---
title: "Evaluate policies"
method: POST
path: "/api/policy-engine/evaluate"
tags: ["Policy"]
---

# Evaluate policies

`POST /api/policy-engine/evaluate`

This endpoint consults all policies and checks the ones that satisfy the request body’s conditions.

## Permissions

Any user or [API key](https://developers.vtex.com/docs/guides/api-authentication-using-api-keys) must have at least one of the appropriate [License Manager resources](https://help.vtex.com/en/tutorial/license-manager-resources--3q6ztrC8YynQf6rdc6euk3) to be able to successfully run this request. Otherwise they will receive a status code `403` error. These are the applicable resources for this endpoint:

| **Product** | **Category** | **Resource** |
| --------------- | ----------------- | ----------------- |
| Promotions Policy Engine | Policies | **Evaluate Policy** |

There are no applicable [predefined roles](https://help.vtex.com/en/tutorial/predefined-roles--jGDurZKJHvHJS13LnO7Dy) for this resource list. You must [create a custom role](https://help.vtex.com/en/tutorial/roles--7HKK5Uau2H6wxE1rH5oRbc#creating-a-role) and add at least one of the resources above in order to use this endpoint.To learn more about machine authentication at VTEX, see [Authentication overview](https://developers.vtex.com/docs/guides/authentication).

>❗ To prevent integrations from having excessive permissions, consider the [best practices for managing API keys](https://help.vtex.com/en/tutorial/best-practices-api-keys--7b6nD1VMHa49aI5brlOvJm) when assigning License Manager roles to integrations.

## Headers

- `Content-Type` string, required
- `Accept` string, required

## Request body

- EvaluatePolicyRequest — Object with policy conditions.
  - `resource` string, required — Scope on which this policy must be evaluated.
  - `context` object, required — Conditions that the policy needs to satisfy.

## Response `200`

OK

- PolicyActionGetResponse[] — Array of objects with policies infomation.
  - `id` string — Action ID.
  - `metadata` object — Metadata object from the current action.

## Changes

- **2023-11-14** `6d229e4cf2f2` — 2 info
  - the `context` request property default value `{"brandId":"2000001","discountPercentage":"91.00"}` was removed
  - the `resource` request property default value `vrn:vtex.promotions-alert:aws-us-east-1:kamila:master:/_v/promotions_alert` was removed

[Change history](https://skmtc.dev/vtex/apis/policies-system-api/changes/api/policy-engine/evaluate/post.md)

---

[API](https://skmtc.dev/vtex/apis/policies-system-api.md) · [All operations](https://skmtc.dev/vtex/apis/policies-system-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/vtex/policies-system-api/revisions/72627866ebf7/schema)
