Ana içeriğe geç

List AI DLP Presets

Endpoint

GET /apiops/settings/ai-dlp-presets/

Authentication

Requires a Personal API Access Token with admin privileges.

Authorization: Bearer YOUR_TOKEN

Request

Headers

HeaderValueRequired
AuthorizationBearer {token}Yes

Path Parameters

None.

Query Parameters

ParameterTypeRequiredDefaultDescription
projectIdstringNoadminScope project id. Omit for the admin/global scope, where built-in and admin-owned presets live.

Response

Success Response (200 OK)

{
"status": "SUCCESS",
"resultList": [
{
"id": "665f2a1c9b3e4a0012ab5501",
"projectId": "admin",
"name": "BUILTIN_DLP_AWS_ACCESS_KEY",
"ruleValue": "\\bAKIA[0-9A-Z]{16}\\b",
"action": "BLOCK",
"category": "aws",
"description": "AWS access key id (AKIA...)",
"enabled": true,
"builtIn": true,
"overridden": false
},
{
"id": "665f2a1c9b3e4a0012ab5507",
"projectId": "admin",
"name": "BUILTIN_DLP_JWT",
"ruleValue": "\\beyJ[A-Za-z0-9_-]+\\.[A-Za-z0-9_-]+\\.[A-Za-z0-9_-]+\\b",
"action": "MASK",
"category": "jwt",
"description": "JSON Web Token (eyJ...header.payload.signature)",
"enabled": true,
"builtIn": true,
"overridden": true
},
{
"id": "665f2a1c9b3e4a0012ab99aa",
"projectId": "admin",
"name": "internal-api-token",
"ruleValue": "ITK-[0-9]{10}",
"action": "MASK",
"category": "internal",
"description": "Internal service API token",
"enabled": true,
"builtIn": false
}
],
"resultCount": 3
}

Response Fields

FieldTypeDescription
statusstringResponse status: SUCCESS or FAILURE
resultListarrayList of DLP preset objects
resultCountintegerTotal number of presets returned

DLP Preset Object Fields

FieldTypeDescription
idstringServer-assigned identifier (read-only)
projectIdstringScope the preset belongs to (admin for global)
namestringUnique preset name (e.g. BUILTIN_DLP_AWS_ACCESS_KEY for seeded rows, free-form for custom)
ruleValuestringJava regex pattern used to detect the secret/credential
literalAnchorsarray[string]Literal substrings used as a fast pre-filter before the regex runs; null when the rule has none (never skipped). Each anchor is guaranteed to appear verbatim in every match — validated on save. See the note below.
actionstringAction applied on match: BLOCK, FLAG, or MASK. DLP is the only preset family where all three are valid — MASK redacts the matched region instead of blocking or just logging
categorystringOptional category label (e.g. aws, openai, github, pem, slack, google, jwt, generic)
descriptionstringOptional description for UI display
enabledbooleanWhether the preset is active
builtInbooleantrue for Mongock-seeded rows, false for user-created — the field itself is server-owned, but the row is not otherwise read-only
overriddenbooleanResponse-only. true when an admin has edited this built-in row — the versioned rule-pack loader then skips it on every future pack refresh instead of overwriting the edit. Always false/absent for custom rows. See Built-in Presets Are Editable.
literalAnchors — a wrong anchor silently disables the rule

Anchors exist purely as a performance pre-filter: the gateway runs one multi-pattern scan over the text and only evaluates the regex of rules whose anchors were found. That means an anchor which is not guaranteed to appear in a match causes the rule to be skipped entirely — the regex never runs, and a BLOCK rule silently stops blocking. The gateway cannot detect this on its own.

Example of a wrong anchor: rule (?i)api[-_]?key\s*[:=]\s*\S+ with literalAnchors: ["API_KEY"]. The text api-key: sk-live-... matches the regex but does not contain the literal API_KEY, so the rule is skipped and the secret passes through.

Save-time validation extracts the literal runs of ruleValue (for the pattern above: api, key) and rejects any anchor that is not a substring of one of them. The check is deliberately conservative — if a legitimate anchor is rejected, remove it rather than working around the check. An anchor-less rule is never skipped, only slower.

This applies to every write path: this API, the AI DLP Guard policy body, and package import.

EnumStatus

  • SUCCESS - Operation successful
  • FAILURE - Operation failed

Error Response (400 Bad Request)

Returned when the caller is authenticated but lacks the ADMIN role.

{
"status": "FAILURE",
"resultMessage": "Unauthorized! Only users with ADMIN role can manage AI presets!"
}

Error Response (401 Unauthorized)

{
"status": "FAILURE",
"resultMessage": "Token is not valid!"
}

cURL Example

Default (admin/global scope)

curl -X GET \
"https://demo.apinizer.com/apiops/settings/ai-dlp-presets/" \
-H "Authorization: Bearer YOUR_TOKEN"

Scoped to a project

curl -X GET \
"https://demo.apinizer.com/apiops/settings/ai-dlp-presets/?projectId=MyProject" \
-H "Authorization: Bearer YOUR_TOKEN"

Notes and Warnings

  • Admin Only:
    • Only sysAdmin users (or users with the ADMIN role) can list AI DLP presets
    • A project-scoped AI_DEVELOPMENT token is not sufficient
  • Built-in Presets:
    • Rows with builtIn: true come from the seeded secret/credential catalog (8 patterns: AWS access key, OpenAI key, GitHub token, PEM private key, Slack token and Google API key — all BLOCK; JWT and a generic password/secret/api_key assignment — both MASK). They are editable and deletable like any other row; an edited one is flagged overridden: true so it survives future rule-pack refreshes unchanged.
  • Scope:
    • The default scope is admin/global; pass projectId to list presets for a specific project
  • No Secret Fields:
    • ruleValue is a detection regex pattern, not a credential itself — DLP presets carry no secret (@SecretData) fields, so no values are masked