List approval policies
Policies in the credential’s own environment, in evaluation order. Needs policies:read, or a console session. With ?actionName= only the policies that could govern that action are returned: the ones naming it plus the broad ones that also catch it. A credential is bound to one environment; an environmentId query that disagrees with it is refused.
/api/v2/approval-policiesAuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
actionNamestringX-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
Approval policies in the workspace.
successbooleanrequiredtruedataApprovalPolicy[]requiredShow propertiesHide properties
ApprovalPolicyidstringrequiredPublic policy id (apol_xxx).
environmentIdstring<uuid>requiredThe environment the policy governs. Policies never span environments.
namestringrequiredpriorityintegerrequiredLower runs first. Ties are broken by creation time, then by id, so the order is always deterministic.
enabledbooleanrequiredscopestringrequiredWhat the policy applies to, derived from match. Never inferred from the name.
specific_actionall_actionscustom_requestsall_requestsneedsScopeReviewbooleanrequiredTrue on a broad policy nobody has confirmed the scope of. Every policy created before explicit targeting is in this state, because the old form sent no action selector. Preserved as it was, and flagged.
matchApprovalPolicyMatchrequiredShow propertiesHide properties
kindstringrequiredanyactioncustomactionNamestring | nullrequiredagentIdstring | nullrequireduserIdstring | nullrequiredtagsstring[] | nullrequiredminAmountnumber | nullrequiredconditionsobject | nullrequiredconditionstring | nullrequiredA CEL expression (https://cel.dev) that must also hold, over input, agent.id, user.id, tags, action.name and kind. Checked against the target action's input schema when saved. An evaluation error (for example a missing field) requires approval rather than skipping the policy; guard optional fields with has().
effectstringrequiredrequire_approvalauto_approveauto_denyrequiredApprovalsintegerrequiredDistinct approvers needed (N-of-M).
versionintegerrequiredBumps on each edit; recorded on approvals this policy governs.
scopeReviewedAtstring<date-time> | nullrequiredcreatedAtstring<date-time>requiredupdatedAtstring<date-time>requiredmanagedByobject | nullSet when a policy file owns this policy. Console and API edits of it are refused; change the file.
Show propertiesHide properties
filestringrequiredkeystringrequiredUnauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectAuthenticated credential lacks the required scope or workspace access.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectToo Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
