Skip to content

client.policies

client.policies — the policies operations.

On AsyncKindgi every method is the same, awaited.

list(
*,
limit: int | None = None,
cursor: str | None = None,
kind: Literal['access-control', 'model-routing', 'adapter-allowlist', 'rate-limit', 'retention', 'compliance', 'tool-errors', 'hitl'] | None = None,
name: str | None = None,
timeout: float | None = None,
) -> PolicyCollectionPage

List tenant policies. GET /v1/policies

Cursor-paginated. Optional ?kind= narrows to a single policy kind (exact match); optional ?name= is a prefix match on Policy.id. Sort order: policy id ascending. Latest version per id.

publish(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
**fields: Any,
) -> PublishPolicyResult

Publish a policy. POST /v1/policies

Body is a full Policy — the server validates top-level shape (id, tenantId, semver version, kind ∈ closed enum, spec is an object). Deeper spec validation is the runtime consumer's responsibility per kind. Re-publishing an existing (policyId, version) returns 409 policy-already-registered. Idempotency-Key applies (retries with the same key replay the original 201).

get(*, timeout: float | None = None) -> Policy

Fetch a policy (latest version). GET /v1/policies/{policyId}

reinstate_version(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
) -> ReinstatePolicyVersionResult

Reinstate a specific tombstoned policy version. POST /v1/policies/{policyId}/versions/{version}/reinstate

Un-tombstones a previously-unregistered version: clears the tombstone on that version and recomputes the latest active version (and refreshes policyKind to match). Restores manifest bytes verbatim (semver hygiene). Idempotent. Reactivates a fully-retired policy identity when applicable. Publish is always allowed regardless of retirement state.