Docs / Native API

Governance policies

CRUD for api_key-scoped policies that gate pipeline modules (cache, RAG, compression, PII). All routes live under /api/v1/sdk and authenticate with your TokenSaver API key.

GET/api/v1/sdk/governance/policies

GET/api/v1/sdk/governance/policies/{id}

POST/api/v1/sdk/governance/policies

PATCH/api/v1/sdk/governance/policies/{id}

DELETE/api/v1/sdk/governance/policies/{id}

Policy kinds

kind Scope Purpose
cache api_key only Exact + semantic LLM response cache
rag api_key only Workspace knowledge retrieval
compression api_key only Context compression (incl. RAG budget)
pii api_key, workspace, org PII detection / masking
prompt_injection api_key Reserved — future guardrail
decorator api_key Reserved — future guardrail

MCP/SDK create policies at scope=api_key only. Org/workspace policies appear in inherited on list (read-only here).

List policies

curl -sS "https://api.tokensaver.fr/api/v1/sdk/governance/policies" \
  -H "Authorization: Bearer $TS_KEY"

# Filter by kind
curl -sS "https://api.tokensaver.fr/api/v1/sdk/governance/policies?kind=cache" \
  -H "Authorization: Bearer $TS_KEY"

Response includes items (editable api_key policies), inherited (org/workspace), effective_gates, and pii_disable_hint when PII stays active via inheritance.

Create policy

curl -sS -X POST "https://api.tokensaver.fr/api/v1/sdk/governance/policies" \
  -H "Authorization: Bearer $TS_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Production cache",
    "kind": "cache",
    "enabled": true,
    "priority": 100,
    "config": {
      "exact_cache": true,
      "semantic_cache": true,
      "similarity_threshold": 0.85
    }
  }'

Body fields: name (required), kind (default pii), config (object, validated per kind), enabled (default true), priority (0–10000, default 100). Returns 201 with the shaped policy; may include pipeline_settings_sync.

Config schemas (module kinds)

kind config keys (high level)
cache exact_cache, semantic_cache, similarity_threshold, ttl_seconds, embedding_compute, embedding_model, message_countback, ignore_* prompt flags
rag similarity_threshold, top_k, embedding_compute, embedding_model
compression level (1–5), rag_token_budget
pii disabled_entity_types, ignore_terms, custom_patterns

Update & delete

# Partial update (any of name, config, enabled, priority)
curl -sS -X PATCH "https://api.tokensaver.fr/api/v1/sdk/governance/policies/<POLICY_UUID>" \
  -H "Authorization: Bearer $TS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"enabled": false}'

# Delete (204 No Content)
curl -sS -X DELETE "https://api.tokensaver.fr/api/v1/sdk/governance/policies/<POLICY_UUID>" \
  -H "Authorization: Bearer $TS_KEY"

Errors

  • 400 — invalid kind query or scope/kind mismatch
  • 404 — policy not found or not owned by this API key
  • 422 — invalid config for the policy kind

Python SDK wrappers: sdk/python/governance. Plan entitlements are enforced client-side in the SDK (validate_plan=True); HTTP callers should check plan_features on pipeline-settings first.