Validate Api Policy
Validates the result of a policy update without persisting it.
curl --request POST \
--url https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy \
--header 'Content-Type: application/json' \
--header 'X-SecretKey: <api-key>' \
--data '
{
"PolicyName": "ApiPolicy",
"Statements": [
{
"Resource": "pfrn:api--/Client/*",
"Action": "*",
"Principal": "*",
"Comment": "Allow all client APIs"
}
],
"OverwritePolicy": true,
"PolicyVersion": 13
}
'import requests
url = "https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy"
payload = {
"PolicyName": "ApiPolicy",
"Statements": [
{
"Resource": "pfrn:api--/Client/*",
"Action": "*",
"Principal": "*",
"Comment": "Allow all client APIs"
}
],
"OverwritePolicy": True,
"PolicyVersion": 13
}
headers = {
"X-SecretKey": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-SecretKey': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
PolicyName: 'ApiPolicy',
Statements: [
{
Resource: 'pfrn:api--/Client/*',
Action: '*',
Principal: '*',
Comment: 'Allow all client APIs'
}
],
OverwritePolicy: true,
PolicyVersion: 13
})
};
fetch('https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'PolicyName' => 'ApiPolicy',
'Statements' => [
[
'Resource' => 'pfrn:api--/Client/*',
'Action' => '*',
'Principal' => '*',
'Comment' => 'Allow all client APIs'
]
],
'OverwritePolicy' => true,
'PolicyVersion' => 13
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-SecretKey: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy"
payload := strings.NewReader("{\n \"PolicyName\": \"ApiPolicy\",\n \"Statements\": [\n {\n \"Resource\": \"pfrn:api--/Client/*\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"Allow all client APIs\"\n }\n ],\n \"OverwritePolicy\": true,\n \"PolicyVersion\": 13\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-SecretKey", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy")
.header("X-SecretKey", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"PolicyName\": \"ApiPolicy\",\n \"Statements\": [\n {\n \"Resource\": \"pfrn:api--/Client/*\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"Allow all client APIs\"\n }\n ],\n \"OverwritePolicy\": true,\n \"PolicyVersion\": 13\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-SecretKey"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"PolicyName\": \"ApiPolicy\",\n \"Statements\": [\n {\n \"Resource\": \"pfrn:api--/Client/*\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"Allow all client APIs\"\n }\n ],\n \"OverwritePolicy\": true,\n \"PolicyVersion\": 13\n}"
response = http.request(request)
puts response.read_body{
"code": 200,
"status": "OK",
"data": {
"PolicyName": "ApiPolicy",
"PolicyVersion": 13,
"ResultingStatements": [
{
"Resource": "pfrn:api--/Client/*",
"Action": "*",
"Principal": "*",
"Comment": "Allow all client APIs"
}
],
"IsValid": true,
"ValidationErrors": [],
"Warnings": [],
"Diff": {
"StatementsRemoved": 5,
"StatementsUnchanged": 1,
"TotalResultingStatements": 1
}
}
}{
"code": 123,
"errorCode": 123,
"status": "<string>",
"error": "<string>",
"errorMessage": "<string>",
"errorDetails": {}
}Authorizations
This API requires a title secret key, available to title admins, from PlayFab Game Manager.
Body
Validates the proposed policy change and returns the resulting merged policy, validation errors, warnings, and a diff summary showing what would change. Use this to validate the impact of a policy update before calling UpdatePolicy. No changes are saved.
Validates the proposed policy change and returns the resulting merged policy, validation errors, warnings, and a diff summary showing what would change. Use this to validate the impact of a policy update before calling UpdatePolicy. No changes are saved.
Whether the validation should simulate overwriting or appending to the existing policy.
Version of the policy to validate against. Must be the latest (as returned by GetPolicy).
The statements to validate.
Show child attributes
Show child attributes
The name of the policy to validate. Only 'ApiPolicy' is supported. This parameter is optional and defaults to 'ApiPolicy' if omitted.
Response
The Http status code. If X-ReportErrorAsSuccess header is set to true, this will report the actual http error code.
The Http status code as a string.
Show child attributes
Show child attributes
{
"PolicyName": "ApiPolicy",
"PolicyVersion": 13,
"ResultingStatements": [
{
"Resource": "pfrn:api--/Client/*",
"Action": "*",
"Principal": "*",
"Comment": "Allow all client APIs"
}
],
"IsValid": true,
"ValidationErrors": [],
"Warnings": [],
"Diff": {
"StatementsRemoved": 5,
"StatementsUnchanged": 1,
"TotalResultingStatements": 1
}
}
Was this page helpful?
curl --request POST \
--url https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy \
--header 'Content-Type: application/json' \
--header 'X-SecretKey: <api-key>' \
--data '
{
"PolicyName": "ApiPolicy",
"Statements": [
{
"Resource": "pfrn:api--/Client/*",
"Action": "*",
"Principal": "*",
"Comment": "Allow all client APIs"
}
],
"OverwritePolicy": true,
"PolicyVersion": 13
}
'import requests
url = "https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy"
payload = {
"PolicyName": "ApiPolicy",
"Statements": [
{
"Resource": "pfrn:api--/Client/*",
"Action": "*",
"Principal": "*",
"Comment": "Allow all client APIs"
}
],
"OverwritePolicy": True,
"PolicyVersion": 13
}
headers = {
"X-SecretKey": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-SecretKey': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
PolicyName: 'ApiPolicy',
Statements: [
{
Resource: 'pfrn:api--/Client/*',
Action: '*',
Principal: '*',
Comment: 'Allow all client APIs'
}
],
OverwritePolicy: true,
PolicyVersion: 13
})
};
fetch('https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'PolicyName' => 'ApiPolicy',
'Statements' => [
[
'Resource' => 'pfrn:api--/Client/*',
'Action' => '*',
'Principal' => '*',
'Comment' => 'Allow all client APIs'
]
],
'OverwritePolicy' => true,
'PolicyVersion' => 13
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-SecretKey: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy"
payload := strings.NewReader("{\n \"PolicyName\": \"ApiPolicy\",\n \"Statements\": [\n {\n \"Resource\": \"pfrn:api--/Client/*\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"Allow all client APIs\"\n }\n ],\n \"OverwritePolicy\": true,\n \"PolicyVersion\": 13\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-SecretKey", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy")
.header("X-SecretKey", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"PolicyName\": \"ApiPolicy\",\n \"Statements\": [\n {\n \"Resource\": \"pfrn:api--/Client/*\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"Allow all client APIs\"\n }\n ],\n \"OverwritePolicy\": true,\n \"PolicyVersion\": 13\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{titleId}.playfabapi.com/Admin/ValidateApiPolicy")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-SecretKey"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"PolicyName\": \"ApiPolicy\",\n \"Statements\": [\n {\n \"Resource\": \"pfrn:api--/Client/*\",\n \"Action\": \"*\",\n \"Principal\": \"*\",\n \"Comment\": \"Allow all client APIs\"\n }\n ],\n \"OverwritePolicy\": true,\n \"PolicyVersion\": 13\n}"
response = http.request(request)
puts response.read_body{
"code": 200,
"status": "OK",
"data": {
"PolicyName": "ApiPolicy",
"PolicyVersion": 13,
"ResultingStatements": [
{
"Resource": "pfrn:api--/Client/*",
"Action": "*",
"Principal": "*",
"Comment": "Allow all client APIs"
}
],
"IsValid": true,
"ValidationErrors": [],
"Warnings": [],
"Diff": {
"StatementsRemoved": 5,
"StatementsUnchanged": 1,
"TotalResultingStatements": 1
}
}
}{
"code": 123,
"errorCode": 123,
"status": "<string>",
"error": "<string>",
"errorMessage": "<string>",
"errorDetails": {}
}