---
title: "Access Policy Upsert"
method: POST
path: "/api/v1.admin.auth-policy.upsert"
tags: ["Admin"]
---

# Access Policy Upsert

`POST /api/v1.admin.auth-policy.upsert`

Create or update an access policy

## Request body

- AdminAccessPolicyUpsertIn
  - `id` string, required
  - `description` string, required
  - `rules` AccessRule[]
    - `effect` 'allow' | 'deny', required
    - `resource` string, required
    - `actions` string[], required

## Response `200`

- AdminAccessPolicyUpsertOut
  - `id` string, required
  - `created` integer, required
  - `updated` integer, required

## Other responses

- `400`
- `401`
- `403`
- `422`

## Changes

- **2026-04-13** `e6c44b12ecfb` — 2 breaking
  - the `created` response's property type changed from `string` to `integer`, and format from `date-time` to `uint64` for status `200`
  - the `updated` response's property type changed from `string` to `integer`, and format from `date-time` to `uint64` for status `200`
- **2026-03-31** `f62be26d2a53` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/svix/apis/diom-api/changes/api/v1.admin.auth-policy.upsert/post.md)

---

[API](https://skmtc.dev/svix/apis/diom-api.md) · [All operations](https://skmtc.dev/svix/apis/diom-api/llms.txt) · [OpenAPI document](https://skmtc.dev/svix/apis/diom-api/revisions/7f5edfb12f87?raw)
