PolicyBundle

Fetch the effective Policy Bundle for the user

Returns the effective Policy Bundle for the user identified by the zone-issued resource-scoped token. When no user-scope binding exists, one will be generated from the default set.

The response body is a binary archive in the codec selected via the Accept header. The only codec supported today is application/vnd.keycard.policy-bundle.v1+tar+gzip. Clients SHOULD send an explicit Accept header; absent one, the server defaults to the tar+gzip codec.

Supports conditional fetch via If-None-Match: when the supplied ETag matches the current bundle, the server responds 304 Not Modified with no body.

get/policy/bundle

Headers

X-Client-Request-IDstring uuid

Unique request identifier specified by the originating caller and passed along by proxies.

If-None-Matchstring

Conditional fetch ETag. If the supplied value matches the current bundle ETag, the server returns 304 Not Modified with no body.

Response

Bundle archive in the negotiated codec

Changes