Skip to main content
GET
Returns the singleton PolicySettings for the given account.
Returns the account’s governance settings in one object: Any account member can read the policy settings.
An absent residency means serving is unrestricted, and an absent zeroDataRetention means the policy is off. An account that has never saved policy settings can return 404, which also means no policy is set.

Authorizations

Authorization
string
header
required

Bearer authentication using your Fireworks API key. Format: Bearer <API_KEY>

Path Parameters

account_id
string
required

The Account Id

Response

200 - application/json

A successful response.

Account-level policy settings (singleton per account). Holds model access and may grow with other policy sections (e.g. regional residency) without separate top-level API resources.

name
string
read-only
defaultPermissions
object

Per-account default permissions. If unset, defaults to allow-all. This powers the UI's "Default" row.

rules
object[]

Per-model override rows. A model not listed here uses default_permissions.

updateTime
string<date-time>
read-only
cmekRequired
boolean

Whether new customer-data resources for this account must be CMEK-encrypted. Readable by the account, but only a Fireworks superuser can change it (the write path gates this explicitly). Enabling requires a READY primary ExternalKey.

residency
enum<string>
default:MULTI_REGION_UNSPECIFIED

Restricts serving to one geography when set. An absent value leaves the account unrestricted.

Available options:
MULTI_REGION_UNSPECIFIED,
GLOBAL,
US,
CANADA,
EUROPE,
APAC
zeroDataRetention
object

Zero Data Retention policy for the account. When absent, ZDR is not enforced. Independent of model access permissions and CMEK.