Set Profile Policy
Sets the profiles access policy
POST
/
Profile
/
SetProfilePolicy
Set Profile Policy
curl --request POST \
--url https://{titleId}.playfabapi.com/Profile/SetProfilePolicy \
--header 'Content-Type: application/json' \
--header 'X-EntityToken: <api-key>' \
--data '
{
"Statements": [
{
"Resource": "pfrn:data--*!*/Profile/Files/avatar.png",
"Action": "Read",
"Principal": {
"FriendOf": "true"
},
"Comment": "Allow my friends to read my avatar"
}
],
"Entity": {
"Id": "90901000",
"Type": "title_player_account",
"TypeString": "title_player_account"
}
}
'import requests
url = "https://{titleId}.playfabapi.com/Profile/SetProfilePolicy"
payload = {
"Statements": [
{
"Resource": "pfrn:data--*!*/Profile/Files/avatar.png",
"Action": "Read",
"Principal": { "FriendOf": "true" },
"Comment": "Allow my friends to read my avatar"
}
],
"Entity": {
"Id": "90901000",
"Type": "title_player_account",
"TypeString": "title_player_account"
}
}
headers = {
"X-EntityToken": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-EntityToken': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
Statements: [
{
Resource: 'pfrn:data--*!*/Profile/Files/avatar.png',
Action: 'Read',
Principal: {FriendOf: 'true'},
Comment: 'Allow my friends to read my avatar'
}
],
Entity: {
Id: '90901000',
Type: 'title_player_account',
TypeString: 'title_player_account'
}
})
};
fetch('https://{titleId}.playfabapi.com/Profile/SetProfilePolicy', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{titleId}.playfabapi.com/Profile/SetProfilePolicy",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'Statements' => [
[
'Resource' => 'pfrn:data--*!*/Profile/Files/avatar.png',
'Action' => 'Read',
'Principal' => [
'FriendOf' => 'true'
],
'Comment' => 'Allow my friends to read my avatar'
]
],
'Entity' => [
'Id' => '90901000',
'Type' => 'title_player_account',
'TypeString' => 'title_player_account'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-EntityToken: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{titleId}.playfabapi.com/Profile/SetProfilePolicy"
payload := strings.NewReader("{\n \"Statements\": [\n {\n \"Resource\": \"pfrn:data--*!*/Profile/Files/avatar.png\",\n \"Action\": \"Read\",\n \"Principal\": {\n \"FriendOf\": \"true\"\n },\n \"Comment\": \"Allow my friends to read my avatar\"\n }\n ],\n \"Entity\": {\n \"Id\": \"90901000\",\n \"Type\": \"title_player_account\",\n \"TypeString\": \"title_player_account\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-EntityToken", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{titleId}.playfabapi.com/Profile/SetProfilePolicy")
.header("X-EntityToken", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"Statements\": [\n {\n \"Resource\": \"pfrn:data--*!*/Profile/Files/avatar.png\",\n \"Action\": \"Read\",\n \"Principal\": {\n \"FriendOf\": \"true\"\n },\n \"Comment\": \"Allow my friends to read my avatar\"\n }\n ],\n \"Entity\": {\n \"Id\": \"90901000\",\n \"Type\": \"title_player_account\",\n \"TypeString\": \"title_player_account\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{titleId}.playfabapi.com/Profile/SetProfilePolicy")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-EntityToken"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"Statements\": [\n {\n \"Resource\": \"pfrn:data--*!*/Profile/Files/avatar.png\",\n \"Action\": \"Read\",\n \"Principal\": {\n \"FriendOf\": \"true\"\n },\n \"Comment\": \"Allow my friends to read my avatar\"\n }\n ],\n \"Entity\": {\n \"Id\": \"90901000\",\n \"Type\": \"title_player_account\",\n \"TypeString\": \"title_player_account\"\n }\n}"
response = http.request(request)
puts response.read_body{
"code": 200,
"status": "OK",
"data": {
"Permissions": [
{
"Resource": "pfrn:data--title_player_account!90901000/Profile/SomethingCool",
"Action": "*",
"Principal": {
"ChildOf": {
"EntityType": "[SELF]"
}
},
"Comment": "An example policy"
}
]
}
}{
"code": 123,
"errorCode": 123,
"status": "<string>",
"error": "<string>",
"errorMessage": "<string>",
"errorDetails": {}
}Authorizations
This API requires an Entity Session Token, available from the Entity GetEntityToken method.
Body
application/json
This will set the access policy statements on the given entity profile. This is not additive, any existing statements will be replaced with the statements in this request.
This will set the access policy statements on the given entity profile. This is not additive, any existing statements will be replaced with the statements in this request.
Response
The Http status code. If X-ReportErrorAsSuccess header is set to true, this will report the actual http error code.
The Http status code as a string.
Show child attributes
Show child attributes
Example:
{ "Permissions": [ { "Resource": "pfrn:data--title_player_account!90901000/Profile/SomethingCool", "Action": "*", "Principal": { "ChildOf": { "EntityType": "[SELF]" } }, "Comment": "An example policy" } ] }
Last modified on October 1, 2026
Was this page helpful?
⌘I
Set Profile Policy
curl --request POST \
--url https://{titleId}.playfabapi.com/Profile/SetProfilePolicy \
--header 'Content-Type: application/json' \
--header 'X-EntityToken: <api-key>' \
--data '
{
"Statements": [
{
"Resource": "pfrn:data--*!*/Profile/Files/avatar.png",
"Action": "Read",
"Principal": {
"FriendOf": "true"
},
"Comment": "Allow my friends to read my avatar"
}
],
"Entity": {
"Id": "90901000",
"Type": "title_player_account",
"TypeString": "title_player_account"
}
}
'import requests
url = "https://{titleId}.playfabapi.com/Profile/SetProfilePolicy"
payload = {
"Statements": [
{
"Resource": "pfrn:data--*!*/Profile/Files/avatar.png",
"Action": "Read",
"Principal": { "FriendOf": "true" },
"Comment": "Allow my friends to read my avatar"
}
],
"Entity": {
"Id": "90901000",
"Type": "title_player_account",
"TypeString": "title_player_account"
}
}
headers = {
"X-EntityToken": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-EntityToken': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
Statements: [
{
Resource: 'pfrn:data--*!*/Profile/Files/avatar.png',
Action: 'Read',
Principal: {FriendOf: 'true'},
Comment: 'Allow my friends to read my avatar'
}
],
Entity: {
Id: '90901000',
Type: 'title_player_account',
TypeString: 'title_player_account'
}
})
};
fetch('https://{titleId}.playfabapi.com/Profile/SetProfilePolicy', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{titleId}.playfabapi.com/Profile/SetProfilePolicy",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'Statements' => [
[
'Resource' => 'pfrn:data--*!*/Profile/Files/avatar.png',
'Action' => 'Read',
'Principal' => [
'FriendOf' => 'true'
],
'Comment' => 'Allow my friends to read my avatar'
]
],
'Entity' => [
'Id' => '90901000',
'Type' => 'title_player_account',
'TypeString' => 'title_player_account'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-EntityToken: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{titleId}.playfabapi.com/Profile/SetProfilePolicy"
payload := strings.NewReader("{\n \"Statements\": [\n {\n \"Resource\": \"pfrn:data--*!*/Profile/Files/avatar.png\",\n \"Action\": \"Read\",\n \"Principal\": {\n \"FriendOf\": \"true\"\n },\n \"Comment\": \"Allow my friends to read my avatar\"\n }\n ],\n \"Entity\": {\n \"Id\": \"90901000\",\n \"Type\": \"title_player_account\",\n \"TypeString\": \"title_player_account\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-EntityToken", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{titleId}.playfabapi.com/Profile/SetProfilePolicy")
.header("X-EntityToken", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"Statements\": [\n {\n \"Resource\": \"pfrn:data--*!*/Profile/Files/avatar.png\",\n \"Action\": \"Read\",\n \"Principal\": {\n \"FriendOf\": \"true\"\n },\n \"Comment\": \"Allow my friends to read my avatar\"\n }\n ],\n \"Entity\": {\n \"Id\": \"90901000\",\n \"Type\": \"title_player_account\",\n \"TypeString\": \"title_player_account\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{titleId}.playfabapi.com/Profile/SetProfilePolicy")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-EntityToken"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"Statements\": [\n {\n \"Resource\": \"pfrn:data--*!*/Profile/Files/avatar.png\",\n \"Action\": \"Read\",\n \"Principal\": {\n \"FriendOf\": \"true\"\n },\n \"Comment\": \"Allow my friends to read my avatar\"\n }\n ],\n \"Entity\": {\n \"Id\": \"90901000\",\n \"Type\": \"title_player_account\",\n \"TypeString\": \"title_player_account\"\n }\n}"
response = http.request(request)
puts response.read_body{
"code": 200,
"status": "OK",
"data": {
"Permissions": [
{
"Resource": "pfrn:data--title_player_account!90901000/Profile/SomethingCool",
"Action": "*",
"Principal": {
"ChildOf": {
"EntityType": "[SELF]"
}
},
"Comment": "An example policy"
}
]
}
}{
"code": 123,
"errorCode": 123,
"status": "<string>",
"error": "<string>",
"errorMessage": "<string>",
"errorDetails": {}
}