Skip to main content
PUT
Reorder organization rules

Authorizations

Authorization
string
header
required

A workspace API key (oc_…) or organization API key (oc_org_…). Workspace-scoped endpoints called with an organization key also need X-Workspace-Id.

Body

application/json
orderedIds
string[]
required
Minimum array length: 1

Response

The reordered rules

id
string
scope
enum<string>
Available options:
organization,
workspace
status
enum<string>
Available options:
draft,
published
generation
integer

0 for the draft working copy; the snapshot number for published rows.

priority
integer

First-match order (lower evaluates first).

enabled
boolean
isDefault
boolean

True on the scope's terminal Default Rule.

logicalId
string

Generation-stable identity; compare rules across draft/published by this, never by id.

source
string

custom (user-owned, editable), default (the Default Rule), or system-managed rows: blocklist (compiled from app blocklists) and, at workspace scope, grant (compiled from agent grants; managed through the Grants endpoints, never edited as rules).

name
string
description
string | null
action
enum<string>
Available options:
allow,
block
rateLimit
integer | null
rateLimitWindow
enum<string> | null
Available options:
minute,
hour,
day,
null
requireApproval
boolean
conditions
any | null

A conditions array, a session-policy object ({repositories} / {folders} / {driveFolders}), or null.

identities
object[]
targets
object[]
createdAt
string<date-time>