APIPolicies

Create policy

Create a policy. Without a placement, a deny goes to the top of the list and any other rule to the bottom.

POST
/policies

Create a policy. Without a placement, a deny goes to the top of the list and any other rule to the bottom.

Authorization

ApiKeyAuth
headerAuthorizationBearer <token>

Bearer token authentication. Send an API key (a saai_api_-prefixed token) as Authorization: Bearer <token>.

Required permission

manage_policies

Request Body

application/json
  1. body

One rule in the ordered list that decides which tools an agent may call, for which users, under what conditions. Rules are evaluated top to bottom and the first match wins; a request that matches no rule is denied by default.

placement?

Where to put the rule. On create, omit it for the default: a deny goes to the top, any other rule to the bottom. On update, omit it to keep the current position.

mcp_ids?array<>|null
agent_slugs?array<string>|null
agent_instance_ids?array<>|null
user_ids?array<>|null
groups?array<string>|null
agent_slug_tag_ids?array<>|null
mcp_tag_ids?array<>|null
tool_tag_ids?array<>|null
condition?|

Optional CEL expression evaluated per call to narrow the match beyond the static selectors above. Its variables are the MCP tool-call context.

condition_description?|

Human-readable summary of condition, shown in place of the raw CEL expression. Cleared whenever the expression changes.

tool_patterns*array<string>

Tool names or glob patterns this rule governs. Required: a rule must name the tools it covers.

effect*PolicyEffect

Whether a matching rule permits, blocks, or gates the call.

Value in"allow""deny""require_approval"
status?PolicyStatus

Whether a policy takes part in evaluation.

Value in"active""draft""disabled"
approval_grace_seconds?|

How long one approval stays reusable for later calls this rule matches, in seconds. Null uses the default. Only meaningful with the require_approval effect.

Formatint32
Range0 <= value
name*string

Short label for the rule, shown in the policy list.

description?|

Optional note explaining the rule's intent.

Response Body

The request has succeeded and a new resource has been created as a result.

application/json
  1. response

One rule in the ordered list that decides which tools an agent may call, for which users, under what conditions. Rules are evaluated top to bottom and the first match wins; a request that matches no rule is denied by default.

id*string
Formatuuid
priority*integer

Position in the evaluation order: lower numbers are checked first. Set it with placement on create or update.

Formatint32
mcp_ids?array<>|null
agent_slugs?array<string>|null
agent_instance_ids?array<>|null
user_ids?array<>|null
groups?array<string>|null
agent_slug_tag_ids?array<>|null
mcp_tag_ids?array<>|null
tool_tag_ids?array<>|null
condition?|

Optional CEL expression evaluated per call to narrow the match beyond the static selectors above. Its variables are the MCP tool-call context.

condition_description?|

Human-readable summary of condition, shown in place of the raw CEL expression. Cleared whenever the expression changes.

tool_patterns*array<string>

Tool names or glob patterns this rule governs. Required: a rule must name the tools it covers.

effect*PolicyEffect

Whether a matching rule permits, blocks, or gates the call.

Value in"allow""deny""require_approval"
status?PolicyStatus

Whether a policy takes part in evaluation.

Value in"active""draft""disabled"
approval_grace_seconds?|

How long one approval stays reusable for later calls this rule matches, in seconds. Null uses the default. Only meaningful with the require_approval effect.

Formatint32
Range0 <= value
name*string

Short label for the rule, shown in the policy list.

description?|

Optional note explaining the rule's intent.

agent_instance_refs?array<>

Running agent instances this rule's scope currently resolves to.

user_refs?array<>

Users this rule's scope currently resolves to.

created_at*string
Formatdate-time
updated_at*string
Formatdate-time
curl -X POST "https://example.com/policies" \  -H "Content-Type: application/json" \  -d '{    "tool_patterns": [      "string"    ],    "effect": "allow",    "name": "string"  }'
{  "id": null,  "priority": 0,  "mcp_ids": [    "c2c9208c-a7ac-41cc-84f1-8c1caec92987"  ],  "agent_slugs": [    "string"  ],  "agent_instance_ids": [    "bc3f18ff-0dcd-4cc7-8f61-6ca61814f10b"  ],  "user_ids": [    "2d98503d-4ab4-41bd-8fc6-78cc006fd2db"  ],  "groups": [    "string"  ],  "agent_slug_tag_ids": [    "e428595a-d9dd-4887-8327-2d9cad5b7425"  ],  "mcp_tag_ids": [    "17d4a46c-d971-4171-9a66-88ec59ce6eeb"  ],  "tool_tag_ids": [    "41068329-9b4f-4cc3-b249-3ec2a7a2cee8"  ],  "condition": "string",  "condition_description": "string",  "tool_patterns": [    "string"  ],  "effect": "allow",  "status": "active",  "approval_grace_seconds": 0,  "name": "string",  "description": "string",  "agent_instance_refs": [    {      "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",      "display_name": "string",      "user_display_name": "string"    }  ],  "user_refs": [    {      "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",      "display_name": "string"    }  ],  "created_at": "2019-08-24T14:15:22Z",  "updated_at": "2019-08-24T14:15:22Z"}