Create a credential inventory policy.
The CredentialInventoryPolicyServiceCreateRequest message.
DelegatedConstraints controls which third-party sign-in providers are accepted as proof of email ownership, and how they are scoped.
A human-readable name for the policy.
EmailOTPConstraints configures one-time codes delivered by email.
The credential types users are permitted to enroll under this policy.
PasskeyConstraints controls how users may enroll passkeys (FIDO2 / WebAuthn).
PasswordConstraints sets the complexity rules a user's password must satisfy.
When a user matches more than one policy, the policy with the highest priority applies.
TOTPConstraints configures authenticator-app one-time codes (RFC 6238).
Successful response
The CredentialInventoryPolicyServiceCreateResponse message.
CredentialInventoryPolicy defines which credential types your users may enroll and the rules for each type.