Ana içeriğe geç

Create AI DLP Preset

Endpoint

POST /apiops/settings/ai-dlp-presets/{presetName}/

Authentication

Requires a Personal API Access Token with admin privileges.

Authorization: Bearer YOUR_TOKEN

Request

Headers

HeaderValueRequired
AuthorizationBearer {token}Yes
Content-Typeapplication/jsonYes

Path Parameters

ParameterTypeRequiredDescription
presetNamestringYesName of the DLP preset. Must match the name in the body (case-insensitive); if name is omitted from the body it defaults to this value.

Query Parameters

ParameterTypeRequiredDefaultDescription
projectIdstringNoadminScope project id. Omit for the admin/global scope.

Request Body

Full JSON Body Example

{
"name": "internal-api-token",
"ruleValue": "ITK-[0-9]{10}",
"action": "MASK",
"category": "internal",
"description": "Internal service API token",
"enabled": true
}

Request Body Fields

FieldTypeRequiredDefaultDescription
namestringNopath valuePreset name. Must equal presetName (case-insensitive); defaults to the path value when omitted.
ruleValuestringYes-Java regex pattern used to detect the secret/credential. Must compile — an invalid regex is rejected.
literalAnchorsarray[string]NonullLiteral substrings used as a fast pre-filter before the regex runs. Each anchor must appear verbatim (case-insensitively) in every possible match of ruleValue — this is validated on save and an inconsistent anchor is rejected. Omit the field when in doubt: a rule with no anchors is always scanned. See the note below.
actionstringYes-Action applied on match: BLOCK, FLAG, or MASK. DLP is the only preset family where all three are valid.
categorystringNo-Optional category label (e.g. aws, openai, github, pem, slack, google, jwt, generic)
descriptionstringNo-Optional description for UI display
enabledbooleanNo-Whether the preset is active
literalAnchors — a wrong anchor silently disables the rule

Anchors exist purely as a performance pre-filter: the gateway runs one multi-pattern scan over the text and only evaluates the regex of rules whose anchors were found. That means an anchor which is not guaranteed to appear in a match causes the rule to be skipped entirely — the regex never runs, and a BLOCK rule silently stops blocking. The gateway cannot detect this on its own.

Example of a wrong anchor: rule (?i)api[-_]?key\s*[:=]\s*\S+ with literalAnchors: ["API_KEY"]. The text api-key: sk-live-... matches the regex but does not contain the literal API_KEY, so the rule is skipped and the secret passes through.

Save-time validation extracts the literal runs of ruleValue (for the pattern above: api, key) and rejects any anchor that is not a substring of one of them. The check is deliberately conservative — if a legitimate anchor is rejected, remove it rather than working around the check. An anchor-less rule is never skipped, only slower.

This applies to every write path: this API, the AI DLP Guard policy body, and package import.

Notes

  • The request body must not be empty
  • name in the body must match presetName in the path (case-insensitive)
  • ruleValue must be a valid Java regular expression; an uncompilable pattern is rejected before the preset is saved
  • When a preset with this name already exists in the scope — including a built-in (builtIn: true) row — it is updated rather than duplicated; the call is safe to repeat from a CI/CD pipeline
  • builtIn is server-controlled and ignored on write — you cannot forge a new row as built-in via the API; it is always derived from the persisted record
  • id is server-controlled and ignored on write

Response

Success Response (200 OK)

{
"status": "SUCCESS",
"deploymentResult": {
"success": true
}
}

Response Fields

FieldTypeDescription
statusstringResponse status: SUCCESS or FAILURE
deploymentResultobjectDeployment result summary
deploymentResult.successbooleantrue when the preset was saved successfully

Error Response (400 Bad Request)

Returned on validation failure, name mismatch, or when the caller lacks the ADMIN role.

{
"status": "FAILURE",
"resultMessage": "AI DLP preset name in path (internal-api-token) does not match name in body (other-name)!"
}

Other possible messages:

{
"status": "FAILURE",
"resultMessage": "AI DLP preset body can not be empty!"
}
{
"status": "FAILURE",
"resultMessage": "ruleValue is required"
}
{
"status": "FAILURE",
"resultMessage": "ruleValue is not a valid regular expression: Unclosed character class near index 5\n[0-9"
}
{
"status": "FAILURE",
"resultMessage": "A preset with this name already exists in the visible scope (built-in, admin-shared, or this project)"
}

Error Response (401 Unauthorized)

{
"status": "FAILURE",
"resultMessage": "Token is not valid!"
}

cURL Example

curl -X POST \
"https://demo.apinizer.com/apiops/settings/ai-dlp-presets/internal-api-token/" \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "internal-api-token",
"ruleValue": "ITK-[0-9]{10}",
"action": "MASK",
"category": "internal",
"description": "Internal service API token",
"enabled": true
}'

Notes and Warnings

  • Admin Only:
    • Only sysAdmin users (or users with the ADMIN role) can create AI DLP presets
    • A project-scoped AI_DEVELOPMENT token is not sufficient
  • Upsert by Name:
    • If a preset with the same name already exists in the scope — this includes a built-in (builtIn: true) row, which is not read-only on this endpoint — this call updates it
    • Otherwise a new custom preset is created
  • Overriding a Built-in Row:
    • Upserting onto an existing built-in row flags it overridden: true in storage — the next platform upgrade's rule-pack refresh then skips it instead of overwriting your edit. See Built-in Presets Are Editable on the resource overview page.
  • Regex Pattern:
    • ruleValue is a Java regex; remember to escape backslashes in JSON (e.g. \\b for a word boundary)
    • An uncompilable pattern is rejected at save time, before it can be copied into a PolicyAiDlpGuard definition list
  • All Three Actions Valid:
    • Unlike prompt-guard/privacy presets, DLP presets accept BLOCK, FLAG and MASKMASK is DLP's own domain (secret/credential redaction)
  • Name Consistency:
    • The name in the body must match presetName in the path (case-insensitive)
  • No Secret Fields:
    • ruleValue is a detection regex pattern, not a credential itself — DLP presets carry no secret (@SecretData) fields, so no values are masked