Create policy¶
POST/
Mobile API · Policies
Create policy.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
fields | query | array of string | No | The fields to return in a partial response. |
view | query | string | No | Type of view to be returned in response. Must be one of: basic, summary, full. |
Request body¶
Content type: application/json
Request body fields
namestringrequiredUnique name of the policy.
Must be at most 255 characters long.
Must be at most 255 characters long.
descriptionstringA description of the policy.
Must be at most 500 characters long.
Must be at most 500 characters long.
platformstring (enum)requiredThe device platform, i.e. the operating system.
Must be one of:
Must be one of:
iOS, macOS, android, chrome, windows.typestringrequiredType of the policy.
Must be at most 100 characters long.
Must be at most 100 characters long.
Request samples¶
curl -X POST "https://api-<data-region>.central.sophos.com/mobile/v1/policies" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
\"name\": \"My policy\",
\"description\": \"Some description for the policy\",
\"platform\": \"android\",
\"type\": \"threatDefense\"
}"
import requests
response = requests.post(
"https://api-<data-region>.central.sophos.com/mobile/v1/policies",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
json={ 'name': 'My policy',
'description': 'Some description for the policy',
'platform': 'android',
'type': 'threatDefense'},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
"Content-Type" = "application/json"
}
$body = '{
"name": "My policy",
"description": "Some description for the policy",
"platform": "android",
"type": "threatDefense"
}'
Invoke-RestMethod -Method POST -Uri "https://api-<data-region>.central.sophos.com/mobile/v1/policies" -Headers $headers -Body $body -ContentType "application/json"
package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
req, err := http.NewRequest("POST", "https://api-<data-region>.central.sophos.com/mobile/v1/policies", strings.NewReader(`{
"name": "My policy",
"description": "Some description for the policy",
"platform": "android",
"type": "threatDefense"
}`))
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
req.Header.Set("Content-Type", "application/json")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/mobile/v1/policies", {
method: "POST",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
body: JSON.stringify({
"name": "My policy",
"description": "Some description for the policy",
"platform": "android",
"type": "threatDefense"
}),
});
const data = await response.json();
console.log(data);
Responses¶
201 — The new policy.¶
Response fields
idstring (uuid)requiredID of the policy.
tenantobjectrequiredTenant this resource belongs to.
Show child attributesHide child attributes
idstring (uuid)requirednamestringnamestringUnique name of the policy.
descriptionstringA description of the policy.
platformstring (enum)The device platform, i.e. the operating system.
Must be one of:
Must be one of:
iOS, macOS, android, chrome, windows.typestringType of the policy.
versionstringVersion of the policy.
createdByobjectPrincipal reference.
Show child attributesHide child attributes
idstring (uuid)Principal ID.
typestring (enum)requiredPrincipal type.
Must be one of:
Must be one of:
user, service, system.accountIdstring (uuid)Account ID.
accountTypestring (enum)Account type.
Must be one of:
Must be one of:
partner, tenant, organization.namestringPrincipal name or email.
createdAtstring (date-time)Indicates when the policy was created.
updatedByobjectPrincipal reference.
Show child attributesHide child attributes
idstring (uuid)Principal ID.
typestring (enum)requiredPrincipal type.
Must be one of:
Must be one of:
user, service, system.accountIdstring (uuid)Account ID.
accountTypestring (enum)Account type.
Must be one of:
Must be one of:
partner, tenant, organization.namestringPrincipal name or email.
updatedAtstring (date-time)Indicates when the policy was last updated.
Errors¶
| Status | Meaning |
|---|---|
400 | Invalid request. |
401 | Unauthorized. |
403 | Forbidden. |
404 | Can't find app group. |
409 | Conflict. |
422 | Maximum number of policies exceeded. |
429 | Too many requests. See Retry-After header. |
500 | Internal server error. |
All error responses share the same shape — see the error response object.
See the guide for a narrative walkthrough of this API.