APIData Protection

Create DLP rule

Create a DLP rule.

POST/dlp/rules

Create a DLP rule.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

A data-protection rule that rewrites tool responses after a policy has allowed the call. It never decides whether a call runs; it only redacts matching content on the way back to the agent. Every rule whose scope matches is applied, not just the first.

Response Body

application/json

application/json

curl -X POST "https://example.com/dlp/rules" \  -H "Content-Type: application/json" \  -d '{    "name": "string",    "scope": {},    "filters": [      {        "type": "regex",        "pattern": "string"      }    ]  }'
{  "id": null,  "name": "string",  "description": "string",  "status": "active",  "target": "mcp_tool_response",  "scope": {    "mcp_ids": [      "c2c9208c-a7ac-41cc-84f1-8c1caec92987"    ],    "agent_slugs": [      "string"    ],    "agent_instance_ids": [      "bc3f18ff-0dcd-4cc7-8f61-6ca61814f10b"    ],    "user_ids": [      "2d98503d-4ab4-41bd-8fc6-78cc006fd2db"    ],    "groups": [      "string"    ],    "agent_slug_tag_ids": [      "e428595a-d9dd-4887-8327-2d9cad5b7425"    ],    "mcp_tag_ids": [      "17d4a46c-d971-4171-9a66-88ec59ce6eeb"    ],    "tool_tag_ids": [      "41068329-9b4f-4cc3-b249-3ec2a7a2cee8"    ],    "tool_patterns": [      "string"    ],    "condition": "string",    "condition_description": "string"  },  "action": "redact",  "filters": [    {      "type": "regex",      "pattern": "string",      "replacement": "string"    }  ],  "on_error": "block",  "created_at": "2019-08-24T14:15:22Z",  "updated_at": "2019-08-24T14:15:22Z"}
{  "code": "bad_request",  "message": "string",  "validation_errors": [    {      "field": "string",      "message": "string",      "rule": "string"    }  ]}