API key required. Sets the decision mode for one or more verbs in
the caller’s tenant. Send either a bare map ({"refund": "deny"})
or wrapped as {"policy": {"refund": "deny"}} — both are accepted.
Keys named tenantId, modes, verbs, or policy are ignored if
they leak in from a GET response. Every verb must be a known verb and
every mode a known mode, otherwise the whole update is rejected with
the offending values listed. The response is the tenant’s full
updated policy, not just what you sent.
Your Writ API key (writ_…) as an Authorization Bearer header. The sponsor token (writ_sp_…) is a separate credential used only for grants, revokes, and reinstate — it goes in the same Authorization header on those endpoints. In the Fern docs playground, paste the key here; it is stored in this browser only.