---
title: "create policy"
method: POST
path: "/auth/policies"
tags: ["auth"]
---

# create policy

`POST /auth/policies`

## Request body

- Policy
  - `id` string, required
  - `creation_date` integer — Unix Epoch in seconds
  - `statement` Statement[], required
    - `effect` 'allow' | 'deny', required
    - `resource` string, required
    - `action` string[], required
    - `condition` object — Optional conditions for when this statement applies.

## Response `201`

policy

- Policy
  - `id` string, required
  - `creation_date` integer — Unix Epoch in seconds
  - `statement` Statement[], required
    - `effect` 'allow' | 'deny', required
    - `resource` string, required
    - `action` string[], required
    - `condition` object — Optional conditions for when this statement applies.

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `409` — Resource Conflicts With Target
- `429` — too many requests
- `default` — Internal Server Error

## Changes

- **2025-10-29** `297b5aa38dfc` — 2 info
  - added the new optional request property `statement/items/condition`
  - added the optional property `statement/items/condition` to the response with the `201` status
- **2025-07-29** `27799ffec9a5` — 2 info
  - added the non-success response with the status `429`
  - removed the non-success response with the status `420`
- **2024-09-17** `3b10653a8013` — 2 warning, 2 info
  - removed the request property `statement/items/condition`
  - removed the optional property `statement/items/condition` from the response with the `201` status
  - added the non-success response with the status `420`
  - removed the non-success response with the status `429`

[Change history](https://skmtc.dev/treeverse/apis/lakefs-api/changes/auth/policies/post.md)

---

[API](https://skmtc.dev/treeverse/apis/lakefs-api.md) · [All operations](https://skmtc.dev/treeverse/apis/lakefs-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/treeverse/lakefs-api/revisions/4617f80bee61/schema)
