---
title: "Create permission rule set"
method: POST
path: "/permission-rule-sets"
tags: ["Permission Rule Sets"]
---

# Create permission rule set

`POST /permission-rule-sets`

Create a named, shareable ordered rule list (theme 5 rule grouping).

N agent-credential bindings can point at one set, so `permissions:test`
and "revoke this operation everywhere" stay single-place edits.

## Request body

- RuleSetCreateRequest — Create a shared permission rule set (theme 5 phase 1, Q-04).
  - `description` string, nullable
  - `name` string, required — Unique human-readable name.
  - `rules` JenticOneControlWebSchemasPermissionRulesPermissionRuleSchema[] — Initial ordered rule list (first-match-wins, default-deny).
    - `effect` 'allow' | 'deny', required — Whether this rule allows or denies the matched request.
    - `match_mode` 'regex' | 'prefix' | 'exact' — How `path` is interpreted: `regex` (full-match), `prefix` (string prefix), or `exact` (equality). Defaults to `regex` for backwards compatibility.
    - `methods` string[], nullable — HTTP methods to match (case-insensitive). None matches all.
    - `operations` string[], nullable — OpenAPI operation IDs to match. None matches all operations.
    - `path` string, nullable — Path pattern to match. Interpreted per `match_mode`: `regex` uses full-match semantics (the pattern must describe the whole path); `prefix` and `exact` are literal. None matches all paths.

## Response `201`

Successful Response

- RuleSetResponse — Rule set detail — the ordered rules plus its referencing-binding count.
  - `binding_count` integer, required — How many agent-credential bindings currently point at this set.
  - `created_at` string, date-time, required
  - `created_by` string, nullable
  - `description` string, nullable
  - `name` string, required
  - `rule_set_id` string, required
  - `rules` PermissionRuleReadSchema[], required
    - `_comment` string, nullable
    - `_system` boolean
    - `effect` 'allow' | 'deny', required
    - `match_mode` 'regex' | 'prefix' | 'exact'
    - `methods` string[], nullable
    - `operations` string[], nullable
    - `path` string, nullable

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `409` — Conflict
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-09-14** `d56864df177c` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/permission-rule-sets/post.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc.dev/jentic/apis/jentic-control-plane-api/revisions/e4688b93dfc7?raw)
