Creates a new Security Policy for users or apps.
Creating a custom (non-default) Security Policy requires the “Custom Security Policies” plan feature. Accounts without this feature enabled receive a
406 Not Acceptableresponse.
Resource URL
https://<subdomain>.onelogin.com/api/2/policiesHeader Parameters
| Parameter | Description |
|---|---|
| Authorization | bearer:<access_token>. Requires a scope of Manage All. |
| Content-Type | application/json |
Request Parameters
| Parameter | Type | Description |
|---|---|---|
| name | String | Required. Policy name. |
| kind | String | Required. user or app. Cannot be changed after creation. |
| ... | Any attribute listed on the Policy Resource page appropriate to the chosen kind. |
Sample Responses
201 Created
{
"status": {
"error": false,
"code": 201,
"type": "success",
"message": "Success"
},
"data": [
{
"id": 3,
"name": "Custom User Policy",
"kind": "user",
"is_default": false,
"minimum_password_length": 10
}
]
}406 Not Acceptable
{
"status": {
"error": true,
"code": 406,
"type": "not_acceptable",
"message": "Custom Security Policies feature is not available on your plan"
}
}422 Unprocessable Entity
{
"status": {
"error": true,
"code": 422,
"type": "unprocessable_entity",
"message": "Validation failed"
},
"data": {
"name": ["can't be blank"]
}
}Postman Collection
Add the Security Policies endpoints to your Postman workspace using the OneLogin Postman collection.
Sample Code
curl -X POST \
https://<subdomain>.onelogin.com/api/2/policies \
-H 'Authorization: bearer:<access_token>' \
-H 'Content-Type: application/json' \
-d '{
"name": "Custom User Policy",
"kind": "user",
"minimum_password_length": 10
}'Have a Question?
Found a problem or a bug? Submit a support ticket.
Looking for walkthroughs or how-to guides? Check out our Knowledge Base.
Have a product idea or request? Share it in our Ideas Portal.