Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview

Apply a policy file

Applies exactly the reviewed plan in one transaction: every change and its history entry commit together or not at all. Refuses with 409 STALE_PLAN when the file, the environment’s policies or the referenced actions changed since the plan, and with 400 POLICY_FILE_INVALID when the plan has errors. The digest is a staleness check, not an authorization. The credential is recorded as the actor on each version.

POST/api/v2/approval-policies/files/apply
Authorization
AuthorizationBearer token (Anlyon API key) · headerrequired

Workspace API key sent as Authorization: Bearer <key>.

or
better-auth.session_tokenAPI key · cookierequired

Browser session used by dashboard-only operations.

Header parameters
X-Request-Idstring

Optional caller correlation ID. Unsafe or oversized values are replaced.

max length 128
Request body
requiredapplication/json
sourcestringrequired
min length 1 · max length 262144
digeststringrequired

The digest from the plan you reviewed.

matches ^[0-9a-f]{64}$
changeNotestring

Recorded on every version this apply writes. Defaults to "Applied policy file <file>".

max length 1000
Responses
200

The applied plan.

successbooleanrequired
Allowed:true
dataobjectrequired
Show properties
filestringrequired
environmentIdstring<uuid>required
digeststringrequired
matches ^[0-9a-f]{64}$
changesPolicyFileChange[]required
Show properties
Array of PolicyFileChange
opstringrequired
Allowed:createupdatedeleteunchanged
keystringrequired
namestringrequired
policyIdstring
versioninteger
fieldsstring[]

For updates: the fields that change.

afterobject

For creates and updates: the policy as the file declares it.

summaryobjectrequired
Show properties
createintegerrequired
updateintegerrequired
deleteintegerrequired
unchangedintegerrequired
errorsstring[]required

Problems that prevent applying. Empty when the file can be applied.

appliedbooleanrequired
Allowed:true
400

Bad Request - Invalid input data

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
401

Unauthorized - Invalid or missing API key

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
403

Authenticated credential lacks the required scope or workspace access.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
409

The request conflicts with current resource state or a concurrent decision.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
429

Too Many Requests - Rate limit exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST 'https://api.anlyon.com/api/v2/approval-policies/files/apply' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "source": "string",
  "digest": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
  "changeNote": "string"
}'
Response
{
  "success": true,
  "data": {
    "file": "string",
    "environmentId": "19f5cc2e-7657-437a-9268-83cd3d563563",
    "digest": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
    "changes": [
      {
        "op": "create",
        "key": "string",
        "name": "string",
        "policyId": "string",
        "version": 0,
        "fields": [
          "string"
        ],
        "after": {}
      }
    ],
    "summary": {
      "create": 0,
      "update": 0,
      "delete": 0,
      "unchanged": 0
    },
    "errors": [
      "string"
    ],
    "applied": true
  }
}