> ## Documentation Index
> Fetch the complete documentation index at: https://devdocs.xbox.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Validate Api Policy

> Validates the result of a policy update without persisting it.



## OpenAPI

````yaml /services/playfab/api-references/rest/admin/admin.openapi.json post /Admin/ValidateApiPolicy
openapi: 3.0.0
info:
  version: '260922'
  title: PlayFab Admin API
  description: >-
    APIs for managing title configurations, uploaded Game Server code
    executables, and user data
  termsOfService: https://playfab.com/terms/
  contact:
    url: https://community.playfab.com/index.html
  license:
    name: Apache 2.0
    url: https://github.com/PlayFab/API_Specs/blob/master/LICENSE
servers:
  - url: https://{titleId}.playfabapi.com
    description: PlayFab title endpoint
    variables:
      titleId:
        default: your_title_id
        description: Your PlayFab title ID (hex).
security: []
tags:
  - name: Account Management
    description: Account Management APIs
  - name: Authentication
    description: Authentication APIs
  - name: Characters
    description: Characters APIs
  - name: Content
    description: Content Service APIs
  - name: Custom Server Management
    description: Custom Server Management APIs
  - name: Matchmaking
    description: Matchmaking APIs
  - name: Player Data Management
    description: Player Data Management APIs
  - name: Player Item Management
    description: Player Item Management APIs
  - name: PlayStream
    description: PlayStream Management APIs
  - name: ScheduledTask
    description: Task management APIs
  - name: Segments
    description: Segment management APIs
  - name: Server-Side Cloud Script
    description: Server-Side Cloud Script APIs
  - name: Shared Group Data
    description: Shared Group Data APIs
  - name: Title-Wide Data Management
    description: Title-Wide Data Management APIs
  - name: Xbox Store
    description: Xbox Store APIs
paths:
  /Admin/ValidateApiPolicy:
    post:
      tags:
        - Authentication
      summary: Validate Api Policy
      description: Validates the result of a policy update without persisting it.
      operationId: ValidateApiPolicy
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ValidateApiPolicyRequest'
        description: >-
          Validates the proposed policy change and returns the resulting merged
          policy, validation errors, warnings, and a diff summary showing what
          would change. Use this to validate the impact of a policy update
          before calling UpdatePolicy. No changes are saved.
      responses:
        '200':
          $ref: '#/components/responses/ValidateApiPolicyResponse'
        '400':
          $ref: '#/components/responses/ApiErrorWrapper'
      security:
        - SecretKey: []
components:
  schemas:
    ValidateApiPolicyRequest:
      description: >-
        Validates the proposed policy change and returns the resulting merged
        policy, validation errors, warnings, and a diff summary showing what
        would change. Use this to validate the impact of a policy update before
        calling UpdatePolicy. No changes are saved.
      type: object
      properties:
        OverwritePolicy:
          description: >-
            Whether the validation should simulate overwriting or appending to
            the existing policy.
          type: boolean
        PolicyName:
          description: >-
            The name of the policy to validate. Only 'ApiPolicy' is supported.
            This parameter is optional and defaults to 'ApiPolicy' if omitted.
          type: string
        PolicyVersion:
          description: >-
            Version of the policy to validate against. Must be the latest (as
            returned by GetPolicy).
          type: number
          x-actualtype: int32
        Statements:
          description: The statements to validate.
          type: array
          items:
            $ref: '#/components/schemas/PermissionStatement'
          x-isclass: true
      required:
        - Statements
        - OverwritePolicy
        - PolicyVersion
      example:
        PolicyName: ApiPolicy
        Statements:
          - Resource: pfrn:api--/Client/*
            Action: '*'
            Principal: '*'
            Comment: Allow all client APIs
        OverwritePolicy: true
        PolicyVersion: 13
    PermissionStatement:
      type: object
      properties:
        Action:
          description: >-
            The action this statement effects. May only be '*'. This parameter
            is optional and defaults to '*' if omitted.
          type: string
        ApiConditions:
          allOf:
            - $ref: '#/components/schemas/ApiCondition'
          description: Additional conditions to be applied for API Resources.
        Comment:
          description: >-
            A comment about the statement. Intended solely for bookkeeping and
            debugging.
          type: string
        Effect:
          allOf:
            - $ref: '#/components/schemas/EffectType'
          description: >-
            The effect this statement will have. It could be either Allow or
            Deny
        Principal:
          description: >-
            The principal this statement will effect. May be '*' to match all
            callers, or a JSON object targeting a specific entity type, e.g.
            {"title_player_account":"*"} for players or
            {"master_player_account":"*"} for master player accounts.
          type: string
        Resource:
          description: >-
            The resource this statements effects. The only supported resources
            look like 'pfrn:api--*' for all apis, or
            'pfrn:api--/Client/ConfirmPurchase' for specific apis.
          type: string
      required:
        - Resource
        - Effect
        - Principal
    ValidateApiPolicyResponse:
      type: object
      properties:
        Diff:
          allOf:
            - $ref: '#/components/schemas/PolicyDiffSummary'
          description: Summary of what would change compared to the current policy.
        IsValid:
          description: >-
            Whether the proposed policy is valid and would be accepted by
            UpdatePolicy.
          type: boolean
        PolicyName:
          description: The name of the policy validated.
          type: string
        PolicyVersion:
          description: Policy version.
          type: number
          x-actualtype: int32
        ResultingStatements:
          description: >-
            The full set of statements that would result from applying this
            update.
          type: array
          items:
            $ref: '#/components/schemas/PermissionStatement'
          x-isclass: true
        ValidationErrors:
          description: >-
            Validation errors that would cause UpdatePolicy to reject this
            request. Empty if IsValid is true.
          type: array
          items:
            type: string
        Warnings:
          description: >-
            Non-blocking warnings about the proposed policy (e.g., near
            statement limit, duplicate statements).
          type: array
          items:
            type: string
      required:
        - PolicyVersion
        - IsValid
      example:
        PolicyName: ApiPolicy
        PolicyVersion: 13
        ResultingStatements:
          - Resource: pfrn:api--/Client/*
            Action: '*'
            Principal: '*'
            Comment: Allow all client APIs
        IsValid: true
        ValidationErrors: []
        Warnings: []
        Diff:
          StatementsRemoved: 5
          StatementsUnchanged: 1
          TotalResultingStatements: 1
    ApiErrorWrapper:
      description: The basic wrapper around every failed API response
      type: object
      properties:
        code:
          description: Numerical HTTP code
          type: integer
        status:
          description: String HTTP code
          type: string
        error:
          description: Playfab error code
          type: string
        errorCode:
          description: Numerical PlayFab error code
          type: integer
        errorMessage:
          description: Description for the PlayFab errorCode
          type: string
        errorDetails:
          description: Detailed description of individual issues with the request object
          type: object
      required:
        - code
        - errorCode
    ApiCondition:
      type: object
      properties:
        HasSignatureOrEncryption:
          allOf:
            - $ref: '#/components/schemas/Conditionals'
          description: >-
            Require that API calls contain an RSA encrypted payload or signed
            headers.
    EffectType:
      type: string
      enum:
        - Allow
        - Deny
    PolicyDiffSummary:
      type: object
      properties:
        StatementsAdded:
          description: Number of new statements that would be added.
          type: number
          x-actualtype: int32
        StatementsRemoved:
          description: >-
            Number of existing statements that would be removed. Only applicable
            when OverwritePolicy is true.
          type: number
          x-actualtype: int32
        StatementsReplaced:
          description: >-
            Number of existing statements that would be replaced by functionally
            equivalent incoming statements (e.g., same resource/effect/principal
            but different comment).
          type: number
          x-actualtype: int32
        StatementsUnchanged:
          description: Number of existing statements that would remain unchanged.
          type: number
          x-actualtype: int32
        TotalResultingStatements:
          description: Total number of statements in the resulting policy.
          type: number
          x-actualtype: int32
      required:
        - StatementsAdded
        - StatementsRemoved
        - StatementsUnchanged
        - StatementsReplaced
        - TotalResultingStatements
    Conditionals:
      type: string
      enum:
        - Any
        - 'True'
        - 'False'
  responses:
    ValidateApiPolicyResponse:
      description: ''
      content:
        application/json:
          schema:
            type: object
            properties:
              code:
                type: integer
                description: >-
                  The Http status code. If X-ReportErrorAsSuccess header is set
                  to true, this will report the actual http error code.
              status:
                type: string
                description: The Http status code as a string.
              data:
                $ref: '#/components/schemas/ValidateApiPolicyResponse'
            example:
              code: 200
              status: OK
              data:
                PolicyName: ApiPolicy
                PolicyVersion: 13
                ResultingStatements:
                  - Resource: pfrn:api--/Client/*
                    Action: '*'
                    Principal: '*'
                    Comment: Allow all client APIs
                IsValid: true
                ValidationErrors: []
                Warnings: []
                Diff:
                  StatementsRemoved: 5
                  StatementsUnchanged: 1
                  TotalResultingStatements: 1
    ApiErrorWrapper:
      description: This is the outer wrapper for all responses with errors
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiErrorWrapper'
  securitySchemes:
    SecretKey:
      type: apiKey
      in: header
      name: X-SecretKey
      description: >-
        This API requires a title secret key, available to title admins, from
        PlayFab Game Manager.

````

## Related topics

- [Validate Api Policy](/services/playfab/api-references/rest/admin/authentication/validate-api-policy.md)
- [PlayFab Services SDK Release Notes 2026](/services/playfab/release-notes/index.md)
- [Release notes](/tools/tools-pc/xbox-pc-remote-tools/release-notes/index.md)
- [API Access Policy](/services/playfab/api-references/api-access-policy.md)
- [Validate Entity Token](/services/playfab/api-references/rest/authentication/authentication/validate-entity-token.md)
