> Call POST /v1/check before a tool that writes. DENY means do not invoke the tool. For clean Markdown of any page, append .md to the page URL. For the complete index, fetch https://docs.withwrit.com/llms.txt. # Create or update an environment policy override PUT https://api.withwrit.com/v1/policies/environments/{env} Content-Type: application/json API key required. Sets the decision mode for one or more verbs in the `{env}` override (`dev`, `staging`, or `prod`). The override is sparse: only the verbs you send are stored; every other verb keeps inheriting the tenant default. Same body shapes and validation as `PUT /v1/policy`. Every successful update bumps that override's `version` by one — the tenant default's version is untouched. The response's `policyProvenance` names the winning layer per verb. Reference: https://docs.withwrit.com/api-reference/policy/create-or-update-an-environment-policy-override ## Servers - `https://api.withwrit.com` (Writ gate, default) - `https://j72ckh66ukck2kcbq3oiwxaalm0olxwb.lambda-url.us-east-1.on.aws` (Direct Lambda Function URL (fallback)) ## Request ### Path parameters - `env` (enum, required) - Allowed values: `dev`, `staging`, `prod` ### Body (application/json) This endpoint expects a map from string to enum. - `map from string to enum` - Allowed values: `allow`, `deny`, `require_grant`, `step_up` ## Response ### 200 The updated override plus its effective policy. ## Errors ### 400 Bad Request Error Empty body, unknown verbs, unknown modes, or unknown environment. - `any` ### 401 Unauthorized Error API key required — missing, malformed, or unknown key. - `any` ## Examples ### Policy_createOrUpdateAnEnvironmentPolicyOverride_example **Response** ```json { "effectivePolicy": { "admit": "require_grant", "prescribe": "require_grant", "provision": "require_grant", "refund": "allow", "verify": "require_grant", "verify_human": "require_grant" }, "environment": "dev", "policy": { "refund": "allow" }, "policyId": "pol_ten_3fa8b91c2d44_env_dev", "scope": "environment", "tenantId": "ten_3fa8b91c2d44", "updatedAt": 1759000200, "version": 2 } ``` **SDK Code** ```python Policy_createOrUpdateAnEnvironmentPolicyOverride_example import requests url = "https://api.withwrit.com/v1/policies/environments/dev" response = requests.put(url) print(response.json()) ``` ```javascript Policy_createOrUpdateAnEnvironmentPolicyOverride_example const url = 'https://api.withwrit.com/v1/policies/environments/dev'; const options = {method: 'PUT'}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go Policy_createOrUpdateAnEnvironmentPolicyOverride_example package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.withwrit.com/v1/policies/environments/dev" req, _ := http.NewRequest("PUT", url, nil) res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Policy_createOrUpdateAnEnvironmentPolicyOverride_example require 'uri' require 'net/http' url = URI("https://api.withwrit.com/v1/policies/environments/dev") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Put.new(url) response = http.request(request) puts response.read_body ``` ```java Policy_createOrUpdateAnEnvironmentPolicyOverride_example import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.put("https://api.withwrit.com/v1/policies/environments/dev") .asString(); ``` ```php Policy_createOrUpdateAnEnvironmentPolicyOverride_example request('PUT', 'https://api.withwrit.com/v1/policies/environments/dev'); echo $response->getBody(); ``` ```csharp Policy_createOrUpdateAnEnvironmentPolicyOverride_example using RestSharp; var client = new RestClient("https://api.withwrit.com/v1/policies/environments/dev"); var request = new RestRequest(Method.PUT); IRestResponse response = client.Execute(request); ``` ```swift Policy_createOrUpdateAnEnvironmentPolicyOverride_example import Foundation let request = NSMutableURLRequest(url: NSURL(string: "https://api.withwrit.com/v1/policies/environments/dev")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "PUT" let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### bare **Request** ```json { "refund": "allow" } ``` **Response** ```json { "effectivePolicy": { "admit": "require_grant", "prescribe": "require_grant", "provision": "require_grant", "refund": "allow", "verify": "require_grant", "verify_human": "require_grant" }, "environment": "dev", "policy": { "refund": "allow" }, "policyId": "pol_ten_3fa8b91c2d44_env_dev", "scope": "environment", "tenantId": "ten_3fa8b91c2d44", "updatedAt": 1759000200, "version": 2 } ``` **SDK Code** ```python bare import requests url = "https://api.withwrit.com/v1/policies/environments/dev" payload = { "refund": "allow" } headers = {"Content-Type": "application/json"} response = requests.put(url, json=payload, headers=headers) print(response.json()) ``` ```javascript bare const url = 'https://api.withwrit.com/v1/policies/environments/dev'; const options = { method: 'PUT', headers: {'Content-Type': 'application/json'}, body: '{"refund":"allow"}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go bare package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.withwrit.com/v1/policies/environments/dev" payload := strings.NewReader("{\n \"refund\": \"allow\"\n}") req, _ := http.NewRequest("PUT", url, payload) req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby bare require 'uri' require 'net/http' url = URI("https://api.withwrit.com/v1/policies/environments/dev") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Put.new(url) request["Content-Type"] = 'application/json' request.body = "{\n \"refund\": \"allow\"\n}" response = http.request(request) puts response.read_body ``` ```java bare import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.put("https://api.withwrit.com/v1/policies/environments/dev") .header("Content-Type", "application/json") .body("{\n \"refund\": \"allow\"\n}") .asString(); ``` ```php bare request('PUT', 'https://api.withwrit.com/v1/policies/environments/dev', [ 'body' => '{ "refund": "allow" }', 'headers' => [ 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp bare using RestSharp; var client = new RestClient("https://api.withwrit.com/v1/policies/environments/dev"); var request = new RestRequest(Method.PUT); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"refund\": \"allow\"\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift bare import Foundation let headers = ["Content-Type": "application/json"] let parameters = ["refund": "allow"] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.withwrit.com/v1/policies/environments/dev")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "PUT" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### wrapped **Request** ```json { "policy": { "refund": "allow" } } ``` **Response** ```json { "effectivePolicy": { "admit": "require_grant", "prescribe": "require_grant", "provision": "require_grant", "refund": "allow", "verify": "require_grant", "verify_human": "require_grant" }, "environment": "dev", "policy": { "refund": "allow" }, "policyId": "pol_ten_3fa8b91c2d44_env_dev", "scope": "environment", "tenantId": "ten_3fa8b91c2d44", "updatedAt": 1759000200, "version": 2 } ``` **SDK Code** ```python wrapped import requests url = "https://api.withwrit.com/v1/policies/environments/dev" payload = { "policy": { "refund": "allow" } } headers = {"Content-Type": "application/json"} response = requests.put(url, json=payload, headers=headers) print(response.json()) ``` ```javascript wrapped const url = 'https://api.withwrit.com/v1/policies/environments/dev'; const options = { method: 'PUT', headers: {'Content-Type': 'application/json'}, body: '{"policy":{"refund":"allow"}}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go wrapped package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.withwrit.com/v1/policies/environments/dev" payload := strings.NewReader("{\n \"policy\": {\n \"refund\": \"allow\"\n }\n}") req, _ := http.NewRequest("PUT", url, payload) req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby wrapped require 'uri' require 'net/http' url = URI("https://api.withwrit.com/v1/policies/environments/dev") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Put.new(url) request["Content-Type"] = 'application/json' request.body = "{\n \"policy\": {\n \"refund\": \"allow\"\n }\n}" response = http.request(request) puts response.read_body ``` ```java wrapped import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.put("https://api.withwrit.com/v1/policies/environments/dev") .header("Content-Type", "application/json") .body("{\n \"policy\": {\n \"refund\": \"allow\"\n }\n}") .asString(); ``` ```php wrapped request('PUT', 'https://api.withwrit.com/v1/policies/environments/dev', [ 'body' => '{ "policy": { "refund": "allow" } }', 'headers' => [ 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp wrapped using RestSharp; var client = new RestClient("https://api.withwrit.com/v1/policies/environments/dev"); var request = new RestRequest(Method.PUT); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"policy\": {\n \"refund\": \"allow\"\n }\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift wrapped import Foundation let headers = ["Content-Type": "application/json"] let parameters = ["policy": ["refund": "allow"]] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api.withwrit.com/v1/policies/environments/dev")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "PUT" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```