> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fireworks.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For Fireworks Nexus, start at https://docs.fireworks.ai/nexus.
> Use https://docs.fireworks.ai/nexus/quickstart for coding harnesses, custom agents, APIs, SDKs, and LLM gateways.
> Use https://docs.fireworks.ai/nexus/firerouter for how model routers work, the supported model list, composition, closed-model credentials, and pricing.
> Prefer canonical short model IDs such as firerouter/opus. In LiteLLM litellm_params.model, use the full path fireworks_ai/accounts/fireworks/routers/firerouter/opus.
> Family names such as opus track the latest evaluated family version; do not describe them as fixed model versions.

# Get Policy Settings

Returns the account's governance settings in one object:

| Field | Setting |
| :- | :- |
| `defaultPermissions`, `rules` | [Model access policy](/accounts/model-access-policy) |
| `residency` | [Data residency](/accounts/data-residency) |
| `zeroDataRetention` | [Zero Data Retention policy](/accounts/zero-data-retention) |
| `cmekRequired` | [Customer-managed encryption keys](/guides/security_compliance/secure_training/cmek) |

Any account member can read the policy settings.

```bash theme={null}
curl -s "https://api.fireworks.ai/v1/accounts/${ACCOUNT_ID}/policySettings" \
  -H "Authorization: Bearer ${FIREWORKS_API_KEY}"
```

An absent `residency` means serving is unrestricted, and an absent `zeroDataRetention` means the policy is off. An account that has never saved policy settings can return `404`, which also means no policy is set.


## OpenAPI

````yaml get /v1/accounts/{account_id}/policySettings
openapi: 3.1.0
info:
  title: Gateway REST API
  version: 5.10.0
servers:
  - url: https://api.fireworks.ai
security:
  - BearerAuth: []
tags:
  - name: AccountService
  - name: DeploymentService
  - name: Gateway
  - name: ModelService
  - name: TrainingService
paths:
  /v1/accounts/{account_id}/policySettings:
    get:
      tags:
        - Gateway
      summary: Returns the singleton PolicySettings for the given account.
      operationId: Gateway_GetPolicySettings
      parameters:
        - name: account_id
          in: path
          required: true
          description: The Account Id
          schema:
            type: string
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/gatewayPolicySettings'
components:
  schemas:
    gatewayPolicySettings:
      type: object
      properties:
        name:
          type: string
          title: Resource name, e.g. accounts/my-account/policySettings
          readOnly: true
        defaultPermissions:
          $ref: '#/components/schemas/PolicySettingsModelPermissions'
          description: |-
            Per-account default permissions. If unset, defaults to allow-all.
            This powers the UI's "Default" row.
        rules:
          type: array
          items:
            $ref: '#/components/schemas/PolicySettingsModelAccessRule'
            type: object
          description: >-
            Per-model override rows. A model not listed here uses
            default_permissions.
        updateTime:
          type: string
          format: date-time
          readOnly: true
        cmekRequired:
          type: boolean
          description: >-
            Whether new customer-data resources for this account must be
            CMEK-encrypted.

            Readable by the account, but only a Fireworks superuser can change
            it (the

            write path gates this explicitly). Enabling requires a READY primary

            ExternalKey.
        residency:
          $ref: '#/components/schemas/gatewayMultiRegion'
          description: >-
            Restricts serving to one geography when set. An absent value leaves
            the

            account unrestricted.
        zeroDataRetention:
          $ref: '#/components/schemas/PolicySettingsZeroDataRetentionPolicy'
          description: |-
            Zero Data Retention policy for the account. When absent, ZDR is not
            enforced. Independent of model access permissions and CMEK.
      description: >-
        Account-level policy settings (singleton per account). Holds model
        access and may grow with

        other policy sections (e.g. regional residency) without separate
        top-level API resources.
    PolicySettingsModelPermissions:
      type: object
      properties:
        allowServerless:
          type: boolean
        allowDedicatedDeployments:
          type: boolean
        allowTraining:
          type: boolean
        allowServerlessFast:
          type: boolean
          description: >-
            Serverless inference through the model's Fast serving mode, which is

            served by a separate router rather than the base model id.
            Independent

            of allow_serverless: an account can be allowed standard serverless
            on a

            model while being denied its Fast variant.
      description: >-
        Each boolean is required when ModelPermissions is sent. Using `optional`

        gives the field presence tracking, and `(buf.validate.field).required`

        makes server-side validation reject messages with any unset boolean.
        This

        forces callers (frontend, firectl, scripts) to always send all four

        permissions explicitly, instead of silently relying on bool's default of

        `false`. It also causes proto3 JSON to emit explicit `false` values on

        output, so a Get response always shows the full picture.
      required:
        - allowServerless
        - allowDedicatedDeployments
        - allowTraining
        - allowServerlessFast
    PolicySettingsModelAccessRule:
      type: object
      properties:
        model:
          type: string
        permissions:
          $ref: '#/components/schemas/PolicySettingsModelPermissions'
      description: >-
        One per-model override. This is not a partial patch; it is a complete
        row

        replacing defaults for this model.
      required:
        - model
        - permissions
    gatewayMultiRegion:
      type: string
      enum:
        - MULTI_REGION_UNSPECIFIED
        - GLOBAL
        - US
        - CANADA
        - EUROPE
        - APAC
      default: MULTI_REGION_UNSPECIFIED
    PolicySettingsZeroDataRetentionPolicy:
      type: object
      properties:
        defaultEnforced:
          type: boolean
          description: >-
            Account default for Inference and Training. Required whenever this
            policy

            is supplied; false means ZDR is off unless a scope enforces it.
        inference:
          $ref: '#/components/schemas/ZeroDataRetentionPolicyInferencePolicy'
          description: Inference enforcement. Omit to inherit default_enforced.
        training:
          $ref: '#/components/schemas/ZeroDataRetentionPolicyTrainingPolicy'
          description: Training enforcement. Omit to inherit default_enforced.
      description: >-
        Zero Data Retention (ZDR) blocks new work that would retain customer
        inputs

        or outputs, such as stored responses, batch jobs, uploads, and training.

        Compatible stateless requests continue. Enabling ZDR does not delete
        existing

        data. Caches, non-content metadata, and third-party retention are
        excluded.


        Each scope uses its own enforcement when set, otherwise
        default_enforced.
      required:
        - defaultEnforced
    ZeroDataRetentionPolicyInferencePolicy:
      type: object
      properties:
        enforcement:
          $ref: >-
            #/components/schemas/ZeroDataRetentionPolicyInferencePolicyEnforcement
      description: >-
        Enforcement for Inference, including chat and completion requests,
        stored

        or background responses, and batch inference.
    ZeroDataRetentionPolicyTrainingPolicy:
      type: object
      properties:
        enforcement:
          $ref: >-
            #/components/schemas/ZeroDataRetentionPolicyTrainingPolicyEnforcement
      description: |-
        Enforcement for Training, including fine-tuning jobs, training sessions,
        checkpoints, and evaluations. Enforced Training blocks all new Training
        work because it retains datasets, checkpoints, and trained weights.
    ZeroDataRetentionPolicyInferencePolicyEnforcement:
      type: string
      enum:
        - ENFORCEMENT_UNSPECIFIED
        - ENFORCED
        - NOT_ENFORCED
      default: ENFORCEMENT_UNSPECIFIED
      description: |-
        - ENFORCEMENT_UNSPECIFIED: Inherits default_enforced.
         - ENFORCED: Blocks new Inference work that retains customer content.
         - NOT_ENFORCED: Allows Inference work that retains customer content.
    ZeroDataRetentionPolicyTrainingPolicyEnforcement:
      type: string
      enum:
        - ENFORCEMENT_UNSPECIFIED
        - ENFORCED
        - NOT_ENFORCED
      default: ENFORCEMENT_UNSPECIFIED
      description: |-
        - ENFORCEMENT_UNSPECIFIED: Inherits default_enforced.
         - ENFORCED: Blocks new Training work.
         - NOT_ENFORCED: Allows new Training work.
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        Bearer authentication using your Fireworks API key. Format: Bearer
        <API_KEY>
      bearerFormat: API_KEY

````