curl --request POST \
--url https://api.opper.ai/management/v1/controls/rules \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"config": {
"monthly_limit_cents": 1,
"type": "budget",
"alerts_enabled": true,
"counted_from": "2023-11-07T05:31:56Z",
"soft_limit_pct": 50
},
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"scope": {
"function_uuids": [
"3c90c3cc-0d44-4b50-8888-8dd25736052a"
],
"member_uuids": [
"3c90c3cc-0d44-4b50-8888-8dd25736052a"
],
"project_uuids": [
"3c90c3cc-0d44-4b50-8888-8dd25736052a"
],
"role_names": [
"<string>"
]
}
}
'import requests
url = "https://api.opper.ai/management/v1/controls/rules"
payload = {
"config": {
"monthly_limit_cents": 1,
"type": "budget",
"alerts_enabled": True,
"counted_from": "2023-11-07T05:31:56Z",
"soft_limit_pct": 50
},
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"scope": {
"function_uuids": ["3c90c3cc-0d44-4b50-8888-8dd25736052a"],
"member_uuids": ["3c90c3cc-0d44-4b50-8888-8dd25736052a"],
"project_uuids": ["3c90c3cc-0d44-4b50-8888-8dd25736052a"],
"role_names": ["<string>"]
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
config: {
monthly_limit_cents: 1,
type: 'budget',
alerts_enabled: true,
counted_from: '2023-11-07T05:31:56Z',
soft_limit_pct: 50
},
id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
scope: {
function_uuids: ['3c90c3cc-0d44-4b50-8888-8dd25736052a'],
member_uuids: ['3c90c3cc-0d44-4b50-8888-8dd25736052a'],
project_uuids: ['3c90c3cc-0d44-4b50-8888-8dd25736052a'],
role_names: ['<string>']
}
})
};
fetch('https://api.opper.ai/management/v1/controls/rules', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"data": {
"config": {},
"created_at": "2023-11-07T05:31:56Z",
"enabled": true,
"id": "<string>",
"kind": "<string>",
"schema_version": 123,
"scope": {
"type": "<string>",
"function_uuids": [
"<string>"
],
"member_uuids": [
"<string>"
],
"project_uuids": [
"<string>"
],
"role_names": [
"<string>"
]
},
"updated_at": "2023-11-07T05:31:56Z",
"allowed_model_ids": [
"<string>"
],
"confirm_file_deletion": true,
"effective_count": 123,
"idempotency_key": "<string>",
"name": "<string>",
"parent_allowlist": {
"countries": [
"<string>"
],
"models": [
"<string>"
],
"providers": [
"<string>"
],
"regions": [
"<string>"
],
"deny_all": true,
"exclude_providers": [
"<string>"
],
"exclude_service_routes": [
"<string>"
],
"handling": {
"cache_scopes": [
"<string>"
],
"caching": [
"<string>"
],
"human_review": [
"<string>"
],
"logging": [
"<string>"
],
"max_retention_days": 123,
"moderation": [
"<string>"
],
"subprocessors_read_content": true,
"training": [
"<string>"
]
},
"maker": {
"jurisdiction": [
"<string>"
],
"name": [
"<string>"
]
},
"provider": {
"locations": {
"inference": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"jurisdiction": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"storage": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
}
},
"name": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"route": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
}
},
"service_routes": [
"<string>"
]
}
},
"meta": {}
}{
"data": {
"config": {},
"created_at": "2023-11-07T05:31:56Z",
"enabled": true,
"id": "<string>",
"kind": "<string>",
"schema_version": 123,
"scope": {
"type": "<string>",
"function_uuids": [
"<string>"
],
"member_uuids": [
"<string>"
],
"project_uuids": [
"<string>"
],
"role_names": [
"<string>"
]
},
"updated_at": "2023-11-07T05:31:56Z",
"allowed_model_ids": [
"<string>"
],
"confirm_file_deletion": true,
"effective_count": 123,
"idempotency_key": "<string>",
"name": "<string>",
"parent_allowlist": {
"countries": [
"<string>"
],
"models": [
"<string>"
],
"providers": [
"<string>"
],
"regions": [
"<string>"
],
"deny_all": true,
"exclude_providers": [
"<string>"
],
"exclude_service_routes": [
"<string>"
],
"handling": {
"cache_scopes": [
"<string>"
],
"caching": [
"<string>"
],
"human_review": [
"<string>"
],
"logging": [
"<string>"
],
"max_retention_days": 123,
"moderation": [
"<string>"
],
"subprocessors_read_content": true,
"training": [
"<string>"
]
},
"maker": {
"jurisdiction": [
"<string>"
],
"name": [
"<string>"
]
},
"provider": {
"locations": {
"inference": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"jurisdiction": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"storage": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
}
},
"name": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"route": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
}
},
"service_routes": [
"<string>"
]
}
},
"meta": {}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
},
"meta": {}
}{
"error": {
"code": "plan_required",
"message": "<string>",
"type": "payment_required"
}
}{
"error": "<string>",
"required_scope": "<string>"
}{
"error": "<string>"
}{
"code": "<string>",
"error": "<string>",
"file_count": 123
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
},
"meta": {}
}Create a control rule
Creates a rule with a client-generated UUID. Setting enabled applies it immediately. Zero-day retention or ZDR may permanently delete files; a 409 warning requires explicit confirm_file_deletion acknowledgement. Read rules again to inspect effective policy. Requires the controls:write scope.
curl --request POST \
--url https://api.opper.ai/management/v1/controls/rules \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"config": {
"monthly_limit_cents": 1,
"type": "budget",
"alerts_enabled": true,
"counted_from": "2023-11-07T05:31:56Z",
"soft_limit_pct": 50
},
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"scope": {
"function_uuids": [
"3c90c3cc-0d44-4b50-8888-8dd25736052a"
],
"member_uuids": [
"3c90c3cc-0d44-4b50-8888-8dd25736052a"
],
"project_uuids": [
"3c90c3cc-0d44-4b50-8888-8dd25736052a"
],
"role_names": [
"<string>"
]
}
}
'import requests
url = "https://api.opper.ai/management/v1/controls/rules"
payload = {
"config": {
"monthly_limit_cents": 1,
"type": "budget",
"alerts_enabled": True,
"counted_from": "2023-11-07T05:31:56Z",
"soft_limit_pct": 50
},
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"scope": {
"function_uuids": ["3c90c3cc-0d44-4b50-8888-8dd25736052a"],
"member_uuids": ["3c90c3cc-0d44-4b50-8888-8dd25736052a"],
"project_uuids": ["3c90c3cc-0d44-4b50-8888-8dd25736052a"],
"role_names": ["<string>"]
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
config: {
monthly_limit_cents: 1,
type: 'budget',
alerts_enabled: true,
counted_from: '2023-11-07T05:31:56Z',
soft_limit_pct: 50
},
id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
scope: {
function_uuids: ['3c90c3cc-0d44-4b50-8888-8dd25736052a'],
member_uuids: ['3c90c3cc-0d44-4b50-8888-8dd25736052a'],
project_uuids: ['3c90c3cc-0d44-4b50-8888-8dd25736052a'],
role_names: ['<string>']
}
})
};
fetch('https://api.opper.ai/management/v1/controls/rules', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"data": {
"config": {},
"created_at": "2023-11-07T05:31:56Z",
"enabled": true,
"id": "<string>",
"kind": "<string>",
"schema_version": 123,
"scope": {
"type": "<string>",
"function_uuids": [
"<string>"
],
"member_uuids": [
"<string>"
],
"project_uuids": [
"<string>"
],
"role_names": [
"<string>"
]
},
"updated_at": "2023-11-07T05:31:56Z",
"allowed_model_ids": [
"<string>"
],
"confirm_file_deletion": true,
"effective_count": 123,
"idempotency_key": "<string>",
"name": "<string>",
"parent_allowlist": {
"countries": [
"<string>"
],
"models": [
"<string>"
],
"providers": [
"<string>"
],
"regions": [
"<string>"
],
"deny_all": true,
"exclude_providers": [
"<string>"
],
"exclude_service_routes": [
"<string>"
],
"handling": {
"cache_scopes": [
"<string>"
],
"caching": [
"<string>"
],
"human_review": [
"<string>"
],
"logging": [
"<string>"
],
"max_retention_days": 123,
"moderation": [
"<string>"
],
"subprocessors_read_content": true,
"training": [
"<string>"
]
},
"maker": {
"jurisdiction": [
"<string>"
],
"name": [
"<string>"
]
},
"provider": {
"locations": {
"inference": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"jurisdiction": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"storage": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
}
},
"name": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"route": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
}
},
"service_routes": [
"<string>"
]
}
},
"meta": {}
}{
"data": {
"config": {},
"created_at": "2023-11-07T05:31:56Z",
"enabled": true,
"id": "<string>",
"kind": "<string>",
"schema_version": 123,
"scope": {
"type": "<string>",
"function_uuids": [
"<string>"
],
"member_uuids": [
"<string>"
],
"project_uuids": [
"<string>"
],
"role_names": [
"<string>"
]
},
"updated_at": "2023-11-07T05:31:56Z",
"allowed_model_ids": [
"<string>"
],
"confirm_file_deletion": true,
"effective_count": 123,
"idempotency_key": "<string>",
"name": "<string>",
"parent_allowlist": {
"countries": [
"<string>"
],
"models": [
"<string>"
],
"providers": [
"<string>"
],
"regions": [
"<string>"
],
"deny_all": true,
"exclude_providers": [
"<string>"
],
"exclude_service_routes": [
"<string>"
],
"handling": {
"cache_scopes": [
"<string>"
],
"caching": [
"<string>"
],
"human_review": [
"<string>"
],
"logging": [
"<string>"
],
"max_retention_days": 123,
"moderation": [
"<string>"
],
"subprocessors_read_content": true,
"training": [
"<string>"
]
},
"maker": {
"jurisdiction": [
"<string>"
],
"name": [
"<string>"
]
},
"provider": {
"locations": {
"inference": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"jurisdiction": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"storage": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
}
},
"name": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"route": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
}
},
"service_routes": [
"<string>"
]
}
},
"meta": {}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
},
"meta": {}
}{
"error": {
"code": "plan_required",
"message": "<string>",
"type": "payment_required"
}
}{
"error": "<string>",
"required_scope": "<string>"
}{
"error": "<string>"
}{
"code": "<string>",
"error": "<string>",
"file_count": 123
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
},
"meta": {}
}Authorizations
Management API authentication. Pass an op-mak-… management token as a Bearer token. Runtime op-… API keys are rejected with 403 — they belong on the data-plane endpoints. Mint a management key from the platform UI under Settings → API keys.
Body
Config for the rule kind. Replaces the full config on update. Read existing rules and get_rule_vocabulary before changing it; organization constraints remain in force. Use schema_version=2 for provider company allowlists. Opper retention_days and upstream handling.max_retention_days are separate controls.
- comply.budget
- comply.allowlist
- comply.retention
- comply.zdr
- route.default_model
- route.cache
- route.pool_order
- guard.regex
- guard.llm
- observe
Show child attributes
Show child attributes
Client-generated UUID for this new rule.
guard, observe, route, comply Use org for organization-wide scope; projects requires project_uuids, functions requires function_uuids. IDs must belong to the caller's organization. Some rule kinds do not support functions. roles (role_names) and members (member_uuids) are only for comply budget rules: a monthly cap on each member's personal-key spend, where a member's own cap wins over their role's.
Show child attributes
Show child attributes
Explicit acknowledgement after a 409 warning: enabling zero-day retention or ZDR permanently deletes existing files in scope. Never set speculatively.
Whether the rule is enforced. Omitted on create means false.
Optional operation identifier. Reuse it with the same rule id and create payload when retrying an uncertain response. A changed payload or a deleted original rule returns 409; successful replay returns the existing rule without recreating it.
1 - 128^[A-Za-z0-9._:-]{1,128}$Display name; null clears it.
Config schema version. Omit on create for version 1. Version 2 comply allowlists identify providers by company slug.
1 <= x <= 2