Endpoint
Authentication
Requires a Personal API Access Token.Header
Request
Headers
Path Parameters
Request Body
Full JSON Body Example
Request Body Fields
The request body structure is identical to Add Policy. See that documentation for complete field descriptions.operationMetadata
Note: If
order is null, the policy keeps its existing position. If order is provided, the policy is moved to that position.
EnumPolicyTargetScope
ALL- Policy applies to all endpointsENDPOINT- Policy applies only to specified endpoint
EnumPolicyTargetPipeline
REQUEST- Executes in request pipelineRESPONSE- Executes in response pipelineERROR- Executes in error pipeline
EnumHttpRequestMethod
GET,POST,PUT,DELETE,PATCH,OPTIONS,HEAD,TRACE,ALL
policy
The policy object structure is identical to Add Policy. All policy fields can be updated. Important: The policytype cannot be changed. If you need a different policy type, delete the existing policy and create a new one.
Response
Success Response (200 OK)
deploy: true is set in the request, the response includes deployment result:
Response Fields
Deployment Result Object (deploymentResult)
Deployment Detail Object (detailList item)
EnumStatus
SUCCESS- Operation successfulFAILURE- Operation failed
Error Response (400 Bad Request)
Common Causes
- Policy name does not exist
- Invalid targetScope (ENDPOINT without targetEndpoint)
- Invalid targetEndpoint (endpoint not found in API Proxy)
- Invalid policy type (cannot change policy type)
- Missing required policy fields
- Invalid condition configuration
- Invalid order value (order < 1)
Error Response (401 Unauthorized)
Error Response (404 Not Found)
cURL Example
Example 1: Update Policy Configuration
Example 2: Update Policy Order
Move a policy to a different position in the pipeline.Example 3: Update Policy Scope
Move a policy from ALL endpoints to a specific endpoint.Example 4: Update Policy Pipeline
Move a policy from REQUEST pipeline to RESPONSE pipeline.Permissions
- User must have
API_MANAGEMENT+MANAGEpermission in the project - If
deploy: trueis set in the request, user must also haveAPI_MANAGEMENT+DEPLOY_UNDEPLOYpermission
Notes and Warnings
- Policy Name: Policy name cannot be changed. Use Delete and Add to rename a policy.
- Policy Type: Policy type cannot be changed. Use Delete and Add to change policy type.
- Order: If
orderis null, the policy keeps its existing position. Iforderis provided, the policy is moved to that position (1-based indexing). - Scope Change: You can change
targetScopefrom ALL to ENDPOINT or vice versa. Ensure the endpoint exists if using ENDPOINT scope. - Pipeline Change: You can change
targetPipeline(REQUEST, RESPONSE, ERROR). The policy will be moved to the new pipeline. - Deployment: If
deploy: true, ensure environments exist and user has deployment permissions. - Validation: All policy-specific validations apply. See individual policy documentation for required fields.
Related Documentation
- Add Policy - Add a new policy
- Delete Policy - Delete a policy
- List Policies - List all policies
- Policy API Based Throttling - Example policy documentation

