curl --request PATCH \
--url https://api.opper.ai/management/v1/controls/rules/{uuid} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{}'import requests
url = "https://api.opper.ai/management/v1/controls/rules/{uuid}"
payload = {}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://api.opper.ai/management/v1/controls/rules/{uuid}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"data": {
"config": {},
"created_at": "2023-11-07T05:31:56Z",
"enabled": true,
"id": "<string>",
"kind": "<string>",
"schema_version": 123,
"scope": {
"type": "<string>",
"function_uuids": [
"<string>"
],
"member_uuids": [
"<string>"
],
"project_uuids": [
"<string>"
],
"role_names": [
"<string>"
]
},
"updated_at": "2023-11-07T05:31:56Z",
"allowed_model_ids": [
"<string>"
],
"confirm_file_deletion": true,
"effective_count": 123,
"idempotency_key": "<string>",
"name": "<string>",
"parent_allowlist": {
"countries": [
"<string>"
],
"models": [
"<string>"
],
"providers": [
"<string>"
],
"regions": [
"<string>"
],
"deny_all": true,
"exclude_providers": [
"<string>"
],
"exclude_service_routes": [
"<string>"
],
"handling": {
"cache_scopes": [
"<string>"
],
"caching": [
"<string>"
],
"human_review": [
"<string>"
],
"logging": [
"<string>"
],
"max_retention_days": 123,
"moderation": [
"<string>"
],
"subprocessors_read_content": true,
"training": [
"<string>"
]
},
"maker": {
"jurisdiction": [
"<string>"
],
"name": [
"<string>"
]
},
"provider": {
"locations": {
"inference": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"jurisdiction": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"storage": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
}
},
"name": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"route": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
}
},
"service_routes": [
"<string>"
]
}
},
"meta": {}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
},
"meta": {}
}{
"error": {
"code": "plan_required",
"message": "<string>",
"type": "payment_required"
}
}{
"error": "<string>",
"required_scope": "<string>"
}{
"error": "<string>"
}{
"code": "<string>",
"error": "<string>",
"file_count": 123
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
},
"meta": {}
}Update a control rule
Updates name, enabled, config or schema_version; omit fields to keep them and use name:null to clear a name. Config is replaced, not merged. ID, kind and scope are immutable. An empty update is rejected. Enabling zero-day retention or ZDR can permanently delete files and may require acknowledgement after a 409 warning. Requires the controls:write scope.
curl --request PATCH \
--url https://api.opper.ai/management/v1/controls/rules/{uuid} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{}'import requests
url = "https://api.opper.ai/management/v1/controls/rules/{uuid}"
payload = {}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://api.opper.ai/management/v1/controls/rules/{uuid}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"data": {
"config": {},
"created_at": "2023-11-07T05:31:56Z",
"enabled": true,
"id": "<string>",
"kind": "<string>",
"schema_version": 123,
"scope": {
"type": "<string>",
"function_uuids": [
"<string>"
],
"member_uuids": [
"<string>"
],
"project_uuids": [
"<string>"
],
"role_names": [
"<string>"
]
},
"updated_at": "2023-11-07T05:31:56Z",
"allowed_model_ids": [
"<string>"
],
"confirm_file_deletion": true,
"effective_count": 123,
"idempotency_key": "<string>",
"name": "<string>",
"parent_allowlist": {
"countries": [
"<string>"
],
"models": [
"<string>"
],
"providers": [
"<string>"
],
"regions": [
"<string>"
],
"deny_all": true,
"exclude_providers": [
"<string>"
],
"exclude_service_routes": [
"<string>"
],
"handling": {
"cache_scopes": [
"<string>"
],
"caching": [
"<string>"
],
"human_review": [
"<string>"
],
"logging": [
"<string>"
],
"max_retention_days": 123,
"moderation": [
"<string>"
],
"subprocessors_read_content": true,
"training": [
"<string>"
]
},
"maker": {
"jurisdiction": [
"<string>"
],
"name": [
"<string>"
]
},
"provider": {
"locations": {
"inference": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"jurisdiction": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"storage": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
}
},
"name": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
},
"route": {
"exclude": [
"<string>"
],
"include": [
"<string>"
]
}
},
"service_routes": [
"<string>"
]
}
},
"meta": {}
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
},
"meta": {}
}{
"error": {
"code": "plan_required",
"message": "<string>",
"type": "payment_required"
}
}{
"error": "<string>",
"required_scope": "<string>"
}{
"error": "<string>"
}{
"code": "<string>",
"error": "<string>",
"file_count": 123
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
},
"meta": {}
}Authorizations
Management API authentication. Pass an op-mak-… management token as a Bearer token. Runtime op-… API keys are rejected with 403 — they belong on the data-plane endpoints. Mint a management key from the platform UI under Settings → API keys.
Path Parameters
Rule id
Body
Config for the rule kind. Replaces the full config on update. Read existing rules and get_rule_vocabulary before changing it; organization constraints remain in force. Use schema_version=2 for provider company allowlists. Opper retention_days and upstream handling.max_retention_days are separate controls.
- comply.budget
- comply.allowlist
- comply.retention
- comply.zdr
- route.default_model
- route.cache
- route.pool_order
- guard.regex
- guard.llm
- observe
Show child attributes
Show child attributes
Explicit acknowledgement after a 409 warning: enabling zero-day retention or ZDR permanently deletes existing files in scope. Never set speculatively.
Whether the rule is enforced. Omitted on create means false.
Display name; null clears it.
Config schema version. Omit on create for version 1. Version 2 comply allowlists identify providers by company slug.
1 <= x <= 2