---
title: "create policy"
method: POST
path: "/auth/policies"
tags: ["auth"]
---

# create policy

`POST /auth/policies`

## Request body

- Policy
  - `id` string, required
  - `creation_date` integer — Unix Epoch in seconds
  - `statement` Statement[], required
    - `effect` 'allow' | 'deny', required
    - `resource` string, required
    - `action` string[], required
    - `condition` object — Optional conditions for when this statement applies.

## Response `201`

policy

- Policy
  - `id` string, required
  - `creation_date` integer — Unix Epoch in seconds
  - `statement` Statement[], required
    - `effect` 'allow' | 'deny', required
    - `resource` string, required
    - `action` string[], required
    - `condition` object — Optional conditions for when this statement applies.

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `409` — Resource Conflicts With Target
- `429` — too many requests
- `default` — Internal Server Error

---

[API](https://skmtc.net/treeverse/apis/lakefs-api.md) · [All operations](https://skmtc.net/treeverse/apis/lakefs-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/treeverse/lakefs-api/revisions/4617f80bee61/schema)
