Get a rego policy
curl --request GET \
--url https://app.kosli.com/api/v2/rego-policies/{org}/{identifier} \
--header 'Authorization: Bearer <token>'import requests
url = "https://app.kosli.com/api/v2/rego-policies/{org}/{identifier}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.kosli.com/api/v2/rego-policies/{org}/{identifier}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.kosli.com/api/v2/rego-policies/{org}/{identifier}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.kosli.com/api/v2/rego-policies/{org}/{identifier}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://app.kosli.com/api/v2/rego-policies/{org}/{identifier}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.kosli.com/api/v2/rego-policies/{org}/{identifier}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"identifier": "<string>",
"name": "<string>",
"newest_version": {
"version": 123,
"status": "pending"
},
"created_at": 123,
"created_by": "<string>",
"updated_at": 123,
"description": "<string>",
"current_version": {
"version": 123,
"digest": "<string>",
"input_schema": "trail",
"params_schema": {}
}
}{
"message": "Input payload validation failed"
}{
"message": "You don't have permission to access this resource"
}{
"message": "Rego policy not found"
}Get a rego policy
Beta — the Server-side evaluation feature is in beta. Requests from organizations without it enabled receive 403 Forbidden.
GET
/
rego-policies
/
{org}
/
{identifier}
Get a rego policy
curl --request GET \
--url https://app.kosli.com/api/v2/rego-policies/{org}/{identifier} \
--header 'Authorization: Bearer <token>'import requests
url = "https://app.kosli.com/api/v2/rego-policies/{org}/{identifier}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.kosli.com/api/v2/rego-policies/{org}/{identifier}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.kosli.com/api/v2/rego-policies/{org}/{identifier}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.kosli.com/api/v2/rego-policies/{org}/{identifier}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://app.kosli.com/api/v2/rego-policies/{org}/{identifier}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.kosli.com/api/v2/rego-policies/{org}/{identifier}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"identifier": "<string>",
"name": "<string>",
"newest_version": {
"version": 123,
"status": "pending"
},
"created_at": 123,
"created_by": "<string>",
"updated_at": 123,
"description": "<string>",
"current_version": {
"version": 123,
"digest": "<string>",
"input_schema": "trail",
"params_schema": {}
}
}{
"message": "Input payload validation failed"
}{
"message": "You don't have permission to access this resource"
}{
"message": "Rego policy not found"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Response
Successful Response
Immutable identifier, as first published
Display name
The newest version whatever its status, which is not necessarily the one an evaluation runs
Show child attributes
Show child attributes
Unix timestamp the policy was created at
Display name of the user who created it
Unix timestamp of the last publish or metadata change
Description, if it has one
The highest-numbered valid version, which is the one an evaluation runs; absent until a version has been validated
Show child attributes
Show child attributes
Last modified on October 9, 2026