AI Privacy Presets API
Endpoints
- List AI Privacy Presets - List built-in and custom privacy presets
- Get AI Privacy Preset - Get a single privacy preset by name
- Create AI Privacy Preset - Create a preset, or update one (built-in or custom) with the same name (upsert)
- Update AI Privacy Preset - Update an existing preset, built-in or custom
- Delete AI Privacy Preset - Delete a preset, built-in or custom
Authentication
All endpoints require authentication using a Personal API Access Token.
Permissions
- Admin Only - All endpoints require admin privileges (sysAdmin user or a user with the
ADMINrole). Presets are a platform-level catalog; a project-scopedAI_DEVELOPMENTtoken is not sufficient.
Project-Scoped Surface
Besides the admin/global endpoints above (/apiops/settings/ai-privacy-presets/...), the same privacy preset family is also exposed under a project-scoped path, so a project's own AI_DEVELOPMENT token can read the effective preset catalog and manage its own custom presets without needing platform ADMIN privileges:
GET /apiops/projects/{projectName}/ai-privacy-presets/
GET /apiops/projects/{projectName}/ai-privacy-presets/{presetName}/
POST /apiops/projects/{projectName}/ai-privacy-presets/{presetName}/
PUT /apiops/projects/{projectName}/ai-privacy-presets/{presetName}/
DELETE /apiops/projects/{projectName}/ai-privacy-presets/{presetName}/
Same 5-endpoint shape, request/response bodies and field surface as the admin endpoints documented on this page — only the base path, scope resolution and permission differ:
Admin surface (/apiops/settings/...) | Project surface (/apiops/projects/{projectName}/...) | |
|---|---|---|
| Scope resolution | Optional ?projectId= query parameter (default admin/global scope) | {projectName} path segment, resolved to the caller's own project — never a query parameter |
| Permission | System admin (sysAdmin user or ADMIN role) | AI_DEVELOPMENT + VIEW (read) / MANAGE (write) in the project |
| Read visibility | Presets in the resolved scope only | Union of built-in presets ∪ admin-shared custom presets ∪ this project's own custom presets |
| Write visibility | Any preset in the resolved scope, including built-in | Only presets this project owns. A name that only resolves to a built-in or admin-shared preset is treated as not existing for this project: POST creates a new project-owned preset (and fails on the name collision), while PUT/DELETE report the preset as not found |
The admin ?projectId= surface is unchanged by this addition and stays fully backward compatible; its permission requirement is not widened.
Built-in Presets Are Editable
A seeded preset (builtIn: true) is not read-only: PUT and DELETE on this surface accept it the same as a custom preset, gated by the same admin permission every endpoint here requires. Deleting one is permanent — Mongock deduplicates seed changesets by id and none of them are runAlways=true, so a deleted built-in preset does not reappear on a version upgrade; it returns only if a future release ships an explicit re-seed changeset.
Related Documentation
- Authentication Guide - How to obtain and use API tokens
- Error Handling - Error response formats
- AI Prompt-Guard Presets API - Manage AI prompt-guard presets
- AI DLP Presets API - Manage AI DLP (secret/credential) presets
- AI Gateway Settings API - Global AI Gateway settings