Remove a credential policy

DELETE/credentials/{credential_id}/policies/{policy_id}

Removes a policy from a credential. The change publishes a new policy revision containing all remaining policies.

Removing the last policy is allowed and leaves the credential without access to any resource.

A credential cannot modify its own policies, and the policies of a revoked credential cannot be changed (credential_revoked).

AuthorizationBearer <token>

Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.

In: header

Path Parameters

credential_id*string

Public ID of the credential, prefixed with key_.

policy_id*string

Public ID of the policy, prefixed with pol_.

Header Parameters

Idempotency-Key?string

Client-generated key that makes the request safe to retry. Must be 1 to 128 characters from [A-Za-z0-9._:-]. Optional on this operation; when sent, a malformed key returns idempotency_key_invalid, and repeating the request with the same key and the same body returns the stored result with Idempotent-Replayed: true.

X-Client-Request-Id?string

Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.

Lengthlength <= 64

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X DELETE "https://example.com/credentials/string/policies/string"
Empty