Skip to content

Policies

These three routes are the policies-as-code API. The CLI calls them. Send an API key the same way as the other /v1/ routes. See Authentication.

GET /v1/policies and POST /v1/policies/test accept any non-revoked key of the organization, LIVE or TEST, bound to an agent or not. POST /v1/policies/apply accepts only an org-wide LIVE key (agentId null). Anything else is HTTP 403:

{ "error": "forbidden", "message": "policies:apply requires an org-wide LIVE key" }

--dry-run is the same route, so it needs that key too. The rate limit on each route is 60 requests per minute per key. HTTP 429 is {"error":"rate_limited"}. A body over 200 KB is HTTP 413 on the two POST routes.

Policy files use Policy files. spec.action in YAML is the action family (EXPORT), and the API name is metadata.name. The tables below are generated from https://api.vulnify.io/openapi.json.

Returns apiVersion vulnify.io/v1 and the organization’s policies sorted by name in Unicode code point order. Each item is a policy plus id and updatedAt.

Policies sorted by name

OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json). Response body.
FieldTypeRequiredDescription
apiVersionvulnify.io/v1yes
policiesarray of objectyesOrganization policies sorted by name.
policies[]objectnoOne policy. name is unique per organization. action is the action family (for example EXPORT), not an event action such as EXPORT_DATA. Omitted enabled defaults to true. Omitted mode defaults to ENFORCE. Omitted resource, null and ANY match every classification.
policies[].namestring (min length 1, max length 120)yes
policies[].descriptionstring (max length 500)no
policies[].enabledboolean (default true)no
policies[].actionANY | READ | WRITE | DELETE | EXPORTyes
policies[].resourceANY | PUBLIC | INTERNAL | SENSITIVE | CUSTOMER_PII | FINANCIAL | EMPLOYEE | nullnoResource classification. ANY and null match every classification.
policies[].conditionobjectnoEvery field that is set must match. minRecords means recordsAffected is greater than or equal to the value. maxRecords means recordsAffected is less than or equal to the value. Groups may nest up to 32 levels, with at most 20000 conditions in one group. minRecords and maxRecords are integers from 0 through 9007199254740991. agentIds holds at most 8000 ids. allOf matches when every nested condition matches. anyOf matches when at least one does. An empty allOf matches. An empty anyOf does not. dlpTypes and lgpdCategories are accepted here and are not part of the policies-as-code YAML schema.
policies[].condition.actionstring (min length 1, max length 64)noEvent action (READ_DATA, WRITE_DATA, DELETE_DATA, EXPORT_DATA, SEND_EMAIL) or an action family. Matched against the event action and its family.
policies[].condition.destinationEXTERNAL | INTERNALnoEXTERNAL matches an external destination. INTERNAL matches an internal one.
policies[].condition.destinationContainsstring (max length 100)noCase-insensitive substring of the destination.
policies[].condition.containsSensitiveDatabooleanno
policies[].condition.minRecordsinteger (0–9007199254740991)no
policies[].condition.maxRecordsinteger (0–9007199254740991)no
policies[].condition.minRiskScoreinteger (0–100)no
policies[].condition.outsideBusinessHoursbooleannoMonday to Friday 09:00-18:00 in the organization time zone, inverted.
policies[].condition.agentIdsarray of string (max items 8000)no
policies[].condition.dlpTypesarray of CPF | CNPJ | RG | CNH | PIX_KEY | PHONE_BR | CEP | CREDIT_CARD | EMAIL | HEALTH_DATA | API_KEY | PRIVATE_KEYno
policies[].condition.lgpdCategoriesarray of IDENTIFICATION | CONTACT | LOCATION | FINANCIAL | HEALTH | COMPANY | CREDENTIALSno
policies[].condition.allOfarray of JSON value (max items 20000)no
policies[].condition.anyOfarray of JSON value (max items 20000)no
policies[].decisionALLOW | REVIEW | BLOCKyes
policies[].modeENFORCE | MONITOR (default "ENFORCE")no
policies[].approverRolesarray of OWNER | ADMIN | MEMBER (unique)noRoles that may approve a REVIEW raised by this policy. Empty means owners and admins.
policies[].idstring (uuid)yes
policies[].updatedAtstring (date-time)yes
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json). Error responses.
StatusMeaning
401Missing or invalid credentials
403Caller IP is not in the API key allowlist.
42960 requests per minute per API key.

The match key is the policy name. prune: true deletes organization policies whose names are missing from policies. dryRun: true returns the plan and writes nothing. The call runs in one transaction. Each create, update, and delete appends an audit entry with metadata.source policies-as-code and the key prefix, and invalidates the decision cache.

HTTP 400 is {"error":"validation_error","fields":{...}}. Field paths look like policies[0].name. Duplicate names in the payload are a validation error, as is an unknown action, decision, mode, or role.

OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json). Request body.
FieldTypeRequiredDescription
policiesarray of objectyes
policies[]objectnoOne policy. name is unique per organization. action is the action family (for example EXPORT), not an event action such as EXPORT_DATA. Omitted enabled defaults to true. Omitted mode defaults to ENFORCE. Omitted resource, null and ANY match every classification.
policies[].namestring (min length 1, max length 120)yes
policies[].descriptionstring (max length 500)no
policies[].enabledboolean (default true)no
policies[].actionANY | READ | WRITE | DELETE | EXPORTyes
policies[].resourceANY | PUBLIC | INTERNAL | SENSITIVE | CUSTOMER_PII | FINANCIAL | EMPLOYEE | nullnoResource classification. ANY and null match every classification.
policies[].conditionobjectnoEvery field that is set must match. minRecords means recordsAffected is greater than or equal to the value. maxRecords means recordsAffected is less than or equal to the value. Groups may nest up to 32 levels, with at most 20000 conditions in one group. minRecords and maxRecords are integers from 0 through 9007199254740991. agentIds holds at most 8000 ids. allOf matches when every nested condition matches. anyOf matches when at least one does. An empty allOf matches. An empty anyOf does not. dlpTypes and lgpdCategories are accepted here and are not part of the policies-as-code YAML schema.
policies[].condition.actionstring (min length 1, max length 64)noEvent action (READ_DATA, WRITE_DATA, DELETE_DATA, EXPORT_DATA, SEND_EMAIL) or an action family. Matched against the event action and its family.
policies[].condition.destinationEXTERNAL | INTERNALnoEXTERNAL matches an external destination. INTERNAL matches an internal one.
policies[].condition.destinationContainsstring (max length 100)noCase-insensitive substring of the destination.
policies[].condition.containsSensitiveDatabooleanno
policies[].condition.minRecordsinteger (0–9007199254740991)no
policies[].condition.maxRecordsinteger (0–9007199254740991)no
policies[].condition.minRiskScoreinteger (0–100)no
policies[].condition.outsideBusinessHoursbooleannoMonday to Friday 09:00-18:00 in the organization time zone, inverted.
policies[].condition.agentIdsarray of string (max items 8000)no
policies[].condition.dlpTypesarray of CPF | CNPJ | RG | CNH | PIX_KEY | PHONE_BR | CEP | CREDIT_CARD | EMAIL | HEALTH_DATA | API_KEY | PRIVATE_KEYno
policies[].condition.lgpdCategoriesarray of IDENTIFICATION | CONTACT | LOCATION | FINANCIAL | HEALTH | COMPANY | CREDENTIALSno
policies[].condition.allOfarray of JSON value (max items 20000)no
policies[].condition.anyOfarray of JSON value (max items 20000)no
policies[].decisionALLOW | REVIEW | BLOCKyes
policies[].modeENFORCE | MONITOR (default "ENFORCE")no
policies[].approverRolesarray of OWNER | ADMIN | MEMBER (unique)noRoles that may approve a REVIEW raised by this policy. Empty means owners and admins.
pruneboolean (default false)noDelete organization policies whose names are missing from policies.
dryRunboolean (default false)noReturn the change plan and write nothing.

Change plan. dryRun true writes nothing.

OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json). Response body.
FieldTypeRequiredDescription
dryRunbooleanyes
changesarray of objectyes
changes[]objectno
changes[].namestringyes
changes[].opcreate | update | delete | unchangedyes
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json). Error responses.
StatusMeaning
400Invalid policy spec, duplicate name, or unknown action, decision, mode or role.
401Missing or invalid credentials
403The key is not an org-wide LIVE key. A source IP outside the key allowlist is also forbidden.
413JSON body larger than 200 KB
42960 requests per minute per API key.

Evaluates cases with the decision path (permissions, risk, policies, and monitor mode). When policies is omitted, the enabled stored policies are used. When policies is set, those specs are evaluated instead. The call writes no security event and no audit entry. At most 200 cases. input.metadata is accepted and not used. pass is null when expect is omitted.

OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json). Request body.
FieldTypeRequiredDescription
policiesarray of objectnoWhen set, these policies are evaluated instead of the stored ones. Omitted uses the enabled stored policies.
policies[]objectnoOne policy. name is unique per organization. action is the action family (for example EXPORT), not an event action such as EXPORT_DATA. Omitted enabled defaults to true. Omitted mode defaults to ENFORCE. Omitted resource, null and ANY match every classification.
policies[].namestring (min length 1, max length 120)yes
policies[].descriptionstring (max length 500)no
policies[].enabledboolean (default true)no
policies[].actionANY | READ | WRITE | DELETE | EXPORTyes
policies[].resourceANY | PUBLIC | INTERNAL | SENSITIVE | CUSTOMER_PII | FINANCIAL | EMPLOYEE | nullnoResource classification. ANY and null match every classification.
policies[].conditionobjectnoEvery field that is set must match. minRecords means recordsAffected is greater than or equal to the value. maxRecords means recordsAffected is less than or equal to the value. Groups may nest up to 32 levels, with at most 20000 conditions in one group. minRecords and maxRecords are integers from 0 through 9007199254740991. agentIds holds at most 8000 ids. allOf matches when every nested condition matches. anyOf matches when at least one does. An empty allOf matches. An empty anyOf does not. dlpTypes and lgpdCategories are accepted here and are not part of the policies-as-code YAML schema.
policies[].condition.actionstring (min length 1, max length 64)noEvent action (READ_DATA, WRITE_DATA, DELETE_DATA, EXPORT_DATA, SEND_EMAIL) or an action family. Matched against the event action and its family.
policies[].condition.destinationEXTERNAL | INTERNALnoEXTERNAL matches an external destination. INTERNAL matches an internal one.
policies[].condition.destinationContainsstring (max length 100)noCase-insensitive substring of the destination.
policies[].condition.containsSensitiveDatabooleanno
policies[].condition.minRecordsinteger (0–9007199254740991)no
policies[].condition.maxRecordsinteger (0–9007199254740991)no
policies[].condition.minRiskScoreinteger (0–100)no
policies[].condition.outsideBusinessHoursbooleannoMonday to Friday 09:00-18:00 in the organization time zone, inverted.
policies[].condition.agentIdsarray of string (max items 8000)no
policies[].condition.dlpTypesarray of CPF | CNPJ | RG | CNH | PIX_KEY | PHONE_BR | CEP | CREDIT_CARD | EMAIL | HEALTH_DATA | API_KEY | PRIVATE_KEYno
policies[].condition.lgpdCategoriesarray of IDENTIFICATION | CONTACT | LOCATION | FINANCIAL | HEALTH | COMPANY | CREDENTIALSno
policies[].condition.allOfarray of JSON value (max items 20000)no
policies[].condition.anyOfarray of JSON value (max items 20000)no
policies[].decisionALLOW | REVIEW | BLOCKyes
policies[].modeENFORCE | MONITOR (default "ENFORCE")no
policies[].approverRolesarray of OWNER | ADMIN | MEMBER (unique)noRoles that may approve a REVIEW raised by this policy. Empty means owners and admins.
casesarray of object (max items 200)yes
cases[]objectno
cases[].namestring (min length 1, max length 200)yes
cases[].inputobjectyesaction is an event action. resource is the resource name registered in the organization, not the policy resource classification. metadata is accepted and not used.
cases[].input.agentstring (min length 1, max length 100)yesAgent name.
cases[].input.actionREAD_DATA | WRITE_DATA | DELETE_DATA | EXPORT_DATA | SEND_EMAILyes
cases[].input.resourcestring (min length 1, max length 100)yesResource name.
cases[].input.destinationINTERNAL | EXTERNAL_EMAIL | EXTERNAL_APIno
cases[].input.recordsAffectedinteger (0–100000000)no
cases[].input.containsSensitiveDatabooleanno
cases[].input.metadataobjectnoAccepted and not used by the policy engine.
cases[].expectobjectno
cases[].expect.decisionALLOW | REVIEW | BLOCKyes
cases[].expect.policystring (min length 1, max length 120)noExpected matched policy name.

One result per case. Nothing is stored.

OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json). Response body.
FieldTypeRequiredDescription
resultsarray of objectyes
results[]objectno
results[].namestringyes
results[].decisionALLOW | REVIEW | BLOCKyes
results[].matchedPolicystring or nullyes
results[].riskScoreinteger (0–100)yes
results[].riskLevelLOW | MEDIUM | HIGH | CRITICALyes
results[].reasonsarray of stringyes
results[].passboolean or nullyesNull when expect was omitted.
OpenAPI 0.3.0 (https://api.vulnify.io/openapi.json). Error responses.
StatusMeaning
400Invalid policy spec, duplicate name, or unknown action, decision, mode or role.
401Missing or invalid credentials
403Caller IP is not in the API key allowlist.
413JSON body larger than 200 KB
42960 requests per minute per API key.