curl --request PATCH \
--url https://api.meshqu.com/v1/policies/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'X-MeshQu-Tenant-Id: <api-key>' \
--data '
{
"name": "<string>",
"description": "<string>",
"is_active": true,
"shadow_mode": true,
"policy_group_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"regulatory_refs": [
"<string>"
]
}
'import requests
url = "https://api.meshqu.com/v1/policies/{id}"
payload = {
"name": "<string>",
"description": "<string>",
"is_active": True,
"shadow_mode": True,
"policy_group_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"regulatory_refs": ["<string>"]
}
headers = {
"Authorization": "Bearer <token>",
"X-MeshQu-Tenant-Id": "<api-key>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {
Authorization: 'Bearer <token>',
'X-MeshQu-Tenant-Id': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: '<string>',
description: '<string>',
is_active: true,
shadow_mode: true,
policy_group_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
regulatory_refs: ['<string>']
})
};
fetch('https://api.meshqu.com/v1/policies/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.meshqu.com/v1/policies/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'description' => '<string>',
'is_active' => true,
'shadow_mode' => true,
'policy_group_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'regulatory_refs' => [
'<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"X-MeshQu-Tenant-Id: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.meshqu.com/v1/policies/{id}"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"description\": \"<string>\",\n \"is_active\": true,\n \"shadow_mode\": true,\n \"policy_group_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"regulatory_refs\": [\n \"<string>\"\n ]\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("X-MeshQu-Tenant-Id", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.meshqu.com/v1/policies/{id}")
.header("Authorization", "Bearer <token>")
.header("X-MeshQu-Tenant-Id", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"description\": \"<string>\",\n \"is_active\": true,\n \"shadow_mode\": true,\n \"policy_group_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"regulatory_refs\": [\n \"<string>\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.meshqu.com/v1/policies/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["X-MeshQu-Tenant-Id"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"description\": \"<string>\",\n \"is_active\": true,\n \"shadow_mode\": true,\n \"policy_group_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"regulatory_refs\": [\n \"<string>\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"tenant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"code": "<string>",
"name": "<string>",
"description": "<string>",
"decision_type": "<string>",
"current_version": 123,
"is_active": true,
"shadow_mode": true,
"policy_group_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"created_by": "<string>",
"updated_at": "2023-11-07T05:31:56Z",
"regulatory_refs": [
"<string>"
],
"regulatory_refs_warnings": [
{
"ref": "<string>",
"reason": "unknown_clause_id"
}
],
"version": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"policy_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"version": 123,
"rules": [
{
"code": "<string>",
"name": "<string>",
"rule_type": "presence",
"condition": {
"required_fields": [
"<string>"
],
"forbidden_fields": [
"<string>"
],
"min_length": {}
},
"severity": "low",
"description": "<string>",
"is_active": true,
"when": {
"field": "<string>",
"equals": "<string>"
},
"source_ref": {
"document": "<string>",
"section": "<string>",
"url": "<string>"
},
"replaces_rule_code": "<string>"
}
],
"is_active": true,
"status": "draft",
"created_at": "2023-11-07T05:31:56Z",
"created_by": "<string>",
"change_reason": "<string>",
"ratified_by": "<string>",
"ratified_at": "2023-11-07T05:31:56Z",
"submitted_by": "<string>",
"submitted_at": "2023-11-07T05:31:56Z",
"rejected_by": "<string>",
"rejected_at": "2023-11-07T05:31:56Z",
"rejection_reason": "<string>"
},
"versionState": "active",
"selectedVersion": 123,
"permissions": {
"canEdit": true,
"canSubmit": true,
"canApprove": true,
"canReject": true,
"canDiscard": true,
"canRestore": true,
"canCompare": true
},
"actions": [
{
"kind": "start_editing",
"label": "<string>",
"disabledReason": "<string>"
}
]
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
},
"correlation_id": "<string>"
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
},
"correlation_id": "<string>"
}Update policy
Updates policy metadata. To update rules, create a new version.
curl --request PATCH \
--url https://api.meshqu.com/v1/policies/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'X-MeshQu-Tenant-Id: <api-key>' \
--data '
{
"name": "<string>",
"description": "<string>",
"is_active": true,
"shadow_mode": true,
"policy_group_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"regulatory_refs": [
"<string>"
]
}
'import requests
url = "https://api.meshqu.com/v1/policies/{id}"
payload = {
"name": "<string>",
"description": "<string>",
"is_active": True,
"shadow_mode": True,
"policy_group_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"regulatory_refs": ["<string>"]
}
headers = {
"Authorization": "Bearer <token>",
"X-MeshQu-Tenant-Id": "<api-key>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {
Authorization: 'Bearer <token>',
'X-MeshQu-Tenant-Id': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: '<string>',
description: '<string>',
is_active: true,
shadow_mode: true,
policy_group_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
regulatory_refs: ['<string>']
})
};
fetch('https://api.meshqu.com/v1/policies/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.meshqu.com/v1/policies/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'name' => '<string>',
'description' => '<string>',
'is_active' => true,
'shadow_mode' => true,
'policy_group_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'regulatory_refs' => [
'<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"X-MeshQu-Tenant-Id: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.meshqu.com/v1/policies/{id}"
payload := strings.NewReader("{\n \"name\": \"<string>\",\n \"description\": \"<string>\",\n \"is_active\": true,\n \"shadow_mode\": true,\n \"policy_group_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"regulatory_refs\": [\n \"<string>\"\n ]\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("X-MeshQu-Tenant-Id", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.meshqu.com/v1/policies/{id}")
.header("Authorization", "Bearer <token>")
.header("X-MeshQu-Tenant-Id", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"<string>\",\n \"description\": \"<string>\",\n \"is_active\": true,\n \"shadow_mode\": true,\n \"policy_group_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"regulatory_refs\": [\n \"<string>\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.meshqu.com/v1/policies/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["X-MeshQu-Tenant-Id"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"<string>\",\n \"description\": \"<string>\",\n \"is_active\": true,\n \"shadow_mode\": true,\n \"policy_group_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"regulatory_refs\": [\n \"<string>\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"tenant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"code": "<string>",
"name": "<string>",
"description": "<string>",
"decision_type": "<string>",
"current_version": 123,
"is_active": true,
"shadow_mode": true,
"policy_group_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"created_at": "2023-11-07T05:31:56Z",
"created_by": "<string>",
"updated_at": "2023-11-07T05:31:56Z",
"regulatory_refs": [
"<string>"
],
"regulatory_refs_warnings": [
{
"ref": "<string>",
"reason": "unknown_clause_id"
}
],
"version": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"policy_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"version": 123,
"rules": [
{
"code": "<string>",
"name": "<string>",
"rule_type": "presence",
"condition": {
"required_fields": [
"<string>"
],
"forbidden_fields": [
"<string>"
],
"min_length": {}
},
"severity": "low",
"description": "<string>",
"is_active": true,
"when": {
"field": "<string>",
"equals": "<string>"
},
"source_ref": {
"document": "<string>",
"section": "<string>",
"url": "<string>"
},
"replaces_rule_code": "<string>"
}
],
"is_active": true,
"status": "draft",
"created_at": "2023-11-07T05:31:56Z",
"created_by": "<string>",
"change_reason": "<string>",
"ratified_by": "<string>",
"ratified_at": "2023-11-07T05:31:56Z",
"submitted_by": "<string>",
"submitted_at": "2023-11-07T05:31:56Z",
"rejected_by": "<string>",
"rejected_at": "2023-11-07T05:31:56Z",
"rejection_reason": "<string>"
},
"versionState": "active",
"selectedVersion": 123,
"permissions": {
"canEdit": true,
"canSubmit": true,
"canApprove": true,
"canReject": true,
"canDiscard": true,
"canRestore": true,
"canCompare": true
},
"actions": [
{
"kind": "start_editing",
"label": "<string>",
"disabledReason": "<string>"
}
]
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
},
"correlation_id": "<string>"
}{
"error": {
"code": "<string>",
"message": "<string>",
"details": "<unknown>"
},
"correlation_id": "<string>"
}Authorizations
MeshQu API key passed as a bearer token: Authorization: Bearer mqu_…. Mint one in the console (Settings → API keys).
Tenant UUID for multi-tenant isolation. Required on all authenticated routes — validated before authentication (middleware/tenant.ts), so a missing or non-UUID header returns 400 (MISSING_TENANT_ID / INVALID_TENANT_ID) before the API key is checked.
Path Parameters
Body
1 - 2002000When true, violations are logged but DENY becomes ALERT. Enables A/B testing.
Assign to a policy group (null to remove from group)
Regulatory references (null to clear)
50200Response
Default Response
When true, violations are logged but DENY becomes ALERT
Policy group this policy belongs to
Regulatory references this policy implements
Warnings for regulatory_refs entries not found in the clause registry. Informational only — the save proceeded.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Lifecycle state of the selected version. "submitted" is reserved for PV2-020; today the server only emits active | draft | historical.
active Convenience permission flags. Clients MUST use actions[] as the source of truth for availability; permissions are for disable-state/tooltip hints only.
Show child attributes
Show child attributes
Show child attributes
Show child attributes