Plan a policy file
Read-only. Parses a policy file (YAML or JSON, at most 256 KiB, no duplicate keys or aliases), checks every policy (targets, CEL conditions against the action’s input schema, name clashes, broad denies, the plan’s policy allowance) and returns what applying it would create, update and delete. Only policies owned by this file are ever changed; console-made and other files’ policies are never taken over. errors lists everything that prevents applying. digest identifies the reviewed state: pass it to apply, which refuses if anything changed since. The file must declare the credential’s environment.
/api/v2/approval-policies/files/planAuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
X-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
application/jsonsourcestringrequiredThe policy file text (YAML or JSON). apiVersion anlyon.com/policies/v1.
The plan.
successbooleanrequiredtruedataPolicyFilePlanrequiredShow propertiesHide properties
filestringrequiredenvironmentIdstring<uuid>requireddigeststringrequiredchangesPolicyFileChange[]requiredShow propertiesHide properties
PolicyFileChangeopstringrequiredcreateupdatedeleteunchangedkeystringrequirednamestringrequiredpolicyIdstringversionintegerfieldsstring[]For updates: the fields that change.
afterobjectFor creates and updates: the policy as the file declares it.
summaryobjectrequiredShow propertiesHide properties
createintegerrequiredupdateintegerrequireddeleteintegerrequiredunchangedintegerrequirederrorsstring[]requiredProblems that prevent applying. Empty when the file can be applied.
Bad Request - Invalid input data
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectUnauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectAuthenticated credential lacks the required scope or workspace access.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectToo Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
