> Call POST /v1/check before a tool that writes. DENY means do not invoke the tool. For clean Markdown of any page, append .md to the page URL. For the complete index, fetch https://docs.withwrit.com/llms.txt. # Get one environment's policy override GET https://api.withwrit.com/v1/policies/environments/{env} API key required. `{env}` is `dev`, `staging`, or `prod`. Returns the environment's sparse override — only the verbs it explicitly sets — in `policy`, plus the `effectivePolicy`: the tenant default with the override applied on top, which is what checks naming this environment actually evaluate against. `policyProvenance` names the winning layer (`tenant` or `environment`) per verb. An override that was never configured returns an empty `policy`, `version: 0` ("no override yet"), and an `effectivePolicy` equal to the tenant default. Reference: https://docs.withwrit.com/api-reference/policy/get-one-environments-policy-override ## Servers - `https://api.withwrit.com` (Writ gate, default) - `https://j72ckh66ukck2kcbq3oiwxaalm0olxwb.lambda-url.us-east-1.on.aws` (Direct Lambda Function URL (fallback)) ## Request ### Path parameters - `env` (enum, required) - Allowed values: `dev`, `staging`, `prod` ## Response ### 200 The override plus its effective policy. ## Errors ### 400 Bad Request Error Unknown environment — must be dev, staging, or prod. - `any` ### 401 Unauthorized Error API key required — missing, malformed, or unknown key. - `any` ## Examples **Response** ```json { "effectivePolicy": { "admit": "require_grant", "prescribe": "require_grant", "provision": "require_grant", "refund": "allow", "verify": "require_grant", "verify_human": "require_grant" }, "environment": "dev", "modes": [ "allow", "deny", "require_grant", "step_up" ], "policy": { "refund": "allow" }, "policyId": "pol_ten_3fa8b91c2d44_env_dev", "scope": "environment", "tenantId": "ten_3fa8b91c2d44", "updatedAt": 1759000100, "verbs": [ "admit", "prescribe", "provision", "refund", "verify", "verify_human" ], "version": 1 } ``` **SDK Code** ```python Policy_getOneEnvironmentsPolicyOverride_example import requests url = "https://api.withwrit.com/v1/policies/environments/dev" response = requests.get(url) print(response.json()) ``` ```javascript Policy_getOneEnvironmentsPolicyOverride_example const url = 'https://api.withwrit.com/v1/policies/environments/dev'; const options = {method: 'GET'}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go Policy_getOneEnvironmentsPolicyOverride_example package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.withwrit.com/v1/policies/environments/dev" req, _ := http.NewRequest("GET", url, nil) res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Policy_getOneEnvironmentsPolicyOverride_example require 'uri' require 'net/http' url = URI("https://api.withwrit.com/v1/policies/environments/dev") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) response = http.request(request) puts response.read_body ``` ```java Policy_getOneEnvironmentsPolicyOverride_example import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api.withwrit.com/v1/policies/environments/dev") .asString(); ``` ```php Policy_getOneEnvironmentsPolicyOverride_example request('GET', 'https://api.withwrit.com/v1/policies/environments/dev'); echo $response->getBody(); ``` ```csharp Policy_getOneEnvironmentsPolicyOverride_example using RestSharp; var client = new RestClient("https://api.withwrit.com/v1/policies/environments/dev"); var request = new RestRequest(Method.GET); IRestResponse response = client.Execute(request); ``` ```swift Policy_getOneEnvironmentsPolicyOverride_example import Foundation let request = NSMutableURLRequest(url: NSURL(string: "https://api.withwrit.com/v1/policies/environments/dev")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```