> Call POST /v1/check before a tool that writes. DENY means do not invoke the tool. For clean Markdown of any page, append .md to the page URL. For the complete index, fetch https://docs.withwrit.com/llms.txt. # Create or update a principal's policy override PUT https://api.withwrit.com/v1/policies/principals/{principalId} Content-Type: application/json API key required. Sets the decision mode for one or more verbs in one principal's override — the top policy layer, beating the environment override and the tenant default. The override is sparse: only the verbs you send are stored; every other verb keeps inheriting downward. Every successful update bumps that override's `version` by one — environment and tenant versions are untouched. Fail closed: configuring policy on a tombstoned or disabled principal is `400` (`principal_inactive`) — an identity that cannot authorize checks cannot carry policy either. Disabling or deleting a principal later makes its override inert (it never supplies a mode); re-enabling re-arms it. The override data is kept, not wiped. Body shapes match `PUT /v1/policies/environments/{env}`, plus `"inherit"`: sending `{"refund": "inherit"}` removes that verb from the override so it inherits downward again. Reference: https://docs.withwrit.com/api-reference/policy/create-or-update-a-principals-policy-override ## Servers - `https://api.withwrit.com` (Writ gate, default) - `https://j72ckh66ukck2kcbq3oiwxaalm0olxwb.lambda-url.us-east-1.on.aws` (Direct Lambda Function URL (fallback)) ## Request ### Path parameters - `principalId` (string, required) ### Body (application/json) This endpoint expects a map from string to enum. - `map from string to enum` - Allowed values: `allow`, `deny`, `require_grant`, `step_up`, `inherit` ## Response ### 200 The updated override plus its effective policy and provenance. ## Errors ### 400 Bad Request Error Empty body, unknown verbs, unknown modes, or the principal is deleted/disabled. ### 401 Unauthorized Error API key required — missing, malformed, or unknown key. - `any` ### 404 Not Found Error No such principal in this tenant. - `any` ## Examples ### Policy_createOrUpdateAPrincipalsPolicyOverride_example **Response** ```json { "effectivePolicy": { "admit": "require_grant", "prescribe": "require_grant", "provision": "require_grant", "refund": "step_up", "verify": "require_grant", "verify_human": "require_grant" }, "environment": null, "policy": { "refund": "step_up" }, "policyId": "pol_ten_3fa8b91c2d44_prn_prn_9d2f4a1b2c3d", "policyProvenance": { "refund": "principal", "verify": "tenant" }, "principalId": "prn_9d2f4a1b2c3d", "principalName": "billing", "scope": "principal", "tenantId": "ten_3fa8b91c2d44", "updatedAt": 1759000300, "version": 3 } ``` **SDK Code** ```python Policy_createOrUpdateAPrincipalsPolicyOverride_example import requests url = "https://api.withwrit.com/v1/policies/principals/principalId" response = requests.put(url) print(response.json()) ``` ```javascript Policy_createOrUpdateAPrincipalsPolicyOverride_example const url = 'https://api.withwrit.com/v1/policies/principals/principalId'; const options = {method: 'PUT'}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go Policy_createOrUpdateAPrincipalsPolicyOverride_example package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.withwrit.com/v1/policies/principals/principalId" req, _ := http.NewRequest("PUT", url, nil) res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Policy_createOrUpdateAPrincipalsPolicyOverride_example require 'uri' require 'net/http' url = URI("https://api.withwrit.com/v1/policies/principals/principalId") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Put.new(url) response = http.request(request) puts response.read_body ``` ```java Policy_createOrUpdateAPrincipalsPolicyOverride_example import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.put("https://api.withwrit.com/v1/policies/principals/principalId") .asString(); ``` ```php Policy_createOrUpdateAPrincipalsPolicyOverride_example request('PUT', 'https://api.withwrit.com/v1/policies/principals/principalId'); echo $response->getBody(); ``` ```csharp Policy_createOrUpdateAPrincipalsPolicyOverride_example using RestSharp; var client = new RestClient("https://api.withwrit.com/v1/policies/principals/principalId"); var request = new RestRequest(Method.PUT); IRestResponse response = client.Execute(request); ``` ```swift Policy_createOrUpdateAPrincipalsPolicyOverride_example import Foundation let request = NSMutableURLRequest(url: NSURL(string: "https://api.withwrit.com/v1/policies/principals/principalId")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "PUT" let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### bare **Request** ```json { "refund": "step_up" } ``` **Response** ```json { "effectivePolicy": { "admit": "require_grant", "prescribe": "require_grant", "provision": "require_grant", "refund": "step_up", "verify": "require_grant", "verify_human": "require_grant" }, "environment": null, "policy": { "refund": "step_up" }, "policyId": "pol_ten_3fa8b91c2d44_prn_prn_9d2f4a1b2c3d", "policyProvenance": { "refund": "principal", "verify": "tenant" }, "principalId": "prn_9d2f4a1b2c3d", "principalName": "billing", "scope": "principal", "tenantId": "ten_3fa8b91c2d44", "updatedAt": 1759000300, "version": 3 } ``` **SDK Code** ```python bare import requests url = "https://api.withwrit.com/v1/policies/principals/principalId" payload = { "refund": "step_up" } headers = {"Content-Type": "application/json"} response = requests.put(url, json=payload, headers=headers) print(response.json()) ``` ```javascript bare const url = 'https://api.withwrit.com/v1/policies/principals/principalId'; const options = { method: 'PUT', headers: {'Content-Type': 'application/json'}, body: '{"refund":"step_up"}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go bare package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.withwrit.com/v1/policies/principals/principalId" payload := strings.NewReader("{\n \"refund\": \"step_up\"\n}") req, _ := http.NewRequest("PUT", url, payload) req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby bare require 'uri' require 'net/http' url = URI("https://api.withwrit.com/v1/policies/principals/principalId") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Put.new(url) request["Content-Type"] = 'application/json' request.body = "{\n \"refund\": \"step_up\"\n}" response = http.request(request) puts response.read_body ``` ```java bare import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.put("https://api.withwrit.com/v1/policies/principals/principalId") .header("Content-Type", "application/json") .body("{\n \"refund\": \"step_up\"\n}") .asString(); ``` ```php bare request('PUT', 'https://api.withwrit.com/v1/policies/principals/principalId', [ 'body' => '{ "refund": "step_up" }', 'headers' => [ 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp bare using RestSharp; var client = new RestClient("https://api.withwrit.com/v1/policies/principals/principalId"); var request = new RestRequest(Method.PUT); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"refund\": \"step_up\"\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift bare import Foundation let headers = ["Content-Type": "application/json"] let parameters = ["refund": "step_up"] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.withwrit.com/v1/policies/principals/principalId")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "PUT" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### wrapped **Request** ```json { "policy": { "provision": "inherit", "refund": "step_up" } } ``` **Response** ```json { "effectivePolicy": { "admit": "require_grant", "prescribe": "require_grant", "provision": "require_grant", "refund": "step_up", "verify": "require_grant", "verify_human": "require_grant" }, "environment": null, "policy": { "refund": "step_up" }, "policyId": "pol_ten_3fa8b91c2d44_prn_prn_9d2f4a1b2c3d", "policyProvenance": { "refund": "principal", "verify": "tenant" }, "principalId": "prn_9d2f4a1b2c3d", "principalName": "billing", "scope": "principal", "tenantId": "ten_3fa8b91c2d44", "updatedAt": 1759000300, "version": 3 } ``` **SDK Code** ```python wrapped import requests url = "https://api.withwrit.com/v1/policies/principals/principalId" payload = { "policy": { "provision": "inherit", "refund": "step_up" } } headers = {"Content-Type": "application/json"} response = requests.put(url, json=payload, headers=headers) print(response.json()) ``` ```javascript wrapped const url = 'https://api.withwrit.com/v1/policies/principals/principalId'; const options = { method: 'PUT', headers: {'Content-Type': 'application/json'}, body: '{"policy":{"provision":"inherit","refund":"step_up"}}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go wrapped package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.withwrit.com/v1/policies/principals/principalId" payload := strings.NewReader("{\n \"policy\": {\n \"provision\": \"inherit\",\n \"refund\": \"step_up\"\n }\n}") req, _ := http.NewRequest("PUT", url, payload) req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby wrapped require 'uri' require 'net/http' url = URI("https://api.withwrit.com/v1/policies/principals/principalId") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Put.new(url) request["Content-Type"] = 'application/json' request.body = "{\n \"policy\": {\n \"provision\": \"inherit\",\n \"refund\": \"step_up\"\n }\n}" response = http.request(request) puts response.read_body ``` ```java wrapped import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.put("https://api.withwrit.com/v1/policies/principals/principalId") .header("Content-Type", "application/json") .body("{\n \"policy\": {\n \"provision\": \"inherit\",\n \"refund\": \"step_up\"\n }\n}") .asString(); ``` ```php wrapped request('PUT', 'https://api.withwrit.com/v1/policies/principals/principalId', [ 'body' => '{ "policy": { "provision": "inherit", "refund": "step_up" } }', 'headers' => [ 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp wrapped using RestSharp; var client = new RestClient("https://api.withwrit.com/v1/policies/principals/principalId"); var request = new RestRequest(Method.PUT); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"policy\": {\n \"provision\": \"inherit\",\n \"refund\": \"step_up\"\n }\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift wrapped import Foundation let headers = ["Content-Type": "application/json"] let parameters = ["policy": [ "provision": "inherit", "refund": "step_up" ]] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.withwrit.com/v1/policies/principals/principalId")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "PUT" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```