a single API Gateway operation.
+ *
+ * Create a single API Gateway operation for a zone, saving it to Endpoint Management.
+ *
+ * @return a {@link ServiceCall} with a result of type {@link ApiGatewayOperationItemResp}
+ */
+ public ServiceCall createApiGatewayOperationItem() {
+ return createApiGatewayOperationItem(null);
+ }
+
+ /**
+ * Add or remove labels from API Gateway operations.
+ *
+ * Add or remove labels from one or more API Gateway operations. Apply the built-in LLM label to endpoints that
+ * receive LLM traffic to enable IBM AI Security for Apps to scan those endpoints for prompt injection, PII, and
+ * unsafe topics.
+ *
+ * @param updateApiGatewayOperationLabelsOptions the {@link UpdateApiGatewayOperationLabelsOptions} containing the options for the call
+ * @return a {@link ServiceCall} with a result of type {@link ApiGatewayOperationsLabelsResp}
+ */
+ public ServiceCall updateApiGatewayOperationLabels(UpdateApiGatewayOperationLabelsOptions updateApiGatewayOperationLabelsOptions) {
+ boolean skipBody = false;
+ if (updateApiGatewayOperationLabelsOptions == null) {
+ updateApiGatewayOperationLabelsOptions = new UpdateApiGatewayOperationLabelsOptions.Builder().build();
+ skipBody = true;
+ }
+ Map pathParamsMap = new HashMap();
+ pathParamsMap.put("crn", this.crn);
+ pathParamsMap.put("zone_identifier", this.zoneIdentifier);
+ RequestBuilder builder = RequestBuilder.post(RequestBuilder.resolveRequestUrl(getServiceUrl(), "/v1/{crn}/zones/{zone_identifier}/api_gateway/operations/labels", pathParamsMap));
+ Map sdkHeaders = SdkCommon.getSdkHeaders("ai_security_for_apps", "v1", "updateApiGatewayOperationLabels");
+ for (Entry header : sdkHeaders.entrySet()) {
+ builder.header(header.getKey(), header.getValue());
+ }
+ builder.header("Accept", "application/json");
+ if (!skipBody) {
+ final JsonObject contentJson = new JsonObject();
+ if (updateApiGatewayOperationLabelsOptions.user() != null) {
+ contentJson.add("user", com.ibm.cloud.sdk.core.util.GsonSingleton.getGson().toJsonTree(updateApiGatewayOperationLabelsOptions.user()));
+ }
+ if (updateApiGatewayOperationLabelsOptions.managed() != null) {
+ contentJson.add("managed", com.ibm.cloud.sdk.core.util.GsonSingleton.getGson().toJsonTree(updateApiGatewayOperationLabelsOptions.managed()));
+ }
+ if (updateApiGatewayOperationLabelsOptions.selector() != null) {
+ contentJson.add("selector", com.ibm.cloud.sdk.core.util.GsonSingleton.getGson().toJsonTree(updateApiGatewayOperationLabelsOptions.selector()));
+ }
+ builder.bodyJson(contentJson);
+ }
+ ResponseConverter responseConverter =
+ ResponseConverterUtils.getValue(new com.google.gson.reflect.TypeToken() { }.getType());
+ return createServiceCall(builder.build(), responseConverter);
+ }
+
+ /**
+ * Add or remove labels from API Gateway operations.
+ *
+ * Add or remove labels from one or more API Gateway operations. Apply the built-in LLM label to endpoints that
+ * receive LLM traffic to enable IBM AI Security for Apps to scan those endpoints for prompt injection, PII, and
+ * unsafe topics.
+ *
+ * @return a {@link ServiceCall} with a result of type {@link ApiGatewayOperationsLabelsResp}
+ */
+ public ServiceCall updateApiGatewayOperationLabels() {
+ return updateApiGatewayOperationLabels(null);
+ }
+
+ /**
+ * Retrieve information about an operation.
+ *
+ * Retrieve information about a specific operation on a zone.
+ *
+ * @param getZoneApiGatewayOperationOptions the {@link GetZoneApiGatewayOperationOptions} containing the options for the call
+ * @return a {@link ServiceCall} with a result of type {@link ApiGatewayOperationItemResp}
+ */
+ public ServiceCall getZoneApiGatewayOperation(GetZoneApiGatewayOperationOptions getZoneApiGatewayOperationOptions) {
+ com.ibm.cloud.sdk.core.util.Validator.notNull(getZoneApiGatewayOperationOptions,
+ "getZoneApiGatewayOperationOptions cannot be null");
+ Map pathParamsMap = new HashMap();
+ pathParamsMap.put("crn", this.crn);
+ pathParamsMap.put("zone_identifier", this.zoneIdentifier);
+ pathParamsMap.put("operation_id", getZoneApiGatewayOperationOptions.operationId());
+ RequestBuilder builder = RequestBuilder.get(RequestBuilder.resolveRequestUrl(getServiceUrl(), "/v1/{crn}/zones/{zone_identifier}/api_gateway/operations/{operation_id}", pathParamsMap));
+ Map sdkHeaders = SdkCommon.getSdkHeaders("ai_security_for_apps", "v1", "getZoneApiGatewayOperation");
+ for (Entry header : sdkHeaders.entrySet()) {
+ builder.header(header.getKey(), header.getValue());
+ }
+ builder.header("Accept", "application/json");
+ ResponseConverter responseConverter =
+ ResponseConverterUtils.getValue(new com.google.gson.reflect.TypeToken() { }.getType());
+ return createServiceCall(builder.build(), responseConverter);
+ }
+
+ /**
+ * Delete an operation.
+ *
+ * Delete an operation from a zone.
+ *
+ * @param deleteZoneApiGatewayOperationOptions the {@link DeleteZoneApiGatewayOperationOptions} containing the options for the call
+ * @return a {@link ServiceCall} with a void result
+ */
+ public ServiceCall deleteZoneApiGatewayOperation(DeleteZoneApiGatewayOperationOptions deleteZoneApiGatewayOperationOptions) {
+ com.ibm.cloud.sdk.core.util.Validator.notNull(deleteZoneApiGatewayOperationOptions,
+ "deleteZoneApiGatewayOperationOptions cannot be null");
+ Map pathParamsMap = new HashMap();
+ pathParamsMap.put("crn", this.crn);
+ pathParamsMap.put("zone_identifier", this.zoneIdentifier);
+ pathParamsMap.put("operation_id", deleteZoneApiGatewayOperationOptions.operationId());
+ RequestBuilder builder = RequestBuilder.delete(RequestBuilder.resolveRequestUrl(getServiceUrl(), "/v1/{crn}/zones/{zone_identifier}/api_gateway/operations/{operation_id}", pathParamsMap));
+ Map sdkHeaders = SdkCommon.getSdkHeaders("ai_security_for_apps", "v1", "deleteZoneApiGatewayOperation");
+ for (Entry header : sdkHeaders.entrySet()) {
+ builder.header(header.getKey(), header.getValue());
+ }
+ ResponseConverter responseConverter = ResponseConverterUtils.getVoid();
+ return createServiceCall(builder.build(), responseConverter);
+ }
+
+ /**
+ * Get API Gateway schemas.
+ *
+ * Retrieve API Gateway schemas for a specified zone rendered as OpenAPI schemas.
+ *
+ * @param getApiGatewaySchemasOptions the {@link GetApiGatewaySchemasOptions} containing the options for the call
+ * @return a {@link ServiceCall} with a result of type {@link ApiGatewaySchemasResp}
+ */
+ public ServiceCall getApiGatewaySchemas(GetApiGatewaySchemasOptions getApiGatewaySchemasOptions) {
+ Map pathParamsMap = new HashMap();
+ pathParamsMap.put("crn", this.crn);
+ pathParamsMap.put("zone_identifier", this.zoneIdentifier);
+ RequestBuilder builder = RequestBuilder.get(RequestBuilder.resolveRequestUrl(getServiceUrl(), "/v1/{crn}/zones/{zone_identifier}/api_gateway/schemas", pathParamsMap));
+ Map sdkHeaders = SdkCommon.getSdkHeaders("ai_security_for_apps", "v1", "getApiGatewaySchemas");
+ for (Entry header : sdkHeaders.entrySet()) {
+ builder.header(header.getKey(), header.getValue());
+ }
+ builder.header("Accept", "application/json");
+ ResponseConverter responseConverter =
+ ResponseConverterUtils.getValue(new com.google.gson.reflect.TypeToken() { }.getType());
+ return createServiceCall(builder.build(), responseConverter);
+ }
+
+ /**
+ * Get API Gateway schemas.
+ *
+ * Retrieve API Gateway schemas for a specified zone rendered as OpenAPI schemas.
+ *
+ * @return a {@link ServiceCall} with a result of type {@link ApiGatewaySchemasResp}
+ */
+ public ServiceCall getApiGatewaySchemas() {
+ return getApiGatewaySchemas(null);
+ }
+
+}
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/AiSecuritySettingsResp.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/AiSecuritySettingsResp.java
new file mode 100644
index 000000000..31c9eb86f
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/AiSecuritySettingsResp.java
@@ -0,0 +1,76 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1.model;
+
+import java.util.List;
+
+import com.ibm.cloud.sdk.core.service.model.GenericModel;
+
+/**
+ * AI Security for Apps settings response.
+ */
+public class AiSecuritySettingsResp extends GenericModel {
+
+ protected Boolean success;
+ protected List> errors;
+ protected List> messages;
+ protected AiSecuritySettingsRespResult result;
+
+ protected AiSecuritySettingsResp() { }
+
+ /**
+ * Gets the success.
+ *
+ * Was operation successful.
+ *
+ * @return the success
+ */
+ public Boolean isSuccess() {
+ return success;
+ }
+
+ /**
+ * Gets the errors.
+ *
+ * Array of errors encountered.
+ *
+ * @return the errors
+ */
+ public List> getErrors() {
+ return errors;
+ }
+
+ /**
+ * Gets the messages.
+ *
+ * Array of messages returned.
+ *
+ * @return the messages
+ */
+ public List> getMessages() {
+ return messages;
+ }
+
+ /**
+ * Gets the result.
+ *
+ * Container for response information.
+ *
+ * @return the result
+ */
+ public AiSecuritySettingsRespResult getResult() {
+ return result;
+ }
+}
+
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/AiSecuritySettingsRespResult.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/AiSecuritySettingsRespResult.java
new file mode 100644
index 000000000..6d49ac52b
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/AiSecuritySettingsRespResult.java
@@ -0,0 +1,38 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1.model;
+
+import com.ibm.cloud.sdk.core.service.model.GenericModel;
+
+/**
+ * Container for response information.
+ */
+public class AiSecuritySettingsRespResult extends GenericModel {
+
+ protected Boolean enabled;
+
+ protected AiSecuritySettingsRespResult() { }
+
+ /**
+ * Gets the enabled.
+ *
+ * Whether AI Security for Apps is enabled on the zone.
+ *
+ * @return the enabled
+ */
+ public Boolean isEnabled() {
+ return enabled;
+ }
+}
+
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayDiscoveryResp.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayDiscoveryResp.java
new file mode 100644
index 000000000..f759c2848
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayDiscoveryResp.java
@@ -0,0 +1,77 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1.model;
+
+import java.util.List;
+import java.util.Map;
+
+import com.ibm.cloud.sdk.core.service.model.GenericModel;
+
+/**
+ * API Gateway discovery response (OpenAPI schema format).
+ */
+public class ApiGatewayDiscoveryResp extends GenericModel {
+
+ protected Boolean success;
+ protected List> errors;
+ protected List> messages;
+ protected Map result;
+
+ protected ApiGatewayDiscoveryResp() { }
+
+ /**
+ * Gets the success.
+ *
+ * Was operation successful.
+ *
+ * @return the success
+ */
+ public Boolean isSuccess() {
+ return success;
+ }
+
+ /**
+ * Gets the errors.
+ *
+ * Array of errors encountered.
+ *
+ * @return the errors
+ */
+ public List> getErrors() {
+ return errors;
+ }
+
+ /**
+ * Gets the messages.
+ *
+ * Array of messages returned.
+ *
+ * @return the messages
+ */
+ public List> getMessages() {
+ return messages;
+ }
+
+ /**
+ * Gets the result.
+ *
+ * Discovered operations rendered as an OpenAPI schema document.
+ *
+ * @return the result
+ */
+ public Map getResult() {
+ return result;
+ }
+}
+
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperation.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperation.java
new file mode 100644
index 000000000..72d31f7ce
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperation.java
@@ -0,0 +1,184 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1.model;
+
+import com.ibm.cloud.sdk.core.service.model.GenericModel;
+
+/**
+ * An API Gateway operation definition.
+ */
+public class ApiGatewayOperation extends GenericModel {
+
+ /**
+ * The HTTP method for the operation.
+ */
+ public interface Method {
+ /** GET. */
+ String GET = "GET";
+ /** POST. */
+ String POST = "POST";
+ /** PUT. */
+ String PUT = "PUT";
+ /** PATCH. */
+ String PATCH = "PATCH";
+ /** DELETE. */
+ String DELETE = "DELETE";
+ /** HEAD. */
+ String HEAD = "HEAD";
+ /** OPTIONS. */
+ String OPTIONS = "OPTIONS";
+ }
+
+ protected String method;
+ protected String host;
+ protected String endpoint;
+
+ /**
+ * Builder.
+ */
+ public static class Builder {
+ private String method;
+ private String host;
+ private String endpoint;
+
+ /**
+ * Instantiates a new Builder from an existing ApiGatewayOperation instance.
+ *
+ * @param apiGatewayOperation the instance to initialize the Builder with
+ */
+ private Builder(ApiGatewayOperation apiGatewayOperation) {
+ this.method = apiGatewayOperation.method;
+ this.host = apiGatewayOperation.host;
+ this.endpoint = apiGatewayOperation.endpoint;
+ }
+
+ /**
+ * Instantiates a new builder.
+ */
+ public Builder() {
+ }
+
+ /**
+ * Instantiates a new builder with required properties.
+ *
+ * @param method the method
+ * @param host the host
+ * @param endpoint the endpoint
+ */
+ public Builder(String method, String host, String endpoint) {
+ this.method = method;
+ this.host = host;
+ this.endpoint = endpoint;
+ }
+
+ /**
+ * Builds a ApiGatewayOperation.
+ *
+ * @return the new ApiGatewayOperation instance
+ */
+ public ApiGatewayOperation build() {
+ return new ApiGatewayOperation(this);
+ }
+
+ /**
+ * Set the method.
+ *
+ * @param method the method
+ * @return the ApiGatewayOperation builder
+ */
+ public Builder method(String method) {
+ this.method = method;
+ return this;
+ }
+
+ /**
+ * Set the host.
+ *
+ * @param host the host
+ * @return the ApiGatewayOperation builder
+ */
+ public Builder host(String host) {
+ this.host = host;
+ return this;
+ }
+
+ /**
+ * Set the endpoint.
+ *
+ * @param endpoint the endpoint
+ * @return the ApiGatewayOperation builder
+ */
+ public Builder endpoint(String endpoint) {
+ this.endpoint = endpoint;
+ return this;
+ }
+ }
+
+ protected ApiGatewayOperation() { }
+
+ protected ApiGatewayOperation(Builder builder) {
+ com.ibm.cloud.sdk.core.util.Validator.notNull(builder.method,
+ "method cannot be null");
+ com.ibm.cloud.sdk.core.util.Validator.notNull(builder.host,
+ "host cannot be null");
+ com.ibm.cloud.sdk.core.util.Validator.notNull(builder.endpoint,
+ "endpoint cannot be null");
+ method = builder.method;
+ host = builder.host;
+ endpoint = builder.endpoint;
+ }
+
+ /**
+ * New builder.
+ *
+ * @return a ApiGatewayOperation builder
+ */
+ public Builder newBuilder() {
+ return new Builder(this);
+ }
+
+ /**
+ * Gets the method.
+ *
+ * The HTTP method for the operation.
+ *
+ * @return the method
+ */
+ public String method() {
+ return method;
+ }
+
+ /**
+ * Gets the host.
+ *
+ * RFC3986-compliant host.
+ *
+ * @return the host
+ */
+ public String host() {
+ return host;
+ }
+
+ /**
+ * Gets the endpoint.
+ *
+ * The endpoint path. Must start with /.
+ *
+ * @return the endpoint
+ */
+ public String endpoint() {
+ return endpoint;
+ }
+}
+
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationItemResp.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationItemResp.java
new file mode 100644
index 000000000..685daa9ed
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationItemResp.java
@@ -0,0 +1,74 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1.model;
+
+import java.util.List;
+
+import com.ibm.cloud.sdk.core.service.model.GenericModel;
+
+/**
+ * Single API Gateway operation create response.
+ */
+public class ApiGatewayOperationItemResp extends GenericModel {
+
+ protected Boolean success;
+ protected List> errors;
+ protected List> messages;
+ protected ApiGatewayOperationItemRespResult result;
+
+ protected ApiGatewayOperationItemResp() { }
+
+ /**
+ * Gets the success.
+ *
+ * Was operation successful.
+ *
+ * @return the success
+ */
+ public Boolean isSuccess() {
+ return success;
+ }
+
+ /**
+ * Gets the errors.
+ *
+ * Array of errors encountered.
+ *
+ * @return the errors
+ */
+ public List> getErrors() {
+ return errors;
+ }
+
+ /**
+ * Gets the messages.
+ *
+ * Array of messages returned.
+ *
+ * @return the messages
+ */
+ public List> getMessages() {
+ return messages;
+ }
+
+ /**
+ * Gets the result.
+ *
+ * @return the result
+ */
+ public ApiGatewayOperationItemRespResult getResult() {
+ return result;
+ }
+}
+
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationItemRespResult.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationItemRespResult.java
new file mode 100644
index 000000000..c587cd0c3
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationItemRespResult.java
@@ -0,0 +1,70 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1.model;
+
+import com.google.gson.annotations.SerializedName;
+import com.ibm.cloud.sdk.core.service.model.GenericModel;
+
+/**
+ * ApiGatewayOperationItemRespResult.
+ */
+public class ApiGatewayOperationItemRespResult extends GenericModel {
+
+ @SerializedName("operation_id")
+ protected String operationId;
+ protected String method;
+ protected String host;
+ protected String endpoint;
+
+ protected ApiGatewayOperationItemRespResult() { }
+
+ /**
+ * Gets the operationId.
+ *
+ * UUID of the created operation.
+ *
+ * @return the operationId
+ */
+ public String getOperationId() {
+ return operationId;
+ }
+
+ /**
+ * Gets the method.
+ *
+ * @return the method
+ */
+ public String getMethod() {
+ return method;
+ }
+
+ /**
+ * Gets the host.
+ *
+ * @return the host
+ */
+ public String getHost() {
+ return host;
+ }
+
+ /**
+ * Gets the endpoint.
+ *
+ * @return the endpoint
+ */
+ public String getEndpoint() {
+ return endpoint;
+ }
+}
+
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsInputManaged.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsInputManaged.java
new file mode 100644
index 000000000..e419ec8da
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsInputManaged.java
@@ -0,0 +1,113 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1.model;
+
+import java.util.ArrayList;
+import java.util.List;
+
+import com.ibm.cloud.sdk.core.service.model.GenericModel;
+
+/**
+ * Managed labels to apply (e.g. cf-llm).
+ */
+public class ApiGatewayOperationsLabelsInputManaged extends GenericModel {
+
+ protected List labels;
+
+ /**
+ * Builder.
+ */
+ public static class Builder {
+ private List labels;
+
+ /**
+ * Instantiates a new Builder from an existing ApiGatewayOperationsLabelsInputManaged instance.
+ *
+ * @param apiGatewayOperationsLabelsInputManaged the instance to initialize the Builder with
+ */
+ private Builder(ApiGatewayOperationsLabelsInputManaged apiGatewayOperationsLabelsInputManaged) {
+ this.labels = apiGatewayOperationsLabelsInputManaged.labels;
+ }
+
+ /**
+ * Instantiates a new builder.
+ */
+ public Builder() {
+ }
+
+ /**
+ * Builds a ApiGatewayOperationsLabelsInputManaged.
+ *
+ * @return the new ApiGatewayOperationsLabelsInputManaged instance
+ */
+ public ApiGatewayOperationsLabelsInputManaged build() {
+ return new ApiGatewayOperationsLabelsInputManaged(this);
+ }
+
+ /**
+ * Adds a new element to labels.
+ *
+ * @param labels the new element to be added
+ * @return the ApiGatewayOperationsLabelsInputManaged builder
+ */
+ public Builder addLabels(String labels) {
+ com.ibm.cloud.sdk.core.util.Validator.notNull(labels,
+ "labels cannot be null");
+ if (this.labels == null) {
+ this.labels = new ArrayList();
+ }
+ this.labels.add(labels);
+ return this;
+ }
+
+ /**
+ * Set the labels.
+ * Existing labels will be replaced.
+ *
+ * @param labels the labels
+ * @return the ApiGatewayOperationsLabelsInputManaged builder
+ */
+ public Builder labels(List labels) {
+ this.labels = labels;
+ return this;
+ }
+ }
+
+ protected ApiGatewayOperationsLabelsInputManaged() { }
+
+ protected ApiGatewayOperationsLabelsInputManaged(Builder builder) {
+ labels = builder.labels;
+ }
+
+ /**
+ * New builder.
+ *
+ * @return a ApiGatewayOperationsLabelsInputManaged builder
+ */
+ public Builder newBuilder() {
+ return new Builder(this);
+ }
+
+ /**
+ * Gets the labels.
+ *
+ * Array of managed label strings.
+ *
+ * @return the labels
+ */
+ public List labels() {
+ return labels;
+ }
+}
+
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsInputSelector.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsInputSelector.java
new file mode 100644
index 000000000..c6b4714a0
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsInputSelector.java
@@ -0,0 +1,104 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1.model;
+
+import com.ibm.cloud.sdk.core.service.model.GenericModel;
+
+/**
+ * Selector specifying which operations to label.
+ */
+public class ApiGatewayOperationsLabelsInputSelector extends GenericModel {
+
+ protected ApiGatewayOperationsLabelsInputSelectorInclude include;
+
+ /**
+ * Builder.
+ */
+ public static class Builder {
+ private ApiGatewayOperationsLabelsInputSelectorInclude include;
+
+ /**
+ * Instantiates a new Builder from an existing ApiGatewayOperationsLabelsInputSelector instance.
+ *
+ * @param apiGatewayOperationsLabelsInputSelector the instance to initialize the Builder with
+ */
+ private Builder(ApiGatewayOperationsLabelsInputSelector apiGatewayOperationsLabelsInputSelector) {
+ this.include = apiGatewayOperationsLabelsInputSelector.include;
+ }
+
+ /**
+ * Instantiates a new builder.
+ */
+ public Builder() {
+ }
+
+ /**
+ * Instantiates a new builder with required properties.
+ *
+ * @param include the include
+ */
+ public Builder(ApiGatewayOperationsLabelsInputSelectorInclude include) {
+ this.include = include;
+ }
+
+ /**
+ * Builds a ApiGatewayOperationsLabelsInputSelector.
+ *
+ * @return the new ApiGatewayOperationsLabelsInputSelector instance
+ */
+ public ApiGatewayOperationsLabelsInputSelector build() {
+ return new ApiGatewayOperationsLabelsInputSelector(this);
+ }
+
+ /**
+ * Set the include.
+ *
+ * @param include the include
+ * @return the ApiGatewayOperationsLabelsInputSelector builder
+ */
+ public Builder include(ApiGatewayOperationsLabelsInputSelectorInclude include) {
+ this.include = include;
+ return this;
+ }
+ }
+
+ protected ApiGatewayOperationsLabelsInputSelector() { }
+
+ protected ApiGatewayOperationsLabelsInputSelector(Builder builder) {
+ com.ibm.cloud.sdk.core.util.Validator.notNull(builder.include,
+ "include cannot be null");
+ include = builder.include;
+ }
+
+ /**
+ * New builder.
+ *
+ * @return a ApiGatewayOperationsLabelsInputSelector builder
+ */
+ public Builder newBuilder() {
+ return new Builder(this);
+ }
+
+ /**
+ * Gets the include.
+ *
+ * Operations to include in the label operation.
+ *
+ * @return the include
+ */
+ public ApiGatewayOperationsLabelsInputSelectorInclude include() {
+ return include;
+ }
+}
+
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsInputSelectorInclude.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsInputSelectorInclude.java
new file mode 100644
index 000000000..979f3230d
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsInputSelectorInclude.java
@@ -0,0 +1,115 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1.model;
+
+import java.util.ArrayList;
+import java.util.List;
+
+import com.google.gson.annotations.SerializedName;
+import com.ibm.cloud.sdk.core.service.model.GenericModel;
+
+/**
+ * Operations to include in the label operation.
+ */
+public class ApiGatewayOperationsLabelsInputSelectorInclude extends GenericModel {
+
+ @SerializedName("operation_ids")
+ protected List operationIds;
+
+ /**
+ * Builder.
+ */
+ public static class Builder {
+ private List operationIds;
+
+ /**
+ * Instantiates a new Builder from an existing ApiGatewayOperationsLabelsInputSelectorInclude instance.
+ *
+ * @param apiGatewayOperationsLabelsInputSelectorInclude the instance to initialize the Builder with
+ */
+ private Builder(ApiGatewayOperationsLabelsInputSelectorInclude apiGatewayOperationsLabelsInputSelectorInclude) {
+ this.operationIds = apiGatewayOperationsLabelsInputSelectorInclude.operationIds;
+ }
+
+ /**
+ * Instantiates a new builder.
+ */
+ public Builder() {
+ }
+
+ /**
+ * Builds a ApiGatewayOperationsLabelsInputSelectorInclude.
+ *
+ * @return the new ApiGatewayOperationsLabelsInputSelectorInclude instance
+ */
+ public ApiGatewayOperationsLabelsInputSelectorInclude build() {
+ return new ApiGatewayOperationsLabelsInputSelectorInclude(this);
+ }
+
+ /**
+ * Adds a new element to operationIds.
+ *
+ * @param operationIds the new element to be added
+ * @return the ApiGatewayOperationsLabelsInputSelectorInclude builder
+ */
+ public Builder addOperationIds(String operationIds) {
+ com.ibm.cloud.sdk.core.util.Validator.notNull(operationIds,
+ "operationIds cannot be null");
+ if (this.operationIds == null) {
+ this.operationIds = new ArrayList();
+ }
+ this.operationIds.add(operationIds);
+ return this;
+ }
+
+ /**
+ * Set the operationIds.
+ * Existing operationIds will be replaced.
+ *
+ * @param operationIds the operationIds
+ * @return the ApiGatewayOperationsLabelsInputSelectorInclude builder
+ */
+ public Builder operationIds(List operationIds) {
+ this.operationIds = operationIds;
+ return this;
+ }
+ }
+
+ protected ApiGatewayOperationsLabelsInputSelectorInclude() { }
+
+ protected ApiGatewayOperationsLabelsInputSelectorInclude(Builder builder) {
+ operationIds = builder.operationIds;
+ }
+
+ /**
+ * New builder.
+ *
+ * @return a ApiGatewayOperationsLabelsInputSelectorInclude builder
+ */
+ public Builder newBuilder() {
+ return new Builder(this);
+ }
+
+ /**
+ * Gets the operationIds.
+ *
+ * Array of operation UUIDs to label.
+ *
+ * @return the operationIds
+ */
+ public List operationIds() {
+ return operationIds;
+ }
+}
+
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsInputUser.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsInputUser.java
new file mode 100644
index 000000000..aa0c3d21e
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsInputUser.java
@@ -0,0 +1,113 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1.model;
+
+import java.util.ArrayList;
+import java.util.List;
+
+import com.ibm.cloud.sdk.core.service.model.GenericModel;
+
+/**
+ * User-defined labels to apply.
+ */
+public class ApiGatewayOperationsLabelsInputUser extends GenericModel {
+
+ protected List labels;
+
+ /**
+ * Builder.
+ */
+ public static class Builder {
+ private List labels;
+
+ /**
+ * Instantiates a new Builder from an existing ApiGatewayOperationsLabelsInputUser instance.
+ *
+ * @param apiGatewayOperationsLabelsInputUser the instance to initialize the Builder with
+ */
+ private Builder(ApiGatewayOperationsLabelsInputUser apiGatewayOperationsLabelsInputUser) {
+ this.labels = apiGatewayOperationsLabelsInputUser.labels;
+ }
+
+ /**
+ * Instantiates a new builder.
+ */
+ public Builder() {
+ }
+
+ /**
+ * Builds a ApiGatewayOperationsLabelsInputUser.
+ *
+ * @return the new ApiGatewayOperationsLabelsInputUser instance
+ */
+ public ApiGatewayOperationsLabelsInputUser build() {
+ return new ApiGatewayOperationsLabelsInputUser(this);
+ }
+
+ /**
+ * Adds a new element to labels.
+ *
+ * @param labels the new element to be added
+ * @return the ApiGatewayOperationsLabelsInputUser builder
+ */
+ public Builder addLabels(String labels) {
+ com.ibm.cloud.sdk.core.util.Validator.notNull(labels,
+ "labels cannot be null");
+ if (this.labels == null) {
+ this.labels = new ArrayList();
+ }
+ this.labels.add(labels);
+ return this;
+ }
+
+ /**
+ * Set the labels.
+ * Existing labels will be replaced.
+ *
+ * @param labels the labels
+ * @return the ApiGatewayOperationsLabelsInputUser builder
+ */
+ public Builder labels(List labels) {
+ this.labels = labels;
+ return this;
+ }
+ }
+
+ protected ApiGatewayOperationsLabelsInputUser() { }
+
+ protected ApiGatewayOperationsLabelsInputUser(Builder builder) {
+ labels = builder.labels;
+ }
+
+ /**
+ * New builder.
+ *
+ * @return a ApiGatewayOperationsLabelsInputUser builder
+ */
+ public Builder newBuilder() {
+ return new Builder(this);
+ }
+
+ /**
+ * Gets the labels.
+ *
+ * Array of user-defined label strings.
+ *
+ * @return the labels
+ */
+ public List labels() {
+ return labels;
+ }
+}
+
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsResp.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsResp.java
new file mode 100644
index 000000000..274954429
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsResp.java
@@ -0,0 +1,76 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1.model;
+
+import java.util.List;
+
+import com.ibm.cloud.sdk.core.service.model.GenericModel;
+
+/**
+ * API Gateway operations labels update response.
+ */
+public class ApiGatewayOperationsLabelsResp extends GenericModel {
+
+ protected Boolean success;
+ protected List> errors;
+ protected List> messages;
+ protected List result;
+
+ protected ApiGatewayOperationsLabelsResp() { }
+
+ /**
+ * Gets the success.
+ *
+ * Was operation successful.
+ *
+ * @return the success
+ */
+ public Boolean isSuccess() {
+ return success;
+ }
+
+ /**
+ * Gets the errors.
+ *
+ * Array of errors encountered.
+ *
+ * @return the errors
+ */
+ public List> getErrors() {
+ return errors;
+ }
+
+ /**
+ * Gets the messages.
+ *
+ * Array of messages returned.
+ *
+ * @return the messages
+ */
+ public List> getMessages() {
+ return messages;
+ }
+
+ /**
+ * Gets the result.
+ *
+ * List of operations with their updated label sets.
+ *
+ * @return the result
+ */
+ public List getResult() {
+ return result;
+ }
+}
+
diff --git a/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsRespResultItem.java b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsRespResultItem.java
new file mode 100644
index 000000000..087a404c4
--- /dev/null
+++ b/modules/ai-security-for-apps/src/main/java/com/ibm/cloud/networking/ai_security_for_apps/v1/model/ApiGatewayOperationsLabelsRespResultItem.java
@@ -0,0 +1,51 @@
+/*
+ * (C) Copyright IBM Corp. 2026.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
+ * an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
+ * specific language governing permissions and limitations under the License.
+ */
+
+package com.ibm.cloud.networking.ai_security_for_apps.v1.model;
+
+import java.util.List;
+import java.util.Map;
+
+import com.google.gson.annotations.SerializedName;
+import com.ibm.cloud.sdk.core.service.model.GenericModel;
+
+/**
+ * ApiGatewayOperationsLabelsRespResultItem.
+ */
+public class ApiGatewayOperationsLabelsRespResultItem extends GenericModel {
+
+ @SerializedName("operation_id")
+ protected String operationId;
+ protected List