Retrieve a credential policy
/credentials/{credential_id}/policies/{policy_id}Retrieves a policy from the credential's active policy revision.
Policies that are no longer part of the active revision, or that belong to a different credential, return 404 Not Found.
The response includes an ETag representing the credential's current revision. Send this value in the If-Match header when updating the policy to avoid overwriting a newer version.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Path Parameters
Response Body
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/credentials/string/policies/string"{ "data": { "capabilities": [ "string" ], "id": "string", "object": "policy", "published_at": "2019-08-24T14:15:22Z", "published_by": { "id": "string", "kind": "admin" }, "resources": [ { "ids": [ "string" ], "include_future": true, "parent": "string", "selector": "instance", "type": "instance" } ], "version": 0 }}Add a credential policy POST
Adds a policy to a credential. The change publishes a new policy revision containing the existing policies plus the new one. Permissions listed in `capabilities` that the calling credential cannot delegate, including the non-delegable `credentials.*` and `administrators.*` permissions, are rejected with `delegation_limit_exceeded`, and no new revision is published. A credential cannot modify its own policies.
Update a credential policy PATCH
Replaces the capabilities and resources of a policy. The change publishes a new policy revision in which the other policies remain unchanged. The policy keeps the same `policy_id` across revisions. Send the `ETag` returned by the retrieve operation in the `If-Match` header to avoid overwriting a newer version. Permissions that the calling credential cannot delegate are rejected with `delegation_limit_exceeded`, and no new revision is published. A credential cannot modify its own policies.