> Call POST /v1/check before a tool that writes. DENY means do not invoke the tool. For clean Markdown of any page, append .md to the page URL. For the complete index, fetch https://docs.withwrit.com/llms.txt. # Get one principal's policy override GET https://api.withwrit.com/v1/policies/principals/{principalId} API key required. Returns the principal's sparse override — only the verbs it explicitly sets — in `policy`, plus the `effectivePolicy` it resolves to and `policyProvenance`, which names the winning layer (`principal`, `environment`, or `tenant`) per verb. `?environment=dev|staging|prod` folds that environment's override into the middle layer, exactly as a check naming it would evaluate. An override that was never configured returns an empty `policy`, `version: 0` ("no override yet"). Tombstoned principals still return 200 — they stay resolvable forever — with `"inert": true`: their override never supplies a mode while the principal is deleted or disabled. A principalId from another tenant is 404. Reference: https://docs.withwrit.com/api-reference/policy/get-one-principals-policy-override ## Servers - `https://api.withwrit.com` (Writ gate, default) - `https://j72ckh66ukck2kcbq3oiwxaalm0olxwb.lambda-url.us-east-1.on.aws` (Direct Lambda Function URL (fallback)) ## Request ### Path parameters - `principalId` (string, required) ### Query parameters - `environment` (enum, optional) - Allowed values: `dev`, `staging`, `prod` ## Response ### 200 The override plus its effective policy and provenance. ## Errors ### 400 Bad Request Error Unknown environment on `?environment=`. - `any` ### 401 Unauthorized Error API key required — missing, malformed, or unknown key. - `any` ### 404 Not Found Error No such principal in this tenant. ## Examples **Response** ```json { "effectivePolicy": { "admit": "require_grant", "prescribe": "require_grant", "provision": "require_grant", "refund": "step_up", "verify": "require_grant", "verify_human": "require_grant" }, "environment": null, "inert": false, "modes": [ "allow", "deny", "require_grant", "step_up" ], "policy": { "refund": "step_up" }, "policyId": "pol_ten_3fa8b91c2d44_prn_prn_9d2f4a1b2c3d", "policyProvenance": { "admit": "tenant", "prescribe": "tenant", "provision": "tenant", "refund": "principal", "verify": "tenant", "verify_human": "tenant" }, "principalId": "prn_9d2f4a1b2c3d", "principalName": "billing", "scope": "principal", "tenantId": "ten_3fa8b91c2d44", "updatedAt": 1759000200, "verbs": [ "admit", "prescribe", "provision", "refund", "verify", "verify_human" ], "version": 2 } ``` **SDK Code** ```python Policy_getOnePrincipalsPolicyOverride_example import requests url = "https://api.withwrit.com/v1/policies/principals/principalId" response = requests.get(url) print(response.json()) ``` ```javascript Policy_getOnePrincipalsPolicyOverride_example const url = 'https://api.withwrit.com/v1/policies/principals/principalId'; const options = {method: 'GET'}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go Policy_getOnePrincipalsPolicyOverride_example package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.withwrit.com/v1/policies/principals/principalId" req, _ := http.NewRequest("GET", url, nil) res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Policy_getOnePrincipalsPolicyOverride_example require 'uri' require 'net/http' url = URI("https://api.withwrit.com/v1/policies/principals/principalId") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) response = http.request(request) puts response.read_body ``` ```java Policy_getOnePrincipalsPolicyOverride_example import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api.withwrit.com/v1/policies/principals/principalId") .asString(); ``` ```php Policy_getOnePrincipalsPolicyOverride_example request('GET', 'https://api.withwrit.com/v1/policies/principals/principalId'); echo $response->getBody(); ``` ```csharp Policy_getOnePrincipalsPolicyOverride_example using RestSharp; var client = new RestClient("https://api.withwrit.com/v1/policies/principals/principalId"); var request = new RestRequest(Method.GET); IRestResponse response = client.Execute(request); ``` ```swift Policy_getOnePrincipalsPolicyOverride_example import Foundation let request = NSMutableURLRequest(url: NSURL(string: "https://api.withwrit.com/v1/policies/principals/principalId")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```