Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview

Plan a policy file

Read-only. Parses a policy file (YAML or JSON, at most 256 KiB, no duplicate keys or aliases), checks every policy (targets, CEL conditions against the action’s input schema, name clashes, broad denies, the plan’s policy allowance) and returns what applying it would create, update and delete. Only policies owned by this file are ever changed; console-made and other files’ policies are never taken over. errors lists everything that prevents applying. digest identifies the reviewed state: pass it to apply, which refuses if anything changed since. The file must declare the credential’s environment.

POST/api/v2/approval-policies/files/plan
Authorization
AuthorizationBearer token (Anlyon API key) · headerrequired

Workspace API key sent as Authorization: Bearer <key>.

or
better-auth.session_tokenAPI key · cookierequired

Browser session used by dashboard-only operations.

Header parameters
X-Request-Idstring

Optional caller correlation ID. Unsafe or oversized values are replaced.

max length 128
Request body
requiredapplication/json
sourcestringrequired

The policy file text (YAML or JSON). apiVersion anlyon.com/policies/v1.

min length 1 · max length 262144
Responses
200

The plan.

successbooleanrequired
Allowed:true
dataPolicyFilePlanrequired
Show properties
filestringrequired
environmentIdstring<uuid>required
digeststringrequired
matches ^[0-9a-f]{64}$
changesPolicyFileChange[]required
Show properties
Array of PolicyFileChange
opstringrequired
Allowed:createupdatedeleteunchanged
keystringrequired
namestringrequired
policyIdstring
versioninteger
fieldsstring[]

For updates: the fields that change.

afterobject

For creates and updates: the policy as the file declares it.

summaryobjectrequired
Show properties
createintegerrequired
updateintegerrequired
deleteintegerrequired
unchangedintegerrequired
errorsstring[]required

Problems that prevent applying. Empty when the file can be applied.

400

Bad Request - Invalid input data

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
401

Unauthorized - Invalid or missing API key

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
403

Authenticated credential lacks the required scope or workspace access.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
429

Too Many Requests - Rate limit exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST 'https://api.anlyon.com/api/v2/approval-policies/files/plan' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "source": "string"
}'
Response
{
  "success": true,
  "data": {
    "file": "string",
    "environmentId": "19f5cc2e-7657-437a-9268-83cd3d563563",
    "digest": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
    "changes": [
      {
        "op": "create",
        "key": "string",
        "name": "string",
        "policyId": "string",
        "version": 0,
        "fields": [
          "string"
        ],
        "after": {}
      }
    ],
    "summary": {
      "create": 0,
      "update": 0,
      "delete": 0,
      "unchanged": 0
    },
    "errors": [
      "string"
    ]
  }
}