> ## Documentation Index
> Fetch the complete documentation index at: https://docs.instacloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set agent policy

> **Token scope:** `account` · `org` · `project` — read-only tokens refused (not a GET).



## OpenAPI

````yaml /openapi/project.json put /projects/{projectId}/agent-policy
openapi: 3.1.0
info:
  title: InstaCloud API — Project level
  version: 0.1.0
  description: >-
    Endpoints under `/projects/{projectId}`: branches, services, deploys,
    secrets, databases, storage, cron, observability, governance. Callable with
    any token whose binding covers the project.


    Generated from the platform's own OpenAPI document
    (https://api.instacloud.com/openapi.json); see the [API
    overview](/reference/api/overview) for authentication and token scopes.
servers:
  - url: https://api.instacloud.com
    description: InstaCloud
security:
  - bearerAuth: []
tags:
  - name: Projects
    description: Projects inside an organization.
  - name: Branches
    description: >-
      Branch environments of a project: isolated database, storage and compute
      per branch.
  - name: Services
    description: 'Services on a branch: compute, postgres, storage and managed databases.'
  - name: Deploy
    description: Deploy an image or a source to a compute service.
  - name: Compute
    description: Build output of a compute service.
  - name: Secrets
    description: User secrets, service credentials and how they bind into compute env.
  - name: Database
    description: Postgres databases, extensions, credentials and ad-hoc SQL.
  - name: Storage
    description: Objects in a storage service.
  - name: Backups
    description: Database backups and restores.
  - name: Cron
    description: Scheduled HTTP calls against a service or an external URL.
  - name: Observability
    description: Logs, metrics, deploy events and database insight.
  - name: Governance
    description: Per-project agent policy and the approval queue.
  - name: Audit
    description: The project's event timeline, including agent-ingested events.
  - name: Domains
    description: >-
      Domains bought through InstaCloud, bring-your-own zones and their DNS
      records.
  - name: Billing
    description: Usage, cycles, invoices and credits.
  - name: Templates
    description: Deploy a template into a project.
paths:
  /projects/{projectId}/agent-policy:
    put:
      tags:
        - Governance
      summary: Set agent policy
      description: >-
        **Token scope:** `account` · `org` · `project` — read-only tokens
        refused (not a GET).
      operationId: setAgentPolicy
      parameters:
        - schema:
            format: uuid
            type: string
          in: path
          name: projectId
          required: true
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                mode:
                  anyOf:
                    - type: string
                      enum:
                        - full_access
                    - type: string
                      enum:
                        - read_only
                    - type: string
                      enum:
                        - branch_specific
                    - type: string
                      enum:
                        - customize
                    - deprecated: true
                      type: string
                      enum:
                        - branch_developer
                protectedBranchIds:
                  type: array
                  items:
                    format: uuid
                    type: string
                rules:
                  type: object
                  additionalProperties:
                    anyOf:
                      - const: allow
                        type: string
                      - const: deny
                        type: string
                      - const: approve
                        type: string
                branchDeveloperRules:
                  deprecated: true
                  type: object
                  additionalProperties:
                    anyOf:
                      - const: allow
                        type: string
                      - const: deny
                        type: string
                      - const: approve
                        type: string
                updatedBy:
                  type: string
                updatedAt:
                  type: string
              required:
                - mode
                - protectedBranchIds
        required: true
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  policy:
                    type: object
                    properties:
                      mode:
                        anyOf:
                          - type: string
                            enum:
                              - full_access
                          - type: string
                            enum:
                              - read_only
                          - type: string
                            enum:
                              - branch_specific
                          - type: string
                            enum:
                              - customize
                      protectedBranchIds:
                        type: array
                        items:
                          format: uuid
                          type: string
                      rules:
                        type: object
                        additionalProperties:
                          anyOf:
                            - const: allow
                              type: string
                            - const: deny
                              type: string
                            - const: approve
                              type: string
                      branchDeveloperRules:
                        deprecated: true
                        type: object
                        additionalProperties:
                          anyOf:
                            - const: allow
                              type: string
                            - const: deny
                              type: string
                            - const: approve
                              type: string
                      updatedBy:
                        type: string
                      updatedAt:
                        type: string
                    required:
                      - mode
                      - protectedBranchIds
                      - rules
                      - branchDeveloperRules
                required:
                  - policy
        '202':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  status:
                    type: string
                  approvalId:
                    type: string
                  action:
                    type: string
                  actions:
                    type: array
                    items:
                      type: string
                  message:
                    type: string
                  url:
                    type: string
                required:
                  - status
                  - approvalId
                  - action
                  - actions
                  - message
                  - url
        '403':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                required:
                  - error
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: Session access JWT or an API token (`insta_<prefix>_<secret>`).

````