> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fireworks.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For Fireworks Nexus, start at https://docs.fireworks.ai/nexus.
> Use https://docs.fireworks.ai/nexus/quickstart for coding harnesses, custom agents, APIs, SDKs, and LLM gateways.
> Use https://docs.fireworks.ai/nexus/firerouter for how model routers work, the supported model list, composition, closed-model credentials, and pricing.
> Prefer canonical short model IDs such as firerouter/opus. In LiteLLM litellm_params.model, use the full path fireworks_ai/accounts/fireworks/routers/firerouter/opus.
> Family names such as opus track the latest evaluated family version; do not describe them as fixed model versions.

# Update Policy Settings

Updates the account's governance settings. The API key must belong to an account **Admin** on an Enterprise account, either a user or a [service account](/accounts/service-accounts) with the Admin role. Requests with any other key fail with a permission error.

Pass `updateMask` with the proto field names of the settings you are changing, comma-separated. If you omit it, the mask is derived from the fields present in your request body. Settings outside the mask are left unchanged.

| Setting | `updateMask` | Notes |
| :- | :- | :- |
| [Model access policy](/accounts/model-access-policy) | `default_permissions`, `rules` | `rules` replaces the whole list. Every permissions object needs all four booleans. |
| [Data residency](/accounts/data-residency) | `residency` | Accepts `US`. Mask `residency` and omit the field to remove the restriction. |
| [Zero Data Retention policy](/accounts/zero-data-retention) | `zero_data_retention` | Replaces the whole section, so always send `defaultEnforced`. A scope you leave out follows `defaultEnforced`. |
| [Customer-managed encryption keys](/guides/security_compliance/secure_training/cmek) | `cmek_required` | Only Fireworks can change it. |

```bash theme={null}
curl -X PATCH \
  "https://api.fireworks.ai/v1/accounts/${ACCOUNT_ID}/policySettings?updateMask=zero_data_retention" \
  -H "Authorization: Bearer ${FIREWORKS_API_KEY}" \
  -H "Content-Type: application/json" \
  -d '{"zeroDataRetention": {"defaultEnforced": true}}'
```


## OpenAPI

````yaml patch /v1/accounts/{account_id}/policySettings
openapi: 3.1.0
info:
  title: Gateway REST API
  version: 5.10.0
servers:
  - url: https://api.fireworks.ai
security:
  - BearerAuth: []
tags:
  - name: AccountService
  - name: DeploymentService
  - name: Gateway
  - name: ModelService
  - name: TrainingService
paths:
  /v1/accounts/{account_id}/policySettings:
    patch:
      tags:
        - Gateway
      summary: Updates the per-account PolicySettings singleton.
      operationId: Gateway_UpdatePolicySettings
      parameters:
        - name: account_id
          in: path
          required: true
          description: The Account Id
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                defaultPermissions:
                  $ref: '#/components/schemas/PolicySettingsModelPermissions'
                  description: >-
                    Per-account default permissions. If unset, defaults to
                    allow-all.

                    This powers the UI's "Default" row.
                rules:
                  type: array
                  items:
                    $ref: '#/components/schemas/PolicySettingsModelAccessRule'
                    type: object
                  description: >-
                    Per-model override rows. A model not listed here uses
                    default_permissions.
                updateTime:
                  type: string
                  format: date-time
                  readOnly: true
                cmekRequired:
                  type: boolean
                  description: >-
                    Whether new customer-data resources for this account must be
                    CMEK-encrypted.

                    Readable by the account, but only a Fireworks superuser can
                    change it (the

                    write path gates this explicitly). Enabling requires a READY
                    primary

                    ExternalKey.
                residency:
                  $ref: '#/components/schemas/gatewayMultiRegion'
                  description: >-
                    Restricts serving to one geography when set. An absent value
                    leaves the

                    account unrestricted.
                zeroDataRetention:
                  $ref: '#/components/schemas/PolicySettingsZeroDataRetentionPolicy'
                  description: >-
                    Zero Data Retention policy for the account. When absent, ZDR
                    is not

                    enforced. Independent of model access permissions and CMEK.
              title: >-
                The policy settings to update. `policy_settings.name` must be
                populated.

                Format: accounts/{account}/policySettings
        description: >-
          The policy settings to update. `policy_settings.name` must be
          populated.

          Format: accounts/{account}/policySettings
        required: true
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/gatewayPolicySettings'
components:
  schemas:
    PolicySettingsModelPermissions:
      type: object
      properties:
        allowServerless:
          type: boolean
        allowDedicatedDeployments:
          type: boolean
        allowTraining:
          type: boolean
        allowServerlessFast:
          type: boolean
          description: >-
            Serverless inference through the model's Fast serving mode, which is

            served by a separate router rather than the base model id.
            Independent

            of allow_serverless: an account can be allowed standard serverless
            on a

            model while being denied its Fast variant.
      description: >-
        Each boolean is required when ModelPermissions is sent. Using `optional`

        gives the field presence tracking, and `(buf.validate.field).required`

        makes server-side validation reject messages with any unset boolean.
        This

        forces callers (frontend, firectl, scripts) to always send all four

        permissions explicitly, instead of silently relying on bool's default of

        `false`. It also causes proto3 JSON to emit explicit `false` values on

        output, so a Get response always shows the full picture.
      required:
        - allowServerless
        - allowDedicatedDeployments
        - allowTraining
        - allowServerlessFast
    PolicySettingsModelAccessRule:
      type: object
      properties:
        model:
          type: string
        permissions:
          $ref: '#/components/schemas/PolicySettingsModelPermissions'
      description: >-
        One per-model override. This is not a partial patch; it is a complete
        row

        replacing defaults for this model.
      required:
        - model
        - permissions
    gatewayMultiRegion:
      type: string
      enum:
        - MULTI_REGION_UNSPECIFIED
        - GLOBAL
        - US
        - CANADA
        - EUROPE
        - APAC
      default: MULTI_REGION_UNSPECIFIED
    PolicySettingsZeroDataRetentionPolicy:
      type: object
      properties:
        defaultEnforced:
          type: boolean
          description: >-
            Account default for Inference and Training. Required whenever this
            policy

            is supplied; false means ZDR is off unless a scope enforces it.
        inference:
          $ref: '#/components/schemas/ZeroDataRetentionPolicyInferencePolicy'
          description: Inference enforcement. Omit to inherit default_enforced.
        training:
          $ref: '#/components/schemas/ZeroDataRetentionPolicyTrainingPolicy'
          description: Training enforcement. Omit to inherit default_enforced.
      description: >-
        Zero Data Retention (ZDR) blocks new work that would retain customer
        inputs

        or outputs, such as stored responses, batch jobs, uploads, and training.

        Compatible stateless requests continue. Enabling ZDR does not delete
        existing

        data. Caches, non-content metadata, and third-party retention are
        excluded.


        Each scope uses its own enforcement when set, otherwise
        default_enforced.
      required:
        - defaultEnforced
    gatewayPolicySettings:
      type: object
      properties:
        name:
          type: string
          title: Resource name, e.g. accounts/my-account/policySettings
          readOnly: true
        defaultPermissions:
          $ref: '#/components/schemas/PolicySettingsModelPermissions'
          description: |-
            Per-account default permissions. If unset, defaults to allow-all.
            This powers the UI's "Default" row.
        rules:
          type: array
          items:
            $ref: '#/components/schemas/PolicySettingsModelAccessRule'
            type: object
          description: >-
            Per-model override rows. A model not listed here uses
            default_permissions.
        updateTime:
          type: string
          format: date-time
          readOnly: true
        cmekRequired:
          type: boolean
          description: >-
            Whether new customer-data resources for this account must be
            CMEK-encrypted.

            Readable by the account, but only a Fireworks superuser can change
            it (the

            write path gates this explicitly). Enabling requires a READY primary

            ExternalKey.
        residency:
          $ref: '#/components/schemas/gatewayMultiRegion'
          description: >-
            Restricts serving to one geography when set. An absent value leaves
            the

            account unrestricted.
        zeroDataRetention:
          $ref: '#/components/schemas/PolicySettingsZeroDataRetentionPolicy'
          description: |-
            Zero Data Retention policy for the account. When absent, ZDR is not
            enforced. Independent of model access permissions and CMEK.
      description: >-
        Account-level policy settings (singleton per account). Holds model
        access and may grow with

        other policy sections (e.g. regional residency) without separate
        top-level API resources.
    ZeroDataRetentionPolicyInferencePolicy:
      type: object
      properties:
        enforcement:
          $ref: >-
            #/components/schemas/ZeroDataRetentionPolicyInferencePolicyEnforcement
      description: >-
        Enforcement for Inference, including chat and completion requests,
        stored

        or background responses, and batch inference.
    ZeroDataRetentionPolicyTrainingPolicy:
      type: object
      properties:
        enforcement:
          $ref: >-
            #/components/schemas/ZeroDataRetentionPolicyTrainingPolicyEnforcement
      description: |-
        Enforcement for Training, including fine-tuning jobs, training sessions,
        checkpoints, and evaluations. Enforced Training blocks all new Training
        work because it retains datasets, checkpoints, and trained weights.
    ZeroDataRetentionPolicyInferencePolicyEnforcement:
      type: string
      enum:
        - ENFORCEMENT_UNSPECIFIED
        - ENFORCED
        - NOT_ENFORCED
      default: ENFORCEMENT_UNSPECIFIED
      description: |-
        - ENFORCEMENT_UNSPECIFIED: Inherits default_enforced.
         - ENFORCED: Blocks new Inference work that retains customer content.
         - NOT_ENFORCED: Allows Inference work that retains customer content.
    ZeroDataRetentionPolicyTrainingPolicyEnforcement:
      type: string
      enum:
        - ENFORCEMENT_UNSPECIFIED
        - ENFORCED
        - NOT_ENFORCED
      default: ENFORCEMENT_UNSPECIFIED
      description: |-
        - ENFORCEMENT_UNSPECIFIED: Inherits default_enforced.
         - ENFORCED: Blocks new Training work.
         - NOT_ENFORCED: Allows new Training work.
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        Bearer authentication using your Fireworks API key. Format: Bearer
        <API_KEY>
      bearerFormat: API_KEY

````