Skip to main content

Policies

The policy in force, for anyone to read — signed in or not — and every revision id has run.

GET only.

GET policies/currentthe Policy in force
GET policies/<revision>a revision id has run, such as a PolicyDecision's status.revision; percent-encode its +

Reading it asks nothing of the policy, so it can be read even when the policy is refused — which is when it matters most.

{
  "kind": "Policy",
  "metadata": { "name": "current" },
  "spec": {
    "engine": "bundle",
    "revision": "2026.10.01+3f9a2c1e4b5d",
    "commit": "058bf45…",
    "organization": { "organization": "Example Club", "source": "https://example.org/club/policies" },
    "layers": [
      { "path": "apps/id/policies", "role": "base", "package": "@fairgarden/id", "version": "1.2.0" },
      { "path": "policies", "role": "organization" }
    ],
    "packages": [
      {
        "name": "fairgarden.id",
        "title": "Your account",
        "related": [],
        "decisions": [
          { "name": "release", "path": "fairgarden/id/release", "title": "What a service may ask you for", "related": [] }
        ],
        "sources": [{ "path": "policies/fairgarden/id/privacy.rego", "layer": "policies", "text": "package fairgarden.id…" }]
      }
    ],
    "settings": {}
  },
  "status": { "phase": "Active", "signature": null }
}

status.phase is Active; Refused, with the message saying why, when a bundle's signature does not hold — unsigned, changed, or signed by someone else; Unavailable when the policy could not be read at all — what went wrong is logged, not published, since it can name private paths and URLs; or Undisclosed, when an OPA server holds the rules. Refused or unavailable, nothing the policy would decide is allowed. With the built-in rules, spec.engine is builtin, and the packages describe them, without sources.

A past revision's metadata.creationTimestamp is when id first loaded it. id keeps each revision as soon as it loads it, and keeps trying until it has.