Create policy
Create a policy. Without a placement, a deny goes to the top of the list and any other rule to the bottom.
Create a policy. Without a placement, a deny goes to the top of the list and any other rule to the bottom.
ApiKeyAuthAuthorizationBearer <token>Bearer token authentication. Send an API key (a saai_api_-prefixed token) as Authorization: Bearer <token>.
Required permission
manage_policiesapplication/json- body
One rule in the ordered list that decides which tools an agent may call, for which users, under what conditions. Rules are evaluated top to bottom and the first match wins; a request that matches no rule is denied by default.
placement?Where to put the rule. On create, omit it for the default: a deny goes to the top, any other rule to the bottom. On update, omit it to keep the current position.
mcp_ids?array<>|nullagent_slugs?array<string>|nullagent_instance_ids?array<>|nulluser_ids?array<>|nullgroups?array<string>|nullagent_slug_tag_ids?array<>|nullmcp_tag_ids?array<>|nulltool_tag_ids?array<>|nullcondition?|Optional CEL expression evaluated per call to narrow the match beyond the static selectors above. Its variables are the MCP tool-call context.
condition_description?|Human-readable summary of condition, shown in place of the raw CEL expression. Cleared whenever the expression changes.
tool_patterns*array<string>Tool names or glob patterns this rule governs. Required: a rule must name the tools it covers.
effect*PolicyEffectWhether a matching rule permits, blocks, or gates the call.
"allow""deny""require_approval"status?PolicyStatusWhether a policy takes part in evaluation.
"active""draft""disabled"approval_grace_seconds?|How long one approval stays reusable for later calls this rule matches, in seconds. Null uses the default. Only meaningful with the require_approval effect.
int320 <= valuename*stringShort label for the rule, shown in the policy list.
description?|Optional note explaining the rule's intent.
The request has succeeded and a new resource has been created as a result.
application/json- response
One rule in the ordered list that decides which tools an agent may call, for which users, under what conditions. Rules are evaluated top to bottom and the first match wins; a request that matches no rule is denied by default.
id*stringuuidpriority*integerPosition in the evaluation order: lower numbers are checked first. Set it with placement on create or update.
int32mcp_ids?array<>|nullagent_slugs?array<string>|nullagent_instance_ids?array<>|nulluser_ids?array<>|nullgroups?array<string>|nullagent_slug_tag_ids?array<>|nullmcp_tag_ids?array<>|nulltool_tag_ids?array<>|nullcondition?|Optional CEL expression evaluated per call to narrow the match beyond the static selectors above. Its variables are the MCP tool-call context.
condition_description?|Human-readable summary of condition, shown in place of the raw CEL expression. Cleared whenever the expression changes.
tool_patterns*array<string>Tool names or glob patterns this rule governs. Required: a rule must name the tools it covers.
effect*PolicyEffectWhether a matching rule permits, blocks, or gates the call.
"allow""deny""require_approval"status?PolicyStatusWhether a policy takes part in evaluation.
"active""draft""disabled"approval_grace_seconds?|How long one approval stays reusable for later calls this rule matches, in seconds. Null uses the default. Only meaningful with the require_approval effect.
int320 <= valuename*stringShort label for the rule, shown in the policy list.
description?|Optional note explaining the rule's intent.
agent_instance_refs?array<>Running agent instances this rule's scope currently resolves to.
user_refs?array<>Users this rule's scope currently resolves to.
created_at*stringdate-timeupdated_at*stringdate-timecurl -X POST "https://example.com/policies" \ -H "Content-Type: application/json" \ -d '{ "tool_patterns": [ "string" ], "effect": "allow", "name": "string" }'{ "id": null, "priority": 0, "mcp_ids": [ "c2c9208c-a7ac-41cc-84f1-8c1caec92987" ], "agent_slugs": [ "string" ], "agent_instance_ids": [ "bc3f18ff-0dcd-4cc7-8f61-6ca61814f10b" ], "user_ids": [ "2d98503d-4ab4-41bd-8fc6-78cc006fd2db" ], "groups": [ "string" ], "agent_slug_tag_ids": [ "e428595a-d9dd-4887-8327-2d9cad5b7425" ], "mcp_tag_ids": [ "17d4a46c-d971-4171-9a66-88ec59ce6eeb" ], "tool_tag_ids": [ "41068329-9b4f-4cc3-b249-3ec2a7a2cee8" ], "condition": "string", "condition_description": "string", "tool_patterns": [ "string" ], "effect": "allow", "status": "active", "approval_grace_seconds": 0, "name": "string", "description": "string", "agent_instance_refs": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "display_name": "string", "user_display_name": "string" } ], "user_refs": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "display_name": "string" } ], "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z"}