APIData protection

Create DLP rule

Create a DLP rule.

POST
/dlp/rules

Create a DLP rule.

Authorization

ApiKeyAuth
headerAuthorizationBearer <token>

Bearer token authentication. Send an API key (a saai_api_-prefixed token) as Authorization: Bearer <token>.

Required permission

manage_data_protection

Request Body

application/json
  1. body

A data-protection rule that rewrites tool responses after a policy has allowed the call. It never decides whether a call runs; it only redacts matching content on the way back to the agent. Every rule whose scope matches is applied, not just the first.

name*string

Short label for the rule, shown in the rule list.

description?|

Optional note explaining what the rule protects against.

status?DlpRuleStatus

Whether a DLP rule takes part in filtering.

Value in"active""draft""disabled"
target?"mcp_tool_response"

Which responses the rule inspects.

Value in"mcp_tool_response"
scope*

Which agents, users, MCP servers, and tools this rule's filters apply to.

action?"redact"

What the rule does to matched content.

Value in"redact"
filters*array<|>

Filters run against each matching response. Every matching filter is applied.

on_error?string

Failure routing for this rule's filters. Treated as block when unset.

Value in"block""allow"

Response Body

The request has succeeded and a new resource has been created as a result.

application/json
  1. response

A data-protection rule that rewrites tool responses after a policy has allowed the call. It never decides whether a call runs; it only redacts matching content on the way back to the agent. Every rule whose scope matches is applied, not just the first.

id*string
Formatuuid
name*string

Short label for the rule, shown in the rule list.

description?|

Optional note explaining what the rule protects against.

status?DlpRuleStatus

Whether a DLP rule takes part in filtering.

Value in"active""draft""disabled"
target?"mcp_tool_response"

Which responses the rule inspects.

Value in"mcp_tool_response"
scope*

Which agents, users, MCP servers, and tools this rule's filters apply to.

action?"redact"

What the rule does to matched content.

Value in"redact"
filters*array<|>

Filters run against each matching response. Every matching filter is applied.

on_error?string

Failure routing for this rule's filters. Treated as block when unset.

Value in"block""allow"
created_at*string
Formatdate-time
updated_at*string
Formatdate-time
curl -X POST "https://example.com/dlp/rules" \  -H "Content-Type: application/json" \  -d '{    "name": "string",    "scope": {},    "filters": [      {        "type": "regex",        "pattern": "string"      }    ]  }'
{  "id": null,  "name": "string",  "description": "string",  "status": "active",  "target": "mcp_tool_response",  "scope": {    "mcp_ids": [      "c2c9208c-a7ac-41cc-84f1-8c1caec92987"    ],    "agent_slugs": [      "string"    ],    "agent_instance_ids": [      "bc3f18ff-0dcd-4cc7-8f61-6ca61814f10b"    ],    "user_ids": [      "2d98503d-4ab4-41bd-8fc6-78cc006fd2db"    ],    "groups": [      "string"    ],    "agent_slug_tag_ids": [      "e428595a-d9dd-4887-8327-2d9cad5b7425"    ],    "mcp_tag_ids": [      "17d4a46c-d971-4171-9a66-88ec59ce6eeb"    ],    "tool_tag_ids": [      "41068329-9b4f-4cc3-b249-3ec2a7a2cee8"    ],    "tool_patterns": [      "string"    ],    "condition": "string",    "condition_description": "string"  },  "action": "redact",  "filters": [    {      "type": "regex",      "pattern": "string",      "replacement": "string"    }  ],  "on_error": "block",  "created_at": "2019-08-24T14:15:22Z",  "updated_at": "2019-08-24T14:15:22Z"}