> ## Documentation Index
> Fetch the complete documentation index at: https://checkfu.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# List ActionPolicies

> List the Workspace's ActionPolicies through the standard `data`/`next_page` envelope, each with its name, state, version, and complete rule set. An ActionPolicy only shapes the disposition of an already-granted action; it can never create access.

Checkfu support posture: alpha; hosted. Required evidence journey: governance-registry. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.



## OpenAPI

````yaml /openapi.json get /v1/action-policies
openapi: 3.1.0
info:
  title: Checkfu API
  version: '2026-08-27'
  description: >-
    Authentication is declared per operation: API-key, runtime, or connector
    bearer; Automation signature; or credential-free pairing redemption. Every
    general Checkfu REST request requires the dated `Checkfu-Version` header
    (one of: 2026-08-27); the three MCP JSON-RPC transports use
    `MCP-Protocol-Version`, A2A uses `A2A-Version`, and the provider OAuth
    callback carries neither Checkfu header. API keys resolve one Workspace
    without a request selector; authenticated responses identify it with
    `Checkfu-Workspace-Id`.
servers:
  - url: https://api.checkfu.com
security:
  - bearerAuth: []
tags:
  - name: organizations
  - name: sourceRepositories
  - name: tenants
  - name: workspaces
  - name: principals
  - name: principalGroups
  - name: principalAccessCredentials
  - name: apiKeys
  - name: agents
  - name: harnesses
  - name: harnessRuntime
  - name: sandboxProfiles
  - name: computerProfiles
  - name: permissionAssignments
  - name: actionPolicies
  - name: files
  - name: memoryStores
  - name: dreams
  - name: modelCredentials
  - name: modelRoutingProfiles
  - name: blueprintInstallations
  - name: toolSources
  - name: skills
  - name: skillSources
  - name: agentSources
  - name: skillProposals
  - name: instructionProposals
  - name: catalog
  - name: concepts
  - name: support
  - name: connections
  - name: connectionVaults
  - name: connectionAssignments
  - name: connectedRuntimes
  - name: projects
  - name: collaboration
  - name: automationGraphs
  - name: automations
  - name: actionApprovals
  - name: standingApprovals
  - name: usage
  - name: models
  - name: outcomes
  - name: budgets
  - name: billing
  - name: sessions
  - name: audit
  - name: sessionExports
  - name: runs
  - name: runnerPools
  - name: transcripts
  - name: sessionWatches
  - name: webhookEndpoints
  - name: integrationGateway
  - name: agentDeployments
  - name: workEnvironments
  - name: computers
  - name: computerScreens
  - name: computerBrowserObservations
  - name: computerBrowserActions
  - name: environments
  - name: vaults
  - name: apiMcp
  - name: a2a
paths:
  /v1/action-policies:
    get:
      tags:
        - actionPolicies
      summary: List ActionPolicies
      description: >-
        List the Workspace's ActionPolicies through the standard
        `data`/`next_page` envelope, each with its name, state, version, and
        complete rule set. An ActionPolicy only shapes the disposition of an
        already-granted action; it can never create access.


        Checkfu support posture: alpha; hosted. Required evidence journey:
        governance-registry. Deployment-specific readiness and the latest proven
        release are available from GET /v1/support/capabilities.
      operationId: actionPolicies.listActionPolicies
      parameters:
        - name: checkfu-version
          in: header
          schema:
            type: string
            enum:
              - '2026-08-27'
          required: true
        - name: limit
          in: query
          schema:
            type: integer
            minimum: 1
          required: false
        - name: page
          in: query
          schema:
            type: string
            allOf:
              - pattern: ^c1_[0-9a-z]+$
          required: false
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/Objects_57'
                  next_page:
                    anyOf:
                      - type: string
                      - type: 'null'
                required:
                  - data
                  - next_page
                additionalProperties: false
          headers:
            checkfu-workspace-id:
              description: The Workspace resolved from the authenticated bearer credential.
              required: true
              schema:
                $ref: '#/components/schemas/WorkspaceId'
        '400':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationMalformedError'
        '401':
          description: Typed Checkfu wire error
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - auth.invalid_key
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#auth-invalid-key
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '403':
          description: >-
            The organization, tenant, or workspace backing this key is
            administratively disabled. | Deployment governance or retention
            policy denied the request.
          content:
            application/json:
              schema:
                anyOf:
                  - type: object
                    required:
                      - error
                    properties:
                      error:
                        type: object
                        properties:
                          type:
                            type: string
                            enum:
                              - auth.disabled_tenancy
                          message:
                            type: string
                          more:
                            type: string
                            enum:
                              - >-
                                https://docs.checkfu.com/reference/errors#auth-disabled-tenancy
                            description: >-
                              Stable public documentation and remedy for this
                              error type.
                        required:
                          - type
                          - message
                          - more
                        additionalProperties: false
                    additionalProperties: false
                  - $ref: '#/components/schemas/PolicyDeniedError'
        '429':
          description: Typed Checkfu wire error
          headers:
            retry-after:
              description: >-
                Delay in seconds for rate limits or deployment quotas with a
                known release or UTC reset boundary
              required: false
              schema:
                type: integer
                minimum: 1
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                properties:
                  error:
                    type: object
                    required:
                      - type
                      - message
                      - more
                    properties:
                      type:
                        type: string
                        enum:
                          - budget.exceeded
                      message:
                        type: string
                      more:
                        type: string
                        enum:
                          - >-
                            https://docs.checkfu.com/reference/errors#budget-exceeded
                        description: >-
                          Stable public documentation and remedy for this error
                          type.
                    additionalProperties: false
                additionalProperties: false
        '500':
          description: >-
            An unexpected internal failure occurred; the message contains an
            opaque incident reference.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RuntimeInternalError'
      security:
        - bearerAuth: []
components:
  schemas:
    Objects_57:
      type: object
      properties:
        id:
          $ref: '#/components/schemas/ActionPolicyId'
        workspace_id:
          $ref: '#/components/schemas/WorkspaceId'
        name:
          type: string
          allOf:
            - minLength: 1
            - maxLength: 255
        state:
          type: string
          enum:
            - active
            - disabled
        rules:
          $ref: '#/components/schemas/Arrays_22'
        version:
          type: integer
          allOf:
            - exclusiveMinimum: 0
        created_at:
          type: string
        updated_at:
          type: string
      required:
        - id
        - workspace_id
        - name
        - state
        - rules
        - version
        - created_at
        - updated_at
      additionalProperties: false
    WorkspaceId:
      type: string
      allOf:
        - pattern: ^wrkspc_[0-9a-f]{32}$
    ValidationMalformedError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - validation.malformed
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#validation-malformed
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        The request could not be decoded or violated a declared input
        constraint.
    PolicyDeniedError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - policy.denied
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#policy-denied
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: Deployment governance or retention policy denied the request.
    RuntimeInternalError:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - runtime.internal
            message:
              type: string
            more:
              type: string
              enum:
                - https://docs.checkfu.com/reference/errors#runtime-internal
              description: Stable public documentation and remedy for this error type.
          required:
            - type
            - message
            - more
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      description: >-
        An unexpected internal failure occurred; the message contains an opaque
        incident reference.
    ActionPolicyId:
      type: string
      allOf:
        - pattern: ^apol_[0-9a-f]{32}$
    Arrays_22:
      type: array
      items:
        type: object
        properties:
          id:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 255
          effect:
            $ref: '#/components/schemas/Union_107'
          subject_kind:
            $ref: '#/components/schemas/Union_108'
          subject_id:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 255
              - pattern: ^[^\p{Cc}]+$
          resource_kind:
            $ref: '#/components/schemas/Union_109'
          resource_id:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 255
              - pattern: ^[^\p{Cc}]+$
          permission:
            type: string
            allOf:
              - minLength: 1
              - maxLength: 255
              - pattern: ^[^\p{Cc}]+$
          surface_scope_id:
            $ref: '#/components/schemas/Union_110'
          surface_scope_kind:
            type: string
            enum:
              - root
              - team
              - channel
              - personal
          argument_conditions:
            type: array
            items:
              type: object
              properties:
                path:
                  $ref: '#/components/schemas/Arrays_20'
                predicate:
                  anyOf:
                    - $ref: '#/components/schemas/Objects_51'
                    - $ref: '#/components/schemas/Objects_52'
                    - $ref: '#/components/schemas/Objects_53'
                    - type: object
                      properties:
                        op:
                          type: string
                          enum:
                            - range
                        min:
                          anyOf:
                            - type: number
                            - type: 'null'
                        max:
                          anyOf:
                            - type: number
                            - type: 'null'
                      required:
                        - op
                        - min
                        - max
                      additionalProperties: false
                    - $ref: '#/components/schemas/Objects_54'
                    - $ref: '#/components/schemas/Objects_55'
                    - $ref: '#/components/schemas/Objects_56'
              required:
                - path
                - predicate
              additionalProperties: false
            allOf:
              - maxItems: 16
        required:
          - id
          - effect
          - subject_kind
          - subject_id
          - resource_kind
          - resource_id
          - permission
          - surface_scope_id
        additionalProperties: false
      allOf:
        - minItems: 1
        - maxItems: 256
    Union_107:
      type: string
      enum:
        - allow
        - require_approval
        - deny
    Union_108:
      anyOf:
        - type: string
          enum:
            - '*'
        - $ref: '#/components/schemas/Union_102'
    Union_109:
      anyOf:
        - type: string
          enum:
            - '*'
        - $ref: '#/components/schemas/Union_98'
    Union_110:
      anyOf:
        - type: string
          allOf:
            - minLength: 1
            - maxLength: 255
            - pattern: ^[^\p{Cc}]+$
        - type: 'null'
    Arrays_20:
      type: array
      items:
        type: string
        allOf:
          - minLength: 1
          - maxLength: 128
          - pattern: ^[^\p{Cc}]+$
      allOf:
        - minItems: 1
        - maxItems: 8
    Objects_51:
      type: object
      properties:
        op:
          type: string
          enum:
            - exact
        to:
          $ref: '#/components/schemas/Union_111'
      required:
        - op
        - to
      additionalProperties: false
    Objects_52:
      type: object
      properties:
        op:
          type: string
          enum:
            - one_of
        values:
          $ref: '#/components/schemas/Arrays_21'
      required:
        - op
        - values
      additionalProperties: false
    Objects_53:
      type: object
      properties:
        op:
          type: string
          enum:
            - not_one_of
        values:
          $ref: '#/components/schemas/Arrays_21'
      required:
        - op
        - values
      additionalProperties: false
    Objects_54:
      type: object
      properties:
        op:
          type: string
          enum:
            - prefix
        value:
          $ref: '#/components/schemas/Union_111'
      required:
        - op
        - value
      additionalProperties: false
    Objects_55:
      type: object
      properties:
        op:
          type: string
          enum:
            - contains
        value:
          $ref: '#/components/schemas/Union_111'
      required:
        - op
        - value
      additionalProperties: false
    Objects_56:
      type: object
      properties:
        op:
          type: string
          enum:
            - subset
        of:
          $ref: '#/components/schemas/Arrays_21'
      required:
        - op
        - of
      additionalProperties: false
    Union_102:
      type: string
      enum:
        - principal
        - group
        - agent_definition
        - agent_installation
        - surface_scope
        - session
    Union_98:
      type: string
      enum:
        - agent-definition
        - connection
        - tool-source
        - skill
        - memory-store
        - model-binding
        - harness
        - sandbox-profile
        - surface
    Union_111:
      anyOf:
        - type: object
          properties:
            source:
              type: string
              enum:
                - literal
            value:
              $ref: '#/components/schemas/Union_112'
          required:
            - source
            - value
          additionalProperties: false
        - type: object
          properties:
            source:
              type: string
              enum:
                - fact
            fact:
              type: string
              enum:
                - workspace_id
                - acted_as
                - surface_scope_id
                - connection_provider
          required:
            - source
            - fact
          additionalProperties: false
    Arrays_21:
      type: array
      items:
        $ref: '#/components/schemas/Union_112'
      allOf:
        - minItems: 1
        - maxItems: 64
    Union_112:
      anyOf:
        - type: string
          allOf:
            - maxLength: 512
        - type: number
        - type: boolean
        - type: 'null'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````