Allowed segments
Which derivation path segment values are allowed for the user for an action. A UNION across all of the user's allow policies in the Vault: allowed pathIds are extracted from the senderPattern selectors of require rules; a policy without a senderPattern allows everything ("*"). Block policies are ignored, since they'll trigger on the submit itself. Used by the address creation form UI to show only the available variants.
curl -X GET "https://policy-engine-rest.ezig.workers.dev/api/v1/me/allowed-segments?vaultId=example_string&action=create_address" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN"
import requests
import json
url = "https://policy-engine-rest.ezig.workers.dev/api/v1/me/allowed-segments?vaultId=example_string&action=create_address"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
response = requests.get(url, headers=headers)
print(response.json())
const response = await fetch("https://policy-engine-rest.ezig.workers.dev/api/v1/me/allowed-segments?vaultId=example_string&action=create_address", {
method: "GET",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://policy-engine-rest.ezig.workers.dev/api/v1/me/allowed-segments?vaultId=example_string&action=create_address", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://policy-engine-rest.ezig.workers.dev/api/v1/me/allowed-segments?vaultId=example_string&action=create_address')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
response = http.request(request)
puts response.body
{
"action": "create_address",
"segments": {
"network": [
195
],
"app_id": [
0
],
"asset": "*"
}
}
{
"error": "Bad Request",
"message": "The request contains invalid parameters or malformed data",
"code": 400,
"details": [
{
"field": "email",
"message": "Invalid email format"
}
]
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Not Found",
"message": "The requested resource was not found",
"code": 404
}
{
"error": "Internal Server Error",
"message": "An unexpected error occurred on the server",
"code": 500,
"requestId": "req_1234567890"
}
/api/v1/me/allowed-segments
Target server for requests. Edit to use your own host.
Session token. Mobile/services. The web uses a cookie.
API key (sent in cookie)
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token. Session token. Mobile/services. The web uses a cookie.
API Key for authentication. Provide your API key in the cookie.
Query Parameters
create_addressResponses
Segment code → allowed pathIds or "*" (no restrictions). An empty object means there are no allow policies