> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kosli.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Publish a version of a rego policy

> **Beta** — the Server-side evaluation feature is in beta. Requests from organizations without it enabled receive `403 Forbidden`.



## OpenAPI

````yaml https://app.kosli.com/api/v2/openapi.json put /rego-policies/{org}/{identifier}
openapi: 3.1.0
info:
  title: Kosli API
  summary: The API for communicating with Kosli
  description: >

    # Authentication 


    When making requests against Kosli API, you can authenticate your requests
    using a bearer token. 

    Set the bearer token in the request Authorization header to a valid API
    key. 

    API Keys can be personal or for service accounts. Check the [service
    accounts
    documentation](https://docs.kosli.com/getting_started/service-accounts/) for
    details. 


    ## Curl example


    ```shell

    curl -H "Authorization: Bearer <<your-api-key>>"
    https://app.kosli.com/api/v2/environments/<<your-org-name>>

    ```
  version: '2.0'
servers:
  - url: https://app.kosli.com/api/v2
    description: EU
  - url: https://app.us.kosli.com/api/v2
    description: US
security:
  - HTTPBearer: []
paths:
  /rego-policies/{org}/{identifier}:
    put:
      tags:
        - Rego Policies
      summary: Publish a version of a rego policy
      description: >-
        **Beta** — the Server-side evaluation feature is in beta. Requests from
        organizations without it enabled receive `403 Forbidden`.
      operationId: publish_rego_policy
      parameters:
        - name: identifier
          in: path
          required: true
          schema:
            type: string
            title: Identifier
        - name: org
          in: path
          required: true
          schema:
            type: string
            title: Org
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RegoPolicyPutInput'
      responses:
        '202':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RegoPolicyVersionResponse'
        '400':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/fastapi_app__errors__BadRequestResponse___locals___BadRequestResponseModel__11
          description: Bad Request
        '403':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/fastapi_app__errors__ForbiddenResponse___locals___ForbiddenResponseModel__21
          description: Forbidden
        '413':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/fastapi_app__errors__RequestEntityTooLargeResponse___locals___RequestEntityTooLargeResponseModel__2
          description: Content Too Large
        '503':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceUnavailableResponseModel'
          description: Service Unavailable
      security:
        - HTTPBearer: []
        - HTTPBasic: []
components:
  schemas:
    RegoPolicyPutInput:
      properties:
        name:
          anyOf:
            - type: string
            - type: 'null'
          title: Name
          description: >-
            Display name. Omit to keep the current one; required when the policy
            does not exist yet, and never cleared
        description:
          anyOf:
            - type: string
            - type: 'null'
          title: Description
          description: Omit to keep the current description, or send null to clear it
        input_schema:
          type: string
          enum:
            - trail
            - trails
          title: Input Schema
          description: >-
            Shape of the input the policy is written against: one trail, or a
            set of them
        comment:
          type: string
          title: Comment
          description: Why this version was published, kept with the version
          default: ''
        files:
          additionalProperties:
            type: string
          type: object
          title: Files
          description: Rego bundle as relative path to source; a single file is one entry
      additionalProperties: false
      type: object
      required:
        - input_schema
        - files
      title: RegoPolicyPutInput
    RegoPolicyVersionResponse:
      properties:
        identifier:
          type: string
          title: Identifier
          description: Identifier of the policy this version belongs to
        version:
          type: integer
          title: Version
          description: Version number, counting up from 1
        status:
          type: string
          enum:
            - pending
            - valid
            - rejected
            - failed
          title: Status
          description: >-
            `pending` until the version has been validated, then `valid`,
            `rejected` if the policy is at fault, or `failed` if we are
        digest:
          type: string
          title: Digest
          description: >-
            `sha256:` and the hex digest of the bundle's files, which is what a
            decision cites
        input_schema:
          type: string
          enum:
            - trail
            - trails
          title: Input Schema
          description: Shape of the input this version is written against
        comment:
          type: string
          title: Comment
          description: Why this version was published
        created_at:
          type: number
          title: Created At
          description: Unix timestamp the version was published at
        created_by:
          type: string
          title: Created By
          description: Display name of the user who published it
        validated_at:
          anyOf:
            - type: number
            - type: 'null'
          title: Validated At
          description: Unix timestamp the version left `pending`
        opa_version:
          anyOf:
            - type: string
            - type: 'null'
          title: Opa Version
          description: Version of OPA that validated it, absent when `pending` or `failed`
        entrypoint:
          anyOf:
            - type: string
            - type: 'null'
          title: Entrypoint
          description: Policy package the evaluator found, present when `valid`
        params_schema:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Params Schema
          description: >-
            JSON Schema the policy declares for its params, present when `valid`
            and the policy declares one
        error:
          anyOf:
            - $ref: '#/components/schemas/ValidationErrorDetail'
            - type: 'null'
          description: Why the version is not valid, present when `rejected` or `failed`
      type: object
      required:
        - identifier
        - version
        - status
        - digest
        - input_schema
        - comment
        - created_at
        - created_by
      title: RegoPolicyVersionResponse
    fastapi_app__errors__BadRequestResponse___locals___BadRequestResponseModel__11:
      properties:
        message:
          type: string
          title: Message
          description: Error message
        errors:
          anyOf:
            - additionalProperties:
                type: string
              type: object
            - type: 'null'
          title: Errors
          description: Validation errors by field
      type: object
      required:
        - message
      title: BadRequestResponseModel
      examples:
        - message: Input payload validation failed
    fastapi_app__errors__ForbiddenResponse___locals___ForbiddenResponseModel__21:
      properties:
        message:
          type: string
          title: Message
          description: Error message
        errors:
          anyOf:
            - additionalProperties:
                type: string
              type: object
            - type: 'null'
          title: Errors
          description: Validation errors by field
      type: object
      required:
        - message
      title: ForbiddenResponseModel
      examples:
        - message: You don't have permission to access this resource
    fastapi_app__errors__RequestEntityTooLargeResponse___locals___RequestEntityTooLargeResponseModel__2:
      properties:
        message:
          type: string
          title: Message
          description: Error message
        errors:
          anyOf:
            - additionalProperties:
                type: string
              type: object
            - type: 'null'
          title: Errors
          description: Validation errors by field
      type: object
      required:
        - message
      title: RequestEntityTooLargeResponseModel
      description: The policy bundle is over the file or byte limit
      examples:
        - message: The policy bundle is over the file or byte limit
    ServiceUnavailableResponseModel:
      properties:
        message:
          type: string
          title: Message
          description: Error message
        errors:
          anyOf:
            - additionalProperties:
                type: string
              type: object
            - type: 'null'
          title: Errors
          description: Validation errors by field
      type: object
      required:
        - message
      title: ServiceUnavailableResponseModel
      description: Service Unavailable
      examples:
        - message: Database temporarily unavailable; retry the request.
    ValidationErrorDetail:
      properties:
        kind:
          type: string
          title: Kind
          description: >-
            Classification of why the version is not valid: the evaluator's kind
            when `rejected`, ours when `failed`
        message:
          type: string
          title: Message
          description: Detail to act on, such as a file and line
      type: object
      required:
        - kind
        - message
      title: ValidationErrorDetail
  securitySchemes:
    HTTPBearer:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.