governance module route (requires governance:policy:read)
POST
/v1/m/governance/pdp/dry-run
const url = 'https://example.com/v1/m/governance/pdp/dry-run';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"engine":"example","request":{"permission":"example","principal":{"id":"example","kind":"example"},"resource":{"extra":{"additionalProperty":"example"},"id":"example","kind":"example","sensitivity":"example"},"tenant":"example"},"source":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/v1/m/governance/pdp/dry-run \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "engine": "example", "request": { "permission": "example", "principal": { "id": "example", "kind": "example" }, "resource": { "extra": { "additionalProperty": "example" }, "id": "example", "kind": "example", "sensitivity": "example" }, "tenant": "example" }, "source": "example" }'Evaluates an authorization request against an unpublished candidate policy; the route is separate from explain so a console can label the intent.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Header Parameters
Section titled “Header Parameters ” X-Olivares-Tenant
string format: uuid
Target tenant id; required when the principal can act in more than one tenant.
Request Body required
Section titled “Request Body required ” Media type application/json
object
engine
required
Case-insensitive after trimming: cedar or opa.
string
request
Any of:
object
principal
resource
Any of:
null
null
Example generated
{ "engine": "example", "request": { "permission": "example", "principal": { "id": "example", "kind": "example" }, "resource": { "extra": { "additionalProperty": "example" }, "id": "example", "kind": "example", "sensitivity": "example" }, "tenant": "example" }, "source": "example"}Responses
Section titled “ Responses ”OK
Media type application/json
object
Example generated
{}Bad request
Media type application/json
object
Example generated
{}Unauthenticated
Media type application/json
object
Example generated
{}Forbidden
Media type application/json
object
Example generated
{}Not found
Media type application/json
object
Example generated
{}Conflict / setup required
Media type application/json
object
Example generated
{}Rate limited
Media type application/json
object
Example generated
{}