Ana içeriğe geç

Update AI DLP Preset

Endpoint

PUT /apiops/settings/ai-dlp-presets/{presetName}/

Authentication

Requires a Personal API Access Token with admin privileges.

Authorization: Bearer YOUR_TOKEN

Request

Headers

HeaderValueRequired
AuthorizationBearer {token}Yes
Content-Typeapplication/jsonYes

Path Parameters

ParameterTypeRequiredDescription
presetNamestringYesName of the existing DLP preset. Must match the name in the body (case-insensitive); if name is omitted it defaults to this value.

Query Parameters

ParameterTypeRequiredDefaultDescription
projectIdstringNoadminScope project id. Omit for the admin/global scope.

Request Body

Full JSON Body Example

{
"name": "internal-api-token",
"ruleValue": "ITK-[0-9]{8,12}",
"action": "BLOCK",
"category": "internal",
"description": "Internal service API token (tightened pattern)",
"enabled": true
}

Request Body Fields

FieldTypeRequiredDefaultDescription
namestringNopath valuePreset name. Must equal presetName (case-insensitive); defaults to the path value when omitted.
ruleValuestringYes-Java regex pattern used to detect the secret/credential. Must compile — an invalid regex is rejected.
actionstringYes-Action applied on match: BLOCK, FLAG, or MASK. DLP is the only preset family where all three are valid.
categorystringNo-Optional category label (e.g. aws, openai, github, pem, slack, google, jwt, generic)
descriptionstringNo-Optional description for UI display
enabledbooleanNo-Whether the preset is active

Notes

  • The preset must already exist in the scope; otherwise a not found error is returned
  • The request body must not be empty
  • name in the body must match presetName in the path (case-insensitive)
  • ruleValue must be a valid Java regular expression; an uncompilable pattern is rejected before the update is saved
  • The preset's projectId (scope) is immutable on update
  • builtIn and id are server-controlled and ignored on write

Response

Success Response (200 OK)

{
"status": "SUCCESS",
"deploymentResult": {
"success": true
}
}

Response Fields

FieldTypeDescription
statusstringResponse status: SUCCESS or FAILURE
deploymentResultobjectDeployment result summary
deploymentResult.successbooleantrue when the preset was updated successfully

Error Response (400 Bad Request)

Returned when the preset is not found, on validation/name-mismatch failure, on a built-in preset, or when the caller lacks the ADMIN role.

{
"status": "FAILURE",
"resultMessage": "AI DLP preset (name: internal-api-token) was not found!"
}

Other possible messages:

{
"status": "FAILURE",
"resultMessage": "AI DLP preset name in path (internal-api-token) does not match name in body (other-name)!"
}
{
"status": "FAILURE",
"resultMessage": "Built-in presets are read-only"
}
{
"status": "FAILURE",
"resultMessage": "ruleValue is required"
}
{
"status": "FAILURE",
"resultMessage": "ruleValue is not a valid regular expression: Unclosed character class near index 5\n[0-9"
}

Error Response (401 Unauthorized)

{
"status": "FAILURE",
"resultMessage": "Token is not valid!"
}

cURL Example

curl -X PUT \
"https://demo.apinizer.com/apiops/settings/ai-dlp-presets/internal-api-token/" \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "internal-api-token",
"ruleValue": "ITK-[0-9]{8,12}",
"action": "BLOCK",
"category": "internal",
"description": "Internal service API token (tightened pattern)",
"enabled": true
}'

Notes and Warnings

  • Admin Only:
    • Only sysAdmin users (or users with the ADMIN role) can update AI DLP presets
    • A project-scoped AI_DEVELOPMENT token is not sufficient
  • Must Exist:
    • The preset must already exist in the scope; to create one, use the create (POST) endpoint
  • Built-in Presets Are Read-only:
    • Updating a built-in (seeded) preset is rejected with a Built-in presets are read-only error
  • Full Replacement:
    • Update applies the full field surface from the body onto the existing preset
  • Regex Pattern:
    • ruleValue is a Java regex; remember to escape backslashes in JSON
    • An uncompilable pattern is rejected at save time
  • No Secret Fields:
    • ruleValue is a detection regex pattern, not a credential itself — DLP presets carry no secret (@SecretData) fields, so no values are masked