Ana içeriğe geç

Create AI Privacy Preset

Endpoint

POST /apiops/settings/ai-privacy-presets/{presetName}/

Authentication

Requires a Personal API Access Token with admin privileges.

Authorization: Bearer YOUR_TOKEN

Request

Headers

HeaderValueRequired
AuthorizationBearer {token}Yes
Content-Typeapplication/jsonYes

Path Parameters

ParameterTypeRequiredDescription
presetNamestringYesName of the privacy preset. Must match the name in the body (case-insensitive); if name is omitted from the body it defaults to this value.

Query Parameters

ParameterTypeRequiredDefaultDescription
projectIdstringNoadminScope project id. Omit for the admin/global scope.

Request Body

Full JSON Body Example

{
"name": "internal-account-id",
"patternType": "REGEX",
"regexPattern": "ACC-[0-9]{8}",
"operation": "MASK",
"enabled": true
}

Full JSON Body Example - Partial Mask

{
"name": "customer-phone",
"patternType": "REGEX",
"regexPattern": "(?<!\\d)0\\d{10}(?!\\d)",
"operation": "MASK",
"maskMode": "KEEP_LAST",
"maskPattern": "*",
"maskVisibleCharCount": 4,
"enabled": true
}

Masks 05321234567 as *******4567.

Request Body Fields

FieldTypeRequiredDefaultDescription
namestringNopath valuePreset name. Must equal presetName (case-insensitive); defaults to the path value when omitted.
patternTypestringYes-Match pattern type: ELEMENT_NAME or REGEX. BUILTIN is rejected — see Notes.
regexPatternstringConditional-Custom regex pattern (Java java.util.regex syntax). Required when patternType = REGEX.
elementNamestringNo-Header/param/body field name to match when patternType = ELEMENT_NAME
operationstringYes-Action applied on match: MASK, DELETE, ENCRYPT, HASH, DETECT
maskModestringNoFIXEDMask shape when operation = MASK: FIXED, KEEP_FIRST, KEEP_LAST, MASK_FIRST
maskPatternstringNo***With FIXED, the full replacement text. With the partial shapes, its first character is used as the mask character (default *).
maskVisibleCharCountintegerNo4Number of characters kept (or masked, with MASK_FIRST) in the partial shapes
enabledbooleanNo-Whether the preset is active

Notes

  • The request body must not be empty
  • name in the body must match presetName in the path (case-insensitive)
  • When a preset with this name already exists in the scope — including a built-in (builtIn: true) row — it is updated rather than duplicated; the call is safe to repeat from a CI/CD pipeline
  • builtIn is server-controlled and ignored on write — it is always derived from the persisted record, so you cannot forge a new row as built-in via the API
  • patternType = BUILTIN is no longer accepted in this catalog and returns 400 with error key patterntypebuiltinunsupported. Existing BUILTIN presets were converted to REGEX on upgrade, with the equivalent built-in pattern written into regexPattern, so every rule is expressed by a visible, editable pattern. Note the behavioural difference: the old BUILTIN path also ran a semantic check after the regex matched (national-ID checksum, IBAN mod-97, card Luhn); the REGEX path does not, so the deliberately broad patterns may produce more false positives — narrow the pattern if that matters.
  • An invalid regexPattern is rejected at write time with error key regexpatterninvalid. A pattern that compiles but fails the runtime ReDoS guard is accepted here yet skipped at request time — validate it with the PII Patterns test panel in the UI before relying on it.
  • id is server-controlled and ignored on write

Response

Success Response (200 OK)

{
"status": "SUCCESS",
"deploymentResult": {
"success": true
}
}

Response Fields

FieldTypeDescription
statusstringResponse status: SUCCESS or FAILURE
deploymentResultobjectDeployment result summary
deploymentResult.successbooleantrue when the preset was saved successfully

Error Response (400 Bad Request)

Returned on validation failure, name mismatch, or when the caller lacks the ADMIN role.

{
"status": "FAILURE",
"resultMessage": "AI privacy preset name in path (internal-account-id) does not match name in body (other-name)!"
}

Other possible messages:

{
"status": "FAILURE",
"resultMessage": "AI privacy preset body can not be empty!"
}

Error Response (401 Unauthorized)

{
"status": "FAILURE",
"resultMessage": "Token is not valid!"
}

cURL Example

curl -X POST \
"https://demo.apinizer.com/apiops/settings/ai-privacy-presets/internal-account-id/" \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "internal-account-id",
"patternType": "REGEX",
"regexPattern": "ACC-[0-9]{8}",
"operation": "MASK",
"enabled": true
}'

Notes and Warnings

  • Admin Only:
    • Only sysAdmin users (or users with the ADMIN role) can create AI privacy presets
    • A project-scoped AI_DEVELOPMENT token is not sufficient
  • Upsert by Name:
    • If a preset with the same name already exists in the scope — this includes a built-in (builtIn: true) row, which is not read-only on this endpoint — this call updates it
    • Otherwise a new custom preset is created
  • Name Consistency:
    • The name in the body must match presetName in the path (case-insensitive)
  • No Secret Fields:
    • Privacy presets carry no secret (@SecretData) fields, so no values are masked