Skip to content

List versions of a policy

GET
/v1/policies/{policyId}/versions
curl --request GET \
--url 'https://example.com/v1/policies/example/versions?limit=25&includeTombstoned=false' \
--header 'Authorization: Bearer <token>'

Cursor-paginated list of policy versions. Defaults to active-only. Pass ?includeTombstoned=true to include soft-tombstoned rows too; tombstoned rows carry unregisteredAt (ISO string), active rows do not.

policyId
required
string
>= 1 characters

PolicyId — stable string chosen by the caller (e.g. acme.model-routing).

limit
integer
default: 25 >= 1 <= 100

1..100. Default 25.

cursor
string

Opaque cursor from a prior response. Absent → first page.

includeTombstoned
boolean

When true, the response includes soft-tombstoned versions in addition to active ones. Tombstoned rows carry an unregisteredAt ISO timestamp; active rows omit the field. Default: false (active-only).

Page of policy versions.

Media typeapplication/json
object
data
required
Array<object>
object
id
required
string
>= 1 characters
tenantId
required
string format: uuid
version
required

Semver — publishing a modified policy produces a new version.

string
/^\d+\.\d+\.\d+$/
kind
required
string
Allowed values: access-control model-routing adapter-allowlist rate-limit retention compliance tool-errors hitl
description
string
spec
required

Kind-specific policy body. For access-control, matches @kindgi/specs/policy.schema.json (rules + defaults). For model-routing, matches TenantPolicy from @kindgi/capabilities (providers.allow / providers.deny / models.allow / models.deny / regionAllow / maxCostPerCallUsd / maxTokensPerCall). For tool-errors, ToolErrorsSpec (maxRetries / retryOn). For hitl, HitlSpec from @kindgi/policy-contract (maxTimeoutMs / minReviewerRole / tools — per tool id a mode or { mode, requiredRole }); it only tightens an agent’s approvals. tool-errors and hitl specs are validated on publish. For other kinds, the shape is defined by the runtime consumer.

object
key
additional properties
any
unregisteredAt

ISO 8601 timestamp — present iff this version has been soft-tombstoned via POST /versions/:v/unregister. Absent on active versions.

string format: date-time
nextCursor
string
hasMore
required
boolean
Example
{
"data": [
{
"kind": "access-control"
}
]
}

Missing / malformed / expired / revoked bearer token.

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}

No policy with that id under this tenant.

Media typeapplication/json
object
error
required
object
code
required

Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).

string
message
required
string
details

Optional, kind-specific.

object
key
additional properties
any
requestId
required

Server-assigned request id; also echoed via X-Request-Id header.

string
Examplegenerated
{
"error": {
"code": "example",
"message": "example",
"details": {},
"requestId": "example"
}
}