---
title: "POST /v1/{+parent}/authorizedOrgsDescs"
method: POST
path: "/v1/{+parent}/authorizedOrgsDescs"
tags: ["accessPolicies"]
---

# POST /v1/{+parent}/authorizedOrgsDescs

`POST /v1/{+parent}/authorizedOrgsDescs`

Creates an authorized orgs desc. The long-running operation from this RPC has a successful status after the authorized orgs desc propagates to long-lasting storage. If a authorized orgs desc contains errors, an error response is returned for the first error encountered. The name of this `AuthorizedOrgsDesc` will be assigned during creation.

## Path parameters

- `parent` string, required

## Request body

- AuthorizedOrgsDesc — `AuthorizedOrgsDesc` contains data for an organization's authorization policy.
  - `orgs` string[] — The list of organization ids in this AuthorizedOrgsDesc. Format: `organizations/` Example: `organizations/123456`
  - `authorizationType` 'AUTHORIZATION_TYPE_UNSPECIFIED' | 'AUTHORIZATION_TYPE_TRUST' — A granular control type for authorization levels. Valid value is `AUTHORIZATION_TYPE_TRUST`.
  - `authorizationDirection` 'AUTHORIZATION_DIRECTION_UNSPECIFIED' | 'AUTHORIZATION_DIRECTION_TO' | 'AUTHORIZATION_DIRECTION_FROM' — The direction of the authorization relationship between this organization and the organizations listed in the `orgs` field. The valid values for this field include the following: `AUTHORIZATION_DIRECTION_FROM`: Allows this organization to evaluate traffic in the organizations listed in the `orgs` field. `AUTHORIZATION_DIRECTION_TO`: Allows the organizations listed in the `orgs` field to evaluate the traffic in this organization. For the authorization relationship to take effect, all of the organizations must authorize and specify the appropriate relationship direction. For example, if organization A authorized organization B and C to evaluate its traffic, by specifying `AUTHORIZATION_DIRECTION_TO` as the authorization direction, organizations B and C must specify `AUTHORIZATION_DIRECTION_FROM` as the authorization direction in their `AuthorizedOrgsDesc` resource.
  - `name` string — Identifier. Resource name for the `AuthorizedOrgsDesc`. Format: `accessPolicies/{access_policy}/authorizedOrgsDescs/{authorized_orgs_desc}`. The `authorized_orgs_desc` component must begin with a letter, followed by alphanumeric characters or `_`. After you create an `AuthorizedOrgsDesc`, you cannot change its `name`.
  - `assetType` 'ASSET_TYPE_UNSPECIFIED' | 'ASSET_TYPE_DEVICE' | 'ASSET_TYPE_CREDENTIAL_STRENGTH' — The asset type of this authorized orgs desc. Valid values are `ASSET_TYPE_DEVICE`, and `ASSET_TYPE_CREDENTIAL_STRENGTH`.

## Response `200`

Successful response

---

[API](https://skmtc.dev/google/apis/accesscontextmanager.md) · [All operations](https://skmtc.dev/google/apis/accesscontextmanager/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/google/accesscontextmanager/revisions/af581187d9ba/schema)
