Scaleway Policies API

Policies control user rights, by defining one or more rules to apply to the attached principals (users, groups or applications). A policy rule has two parts:\ permission set and scope. For each policy rule, you specify one or more permission sets (eg. “list all Instances”) and their scope (eg. “on Project A only”). This therefore defines the actions that the principles can carry out on resources within the scope.

Business capability
Identity & Access Management BC-620.20

Operations 6

GET /iam/v1alpha1/policies List policies of an Organization #
POST /iam/v1alpha1/policies Create a new policy #
GET /iam/v1alpha1/policies/{policy_id} Get an existing policy #
PATCH /iam/v1alpha1/policies/{policy_id} Update an existing policy #
DELETE /iam/v1alpha1/policies/{policy_id} Delete a policy #
POST /iam/v1alpha1/policies/{policy_id}/clone Clone a policy #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/scaleway-policies-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

scaleway-policies-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: IAM Policies API
  description: Identity and Access Management (IAM) allows you to share access to the management of your Scaleway resources and Organization settings, in a controlled and secure manner.
  version: v1alpha1
servers:
- url: https://api.scaleway.com
tags:
- name: Policies
  description: 'Policies control user rights, by defining one or more rules to apply to the attached principals (users, groups or applications). A policy rule has two parts:\ permission set and scope.


    For each policy rule, you specify one or more permission sets (eg. “list all Instances”) and their scope (eg. “on Project A only”). This therefore defines the actions that the principles can carry out on resources within the scope.'
paths:
  /iam/v1alpha1/policies:
    get:
      tags:
      - Policies
      operationId: ListPolicies
      summary: List policies of an Organization
      description: List the policies of an Organization. By default, the policies listed are ordered by creation date in ascending order. This can be modified via the `order_by` field. You must define the `organization_id` in the query path of your request. You can also define additional parameters to filter your query, such as `user_ids`, `groups_ids`, `application_ids`, and `policy_name`.
      parameters:
      - in: query
        name: order_by
        description: Criteria for sorting results.
        schema:
          type: string
          enum:
          - policy_name_asc
          - policy_name_desc
          - created_at_asc
          - created_at_desc
          x-enum-descriptions:
            values:
              policy_name_asc: Policy name ascending
              policy_name_desc: Policy name descending
              created_at_asc: Creation date ascending
              created_at_desc: Creation date descending
          default: policy_name_asc
      - in: query
        name: page_size
        description: Number of results per page. Value must be between 1 and 100.
        schema:
          type: integer
          format: uint32
      - in: query
        name: page
        description: Page number. Value must be greater than 1.
        schema:
          type: integer
          format: int32
      - in: query
        name: organization_id
        description: ID of the Organization to filter.
        schema:
          type: string
      - in: query
        name: editable
        description: Defines whether or not filter out editable policies.
        schema:
          type: boolean
      - in: query
        name: user_ids
        description: Defines whether or not to filter by list of user IDs.
        schema:
          type: array
          items:
            type: string
      - in: query
        name: group_ids
        description: Defines whether or not to filter by list of group IDs.
        schema:
          type: array
          items:
            type: string
      - in: query
        name: application_ids
        description: Filter by a list of application IDs.
        schema:
          type: array
          items:
            type: string
      - in: query
        name: no_principal
        description: Defines whether or not the policy is attributed to a principal.
        schema:
          type: boolean
      - in: query
        name: policy_name
        description: Name of the policy to fetch.
        schema:
          type: string
      - in: query
        name: tag
        description: Filter by tags containing a given string.
        schema:
          type: string
      - in: query
        name: policy_ids
        description: Filter by a list of IDs.
        schema:
          type: array
          items:
            type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/scaleway.iam.v1alpha1.ListPoliciesResponse'
      security:
      - scaleway: []
      x-codeSamples:
      - lang: cURL
        source: "curl -X GET \\\n  -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n  \"https://api.scaleway.com/iam/v1alpha1/policies?organization_id=string\""
      - lang: HTTPie
        source: "http GET \"https://api.scaleway.com/iam/v1alpha1/policies\" \\\n  X-Auth-Token:$SCW_SECRET_KEY \\\n  organization_id==string"
    post:
      tags:
      - Policies
      operationId: CreatePolicy
      summary: Create a new policy
      description: Create a new application. You must define the `name` parameter in the request. You can specify parameters such as `user_id`, `groups_id`, `application_id`, `no_principal`, `rules` and its child attributes.
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/scaleway.iam.v1alpha1.Policy'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  description: Name of the policy to create (max length is 64 characters).
                description:
                  type: string
                  description: Description of the policy to create (max length is 200 characters).
                organization_id:
                  type: string
                  description: ID of the Organization.
                rules:
                  type: array
                  description: Rules of the policy to create.
                  items:
                    $ref: '#/components/schemas/scaleway.iam.v1alpha1.RuleSpecs'
                tags:
                  type: array
                  description: Tags associated with the policy (maximum of 10 tags).
                  items:
                    type: string
                user_id:
                  type: string
                  description: ID of user attributed to the policy.
                  nullable: true
                  x-one-of: principal
                group_id:
                  type: string
                  description: ID of group attributed to the policy.
                  nullable: true
                  x-one-of: principal
                application_id:
                  type: string
                  description: ID of application attributed to the policy.
                  nullable: true
                  x-one-of: principal
                no_principal:
                  type: boolean
                  description: Defines whether or not a policy is attributed to a principal.
                  nullable: true
                  x-one-of: principal
              required:
              - name
              x-properties-order:
              - name
              - description
              - organization_id
              - rules
              - tags
              - user_id
              - group_id
              - application_id
              - no_principal
      security:
      - scaleway: []
      x-codeSamples:
      - lang: cURL
        source: "curl -X POST \\\n  -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"description\": \"string\",\n    \"name\": \"string\",\n    \"organization_id\": \"string\"\n  }' \\\n  \"https://api.scaleway.com/iam/v1alpha1/policies\""
      - lang: HTTPie
        source: "http POST \"https://api.scaleway.com/iam/v1alpha1/policies\" \\\n  X-Auth-Token:$SCW_SECRET_KEY \\\n  description=\"string\" \\\n  name=\"string\" \\\n  organization_id=\"string\""
  /iam/v1alpha1/policies/{policy_id}:
    get:
      tags:
      - Policies
      operationId: GetPolicy
      summary: Get an existing policy
      description: Retrieve information about a policy, specified by the `policy_id` parameter. The policy's full details, including `id`, `name`, `organization_id`, `nb_rules` and `nb_scopes`, `nb_permission_sets` are returned in the response.
      parameters:
      - in: path
        name: policy_id
        description: Id of policy to search.
        required: true
        schema:
          type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/scaleway.iam.v1alpha1.Policy'
      security:
      - scaleway: []
      x-codeSamples:
      - lang: cURL
        source: "curl -X GET \\\n  -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n  \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}\""
      - lang: HTTPie
        source: "http GET \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}\" \\\n  X-Auth-Token:$SCW_SECRET_KEY"
    patch:
      tags:
      - Policies
      operationId: UpdatePolicy
      summary: Update an existing policy
      description: Update the parameters of a policy, including `name`, `description`, `user_id`, `group_id`, `application_id` and `no_principal`.
      parameters:
      - in: path
        name: policy_id
        description: Id of policy to update.
        required: true
        schema:
          type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/scaleway.iam.v1alpha1.Policy'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                name:
                  type: string
                  description: New name for the policy (max length is 64 characters).
                  nullable: true
                description:
                  type: string
                  description: New description of policy (max length is 200 characters).
                  nullable: true
                tags:
                  type: array
                  description: New tags for the policy (maximum of 10 tags).
                  nullable: true
                  items:
                    type: string
                user_id:
                  type: string
                  description: New ID of user attributed to the policy.
                  nullable: true
                  x-one-of: principal
                group_id:
                  type: string
                  description: New ID of group attributed to the policy.
                  nullable: true
                  x-one-of: principal
                application_id:
                  type: string
                  description: New ID of application attributed to the policy.
                  nullable: true
                  x-one-of: principal
                no_principal:
                  type: boolean
                  description: Defines whether or not the policy is attributed to a principal.
                  nullable: true
                  x-one-of: principal
              x-properties-order:
              - name
              - description
              - tags
              - user_id
              - group_id
              - application_id
              - no_principal
      security:
      - scaleway: []
      x-codeSamples:
      - lang: cURL
        source: "curl -X PATCH \\\n  -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{}' \\\n  \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}\""
      - lang: HTTPie
        source: "http PATCH \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}\" \\\n  X-Auth-Token:$SCW_SECRET_KEY"
    delete:
      tags:
      - Policies
      operationId: DeletePolicy
      summary: Delete a policy
      description: Delete a policy. You must define specify the `policy_id` parameter in your request. Note that when deleting a policy, all permissions it gives to its principal (user, group or application) will be revoked.
      parameters:
      - in: path
        name: policy_id
        description: Id of policy to delete.
        required: true
        schema:
          type: string
      responses:
        '204':
          description: ''
      security:
      - scaleway: []
      x-codeSamples:
      - lang: cURL
        source: "curl -X DELETE \\\n  -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n  \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}\""
      - lang: HTTPie
        source: "http DELETE \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}\" \\\n  X-Auth-Token:$SCW_SECRET_KEY"
  /iam/v1alpha1/policies/{policy_id}/clone:
    post:
      tags:
      - Policies
      operationId: ClonePolicy
      summary: Clone a policy
      description: Clone a policy. You must define specify the `policy_id` parameter in your request.
      parameters:
      - in: path
        name: policy_id
        required: true
        schema:
          type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/scaleway.iam.v1alpha1.Policy'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
      security:
      - scaleway: []
      x-codeSamples:
      - lang: cURL
        source: "curl -X POST \\\n  -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{}' \\\n  \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}/clone\""
      - lang: HTTPie
        source: "http POST \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}/clone\" \\\n  X-Auth-Token:$SCW_SECRET_KEY"
components:
  schemas:
    scaleway.iam.v1alpha1.Policy:
      type: object
      properties:
        id:
          type: string
          description: Id of the policy.
        name:
          type: string
          description: Name of the policy.
        description:
          type: string
          description: Description of the policy.
        organization_id:
          type: string
          description: Organization ID of the policy.
        created_at:
          type: string
          description: Date and time of policy creation. (RFC 3339 format)
          format: date-time
          example: '2022-03-22T12:34:56.123456Z'
          nullable: true
        updated_at:
          type: string
          description: Date and time of last policy update. (RFC 3339 format)
          format: date-time
          example: '2022-03-22T12:34:56.123456Z'
          nullable: true
        editable:
          type: boolean
          description: Defines whether or not a policy is editable.
        deletable:
          type: boolean
          description: Defines whether or not a policy is deletable.
        managed:
          type: boolean
          description: Defines whether or not a policy is managed.
        nb_rules:
          type: integer
          description: Number of rules of the policy.
          format: uint32
        nb_scopes:
          type: integer
          description: Number of policy scopes.
          format: uint32
        nb_permission_sets:
          type: integer
          description: Number of permission sets of the policy.
          format: uint32
        tags:
          type: array
          description: Tags associated with the policy.
          items:
            type: string
        user_id:
          type: string
          description: ID of the user attributed to the policy.
          nullable: true
          x-one-of: principal
        group_id:
          type: string
          description: ID of the group attributed to the policy.
          nullable: true
          x-one-of: principal
        application_id:
          type: string
          description: ID of the application attributed to the policy.
          nullable: true
          x-one-of: principal
        no_principal:
          type: boolean
          description: Defines whether or not a policy is attributed to a principal.
          nullable: true
          x-one-of: principal
      x-properties-order:
      - id
      - name
      - description
      - organization_id
      - created_at
      - updated_at
      - editable
      - deletable
      - managed
      - nb_rules
      - nb_scopes
      - nb_permission_sets
      - tags
      - user_id
      - group_id
      - application_id
      - no_principal
    scaleway.iam.v1alpha1.RuleSpecs:
      type: object
      properties:
        permission_set_names:
          type: array
          description: Names of permission sets bound to the rule.
          nullable: true
          items:
            type: string
        condition:
          type: string
          description: Condition expression to evaluate.
        project_ids:
          type: array
          description: List of Project IDs the rule is scoped to.
          nullable: true
          x-one-of: scope
          items:
            type: string
        organization_id:
          type: string
          description: ID of Organization the rule is scoped to.
          nullable: true
          x-one-of: scope
      x-properties-order:
      - permission_set_names
      - condition
      - project_ids
      - organization_id
    scaleway.iam.v1alpha1.ListPoliciesResponse:
      type: object
      properties:
        policies:
          type: array
          description: List of policies.
          items:
            $ref: '#/components/schemas/scaleway.iam.v1alpha1.Policy'
        total_count:
          type: integer
          description: Total count of policies.
          format: uint32
      x-properties-order:
      - policies
      - total_count
  securitySchemes:
    scaleway:
      in: header
      name: X-Auth-Token
      type: apiKey