Skip to main content
POST
Create an organization rule

Authorizations

Authorization
string
header
required

A workspace API key (oc_…) or organization API key (oc_org_…). Workspace-scoped endpoints called with an organization key also need X-Workspace-Id.

Body

application/json

A rule must name at least one target (an empty or missing targets list is refused with 422). rateLimit/rateLimitWindow are paired and, like requireApproval, valid only with action: allow. On Cloud, rateLimit needs the Pro plan or above and group identities need the Enterprise plan; manual approval is available on every plan.

name
string
required
Maximum string length: 255
action
enum<string>
required
Available options:
allow,
block
targets
object[]
required
Required array length: 1 - 100 elements
description
string
Maximum string length: 1000
enabled
boolean
default:true
rateLimit
integer
Required range: 1 <= x <= 1000000
rateLimitWindow
enum<string>
Available options:
minute,
hour,
day
requireApproval
boolean
conditions
any

A conditions array (max 10) or a session-policy object ({repositories: [...]} / {folders: [...]} / {driveFolders: [...]}; allow rules with a connection target only).

identities
object[]
Maximum array length: 100

Response

The rule

A policy-engine rule. Every write is enforced immediately; the draft/published split survives only for older clients. Published row ids regenerate on every publish; logicalId is the identity stable across statuses and generations.

id
string
scope
enum<string>
Available options:
organization,
workspace
status
enum<string>
Available options:
draft,
published
generation
integer

0 for the draft working copy; the snapshot number for published rows.

priority
integer

First-match order (lower evaluates first).

enabled
boolean
isDefault
boolean

True on the scope's terminal Default Rule.

logicalId
string

Generation-stable identity; compare rules across draft/published by this, never by id.

source
string

custom (user-owned, editable), default (the Default Rule), or system-managed rows: blocklist (compiled from app blocklists) and, at workspace scope, grant (compiled from agent grants; managed through the Grants endpoints, never edited as rules).

name
string
description
string | null
action
enum<string>
Available options:
allow,
block
rateLimit
integer | null
rateLimitWindow
enum<string> | null
Available options:
minute,
hour,
day,
null
requireApproval
boolean
conditions
any | null

A conditions array, a session-policy object ({repositories} / {folders} / {driveFolders}), or null.

identities
object[]
targets
object[]
createdAt
string<date-time>