Policies
Fetch a single policy.
**Required scope:** `rls_policies:read`
Authorization
BearerAuth AuthorizationBearer <token>
Security scheme for OpenAPI endpoints. Validates both JWT tokens and API keys.
In: header
Path Parameters
org_id*string
Format
uuidid*string
Format
uuidResponse Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v1/organisations/497f6eca-6276-4993-bfeb-53cbbbba6f08/policies/497f6eca-6276-4993-bfeb-53cbbbba6f08"{ "id": "string", "tableFqn": "string", "tableId": "string", "columnName": "string", "kind": "rls", "policyText": "string", "definition": { "effect": "permit", "subject": { "everyone": null, "role": null, "attribute": null, "op": null, "value": null }, "condition": null }, "enabled": true, "version": 0, "createdAt": "string", "updatedAt": "string"}Empty
Empty
{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}{ "code": "string", "message": "string", "request_id": "string", "details": [ { "field": "string", "message": "string" } ]}Create a Cedar RLS/CLS policy for the organisation.
**Required scope:** `rls_policies:write`
Partially update a policy. Omitted fields keep their current value — the enable/disable toggle sends only `{"enabled": …, "expectedVersion": …}` and can never rewrite semantics. A builder-managed policy whose `kind`/`columnName` changes is re-generated from its stored definition.
**Required scope:** `rls_policies:write`