Create MAIP Policy
curl --request POST \
--url https://api.truthlocks.com/v1/maip/policies \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"name": "<string>",
"rules": [
{
"conditions": [
{
"value": "<unknown>"
}
],
"requires_approval": true
}
],
"description": "<string>",
"category": "custom",
"priority": 100
}
'import requests
url = "https://api.truthlocks.com/v1/maip/policies"
payload = {
"name": "<string>",
"rules": [
{
"conditions": [{ "value": "<unknown>" }],
"requires_approval": True
}
],
"description": "<string>",
"category": "custom",
"priority": 100
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
rules: [{conditions: [{value: '<unknown>'}], requires_approval: true}],
description: '<string>',
category: 'custom',
priority: 100
})
};
fetch('https://api.truthlocks.com/v1/maip/policies', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.truthlocks.com/v1/maip/policies",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'rules' => [
[
'conditions' => [
[
'value' => '<unknown>'
]
],
'requires_approval' => true
]
],
'description' => '<string>',
'category' => 'custom',
'priority' => 100
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.truthlocks.com/v1/maip/policies"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"rules\": [\n {\n \"conditions\": [\n {\n \"value\": \"<unknown>\"\n }\n ],\n \"requires_approval\": true\n }\n ],\n \"description\": \"<string>\",\n \"category\": \"custom\",\n \"priority\": 100\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.truthlocks.com/v1/maip/policies")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"rules\": [\n {\n \"conditions\": [\n {\n \"value\": \"<unknown>\"\n }\n ],\n \"requires_approval\": true\n }\n ],\n \"description\": \"<string>\",\n \"category\": \"custom\",\n \"priority\": 100\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.truthlocks.com/v1/maip/policies")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"rules\": [\n {\n \"conditions\": [\n {\n \"value\": \"<unknown>\"\n }\n ],\n \"requires_approval\": true\n }\n ],\n \"description\": \"<string>\",\n \"category\": \"custom\",\n \"priority\": 100\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"tenant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"description": "<string>",
"category": "scope",
"status": "active",
"priority": 123,
"rules": [
{
"conditions": [
{
"field": "trust_score",
"op": "eq",
"value": "<unknown>"
}
],
"effect": "allow",
"requires_approval": true
}
],
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}MAIP Policies
Create MAIP Policy
Create a new agent enforcement policy with conditional rules for runtime access control
POST
/
v1
/
maip
/
policies
Create MAIP Policy
curl --request POST \
--url https://api.truthlocks.com/v1/maip/policies \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"name": "<string>",
"rules": [
{
"conditions": [
{
"value": "<unknown>"
}
],
"requires_approval": true
}
],
"description": "<string>",
"category": "custom",
"priority": 100
}
'import requests
url = "https://api.truthlocks.com/v1/maip/policies"
payload = {
"name": "<string>",
"rules": [
{
"conditions": [{ "value": "<unknown>" }],
"requires_approval": True
}
],
"description": "<string>",
"category": "custom",
"priority": 100
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
rules: [{conditions: [{value: '<unknown>'}], requires_approval: true}],
description: '<string>',
category: 'custom',
priority: 100
})
};
fetch('https://api.truthlocks.com/v1/maip/policies', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.truthlocks.com/v1/maip/policies",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'rules' => [
[
'conditions' => [
[
'value' => '<unknown>'
]
],
'requires_approval' => true
]
],
'description' => '<string>',
'category' => 'custom',
'priority' => 100
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.truthlocks.com/v1/maip/policies"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"rules\": [\n {\n \"conditions\": [\n {\n \"value\": \"<unknown>\"\n }\n ],\n \"requires_approval\": true\n }\n ],\n \"description\": \"<string>\",\n \"category\": \"custom\",\n \"priority\": 100\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.truthlocks.com/v1/maip/policies")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"rules\": [\n {\n \"conditions\": [\n {\n \"value\": \"<unknown>\"\n }\n ],\n \"requires_approval\": true\n }\n ],\n \"description\": \"<string>\",\n \"category\": \"custom\",\n \"priority\": 100\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.truthlocks.com/v1/maip/policies")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"rules\": [\n {\n \"conditions\": [\n {\n \"value\": \"<unknown>\"\n }\n ],\n \"requires_approval\": true\n }\n ],\n \"description\": \"<string>\",\n \"category\": \"custom\",\n \"priority\": 100\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"tenant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "<string>",
"description": "<string>",
"category": "scope",
"status": "active",
"priority": 123,
"rules": [
{
"conditions": [
{
"field": "trust_score",
"op": "eq",
"value": "<unknown>"
}
],
"effect": "allow",
"requires_approval": true
}
],
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z"
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}{
"code": "AUTH_REQUIRED",
"message": "Authentication required",
"http_status": 401
}Create MAIP Policy
POST /v1/maip/policies
Creates a new MAIP agent enforcement policy for the authenticated tenant. Policies define runtime rules that are evaluated when agents request access to scoped resources via the Evaluate Policy endpoint.
MAIP policies are different from RBAC issuance
policies. MAIP policies govern machine
agent behavior at runtime based on trust scores, delegation depth, scopes,
and agent type. RBAC policies govern credential issuance and human user
access.
Authentication
RequiresX-API-Key header or Bearer JWT token. Tenant-scoped via cookie or JWT claim.
Request Body
string
required
Human-readable policy name. Used in denial messages and audit logs when the
policy blocks an action. Must be unique per tenant. Maximum 256 characters.
string
Detailed description of what the policy enforces and why. Maximum 2048
characters.
string
Policy category for organizational purposes. One of:
"scope"— Restricts access based on scopes or resources"trust"— Restricts access based on trust scores"rate"— Restricts access frequency or volume"custom"— Custom enforcement logic
"custom" if omitted.integer
Evaluation priority. Lower numbers are evaluated first. Range: 1-1000.
Defaults to
100 if omitted. Multiple policies at the same priority are
evaluated in creation order.object
required
JSON array of policy rules. Each rule is evaluated independently. If any rule with Condition fields:
Operators:
Effects:
"effect": "deny" matches, the action is denied.Rule schema:{
"conditions": [{ "field": "trust_score", "op": "lt", "value": 0.5 }],
"effect": "deny",
"requires_approval": false
}
| Field | Type | Operators | Description |
|---|---|---|---|
trust_score | number | lt, gt, le, ge | Agent’s current trust score (0.0-1.0) |
scope | string | eq, ne, in, contains | The scope being accessed (e.g., "data:write") |
agent_type | string | eq, ne, in | Agent type (e.g., "llm", "worker", "orchestrator") |
delegation_depth | number | gt, ge, lt, le | Agent’s position in the delegation chain (0 = direct) |
| Operator | Description | Example value |
|---|---|---|
eq | Equals | "data:write" |
ne | Not equals | "system" |
lt | Less than | 0.5 |
gt | Greater than | 3 |
le | Less than or equal | 0.3 |
ge | Greater than or equal | 0.7 |
in | Matches any value in a list | ["llm", "worker"] |
contains | String contains substring | "write" |
"allow"— Explicitly allow (does not override denials)"deny"— Block the action. First deny wins."require_approval"— Require human approval before proceeding
Response
Returns the created policy object with server-generated fields (id, tenant_id, status, timestamps).
string
UUID primary key of the created policy.
string
UUID of the owning tenant.
string
Policy name as provided.
string
Policy description, if provided.
string
Policy category.
string
Always
"active" on creation.integer
Evaluation priority.
object
The rules array as provided.
string
ISO 8601 creation timestamp.
string
ISO 8601 last-updated timestamp.
Example
curl -X POST https://api.truthlocks.com/v1/maip/policies \
-H "X-API-Key: tl_live_..." \
-H "Content-Type: application/json" \
-d '{
"name": "Block Low-Trust Write Operations",
"description": "Deny data:write scope access for agents with trust score below 0.5",
"category": "trust",
"priority": 10,
"rules": [
{
"conditions": [
{"field": "trust_score", "op": "lt", "value": 0.5},
{"field": "scope", "op": "eq", "value": "data:write"}
],
"effect": "deny",
"requires_approval": false
}
]
}'
const response = await fetch("https://api.truthlocks.com/v1/maip/policies", {
method: "POST",
headers: {
"X-API-Key": "tl_live_...",
"Content-Type": "application/json",
},
body: JSON.stringify({
name: "Block Low-Trust Write Operations",
description:
"Deny data:write scope access for agents with trust score below 0.5",
category: "trust",
priority: 10,
rules: [
{
conditions: [
{ field: "trust_score", op: "lt", value: 0.5 },
{ field: "scope", op: "eq", value: "data:write" },
],
effect: "deny",
requires_approval: false,
},
],
}),
});
const policy = await response.json();
import requests
response = requests.post(
"https://api.truthlocks.com/v1/maip/policies",
headers={
"X-API-Key": "tl_live_...",
"Content-Type": "application/json",
},
json={
"name": "Block Low-Trust Write Operations",
"description": "Deny data:write scope access for agents with trust score below 0.5",
"category": "trust",
"priority": 10,
"rules": [
{
"conditions": [
{"field": "trust_score", "op": "lt", "value": 0.5},
{"field": "scope", "op": "eq", "value": "data:write"},
],
"effect": "deny",
"requires_approval": False,
}
],
},
)
policy = response.json()
Authorizations
API key for machine-to-machine authentication
Body
application/json
Human-readable policy name
Maximum string length:
256Array of policy rules
Show child attributes
Show child attributes
Detailed description of the policy
Maximum string length:
2048Policy category
Available options:
scope, trust, rate, custom Evaluation priority (lower = first)
Required range:
1 <= x <= 1000Response
Policy created
UUID primary key
UUID of the owning tenant
Human-readable policy name
Detailed policy description
Policy category
Available options:
scope, trust, rate, custom Policy lifecycle status
Available options:
active, disabled, archived Evaluation priority (lower = first)
Array of policy rules
Show child attributes
Show child attributes

