---
title: "Set the session's egress policy"
method: PUT
path: "/network/egress-policy"
---

# Set the session's egress policy

`PUT /network/egress-policy`

Tells the VM whether its session's egress is restricted to an allowlist. The allowlist itself is enforced outside the VM, by Kernel's egress proxy, and is deliberately not sent here: the proxy is the only enforcement point, and a second copy of the destination list inside the VM could only drift from it.

The VM uses this to refuse requests that would route traffic around that proxy. Today that is the CDP command `Target.createBrowserContext` carrying `proxyServer` or `proxyBypassList`, which Playwright exposes as `browser.newContext({ proxy })`: with `filtered: true` the proxy answers it with a protocol error instead of forwarding it to Chromium.

Idempotent, and applied by the control plane both when the session is set up and whenever an allowlist is added to or removed from a running session. The policy is persisted, so it survives a restart of the instance API process; a request that cannot persist it returns 500 rather than reporting a policy that would be lost.

## Request body

- NetworkEgressPolicy — What the VM knows about its session's egress policy. Not the policy itself, which is enforced outside the VM.
  - `filtered` boolean, required — Whether the session's egress is restricted to an allowlist. When true, the VM refuses requests that would reach destinations without going through the proxy that enforces it.

## Response `200`

Egress policy applied

- NetworkEgressPolicy — What the VM knows about its session's egress policy. Not the policy itself, which is enforced outside the VM.
  - `filtered` boolean, required — Whether the session's egress is restricted to an allowlist. When true, the VM refuses requests that would reach destinations without going through the proxy that enforces it.

## Other responses

- `400` — Bad Request
- `500` — Internal Server Error

## Changes

- **2026-10-07** `a1c46fb41d0f` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/kernel/apis/kernel-images-api/changes/network/egress-policy/put.md)

---

[API](https://skmtc.dev/kernel/apis/kernel-images-api.md) · [All operations](https://skmtc.dev/kernel/apis/kernel-images-api/llms.txt) · [OpenAPI document](https://skmtc.dev/kernel/apis/kernel-images-api/revisions/a1c46fb41d0f?raw)
