Evaluate current policies without executing
Read-only evaluation against the credential’s environment. Uses production matcher ordering and fail-closed behavior. Attribution is hypothetical. The result is policy-only, not an authorization or a final invocation decision; action version pins, approval floor, schema validation, budgets, halt state and runtime authority are not evaluated. Amount is derived from payload.amount, custom tags from payload.tags. Action contexts require an existing action name.
/api/v2/approval-policies/evaluateAuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
X-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
application/jsonkindstringrequiredactioncustomactionNamestringRequired for action contexts; forbidden for custom contexts.
agentIdstring | nullHypothetical attribution, never runtime authority.
userIdstring | nullpayloadobjectAction input or custom payload. Amount is read from the numeric amount field; only custom requests use the tags field.
Policy-only evaluation; no dispatch or policy mutation.
successbooleanrequiredtruedataPolicyEvaluationrequiredShow propertiesHide properties
evaluationstringrequiredpolicy_onlyenvironmentIdstringrequiredlimitationsstringrequireddecisionobjectrequiredShow propertiesHide properties
matchedbooleanrequiredeffectstringrequiredrequire_approvalauto_approveauto_denyrequiredApprovalsintegerrequiredmatchedPolicyIdstring | nullrequiredmatchedPolicyVersioninteger | nullrequiredmatchedPolicyNamestring | nullrequiredmatchedActionNamestring | nullrequiredexplanationstringrequiredBad Request - Invalid input data
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectUnauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectAuthenticated credential lacks the required scope or workspace access.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectNot Found - Resource does not exist
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectToo Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
