Update Policy
Changes a policy for a title
curl --request POST \
--url https://{titleId}.playfabapi.com/Admin/UpdatePolicy \
--header 'Content-Type: application/json' \
--header 'X-SecretKey: <api-key>' \
--data '
{
"PolicyName": "ApiPolicy",
"Statements": [
{
"Resource": "pfrn:api--*",
"Action": "*",
"Principal": "*",
"Comment": "The default allow all policy"
},
{
"Resource": "pfrn:api--/Client/ConfirmPurchase",
"Action": "*",
"Principal": "*",
"Comment": "This statement allows only request to ConfirmPurchase"
}
]
}
'import requests
url = "https://{titleId}.playfabapi.com/Admin/UpdatePolicy"
payload = {
"PolicyName": "ApiPolicy",
"Statements": [
{
"Resource": "pfrn:api--*",
"Action": "*",
"Principal": "*",
"Comment": "The default allow all policy"
},
{
"Resource": "pfrn:api--/Client/ConfirmPurchase",
"Action": "*",
"Principal": "*",
"Comment": "This statement allows only request to ConfirmPurchase"
}
]
}
headers = {
"X-SecretKey": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-SecretKey': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
PolicyName: 'ApiPolicy',
Statements: [
{
Resource: 'pfrn:api--*',
Action: '*',
Principal: '*',
Comment: 'The default allow all policy'
},
{
Resource: 'pfrn:api--/Client/ConfirmPurchase',
Action: '*',
Principal: '*',
Comment: 'This statement allows only request to ConfirmPurchase'
}
]
})
};
fetch('https://{titleId}.playfabapi.com/Admin/UpdatePolicy', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{titleId}.playfabapi.com/Admin/UpdatePolicy",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'PolicyName' => 'ApiPolicy',
'Statements' => [
[
'Resource' => 'pfrn:api--*',
'Action' => '*',
'Principal' => '*',
'Comment' => 'The default allow all policy'
],
[
'Resource' => 'pfrn:api--/Client/ConfirmPurchase',
'Action' => '*',
'Principal' => '*',
'Comment' => 'This statement allows only request to ConfirmPurchase'
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-SecretKey: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{titleId}.playfabapi.com/Admin/UpdatePolicy"
payload := strings.NewReader("{\n \"PolicyName\": \"ApiPolicy\",\n \"Statements\": [\n {\n \"Resource\": \"pfrn:api--*\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"The default allow all policy\"\n },\n {\n \"Resource\": \"pfrn:api--/Client/ConfirmPurchase\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"This statement allows only request to ConfirmPurchase\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-SecretKey", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{titleId}.playfabapi.com/Admin/UpdatePolicy")
.header("X-SecretKey", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"PolicyName\": \"ApiPolicy\",\n \"Statements\": [\n {\n \"Resource\": \"pfrn:api--*\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"The default allow all policy\"\n },\n {\n \"Resource\": \"pfrn:api--/Client/ConfirmPurchase\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"This statement allows only request to ConfirmPurchase\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{titleId}.playfabapi.com/Admin/UpdatePolicy")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-SecretKey"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"PolicyName\": \"ApiPolicy\",\n \"Statements\": [\n {\n \"Resource\": \"pfrn:api--*\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"The default allow all policy\"\n },\n {\n \"Resource\": \"pfrn:api--/Client/ConfirmPurchase\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"This statement allows only request to ConfirmPurchase\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"code": 200,
"status": "OK",
"data": {
"PolicyName": "ApiPolicy",
"Statements": [
{
"Resource": "pfrn:api--*",
"Action": "*",
"Principal": "*",
"Comment": "The default allow all policy"
},
{
"Resource": "pfrn:api--/Client/ConfirmPurchase",
"Action": "*",
"Principal": "*",
"Comment": "This statement allows only request to ConfirmPurchase"
}
]
}
}{
"code": 123,
"errorCode": 123,
"status": "<string>",
"error": "<string>",
"errorMessage": "<string>",
"errorDetails": {}
}Authorizations
This API requires a title secret key, available to title admins, from PlayFab Game Manager.
Body
Updates permissions for your title. Policies affect what is allowed to happen on your title. Your policy is a collection of statements that, together, govern particular area for your title. Today, the only allowed policy is called 'ApiPolicy' and it governs what API calls are allowed. To verify that you have the latest version always download the current policy from GetPolicy before uploading a new policy. PlayFab updates the base policy periodically and will automatically apply it to the uploaded policy. Overwriting the combined policy blindly may result in unexpected API errors.
Updates permissions for your title. Policies affect what is allowed to happen on your title. Your policy is a collection of statements that, together, govern particular area for your title. Today, the only allowed policy is called 'ApiPolicy' and it governs what API calls are allowed. To verify that you have the latest version always download the current policy from GetPolicy before uploading a new policy. PlayFab updates the base policy periodically and will automatically apply it to the uploaded policy. Overwriting the combined policy blindly may result in unexpected API errors.
Whether to overwrite or append to the existing policy.
Version of the policy to update. Must be the latest (as returned by GetPolicy).
The new statements to include in the policy.
Show child attributes
Show child attributes
The name of the policy being updated. Only 'ApiPolicy' is supported. This parameter is optional and defaults to 'ApiPolicy' if omitted.
Response
The Http status code. If X-ReportErrorAsSuccess header is set to true, this will report the actual http error code.
The Http status code as a string.
Show child attributes
Show child attributes
{
"PolicyName": "ApiPolicy",
"Statements": [
{
"Resource": "pfrn:api--*",
"Action": "*",
"Principal": "*",
"Comment": "The default allow all policy"
},
{
"Resource": "pfrn:api--/Client/ConfirmPurchase",
"Action": "*",
"Principal": "*",
"Comment": "This statement allows only request to ConfirmPurchase"
}
]
}
Was this page helpful?
curl --request POST \
--url https://{titleId}.playfabapi.com/Admin/UpdatePolicy \
--header 'Content-Type: application/json' \
--header 'X-SecretKey: <api-key>' \
--data '
{
"PolicyName": "ApiPolicy",
"Statements": [
{
"Resource": "pfrn:api--*",
"Action": "*",
"Principal": "*",
"Comment": "The default allow all policy"
},
{
"Resource": "pfrn:api--/Client/ConfirmPurchase",
"Action": "*",
"Principal": "*",
"Comment": "This statement allows only request to ConfirmPurchase"
}
]
}
'import requests
url = "https://{titleId}.playfabapi.com/Admin/UpdatePolicy"
payload = {
"PolicyName": "ApiPolicy",
"Statements": [
{
"Resource": "pfrn:api--*",
"Action": "*",
"Principal": "*",
"Comment": "The default allow all policy"
},
{
"Resource": "pfrn:api--/Client/ConfirmPurchase",
"Action": "*",
"Principal": "*",
"Comment": "This statement allows only request to ConfirmPurchase"
}
]
}
headers = {
"X-SecretKey": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-SecretKey': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
PolicyName: 'ApiPolicy',
Statements: [
{
Resource: 'pfrn:api--*',
Action: '*',
Principal: '*',
Comment: 'The default allow all policy'
},
{
Resource: 'pfrn:api--/Client/ConfirmPurchase',
Action: '*',
Principal: '*',
Comment: 'This statement allows only request to ConfirmPurchase'
}
]
})
};
fetch('https://{titleId}.playfabapi.com/Admin/UpdatePolicy', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{titleId}.playfabapi.com/Admin/UpdatePolicy",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'PolicyName' => 'ApiPolicy',
'Statements' => [
[
'Resource' => 'pfrn:api--*',
'Action' => '*',
'Principal' => '*',
'Comment' => 'The default allow all policy'
],
[
'Resource' => 'pfrn:api--/Client/ConfirmPurchase',
'Action' => '*',
'Principal' => '*',
'Comment' => 'This statement allows only request to ConfirmPurchase'
]
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-SecretKey: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{titleId}.playfabapi.com/Admin/UpdatePolicy"
payload := strings.NewReader("{\n \"PolicyName\": \"ApiPolicy\",\n \"Statements\": [\n {\n \"Resource\": \"pfrn:api--*\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"The default allow all policy\"\n },\n {\n \"Resource\": \"pfrn:api--/Client/ConfirmPurchase\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"This statement allows only request to ConfirmPurchase\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-SecretKey", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{titleId}.playfabapi.com/Admin/UpdatePolicy")
.header("X-SecretKey", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"PolicyName\": \"ApiPolicy\",\n \"Statements\": [\n {\n \"Resource\": \"pfrn:api--*\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"The default allow all policy\"\n },\n {\n \"Resource\": \"pfrn:api--/Client/ConfirmPurchase\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"This statement allows only request to ConfirmPurchase\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{titleId}.playfabapi.com/Admin/UpdatePolicy")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-SecretKey"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"PolicyName\": \"ApiPolicy\",\n \"Statements\": [\n {\n \"Resource\": \"pfrn:api--*\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"The default allow all policy\"\n },\n {\n \"Resource\": \"pfrn:api--/Client/ConfirmPurchase\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"This statement allows only request to ConfirmPurchase\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"code": 200,
"status": "OK",
"data": {
"PolicyName": "ApiPolicy",
"Statements": [
{
"Resource": "pfrn:api--*",
"Action": "*",
"Principal": "*",
"Comment": "The default allow all policy"
},
{
"Resource": "pfrn:api--/Client/ConfirmPurchase",
"Action": "*",
"Principal": "*",
"Comment": "This statement allows only request to ConfirmPurchase"
}
]
}
}{
"code": 123,
"errorCode": 123,
"status": "<string>",
"error": "<string>",
"errorMessage": "<string>",
"errorDetails": {}
}