> ## Documentation Index
> Fetch the complete documentation index at: https://devdocs.xbox.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Policy

> Gets the requested policy.



## OpenAPI

````yaml /services/playfab/api-references/rest/admin/admin.openapi.json post /Admin/GetPolicy
openapi: 3.0.0
info:
  version: '260922'
  title: PlayFab Admin API
  description: >-
    APIs for managing title configurations, uploaded Game Server code
    executables, and user data
  termsOfService: https://playfab.com/terms/
  contact:
    url: https://community.playfab.com/index.html
  license:
    name: Apache 2.0
    url: https://github.com/PlayFab/API_Specs/blob/master/LICENSE
servers:
  - url: https://{titleId}.playfabapi.com
    description: PlayFab title endpoint
    variables:
      titleId:
        default: your_title_id
        description: Your PlayFab title ID (hex).
security: []
tags:
  - name: Account Management
    description: Account Management APIs
  - name: Authentication
    description: Authentication APIs
  - name: Characters
    description: Characters APIs
  - name: Content
    description: Content Service APIs
  - name: Custom Server Management
    description: Custom Server Management APIs
  - name: Matchmaking
    description: Matchmaking APIs
  - name: Player Data Management
    description: Player Data Management APIs
  - name: Player Item Management
    description: Player Item Management APIs
  - name: PlayStream
    description: PlayStream Management APIs
  - name: ScheduledTask
    description: Task management APIs
  - name: Segments
    description: Segment management APIs
  - name: Server-Side Cloud Script
    description: Server-Side Cloud Script APIs
  - name: Shared Group Data
    description: Shared Group Data APIs
  - name: Title-Wide Data Management
    description: Title-Wide Data Management APIs
  - name: Xbox Store
    description: Xbox Store APIs
paths:
  /Admin/GetPolicy:
    post:
      tags:
        - Authentication
      summary: Get Policy
      description: Gets the requested policy.
      operationId: GetPolicy
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GetPolicyRequest'
        description: >-
          Views the requested policy. Today, the only supported policy is
          'ApiPolicy'.
      responses:
        '200':
          $ref: '#/components/responses/GetPolicyResponse'
        '400':
          $ref: '#/components/responses/ApiErrorWrapper'
      security:
        - SecretKey: []
components:
  schemas:
    GetPolicyRequest:
      description: >-
        Views the requested policy. Today, the only supported policy is
        'ApiPolicy'.
      type: object
      properties:
        PolicyName:
          description: >-
            The name of the policy to read. Only 'ApiPolicy' is supported. This
            parameter is optional and defaults to 'ApiPolicy' if omitted.
          type: string
      example:
        PolicyName: ApiPolicy
    GetPolicyResponse:
      type: object
      properties:
        LastUpdated:
          description: >-
            The UTC date and time when the policy was last updated. Null if the
            policy has never been customized.
          type: string
        PolicyName:
          description: The name of the policy read.
          type: string
        PolicyVersion:
          description: Policy version.
          type: number
          x-actualtype: int32
        Statements:
          description: The statements in the requested policy.
          type: array
          items:
            $ref: '#/components/schemas/PermissionStatement'
          x-isclass: true
      required:
        - PolicyVersion
      example:
        PolicyName: ApiPolicy
        Statements:
          - Resource: pfrn:api--*
            Action: '*'
            Principal: '*'
            Comment: The default allow all policy
          - Resource: pfrn:api--/Client/ConfirmPurchase
            Action: '*'
            Principal: '*'
            Comment: This statement allows only request to ConfirmPurchase
    ApiErrorWrapper:
      description: The basic wrapper around every failed API response
      type: object
      properties:
        code:
          description: Numerical HTTP code
          type: integer
        status:
          description: String HTTP code
          type: string
        error:
          description: Playfab error code
          type: string
        errorCode:
          description: Numerical PlayFab error code
          type: integer
        errorMessage:
          description: Description for the PlayFab errorCode
          type: string
        errorDetails:
          description: Detailed description of individual issues with the request object
          type: object
      required:
        - code
        - errorCode
    PermissionStatement:
      type: object
      properties:
        Action:
          description: >-
            The action this statement effects. May only be '*'. This parameter
            is optional and defaults to '*' if omitted.
          type: string
        ApiConditions:
          allOf:
            - $ref: '#/components/schemas/ApiCondition'
          description: Additional conditions to be applied for API Resources.
        Comment:
          description: >-
            A comment about the statement. Intended solely for bookkeeping and
            debugging.
          type: string
        Effect:
          allOf:
            - $ref: '#/components/schemas/EffectType'
          description: >-
            The effect this statement will have. It could be either Allow or
            Deny
        Principal:
          description: >-
            The principal this statement will effect. May be '*' to match all
            callers, or a JSON object targeting a specific entity type, e.g.
            {"title_player_account":"*"} for players or
            {"master_player_account":"*"} for master player accounts.
          type: string
        Resource:
          description: >-
            The resource this statements effects. The only supported resources
            look like 'pfrn:api--*' for all apis, or
            'pfrn:api--/Client/ConfirmPurchase' for specific apis.
          type: string
      required:
        - Resource
        - Effect
        - Principal
    ApiCondition:
      type: object
      properties:
        HasSignatureOrEncryption:
          allOf:
            - $ref: '#/components/schemas/Conditionals'
          description: >-
            Require that API calls contain an RSA encrypted payload or signed
            headers.
    EffectType:
      type: string
      enum:
        - Allow
        - Deny
    Conditionals:
      type: string
      enum:
        - Any
        - 'True'
        - 'False'
  responses:
    GetPolicyResponse:
      description: ''
      content:
        application/json:
          schema:
            type: object
            properties:
              code:
                type: integer
                description: >-
                  The Http status code. If X-ReportErrorAsSuccess header is set
                  to true, this will report the actual http error code.
              status:
                type: string
                description: The Http status code as a string.
              data:
                $ref: '#/components/schemas/GetPolicyResponse'
            example:
              code: 200
              status: OK
              data:
                PolicyName: ApiPolicy
                Statements:
                  - Resource: pfrn:api--*
                    Action: '*'
                    Principal: '*'
                    Comment: The default allow all policy
                  - Resource: pfrn:api--/Client/ConfirmPurchase
                    Action: '*'
                    Principal: '*'
                    Comment: This statement allows only request to ConfirmPurchase
    ApiErrorWrapper:
      description: This is the outer wrapper for all responses with errors
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiErrorWrapper'
  securitySchemes:
    SecretKey:
      type: apiKey
      in: header
      name: X-SecretKey
      description: >-
        This API requires a title secret key, available to title admins, from
        PlayFab Game Manager.

````

## Related topics

- [Get Policy](/services/playfab/api-references/rest/admin/authentication/get-policy.md)
- [Update Policy](/api-reference/authentication/update-policy.md)
- [API Access Policy](/services/playfab/api-references/api-access-policy.md)
- [Validate Api Policy](/api-reference/authentication/validate-api-policy.md)
- [Get Global Policy](/services/playfab/api-references/rest/profiles/account-management/get-global-policy.md)
