Skip to main content
POST
Validate policy

Authorizations

Authorization
string
header
required

MeshQu API key passed as a bearer token: Authorization: Bearer mqu_…. Mint one in the console (Settings → API keys).

X-MeshQu-Tenant-Id
string
header
required

Tenant UUID for multi-tenant isolation. Required on all authenticated routes — validated before authentication (middleware/tenant.ts), so a missing or non-UUID header returns 400 (MISSING_TENANT_ID / INVALID_TENANT_ID) before the API key is checked.

Body

application/json
decision_type
string
required
Minimum string length: 1
rules
object[]
required
Minimum array length: 1

Response

200 - application/json

Default Response

valid
boolean
required
errors
object[]
required
warnings
object[]
required