> ## Documentation Index
> Fetch the complete documentation index at: https://devdocs.xbox.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update Policy

> Changes a policy for a title



## OpenAPI

````yaml /services/playfab/api-references/rest/admin/admin.openapi.json post /Admin/UpdatePolicy
openapi: 3.0.0
info:
  version: '260922'
  title: PlayFab Admin API
  description: >-
    APIs for managing title configurations, uploaded Game Server code
    executables, and user data
  termsOfService: https://playfab.com/terms/
  contact:
    url: https://community.playfab.com/index.html
  license:
    name: Apache 2.0
    url: https://github.com/PlayFab/API_Specs/blob/master/LICENSE
servers:
  - url: https://{titleId}.playfabapi.com
    description: PlayFab title endpoint
    variables:
      titleId:
        default: your_title_id
        description: Your PlayFab title ID (hex).
security: []
tags:
  - name: Account Management
    description: Account Management APIs
  - name: Authentication
    description: Authentication APIs
  - name: Characters
    description: Characters APIs
  - name: Content
    description: Content Service APIs
  - name: Custom Server Management
    description: Custom Server Management APIs
  - name: Matchmaking
    description: Matchmaking APIs
  - name: Player Data Management
    description: Player Data Management APIs
  - name: Player Item Management
    description: Player Item Management APIs
  - name: PlayStream
    description: PlayStream Management APIs
  - name: ScheduledTask
    description: Task management APIs
  - name: Segments
    description: Segment management APIs
  - name: Server-Side Cloud Script
    description: Server-Side Cloud Script APIs
  - name: Shared Group Data
    description: Shared Group Data APIs
  - name: Title-Wide Data Management
    description: Title-Wide Data Management APIs
  - name: Xbox Store
    description: Xbox Store APIs
paths:
  /Admin/UpdatePolicy:
    post:
      tags:
        - Authentication
      summary: Update Policy
      description: Changes a policy for a title
      operationId: UpdatePolicy
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdatePolicyRequest'
        description: >-
          Updates permissions for your title. Policies affect what is allowed to
          happen on your title. Your policy is a collection of statements that,
          together, govern particular area for your title. Today, the only
          allowed policy is called 'ApiPolicy' and it governs what API calls are
          allowed. To verify that you have the latest version always download
          the current policy from GetPolicy before uploading a new policy.
          PlayFab updates the base policy periodically and will automatically
          apply it to the uploaded policy. Overwriting the combined policy
          blindly may result in unexpected API errors.
      responses:
        '200':
          $ref: '#/components/responses/UpdatePolicyResponse'
        '400':
          $ref: '#/components/responses/ApiErrorWrapper'
      security:
        - SecretKey: []
components:
  schemas:
    UpdatePolicyRequest:
      description: >-
        Updates permissions for your title. Policies affect what is allowed to
        happen on your title. Your policy is a collection of statements that,
        together, govern particular area for your title. Today, the only allowed
        policy is called 'ApiPolicy' and it governs what API calls are allowed.
        To verify that you have the latest version always download the current
        policy from GetPolicy before uploading a new policy. PlayFab updates the
        base policy periodically and will automatically apply it to the uploaded
        policy. Overwriting the combined policy blindly may result in unexpected
        API errors.
      type: object
      properties:
        OverwritePolicy:
          description: Whether to overwrite or append to the existing policy.
          type: boolean
        PolicyName:
          description: >-
            The name of the policy being updated. Only 'ApiPolicy' is supported.
            This parameter is optional and defaults to 'ApiPolicy' if omitted.
          type: string
        PolicyVersion:
          description: >-
            Version of the policy to update. Must be the latest (as returned by
            GetPolicy).
          type: number
          x-actualtype: int32
        Statements:
          description: The new statements to include in the policy.
          type: array
          items:
            $ref: '#/components/schemas/PermissionStatement'
          x-isclass: true
      required:
        - Statements
        - OverwritePolicy
        - PolicyVersion
      example:
        PolicyName: ApiPolicy
        Statements:
          - Resource: pfrn:api--*
            Action: '*'
            Principal: '*'
            Comment: The default allow all policy
          - Resource: pfrn:api--/Client/ConfirmPurchase
            Action: '*'
            Principal: '*'
            Comment: This statement allows only request to ConfirmPurchase
    PermissionStatement:
      type: object
      properties:
        Action:
          description: >-
            The action this statement effects. May only be '*'. This parameter
            is optional and defaults to '*' if omitted.
          type: string
        ApiConditions:
          allOf:
            - $ref: '#/components/schemas/ApiCondition'
          description: Additional conditions to be applied for API Resources.
        Comment:
          description: >-
            A comment about the statement. Intended solely for bookkeeping and
            debugging.
          type: string
        Effect:
          allOf:
            - $ref: '#/components/schemas/EffectType'
          description: >-
            The effect this statement will have. It could be either Allow or
            Deny
        Principal:
          description: >-
            The principal this statement will effect. May be '*' to match all
            callers, or a JSON object targeting a specific entity type, e.g.
            {"title_player_account":"*"} for players or
            {"master_player_account":"*"} for master player accounts.
          type: string
        Resource:
          description: >-
            The resource this statements effects. The only supported resources
            look like 'pfrn:api--*' for all apis, or
            'pfrn:api--/Client/ConfirmPurchase' for specific apis.
          type: string
      required:
        - Resource
        - Effect
        - Principal
    UpdatePolicyResponse:
      type: object
      properties:
        PolicyName:
          description: The name of the policy that was updated.
          type: string
        Statements:
          description: The statements included in the new version of the policy.
          type: array
          items:
            $ref: '#/components/schemas/PermissionStatement'
          x-isclass: true
        Warnings:
          description: >-
            Optional warnings about policy statements that may not have the
            intended effect. For example, resource paths that don't match any
            known API endpoint. The policy update still succeeds when warnings
            are present.
          type: array
          items:
            type: string
      example:
        PolicyName: ApiPolicy
        Statements:
          - Resource: pfrn:api--*
            Action: '*'
            Principal: '*'
            Comment: The default allow all policy
          - Resource: pfrn:api--/Client/ConfirmPurchase
            Action: '*'
            Principal: '*'
            Comment: This statement allows only request to ConfirmPurchase
    ApiErrorWrapper:
      description: The basic wrapper around every failed API response
      type: object
      properties:
        code:
          description: Numerical HTTP code
          type: integer
        status:
          description: String HTTP code
          type: string
        error:
          description: Playfab error code
          type: string
        errorCode:
          description: Numerical PlayFab error code
          type: integer
        errorMessage:
          description: Description for the PlayFab errorCode
          type: string
        errorDetails:
          description: Detailed description of individual issues with the request object
          type: object
      required:
        - code
        - errorCode
    ApiCondition:
      type: object
      properties:
        HasSignatureOrEncryption:
          allOf:
            - $ref: '#/components/schemas/Conditionals'
          description: >-
            Require that API calls contain an RSA encrypted payload or signed
            headers.
    EffectType:
      type: string
      enum:
        - Allow
        - Deny
    Conditionals:
      type: string
      enum:
        - Any
        - 'True'
        - 'False'
  responses:
    UpdatePolicyResponse:
      description: ''
      content:
        application/json:
          schema:
            type: object
            properties:
              code:
                type: integer
                description: >-
                  The Http status code. If X-ReportErrorAsSuccess header is set
                  to true, this will report the actual http error code.
              status:
                type: string
                description: The Http status code as a string.
              data:
                $ref: '#/components/schemas/UpdatePolicyResponse'
            example:
              code: 200
              status: OK
              data:
                PolicyName: ApiPolicy
                Statements:
                  - Resource: pfrn:api--*
                    Action: '*'
                    Principal: '*'
                    Comment: The default allow all policy
                  - Resource: pfrn:api--/Client/ConfirmPurchase
                    Action: '*'
                    Principal: '*'
                    Comment: This statement allows only request to ConfirmPurchase
    ApiErrorWrapper:
      description: This is the outer wrapper for all responses with errors
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiErrorWrapper'
  securitySchemes:
    SecretKey:
      type: apiKey
      in: header
      name: X-SecretKey
      description: >-
        This API requires a title secret key, available to title admins, from
        PlayFab Game Manager.

````

## Related topics

- [Update Policy](/services/playfab/api-references/rest/admin/authentication/update-policy.md)
- [Validate Api Policy](/api-reference/authentication/validate-api-policy.md)
- [API Access Policy](/services/playfab/api-references/api-access-policy.md)
- [OS update page](/tools/tools-console/wdp/windows-device-portal-on-xbox-os-update.md)
- [PlayFab Services SDK Release Notes 2026](/services/playfab/release-notes/index.md)
