Skip to main content
POST
Create a control rule

Authorizations

Authorization
string
header
required

Management API authentication. Pass an op-mak-… management token as a Bearer token. Runtime op-… API keys are rejected with 403 — they belong on the data-plane endpoints. Mint a management key from the platform UI under Settings → API keys.

Body

application/json
config
comply.budget · object
required

Config for the rule kind. Replaces the full config on update. Read existing rules and get_rule_vocabulary before changing it; organization constraints remain in force. Use schema_version=2 for provider company allowlists. Opper retention_days and upstream handling.max_retention_days are separate controls.

id
string<uuid>
required

Client-generated UUID for this new rule.

kind
enum<string>
required
Available options:
guard,
observe,
route,
comply
scope
object
required

Use org for organization-wide scope; projects requires project_uuids, functions requires function_uuids. IDs must belong to the caller's organization. Some rule kinds do not support functions. roles (role_names) and members (member_uuids) are only for comply budget rules: a monthly cap on each member's personal-key spend, where a member's own cap wins over their role's.

confirm_file_deletion
boolean

Explicit acknowledgement after a 409 warning: enabling zero-day retention or ZDR permanently deletes existing files in scope. Never set speculatively.

enabled
boolean

Whether the rule is enforced. Omitted on create means false.

idempotency_key
string

Optional operation identifier. Reuse it with the same rule id and create payload when retrying an uncertain response. A changed payload or a deleted original rule returns 409; successful replay returns the existing rule without recreating it.

Required string length: 1 - 128
Pattern: ^[A-Za-z0-9._:-]{1,128}$
name
string | null

Display name; null clears it.

schema_version
integer

Config schema version. Omit on create for version 1. Version 2 comply allowlists identify providers by company slug.

Required range: 1 <= x <= 2

Response

Idempotent replay: current state of the previously created rule.

data
object
meta
object

Empty for a single resource. Endpoint-specific context appears here rather than as a sibling of data.

Last modified on September 17, 2026