Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview

Evaluate current policies without executing

Read-only evaluation against the credential’s environment. Uses production matcher ordering and fail-closed behavior. Attribution is hypothetical. The result is policy-only, not an authorization or a final invocation decision; action version pins, approval floor, schema validation, budgets, halt state and runtime authority are not evaluated. Amount is derived from payload.amount, custom tags from payload.tags. Action contexts require an existing action name.

POST/api/v2/approval-policies/evaluate
Authorization
AuthorizationBearer token (Anlyon API key) · headerrequired

Workspace API key sent as Authorization: Bearer <key>.

or
better-auth.session_tokenAPI key · cookierequired

Browser session used by dashboard-only operations.

Header parameters
X-Request-Idstring

Optional caller correlation ID. Unsafe or oversized values are replaced.

max length 128
Request body
requiredapplication/json
kindstringrequired
Allowed:actioncustom
actionNamestring

Required for action contexts; forbidden for custom contexts.

min length 1 · max length 200
agentIdstring | null

Hypothetical attribution, never runtime authority.

max length 60
userIdstring | null
max length 200
payloadobject

Action input or custom payload. Amount is read from the numeric amount field; only custom requests use the tags field.

Responses
200

Policy-only evaluation; no dispatch or policy mutation.

successbooleanrequired
Allowed:true
dataPolicyEvaluationrequired
Show properties
evaluationstringrequired
Allowed:policy_only
environmentIdstringrequired
limitationsstringrequired
decisionobjectrequired
Show properties
matchedbooleanrequired
effectstringrequired
Allowed:require_approvalauto_approveauto_deny
requiredApprovalsintegerrequired
matchedPolicyIdstring | nullrequired
matchedPolicyVersioninteger | nullrequired
matchedPolicyNamestring | nullrequired
matchedActionNamestring | nullrequired
explanationstringrequired
400

Bad Request - Invalid input data

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
401

Unauthorized - Invalid or missing API key

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
403

Authenticated credential lacks the required scope or workspace access.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
404

Not Found - Resource does not exist

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
429

Too Many Requests - Rate limit exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST 'https://api.anlyon.com/api/v2/approval-policies/evaluate' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "kind": "action",
  "actionName": "string",
  "agentId": "string",
  "userId": "string",
  "payload": {}
}'
Response
{
  "success": true,
  "data": {
    "evaluation": "policy_only",
    "environmentId": "string",
    "limitations": "string",
    "decision": {
      "matched": true,
      "effect": "require_approval",
      "requiredApprovals": 0,
      "matchedPolicyId": "string",
      "matchedPolicyVersion": 0,
      "matchedPolicyName": "string",
      "matchedActionName": "string",
      "explanation": "string"
    }
  }
}