Apply a policy file
Applies exactly the reviewed plan in one transaction: every change and its history entry commit together or not at all. Refuses with 409 STALE_PLAN when the file, the environment’s policies or the referenced actions changed since the plan, and with 400 POLICY_FILE_INVALID when the plan has errors. The digest is a staleness check, not an authorization. The credential is recorded as the actor on each version.
/api/v2/approval-policies/files/applyAuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
X-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
application/jsonsourcestringrequireddigeststringrequiredThe digest from the plan you reviewed.
changeNotestringRecorded on every version this apply writes. Defaults to "Applied policy file <file>".
The applied plan.
successbooleanrequiredtruedataobjectrequiredShow propertiesHide properties
filestringrequiredenvironmentIdstring<uuid>requireddigeststringrequiredchangesPolicyFileChange[]requiredShow propertiesHide properties
PolicyFileChangeopstringrequiredcreateupdatedeleteunchangedkeystringrequirednamestringrequiredpolicyIdstringversionintegerfieldsstring[]For updates: the fields that change.
afterobjectFor creates and updates: the policy as the file declares it.
summaryobjectrequiredShow propertiesHide properties
createintegerrequiredupdateintegerrequireddeleteintegerrequiredunchangedintegerrequirederrorsstring[]requiredProblems that prevent applying. Empty when the file can be applied.
appliedbooleanrequiredtrueBad Request - Invalid input data
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectUnauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectAuthenticated credential lacks the required scope or workspace access.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectThe request conflicts with current resource state or a concurrent decision.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectToo Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
