PUT/v1/policy

Create a policy

Creates a new policy. If you submit a request body, include name, operator, uuid, and violationState; the body itself may be omitted. The authenticated user must have POLICY_MANAGEMENT or POLICY_MANAGEMENT_CREATE permission.

11 body fields

Optional policy data for creation. If you send a body, name, operator, uuid, and violationState are required.

globalbooleanoptional
Whether the policy applies globally.
includeChildrenbooleanoptional
Whether the policy includes child projects.
invertTagMatchbooleanoptional
Whether to invert the policy's tag-matching behavior.
namestringrequired
The policy name. Must be 1 to 255 characters.
onlyLatestProjectVersionbooleanoptional
Whether the policy applies only to the latest project version.
operatorstringrequired
The policy matching operator: `ALL` or `ANY`.
Allowed:ALLANY
policyConditionsarray<object>optional
Conditions used to evaluate the policy. Each condition requires `operator`, `subject`, `uuid`, and `value`; its operator and violation type must use the schema's listed values.
projectsarray<object>optional
Project records associated with the policy. Each project requires `lastBomImport`, `name`, and `uuid`.
tagsarray<object>optional
Unique tags associated with the policy. Each tag requires a `name`.
uuidstringrequired
The policy's UUID, in UUID format.
violationStatestringrequired
The policy violation state: `INFO`, `WARN`, or `FAIL`.
Allowed:INFOWARNFAIL

3 status codes
201Returns the created policy object, including its policy settings, conditions, associated projects, and tags.
globalbooleanoptional
includeChildrenbooleanoptional
invertTagMatchbooleanoptional
namestringrequired
onlyLatestProjectVersionbooleanoptional
operatorstringrequired
Allowed:ALLANY
policyConditionsarray<object>optional
projectsarray<object>optional
tagsarray<object>optional
uuidstringrequired
violationStatestringrequired
Allowed:INFOWARNFAIL
401Returned when the authenticated user is unauthorized to create a policy.
409Returned when a policy with the specified name already exists.

Error handling

A 401 is returned when the authenticated user lacks POLICY_MANAGEMENT or POLICY_MANAGEMENT_CREATE. A 409 is returned when a policy with the submitted name already exists. If you send a body, name, operator, uuid, and violationState are required; operator must be ALL or ANY, violationState must be INFO, WARN, or FAIL, and uuid must use UUID format.