Update a credential policy

PATCH/credentials/{credential_id}/policies/{policy_id}

Replaces the capabilities and resources of a policy. The change publishes a new policy revision in which the other policies remain unchanged. The policy keeps the same policy_id across revisions.

Send the ETag returned by the retrieve operation in the If-Match header to avoid overwriting a newer version.

Permissions that the calling credential cannot delegate are rejected with delegation_limit_exceeded, and no new revision is published. A credential cannot modify its own policies, and the policies of a revoked credential cannot be changed (credential_revoked).

AuthorizationBearer <token>

Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.

In: header

Path Parameters

credential_id*string

Public ID of the credential, prefixed with key_.

policy_id*string

Public ID of the policy, prefixed with pol_.

Header Parameters

Idempotency-Key?string

Client-generated key that makes the request safe to retry. Must be 1 to 128 characters from [A-Za-z0-9._:-]. Optional on this operation; when sent, a malformed key returns idempotency_key_invalid, and repeating the request with the same key and the same body returns the stored result with Idempotent-Replayed: true.

If-Match?string

Expected revision of the resource, in the same format as the ETag header (W/"<type>:<id>:<revision>"). If the resource has changed since that revision, the request fails with 412 and the revision_mismatch error code. * matches the current revision. Any other value fails with 400 and the if_match_invalid error code. When omitted, the update is applied to the current revision.

X-Client-Request-Id?string

Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id.

Lengthlength <= 64

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X PATCH "https://example.com/credentials/string/policies/string" \  -H "Content-Type: application/json" \  -d '{    "capabilities": [      "string"    ],    "resources": [      {}    ]  }'
{  "data": {    "capabilities": [      "string"    ],    "id": "string",    "object": "policy",    "published_at": "2019-08-24T14:15:22Z",    "published_by": {      "id": "string",      "kind": "admin"    },    "resources": [      {        "ids": [          "string"        ],        "include_future": true,        "parent": "string",        "selector": "instance",        "type": "instance"      }    ],    "version": 0  }}