Skip to content

`POST /v1/orgs/{org}/policies`.

POST
/v1/orgs/{org}/policies
curl --request POST \
--url https://api.updawg.net/v1/orgs/example/policies \
--header 'Content-Type: application/json' \
--data '{ "yaml": "example" }'
org
required
string

Organization slug.

Media typeapplication/json
object
yaml

Option so that a missing field produces this API’s own 400 rather than axum’s plain-text 422 — see DAWG-246 and the note in routes::proposals::reject.

string | null
Examplegenerated
{
"yaml": "example"
}

Created at version 1.

Media typeapplication/json
object
created_at
required
string format: date-time
enabled
required
boolean
id
required
string
name
required
string
priority
required
integer format: int32
updated_at
required
string format: date-time
version
required

Which version is in force. Named version rather than current_version because from outside there is only one that matters, and ?version= takes this same number.

integer format: int32
author
string | null
showing
required

The version this body carries, which differs from version when an older one was asked for. Both are here on purpose: a portal showing version 2 of a policy on version 5 needs to know it is looking at history rather than at the policy.

integer format: int32
written_at
required
string format: date-time
yaml
required

Byte for byte what somebody wrote. The compiled form is derived from it and is not handed back — there is one source of truth for what a policy says and it is the text.

string
Examplegenerated
{
"created_at": "2026-04-15T12:00:00Z",
"enabled": true,
"id": "example",
"name": "example",
"priority": 1,
"updated_at": "2026-04-15T12:00:00Z",
"version": 1,
"author": "example",
"showing": 1,
"written_at": "2026-04-15T12:00:00Z",
"yaml": "example"
}

The document does not compile.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

No session.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

Not permitted for this role. Or a plan that does not include a feature it uses: plan-required.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

No such organization, or not yours.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

A live policy already has that name.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

Over the organization’s request limit. Retry-After says when to try again; RateLimit-Limit is the burst.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}