WSO2 Governance Policies API

for managing governance policies.

Operations 5

GET /policies Retrieves a list of all governance policies #
POST /policies Creates a new governance policy #
GET /policies/{policyId} Get a specific governance policy #
PUT /policies/{policyId} Update a specific governance policy #
DELETE /policies/{policyId} Delete a specific governance policy #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/wso2-governance-policies-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

wso2-governance-policies-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: v1.1
  title: WSO2 API Manager - Governance Governance Policies API
  description: This document specifies a **RESTful API** for WSO2 **API Manager** - Governance.
  contact:
    name: WSO2
    url: http://wso2.com/products/api-manager/
    email: architecture@wso2.com
  license:
    name: Apache 2.0
    url: http://www.apache.org/licenses/LICENSE-2.0.html
servers:
- url: https://apis.wso2.com/api/am/governance/v1
tags:
- name: Governance Policies
  description: for managing governance policies.
paths:
  /policies:
    get:
      summary: Retrieves a list of all governance policies
      description: Retrieves a list of governance policies for the user's organization.
      operationId: getGovernancePolicies
      tags:
      - Governance Policies
      parameters:
      - $ref: '#/components/parameters/limit'
      - $ref: '#/components/parameters/offset'
      - name: query
        in: query
        schema:
          type: string
          example: name:WSO2 Best Practices state:API_CREATE label:GLOBAL
        description: "You can search for governance policies using following format.\n\n  - \"query=name:{NAME}\" searches policies by name.\n  - \"query=state:{STATE} \" searches policies by state.\n\nYou can also use multiple attributes to search for policies.\n  - \"query=name:{NAME} state:{STATE}\" searches policies by name, state, and label.\n\nRemember to use URL encoding if your client doesn't support it (e.g., curl).\n"
      responses:
        '200':
          description: OK. Successful response with a list of governance policies.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIMGovernancePolicyList'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - OAuth2Security:
        - apim:gov_policy_read
    post:
      summary: Creates a new governance policy
      description: Creates a new governance policy for the user's organization.
      operationId: createGovernancePolicy
      tags:
      - Governance Policies
      requestBody:
        required: true
        description: JSON object containing the details of the new governance policy.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIMGovernancePolicy'
      responses:
        '201':
          description: OK. Governance policy created successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIMGovernancePolicy'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - OAuth2Security:
        - apim:gov_policy_manage
  /policies/{policyId}:
    get:
      summary: Get a specific governance policy
      description: Retrieves details of a specific governance policy identified by the policyId.
      operationId: getGovernancePolicyById
      tags:
      - Governance Policies
      parameters:
      - $ref: '#/components/parameters/policyId'
      responses:
        '200':
          description: OK. Governance policy details retrieved successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIMGovernancePolicy'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - OAuth2Security:
        - apim:gov_policy_read
    put:
      summary: Update a specific governance policy
      description: Updates the details of an existing governance policy identified by the policyId.
      operationId: updateGovernancePolicyById
      tags:
      - Governance Policies
      parameters:
      - $ref: '#/components/parameters/policyId'
      requestBody:
        required: true
        description: JSON object containing the updated governance policy details.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/APIMGovernancePolicy'
      responses:
        '200':
          description: OK. Governance policy updated successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIMGovernancePolicy'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - OAuth2Security:
        - apim:gov_policy_manage
    delete:
      summary: Delete a specific governance policy
      description: Deletes an existing governance policy identified by the policyId.
      operationId: deleteGovernancePolicy
      tags:
      - Governance Policies
      parameters:
      - $ref: '#/components/parameters/policyId'
      responses:
        '204':
          description: OK. Governance policy deleted successfully.
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal Server Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
      - OAuth2Security:
        - apim:gov_policy_manage
components:
  schemas:
    Pagination:
      title: Pagination
      type: object
      properties:
        offset:
          type: integer
          example: 0
        limit:
          type: integer
          example: 1
        total:
          type: integer
          example: 10
        next:
          type: string
          description: 'Link to the next subset of resources qualified.

            Empty if no more resources are to be returned.

            '
        previous:
          type: string
          description: 'Link to the previous subset of resources qualified.

            Empty if current subset is the first subset returned.

            '
    APIMGovernancePolicy:
      type: object
      description: Detailed information about a governance policy.
      properties:
        id:
          type: string
          description: UUID of the governance policy.
          readOnly: true
          example: 987e6543-d21b-34d5-b678-912345678900
        name:
          type: string
          description: Name of the governance policy.
          maxLength: 256
          example: API Security Policy
        description:
          type: string
          description: A brief description of the governance policy.
          maxLength: 1024
          example: Policy for enforcing security standards across all APIs.
        governableStates:
          type: array
          description: List of states at which the governance policy should be enforced.
          items:
            type: string
            description: The state at which an governance policy should be enforced.
            enum:
            - API_CREATE
            - API_UPDATE
            - API_DEPLOY
            - API_PUBLISH
            example: API_DEPLOY
            x-enum-varnames:
            - API_CREATE
            - API_UPDATE
            - API_DEPLOY
            - API_PUBLISH
        actions:
          type: array
          description: List of actions taken when the governance policy is violated. An action is defined by the state and rule severity. If an action is not specified to each state and rule severity, the default action is `NOTIFY`.
          items:
            $ref: '#/components/schemas/Action'
        rulesets:
          type: array
          description: List of rulesets associated with the governance policy.
          items:
            type: string
            example: 94566543-d21b-34d5-b678-912345678900
        labels:
          type: array
          description: List of labels IDs associated with the governance policy.
          items:
            type: string
          example:
          - 54d5833a-ca86-44bb-bcda-5b9fcdacd79d
        createdBy:
          type: string
          description: Identifier of the user who created the governance policy.
          readOnly: true
          example: admin@wso2.com
        createdTime:
          type: string
          description: Timestamp when the governance policy was created.
          readOnly: true
          example: '2024-08-01T12:00:00Z'
        updatedBy:
          type: string
          description: Identifier of the user who last updated the governance policy.
          readOnly: true
          example: admin@wso2.com
        updatedTime:
          type: string
          description: Timestamp when the governance policy was last updated.
          readOnly: true
          example: '2024-08-02T12:00:00Z'
      required:
      - name
      - rulesets
      - labels
      - governableStates
      - actions
    Action:
      type: object
      description: Action to be taken when a governance policy is violated.
      properties:
        state:
          type: string
          description: The state of the artifact to which the action is linked to.
          enum:
          - API_CREATE
          - API_UPDATE
          - API_DEPLOY
          - API_PUBLISH
          example: API_DEPLOY
          x-enum-varnames:
          - API_CREATE
          - API_UPDATE
          - API_DEPLOY
          - API_PUBLISH
        ruleSeverity:
          type: string
          description: The severity of the rule to which the action is linked to.
          enum:
          - ERROR
          - WARN
          - INFO
          example: ERROR
        type:
          type: string
          description: The type of action to be taken when a governance policy is violated in the given state withe given rule severity.
          enum:
          - BLOCK
          - NOTIFY
          example: BLOCK
    Error:
      title: Error object returned with 4XX HTTP Status
      required:
      - code
      - message
      properties:
        code:
          type: integer
          format: int64
        message:
          type: string
          description: Error message.
        description:
          type: string
          description: 'A detail description about the error message.

            '
    APIMGovernancePolicyList:
      type: object
      description: A list of governance policies.
      properties:
        count:
          type: integer
          description: Number of governance policies returned.
          example: 10
        list:
          type: array
          description: List of governance policies.
          items:
            $ref: '#/components/schemas/APIMGovernancePolicy'
        pagination:
          $ref: '#/components/schemas/Pagination'
  parameters:
    limit:
      name: limit
      in: query
      description: 'Maximum size of resource array to return.

        '
      schema:
        type: integer
        default: 25
    policyId:
      name: policyId
      in: path
      description: '**UUID** of the Policy.

        '
      required: true
      schema:
        type: string
    offset:
      name: offset
      in: query
      description: 'Starting point within the complete list of items qualified.

        '
      schema:
        type: integer
        default: 0
  securitySchemes:
    OAuth2Security:
      type: oauth2
      flows:
        password:
          tokenUrl: https://localhost:9443/oauth2/token
          scopes:
            openid: Authorize access to user details
            apim:gov_rule_read: Read governance rulesets
            apim:gov_rule_manage: Manage governance rulesets
            apim:gov_policy_read: Read governance policies
            apim:gov_policy_manage: Manage governance policies
            apim:gov_result_read: Read governance results