> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kosli.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get a rego policy

> **Beta** — the Server-side evaluation feature is in beta. Requests from organizations without it enabled receive `403 Forbidden`.



## OpenAPI

````yaml https://app.kosli.com/api/v2/openapi.json get /rego-policies/{org}/{identifier}
openapi: 3.1.0
info:
  title: Kosli API
  summary: The API for communicating with Kosli
  description: >

    # Authentication 


    When making requests against Kosli API, you can authenticate your requests
    using a bearer token. 

    Set the bearer token in the request Authorization header to a valid API
    key. 

    API Keys can be personal or for service accounts. Check the [service
    accounts
    documentation](https://docs.kosli.com/getting_started/service-accounts/) for
    details. 


    ## Curl example


    ```shell

    curl -H "Authorization: Bearer <<your-api-key>>"
    https://app.kosli.com/api/v2/environments/<<your-org-name>>

    ```
  version: '2.0'
servers:
  - url: https://app.kosli.com/api/v2
    description: EU
  - url: https://app.us.kosli.com/api/v2
    description: US
security:
  - HTTPBearer: []
paths:
  /rego-policies/{org}/{identifier}:
    get:
      tags:
        - Rego Policies
      summary: Get a rego policy
      description: >-
        **Beta** — the Server-side evaluation feature is in beta. Requests from
        organizations without it enabled receive `403 Forbidden`.
      operationId: get_rego_policy
      parameters:
        - name: identifier
          in: path
          required: true
          schema:
            type: string
            title: Identifier
        - name: org
          in: path
          required: true
          schema:
            type: string
            title: Org
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RegoPolicyResponse'
        '400':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/fastapi_app__errors__BadRequestResponse___locals___BadRequestResponseModel__10
          description: Bad Request
        '403':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/fastapi_app__errors__ForbiddenResponse___locals___ForbiddenResponseModel__19
          description: Forbidden
        '404':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/fastapi_app__errors__NotFoundResponse___locals___NotFoundResponseModel__58
          description: Not Found
      security:
        - HTTPBearer: []
        - HTTPBasic: []
components:
  schemas:
    RegoPolicyResponse:
      properties:
        identifier:
          type: string
          title: Identifier
          description: Immutable identifier, as first published
        name:
          type: string
          title: Name
          description: Display name
        description:
          anyOf:
            - type: string
            - type: 'null'
          title: Description
          description: Description, if it has one
        newest_version:
          $ref: '#/components/schemas/NewestVersionResponse'
          description: >-
            The newest version whatever its status, which is not necessarily the
            one an evaluation runs
        current_version:
          anyOf:
            - $ref: '#/components/schemas/CurrentVersionResponse'
            - type: 'null'
          description: >-
            The highest-numbered valid version, which is the one an evaluation
            runs; absent until a version has been validated
        created_at:
          type: number
          title: Created At
          description: Unix timestamp the policy was created at
        created_by:
          type: string
          title: Created By
          description: Display name of the user who created it
        updated_at:
          type: number
          title: Updated At
          description: Unix timestamp of the last publish or metadata change
      type: object
      required:
        - identifier
        - name
        - newest_version
        - created_at
        - created_by
        - updated_at
      title: RegoPolicyResponse
    fastapi_app__errors__BadRequestResponse___locals___BadRequestResponseModel__10:
      properties:
        message:
          type: string
          title: Message
          description: Error message
        errors:
          anyOf:
            - additionalProperties:
                type: string
              type: object
            - type: 'null'
          title: Errors
          description: Validation errors by field
      type: object
      required:
        - message
      title: BadRequestResponseModel
      examples:
        - message: Input payload validation failed
    fastapi_app__errors__ForbiddenResponse___locals___ForbiddenResponseModel__19:
      properties:
        message:
          type: string
          title: Message
          description: Error message
        errors:
          anyOf:
            - additionalProperties:
                type: string
              type: object
            - type: 'null'
          title: Errors
          description: Validation errors by field
      type: object
      required:
        - message
      title: ForbiddenResponseModel
      examples:
        - message: You don't have permission to access this resource
    fastapi_app__errors__NotFoundResponse___locals___NotFoundResponseModel__58:
      properties:
        message:
          type: string
          title: Message
          description: Error message
        errors:
          anyOf:
            - additionalProperties:
                type: string
              type: object
            - type: 'null'
          title: Errors
          description: Validation errors by field
      type: object
      required:
        - message
      title: NotFoundResponseModel
      description: Rego policy not found
      examples:
        - message: Rego policy not found
    NewestVersionResponse:
      properties:
        version:
          type: integer
          title: Version
          description: Version number of the newest version
        status:
          type: string
          enum:
            - pending
            - valid
            - rejected
            - failed
          title: Status
          description: Status of the newest version
      type: object
      required:
        - version
        - status
      title: NewestVersionResponse
    CurrentVersionResponse:
      properties:
        version:
          type: integer
          title: Version
          description: Version number of the current version
        digest:
          type: string
          title: Digest
          description: '`sha256:` and the hex digest of the current version''s files'
        input_schema:
          type: string
          enum:
            - trail
            - trails
          title: Input Schema
          description: Shape of the input the current version is written against
        params_schema:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Params Schema
          description: >-
            JSON Schema the current version declares for its params, if it
            declares one
      type: object
      required:
        - version
        - digest
        - input_schema
      title: CurrentVersionResponse
  securitySchemes:
    HTTPBearer:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.