Update a credential policy
/credentials/{credential_id}/policies/{policy_id}Replaces the capabilities and resources of a policy. The change publishes a new policy revision in which the other policies remain unchanged. The policy keeps the same policy_id across revisions.
Send the ETag returned by the retrieve operation in the If-Match header to avoid overwriting a newer version.
Permissions that the calling credential cannot delegate are rejected with delegation_limit_exceeded, and no new revision is published. A credential cannot modify its own policies.
Autonomous mode: the API credential secret, sent as a bearer token. Credential secrets are identified by a fixed prefix.
In: header
Path Parameters
Header Parameters
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X PATCH "https://example.com/credentials/string/policies/string" \ -H "Content-Type: application/json" \ -d '{ "capabilities": [ "string" ], "resources": [ {} ] }'{ "data": { "capabilities": [ "string" ], "id": "string", "object": "policy", "published_at": "2019-08-24T14:15:22Z", "published_by": { "id": "string", "kind": "admin" }, "resources": [ { "ids": [ "string" ], "include_future": true, "parent": "string", "selector": "instance", "type": "instance" } ], "version": 0 }}Retrieve a credential policy GET
Retrieves a policy from the credential's active policy revision. Policies that are no longer part of the active revision, or that belong to a different credential, return `404 Not Found`. The response includes an `ETag` representing the credential's current revision. Send this value in the `If-Match` header when updating the policy to avoid overwriting a newer version.
Remove a credential policy DELETE
Removes a policy from a credential. The change publishes a new policy revision containing all remaining policies. Removing the last policy is allowed and leaves the credential without access to any resource. A credential cannot modify its own policies.