Update an approval policy
Needs policies:write. Omitted fields are unchanged; an explicit null clears a nullable matcher. Enabling or disabling a policy is a patch of enabled. Bumps the version. Decisions already recorded on invocations keep the explanation they were made with.
/api/v2/approval-policies/{policyId}AuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
policyIdstringrequiredPublic approval-policy id (apol_xxx).
X-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
application/jsonnamestringpriorityintegerenabledbooleanmatchKindstringanyactioncustommatchActionNamestring | nullmatchAgentIdstring | nullmatchUserIdstring | nullmatchTagsstring[] | nullminAmountnumber | nullconditionsobject | nullconditionstring | nullA CEL expression (https://cel.dev) that must also hold, over input, agent.id, user.id, tags, action.name and kind. Checked against the target action's input schema when saved. An evaluation error (for example a missing field) requires approval rather than skipping the policy; guard optional fields with has().
effectstringrequire_approvalauto_approveauto_denyrequiredApprovalsintegeracknowledgeBroadScopebooleanA single approval policy.
successbooleanrequiredtruedataApprovalPolicyrequiredShow propertiesHide properties
idstringrequiredPublic policy id (apol_xxx).
environmentIdstring<uuid>requiredThe environment the policy governs. Policies never span environments.
namestringrequiredpriorityintegerrequiredLower runs first. Ties are broken by creation time, then by id, so the order is always deterministic.
enabledbooleanrequiredscopestringrequiredWhat the policy applies to, derived from match. Never inferred from the name.
specific_actionall_actionscustom_requestsall_requestsneedsScopeReviewbooleanrequiredTrue on a broad policy nobody has confirmed the scope of. Every policy created before explicit targeting is in this state, because the old form sent no action selector. Preserved as it was, and flagged.
matchApprovalPolicyMatchrequiredShow propertiesHide properties
kindstringrequiredanyactioncustomactionNamestring | nullrequiredagentIdstring | nullrequireduserIdstring | nullrequiredtagsstring[] | nullrequiredminAmountnumber | nullrequiredconditionsobject | nullrequiredconditionstring | nullrequiredA CEL expression (https://cel.dev) that must also hold, over input, agent.id, user.id, tags, action.name and kind. Checked against the target action's input schema when saved. An evaluation error (for example a missing field) requires approval rather than skipping the policy; guard optional fields with has().
effectstringrequiredrequire_approvalauto_approveauto_denyrequiredApprovalsintegerrequiredDistinct approvers needed (N-of-M).
versionintegerrequiredBumps on each edit; recorded on approvals this policy governs.
scopeReviewedAtstring<date-time> | nullrequiredcreatedAtstring<date-time>requiredupdatedAtstring<date-time>requiredmanagedByobject | nullSet when a policy file owns this policy. Console and API edits of it are refused; change the file.
Show propertiesHide properties
filestringrequiredkeystringrequiredBad Request - Invalid input data
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectUnauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectAuthenticated credential lacks the required scope or workspace access.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectNot Found - Resource does not exist
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectThe request conflicts with current resource state or a concurrent decision.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectToo Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
