Skip to main content
PATCH
Updates the per-account PolicySettings singleton.
Updates the account’s governance settings. The API key must belong to an account Admin on an Enterprise account, either a user or a service account with the Admin role. Requests with any other key fail with a permission error. Pass updateMask with the proto field names of the settings you are changing, comma-separated. If you omit it, the mask is derived from the fields present in your request body. Settings outside the mask are left unchanged.

Authorizations

Authorization
string
header
required

Bearer authentication using your Fireworks API key. Format: Bearer <API_KEY>

Path Parameters

account_id
string
required

The Account Id

Body

application/json

The policy settings to update. policy_settings.name must be populated. Format: accounts/{account}/policySettings

defaultPermissions
object

Per-account default permissions. If unset, defaults to allow-all. This powers the UI's "Default" row.

rules
object[]

Per-model override rows. A model not listed here uses default_permissions.

cmekRequired
boolean

Whether new customer-data resources for this account must be CMEK-encrypted. Readable by the account, but only a Fireworks superuser can change it (the write path gates this explicitly). Enabling requires a READY primary ExternalKey.

residency
enum<string>
default:MULTI_REGION_UNSPECIFIED

Restricts serving to one geography when set. An absent value leaves the account unrestricted.

Available options:
MULTI_REGION_UNSPECIFIED,
GLOBAL,
US,
CANADA,
EUROPE,
APAC
zeroDataRetention
object

Zero Data Retention policy for the account. When absent, ZDR is not enforced. Independent of model access permissions and CMEK.

Response

200 - application/json

A successful response.

Account-level policy settings (singleton per account). Holds model access and may grow with other policy sections (e.g. regional residency) without separate top-level API resources.

name
string
read-only
defaultPermissions
object

Per-account default permissions. If unset, defaults to allow-all. This powers the UI's "Default" row.

rules
object[]

Per-model override rows. A model not listed here uses default_permissions.

updateTime
string<date-time>
read-only
cmekRequired
boolean

Whether new customer-data resources for this account must be CMEK-encrypted. Readable by the account, but only a Fireworks superuser can change it (the write path gates this explicitly). Enabling requires a READY primary ExternalKey.

residency
enum<string>
default:MULTI_REGION_UNSPECIFIED

Restricts serving to one geography when set. An absent value leaves the account unrestricted.

Available options:
MULTI_REGION_UNSPECIFIED,
GLOBAL,
US,
CANADA,
EUROPE,
APAC
zeroDataRetention
object

Zero Data Retention policy for the account. When absent, ZDR is not enforced. Independent of model access permissions and CMEK.