API reference
Policy
GET
/policy/v1The organisation's effective policy for a workbench, or for one project when projectId is given: runtimes, providers, data loss prevention, approvals, remote control, network, tools, governed settings and more.
AuthorizationBearer <token>
A device access token from the device-code flow (aioe_at_…). A DPoP-bound token is sent as Authorization: DPoP <token> with a fresh DPoP proof on every request.
In: header
Query Parameters
projectId?string
The organisation project to resolve the policy for.
Header Parameters
X-Aioe-Organisation?string
Mojo Up AI Cloud only, with a person's access token: the id of the organisation the request is for. A person's session is not tied to one organisation, so each request names it. Device tokens already carry their organisation.
Response Body
application/json
application/json
curl -X GET "https://example.com/policy/v1"{ "revision": "string", "policy": { "version": 1, "source": "string", "allowedRuntimes": [ "string" ], "allowedProviders": [ "string" ], "inference": { "property1": null, "property2": null }, "dlp": { "classify": false, "classifier": { "provider": "ollama", "model": "string", "endpoint": "string", "node": "string", "tags": [ "string" ] }, "onSecrets": "allow", "onPii": "allow", "onPromptInjection": "allow", "blockSensitivity": [ "restricted" ], "onUnclassified": "allow", "latencyBudgetMs": 300 }, "approvals": { "remoteApprovals": { "low": "allow", "medium": "allow", "high": "allow" }, "requireHumanReviewLabels": [], "decisionApproval": "none" }, "remote": { "allowTransports": [ "ipc", "lan", "relay" ], "maxScopes": [ "string" ], "idleTimeoutMinutes": 60, "requireTls": true, "killSwitchLockedOn": true }, "git": { "protectedBranches": [], "requirePullRequest": false }, "agents": { "sandbox": "off" }, "network": { "allowHosts": [], "denyHosts": [], "defaultAction": "allow", "enforcement": "audit", "rules": [] }, "tools": { "enforcement": "audit", "unlistedServers": "allow", "defaults": { "reads": "allow", "changes": "allow", "destroys": "allow" }, "rules": [], "recordArguments": "none", "servers": [ { "id": "string", "name": "string", "fingerprint": "string", "status": "published", "tools": {} } ] }, "secrets": { "agentEnvironment": "allow", "machineEnvironment": "allow", "personalSecrets": "allow" }, "teams": { "allowGranted": true, "allowPersonal": true, "granted": [] }, "pullRequests": { "requiredApprovals": 1, "allowSelfMerge": false, "mergeMethods": [ "merge", "squash", "rebase" ], "requireChecks": true, "agentsMayMerge": false }, "settings": { "property1": null, "property2": null }, "settingsMode": { "property1": "locked", "property2": "locked" } }, "published": true}