List policies in a zone
Returns a paginated list of policies in the zone. Supports cursor-based pagination, sorting, full-text search, and composable filters.
The filter[id] parameter restricts results to a known set of policy IDs (up to 100). It composes with other filters (filter[owner_type], query[], etc.) but cannot be combined with cursor pagination (after / before) — the server returns 400 if both are present. When filter[id] is used without an explicit limit, the limit defaults to the number of requested IDs so all results fit in a single page. IDs that don't exist or fall outside the zone are silently omitted.
Path parameters
The zone identifier
Query parameters
An opaque cursor used for paginating through a list of results
Cursor for forward pagination. Returned in Pagination.after_cursor. Mutually exclusive with before.
An opaque cursor used for paginating through a list of results
Cursor for backward pagination. Returned in Pagination.before_cursor. Mutually exclusive with after.
Maximum number of items to return per page.
Deprecated. Use expand[] instead.
Opt-in to additional response fields. Still honored for backward compatibility; supplying both expand and expand[] with disagreeing values returns 400 Bad Request.
Opt-in to additional response fields. Repeatable; matches the expand[] convention used across the Keycard API.
Field to sort by.
Sort direction. Default is desc (newest first).
Value shape for query[] and query[<field>] search parameters.
Wire conventions:
- Case-insensitive substring match (ILIKE).
- Repeated parameter instances are OR-ed across terms.
- Comma splitting is NOT performed; literal commas in a search term are preserved as part of the term.
Examples: ?query[name]=alpha&query[name]=beta -> name ILIKE %alpha% OR name ILIKE %beta% ?query[]=alpha -> any searchable field ILIKE %alpha%
Cross-field form is query[]; field-scoped form is query[<field>]. Field names are endpoint-specific; services declare each query parameter per operation.
Case-insensitive substring search on name. Repeatable; if multiple terms are supplied they are OR-ed (any matching term returns the row).
Value shape for query[] and query[<field>] search parameters.
Wire conventions:
- Case-insensitive substring match (ILIKE).
- Repeated parameter instances are OR-ed across terms.
- Comma splitting is NOT performed; literal commas in a search term are preserved as part of the term.
Examples: ?query[name]=alpha&query[name]=beta -> name ILIKE %alpha% OR name ILIKE %beta% ?query[]=alpha -> any searchable field ILIKE %alpha%
Cross-field form is query[]; field-scoped form is query[<field>]. Field names are endpoint-specific; services declare each query parameter per operation.
Case-insensitive substring search on description (policies only). Repeatable; if multiple terms are supplied they are OR-ed.
Value shape for query[] and query[<field>] search parameters.
Wire conventions:
- Case-insensitive substring match (ILIKE).
- Repeated parameter instances are OR-ed across terms.
- Comma splitting is NOT performed; literal commas in a search term are preserved as part of the term.
Examples: ?query[name]=alpha&query[name]=beta -> name ILIKE %alpha% OR name ILIKE %beta% ?query[]=alpha -> any searchable field ILIKE %alpha%
Cross-field form is query[]; field-scoped form is query[<field>]. Field names are endpoint-specific; services declare each query parameter per operation.
Case-insensitive substring search across all searchable fields of the resource. For policies that is name and description; for policy sets that is name. Repeatable; if multiple terms are supplied they are OR-ed.
Value shape for filter[<field>] query parameters.
Wire conventions:
- Repeated parameter instances are OR-ed across values.
- A single value containing comma-separated tokens is AND-ed across tokens.
Examples: ?filter[status]=a&filter[status]=b -> status in (a, b) ?filter[tag]=foo,bar -> tag contains foo AND bar ?filter[tag]=foo,bar&filter[tag]=baz -> (foo AND bar) OR baz
Field names and allowed values are endpoint-specific; services declare each filter[<field>] parameter per operation with an appropriate items.type/items.enum override.
Filter on owner_type. Repeatable; repeated instances OR across values (e.g. ?filter[owner_type]=platform&filter[owner_type]=customer matches either). See FilterValues in the shared spec for the full wire convention.
Allowed values: platform, customer. Unknown values return 400 with the list of allowed values. Comma-separated single values (e.g. ?filter[owner_type]=platform,customer) are rejected with a 400 pointing at the repeated-parameter OR form.
Note: the allowed-value enum is enforced in the handler (not as an OpenAPI items.enum) so the server can return a targeted error for the comma-AND form instead of a generic "not in allowed values" response.
Filter by policy ID. Repeatable; multiple values are OR-ed (e.g. ?filter[id]=p1&filter[id]=p2). Capped at 100 IDs per request — over-cap returns 400.
Cannot be combined with cursor pagination (after or before). The server returns 400 if both are present.
Composes with other filters (filter[owner_type], query[], etc.). When no explicit limit is provided, it defaults to the number of requested IDs so all results fit in a single page.
IDs that don't exist or fall outside the zone scope are silently omitted; callers diff against the request set if they care about missing IDs.
Headers
API version header (date-based, e.g. 2026-02-01)
Unique request identifier specified by the originating caller and passed along by proxies.
Response
A paginated list of policies