REST API Reference v2.1 -- Policies
GET /policies
Returns all security policies for the organization. Policies define automated rules that govern scanning requirements, deployment approvals, and compliance controls. Query parameters: type (scan, deployment, compliance), status (active, draft, disabled), page, limit.
Response: {"data": [{"id": "pol_abc", "name": "Production Deployment Gate", "type": "deployment", "status": "active", "rules": [{"condition": "scan.critical_findings == 0", "action": "block"}, {"condition": "scan.high_findings <= 3", "action": "warn"}], "targets": ["env:production"], "created_at": "2025-01-15T00:00:00Z"}]}. Policies can target specific environments, projects, or teams using label selectors.
POST /policies
Creates a new security policy. Requires policies:write scope. Request body: {"name": "Critical Vuln Block", "type": "deployment", "rules": [{"condition": "scan.critical_findings == 0", "action": "block", "message": "Cannot deploy with critical vulnerabilities"}, {"condition": "scan.sbom_generated", "action": "require", "message": "SBOM must be generated before deployment"}], "targets": ["env:production", "env:staging"], "enforcement": "strict"}.
The enforcement field controls policy behavior: strict blocks the action if any rule fails, warn allows the action but logs a policy violation, audit logs only without any notification. New policies are created in draft status and must be explicitly activated via PUT /policies/:id with {"status": "active"}.
POST /policies/:id/evaluate
Evaluates a policy against a specific context without enforcing it. Useful for testing policies before activation or for dry-run deployment checks. Request body: {"context": {"scan_id": "scan_abc123", "environment": "production", "deployer": "user_xyz"}}. The context is evaluated against all rules in the policy.
Response: {"policy_id": "pol_abc", "result": "fail", "evaluated_rules": [{"condition": "scan.critical_findings == 0", "result": "fail", "actual_value": 2, "action": "block", "message": "Cannot deploy with critical vulnerabilities"}, {"condition": "scan.sbom_generated", "result": "pass", "actual_value": true, "action": "require"}]}. Each rule includes the actual value from the context and whether it passed or failed.
Links in this article were last verified on March 2025.