> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blindsight.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Agent Get Pause

> Whether this device is paused, and whether its person may change that.

``allowed`` is what the desktop app uses to decide if the toggle is even
offered. It is a courtesy, not the control: the POST above is what
actually enforces it -- but both read the same
:func:`pause_authority`, because a courtesy that disagrees with the
control is worse than no courtesy at all.

``reason`` / ``reason_message`` say WHY it is refused. Without them the app
could only grey the switch out and say nothing, leaving the person to guess
between "your admin has not allowed this", "nobody has proved this machine
is yours" and "the product is broken".

``reason`` is the stable code to branch on; ``reason_message`` is the
sentence the app shows the person unchanged, so it is written for them and
not for us. The codes are:

``device_identity_unverified``   this machine's owner is unproved, and the
                                 person can fix it by signing in
``identity_binding_unavailable`` same gate, but the workspace has no SSO,
                                 so only an administrator can fix it
``device_unattributed``          no person on the device to check at all
``owner_inactive``               the account it belongs to is switched off
``permission_denied``            proved owner, permission not granted
``null``                         nothing is refused (``allowed`` is true)



## OpenAPI

````yaml /api-reference/openapi.json get /api/runtime-security/agent/protection/pause
openapi: 3.1.0
info:
  title: Blindsight API
  version: 0.1.0
  description: >-
    The full Blindsight REST surface, generated from the running application.
    Replace the server host with your own deployment.


    For the Runtime Security integration surface (scan, proxy, tool calls) see
    the Runtime Security spec, which is hand written and carries worked
    examples.
servers:
  - url: https://api.your-blindsight.com
    description: Your Blindsight deployment
security: []
paths:
  /api/runtime-security/agent/protection/pause:
    get:
      tags:
        - runtime-security-agent
      summary: Agent Get Pause
      description: >-
        Whether this device is paused, and whether its person may change that.


        ``allowed`` is what the desktop app uses to decide if the toggle is even

        offered. It is a courtesy, not the control: the POST above is what

        actually enforces it -- but both read the same

        :func:`pause_authority`, because a courtesy that disagrees with the

        control is worse than no courtesy at all.


        ``reason`` / ``reason_message`` say WHY it is refused. Without them the
        app

        could only grey the switch out and say nothing, leaving the person to
        guess

        between "your admin has not allowed this", "nobody has proved this
        machine

        is yours" and "the product is broken".


        ``reason`` is the stable code to branch on; ``reason_message`` is the

        sentence the app shows the person unchanged, so it is written for them
        and

        not for us. The codes are:


        ``device_identity_unverified``   this machine's owner is unproved, and
        the
                                         person can fix it by signing in
        ``identity_binding_unavailable`` same gate, but the workspace has no
        SSO,
                                         so only an administrator can fix it
        ``device_unattributed``          no person on the device to check at all

        ``owner_inactive``               the account it belongs to is switched
        off

        ``permission_denied``            proved owner, permission not granted

        ``null``                         nothing is refused (``allowed`` is
        true)
      operationId: agent_get_pause_api_runtime_security_agent_protection_pause_get
      parameters:
        - name: X-Blindsight-Device-Token
          in: header
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: X-Blindsight-Device-Token
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema: {}
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError

````