EvaluationEvaluate a request against policies

Evaluate a request against policies

The core of the policy engine (deny-overrides):

  1. All of the user's policies in the Vault are collected (through group memberships)
  2. Filter: enabled=true and actionType = action
  3. Applicability: a single boolean condition tree (and/or/not/leaf). condition=null → the policy always applies
  4. Resolution (Phase 2): block → violated limit (denial or escalation to signing) → signature requirements → allow → deny (default-deny). Requirements are COLLECTED from all applicable policies (requirements[]) rather than choosing the single one with the highest threshold; this is how "CFO AND compliance" is expressed

Called internally from createAddress/createTransaction, but also available directly for dry-run checks from the UI.

curl -X POST "https://policy-engine-rest.ezig.workers.dev/api/v1/evaluate" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN" \
  -d '{
  "vaultId": "example_string",
  "userId": "user-1",
  "action": "transfer",
  "context": {
    "derivationPath": "m/44/195/0/0/1/1/0",
    "destinationAddress": "123 Main St",
    "destinationNetwork": "tron",
    "amount": {
      "value": "1.5",
      "asset": "usdt"
    },
    "totalSpent": {
      "value": "example_string",
      "asset": "example_string"
    },
    "tokenCode": "example_string",
    "signersConfig": {
      "mode": "example_string"
    }
  }
}'
{
  "decision": "example_string",
  "matchedPolicyIds": [
    "example_string"
  ],
  "trace": [
    {
      "policyId": "example_string",
      "policyCode": "example_string",
      "policyName": "John Doe",
      "effect": "example_string",
      "applied": true,
      "skipReason": "excluded",
      "failedSelector": {
        "conditionType": "example_string",
        "selectorType": "example_string",
        "detail": "initiator's spending over 24 h including the current operation is 11000 usdt, limit 10000 usdt"
      }
    }
  ]
}
POST
/api/v1/evaluate
POST
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token
Bearer Tokenstring
Required

Session token. Mobile/services. The web uses a cookie.

Session token. Mobile/services. The web uses a cookie.
API Key (cookie: session_token)
session_tokenstring
Required

API key (sent in cookie)

Content-Typestring
Required

The media type of the request body

Options: application/json
actionstring
Required

The action type the policy applies to. Member visibility is NOT part of this: it's a grant (/vaults/:code/visibility-grants), not a policy

Options: transfer, create_address, counterparty_create, counterparty_update, counterparty_archive, counterparty_group_create, counterparty_group_update, counterparty_group_archive, counterparty_group_add, counterparty_group_remove
contextobject
Required

Request context: only the fields relevant to the action are filled in. Which ones production calls set is pinned by the tests/selectorContextParity.test.ts metatest: a selector can't be allowed if the context doesn't feed it (otherwise the policy silently stops applying)

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token. Session token. Mobile/services. The web uses a cookie.

path
parameterstring
Required

API Key for authentication. Provide your API key in the cookie.

Body

application/json
userIdstring
Required
Example:
user-1
actionstring
Required

The action type the policy applies to. Member visibility is NOT part of this: it's a grant (/vaults/:code/visibility-grants), not a policy

Allowed values:transfercreate_addresscounterparty_createcounterparty_updatecounterparty_archivecounterparty_group_createcounterparty_group_updatecounterparty_group_archivecounterparty_group_addcounterparty_group_remove
contextobject
Required

Request context: only the fields relevant to the action are filled in. Which ones production calls set is pinned by the tests/selectorContextParity.test.ts metatest: a selector can't be allowed if the context doesn't feed it (otherwise the policy silently stops applying)

Responses

decisionstring
Required
matchedPolicyIdsstring[]
Required
tracearray