Mojo UpDocs
API reference

Policy

The policy that applies

GET/policy/v1

The organisation's effective policy for a workbench, or for one project when projectId is given: runtimes, providers, data loss prevention, approvals, remote control, network, tools, governed settings and more.

Authorization

AuthorizationBearer <token>

A device access token from the device-code flow (aioe_at_…). A DPoP-bound token is sent as Authorization: DPoP <token> with a fresh DPoP proof on every request.

In: header

Query Parameters

projectId?string

The organisation project to resolve the policy for.

Header Parameters

X-Aioe-Organisation?string

Mojo Up AI Cloud only, with a person's access token: the id of the organisation the request is for. A person's session is not tied to one organisation, so each request names it. Device tokens already carry their organisation.

Response Body

application/json

application/json

curl -X GET "https://example.com/policy/v1"
{  "revision": "string",  "policy": {    "version": 1,    "source": "string",    "allowedRuntimes": [      "string"    ],    "allowedProviders": [      "string"    ],    "inference": {      "property1": null,      "property2": null    },    "dlp": {      "classify": false,      "classifier": {        "provider": "ollama",        "model": "string",        "endpoint": "string",        "node": "string",        "tags": [          "string"        ]      },      "onSecrets": "allow",      "onPii": "allow",      "onPromptInjection": "allow",      "blockSensitivity": [        "restricted"      ],      "onUnclassified": "allow",      "latencyBudgetMs": 300    },    "approvals": {      "remoteApprovals": {        "low": "allow",        "medium": "allow",        "high": "allow"      },      "requireHumanReviewLabels": [],      "decisionApproval": "none"    },    "remote": {      "allowTransports": [        "ipc",        "lan",        "relay"      ],      "maxScopes": [        "string"      ],      "idleTimeoutMinutes": 60,      "requireTls": true,      "killSwitchLockedOn": true    },    "git": {      "protectedBranches": [],      "requirePullRequest": false    },    "agents": {      "sandbox": "off"    },    "network": {      "allowHosts": [],      "denyHosts": [],      "defaultAction": "allow",      "enforcement": "audit",      "rules": []    },    "tools": {      "enforcement": "audit",      "unlistedServers": "allow",      "defaults": {        "reads": "allow",        "changes": "allow",        "destroys": "allow"      },      "rules": [],      "recordArguments": "none",      "servers": [        {          "id": "string",          "name": "string",          "fingerprint": "string",          "status": "published",          "tools": {}        }      ]    },    "secrets": {      "agentEnvironment": "allow",      "machineEnvironment": "allow",      "personalSecrets": "allow"    },    "teams": {      "allowGranted": true,      "allowPersonal": true,      "granted": []    },    "pullRequests": {      "requiredApprovals": 1,      "allowSelfMerge": false,      "mergeMethods": [        "merge",        "squash",        "rebase"      ],      "requireChecks": true,      "agentsMayMerge": false    },    "settings": {      "property1": null,      "property2": null    },    "settingsMode": {      "property1": "locked",      "property2": "locked"    }  },  "published": true}