> ## Documentation Index
> Fetch the complete documentation index at: https://pipedream.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Update policy

> Replace an allow policy's name, subjects, and connector entries

Requires the `policies:write` scope.



## OpenAPI

````yaml /conduit/openapi/api.yaml post /conduit.v1.ConduitService/UpdatePolicy
openapi: 3.1.0
info:
  title: Conduit API
  version: v1
  description: |
    Machine-to-machine API for Conduit workspaces. Authenticate a
    workspace API client with OAuth 2.0 client credentials at
    `/oauth/token`, then call these methods with the resulting bearer token.
    Read-only methods are documented as `GET`, with their JSON request encoded
    in the `message` query parameter. Mutating methods use `POST` with a JSON
    body. The server also accepts `POST` for reads. See the API guide for
    auth, scopes, and error handling.
servers:
  - url: https://conduit.example.com
    description: Your Conduit instance — replace with your CONDUIT_BASE_URL
security:
  - bearerAuth: []
tags:
  - name: connectors
    x-group: Connectors
    description: Create and manage connectors and the workspace's Pipedream configuration.
  - name: policies-and-groups
    x-group: Policies & groups
    description: Allow policies, groups, group membership, and effective-access debugging.
  - name: members
    x-group: Members
    description: Read the workspace's member roster.
  - name: single-sign-on
    x-group: Single sign-on
    description: Read sanitized workspace identity-provider configuration.
  - name: provisioning
    x-group: Provisioning
    description: Read sanitized SCIM metadata, provisioning rules, and resource mappings.
  - name: workspace-settings
    x-group: Workspace settings
    description: Change general workspace settings.
  - name: audit-log
    x-group: Audit log
    description: Read the workspace audit log.
paths:
  /conduit.v1.ConduitService/UpdatePolicy:
    post:
      tags:
        - policies-and-groups
      summary: Update policy
      description: |-
        Replace an allow policy's name, subjects, and connector entries

        Requires the `policies:write` scope.
      operationId: UpdatePolicy
      parameters:
        - name: Connect-Protocol-Version
          in: header
          required: true
          schema:
            $ref: '#/components/schemas/connect-protocol-version'
        - name: Connect-Timeout-Ms
          in: header
          schema:
            $ref: '#/components/schemas/connect-timeout-header'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/conduit.v1.UpdatePolicyRequest'
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/conduit.v1.UpdatePolicyResponse'
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
components:
  schemas:
    connect-protocol-version:
      type: number
      title: Connect-Protocol-Version
      enum:
        - 1
      description: Define the version of the Connect protocol
      const: 1
    connect-timeout-header:
      type: number
      title: Connect-Timeout-Ms
      description: Define the timeout, in ms
    conduit.v1.UpdatePolicyRequest:
      type: object
      properties:
        id:
          type: string
          title: id
        name:
          type: string
          title: name
        links:
          type: array
          items:
            $ref: '#/components/schemas/conduit.v1.PolicyLink'
          title: links
        entries:
          type: array
          items:
            $ref: '#/components/schemas/conduit.v1.PolicyEntry'
          title: entries
        organizationId:
          type: string
          title: organization_id
      title: UpdatePolicyRequest
      additionalProperties: false
    conduit.v1.UpdatePolicyResponse:
      type: object
      properties:
        policy:
          $ref: '#/components/schemas/conduit.v1.Policy'
          title: policy
      title: UpdatePolicyResponse
      additionalProperties: false
    connect.error:
      type: object
      properties:
        code:
          type: string
          examples:
            - not_found
          enum:
            - canceled
            - unknown
            - invalid_argument
            - deadline_exceeded
            - not_found
            - already_exists
            - permission_denied
            - resource_exhausted
            - failed_precondition
            - aborted
            - out_of_range
            - unimplemented
            - internal
            - unavailable
            - data_loss
            - unauthenticated
          description: >-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
        message:
          type: string
          description: >-
            A developer-facing error message, which should be in English. Any
            user-facing error message should be localized and sent in the
            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized by the client.
        details:
          type: array
          items:
            $ref: '#/components/schemas/connect.error_details.Any'
          description: >-
            A list of messages that carry the error details. There is no limit
            on the number of messages.
      title: Connect Error
      additionalProperties: true
      description: >-
        Error type returned by Connect:
        https://connectrpc.com/docs/go/errors/#http-representation
    conduit.v1.PolicyLink:
      type: object
      properties:
        workspace:
          type: boolean
          title: workspace
        groupId:
          type: string
          title: group_id
        userId:
          type: string
          title: user_id
      title: PolicyLink
      additionalProperties: false
      description: >-
        Subject a policy applies to: exactly one of workspace (every member of
        the
         policy's workspace), a group, or a user.
    conduit.v1.PolicyEntry:
      type: object
      properties:
        connectorId:
          type: string
          title: connector_id
        allTools:
          type: boolean
          title: all_tools
        tools:
          type: array
          items:
            type: string
          title: tools
      title: PolicyEntry
      additionalProperties: false
      description: >-
        One connector grant: all of the connector's tools, or an explicit
        allowlist.
         connector_id: 'app:<slug>' | 'mcp:<name>' | 'local:<name>' |
         'builtin:<name>', or the wildcards 'app:*' | 'mcp:*' | 'local:*' |
         'builtin:*' | '*'.
    conduit.v1.Policy:
      type: object
      properties:
        id:
          type: string
          title: id
        name:
          type: string
          title: name
        type:
          type: string
          title: type
          description: '"allow" | "enable"'
        links:
          type: array
          items:
            $ref: '#/components/schemas/conduit.v1.PolicyLink'
          title: links
        entries:
          type: array
          items:
            $ref: '#/components/schemas/conduit.v1.PolicyEntry'
          title: entries
        createdAt:
          type:
            - integer
            - string
          title: created_at
          format: int64
      title: Policy
      additionalProperties: false
    connect.error_details.Any:
      type: object
      properties:
        type:
          type: string
          description: >-
            A URL that acts as a globally unique identifier for the type of the
            serialized message. For example:
            `type.googleapis.com/google.rpc.ErrorInfo`. This is used to
            determine the schema of the data in the `value` field and is the
            discriminator for the `debug` field.
        value:
          type: string
          format: binary
          description: >-
            The Protobuf message, serialized as bytes and base64-encoded. The
            specific message type is identified by the `type` field.
        debug:
          oneOf:
            - type: object
              title: Any
              additionalProperties: true
              description: Detailed error information.
          discriminator:
            propertyName: type
          title: Debug
          description: >-
            Deserialized error detail payload. The 'type' field indicates the
            schema. This field is for easier debugging and should not be relied
            upon for application logic.
      additionalProperties: true
      description: >-
        Contains an arbitrary serialized message along with a @type that
        describes the type of the serialized message, with an additional debug
        field for ConnectRPC error details.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: opaque

````