Skip to main content
POST
Confirm your deployment before running this request. This page describes an API contract; a published reference does not establish hosted availability. Check the dated host report and obtain your deployment URL and credentials. Replace the example host if your provisioned service uses a different URL.
Create an approval policy. The policy fires when a worker tool-call’s name matches any of tool_patterns. Without auto_approve_rules, every match pauses the job and creates an ApprovalRequest for human review. With auto-approve rules, matches are silently approved based on the rule (rate-limit windows, allow-listed input subsets, etc. — see operator docs). Admin scope only — these gates are security-sensitive.

Request body

ApprovalPolicyRequest
string
required
Human-readable policy name (≤128 chars). Used in audit logs. Minimum length: 1. Maximum length: 128.
string[]
Tool-name patterns that trigger this policy. Glob-style: computer:* matches every computer-tool action, bash:rm * matches bash with rm-prefixed input. Each pattern ≤256 chars. Maximum items: 100.
object
Optional rules that auto-approve a matching tool call without human review. Free-form dict — see operator docs for the supported keys (max_per_hour, allow_safe_subset, etc.).

Response

ApprovalPolicySummary
string
required
string
required
string[]
required
object
required
boolean
required
string
required
string
required

Status codes

Using this contract

Read the source OpenAPI document for declared schemas and alternatives. This page also includes documented corrections from the spec overlays. Example IDs and values are illustrative; replace them with records from your workspace.
Last modified on September 21, 2026