---
title: Autonomy policy endpoints
sidebar_title: Autonomy policy
description: Read and write the account autonomy policy and per-repository overrides, with optimistic version checks.
---

These endpoints read and write the settings described in
[Autonomy policy](../../workspace/autonomy-policy.md).

## Get the account policy

`GET`{ .get } `/developer/account/policy`
{ .endpoint }

```jsonc title="200 OK · DeveloperPolicyRead"
{
  "scope": "account",
  "scope_id": "a41e…",
  "version": 0,          // 0 = nothing saved yet; these are the safe defaults
  "policy": { "force_push": "ask", "delivery_mode": "preserve_only", … },
  "updated_at": null
}
```

## Replace the account policy

`PUT`{ .put } `/developer/account/policy`
{ .endpoint }

Send all twelve fields. Omit `expected_version` on the first write; afterwards,
send the `version` you last received.

```json title="Request"
{
  "policy": {
    "force_push": "deny",
    "run_tests_before_claim": true,
    "package_installs": "ask",
    "network": "ask",
    "destructive_actions": "ask",
    "production_credentials": "deny",
    "delivery_mode": "draft_pr",
    "unverified_delivery": "preserve_only",
    "deployment": "deny",
    "autonomy_ceiling": "draft_pr",
    "nightly_backlog_sweep": false,
    "show_execution_rationale": true
  },
  "expected_version": 1
}
```

Errors: `409` when the version is stale, `422` when a value is invalid —
including `run_tests_before_claim: false`.

## Repository overrides

`GET`{ .get } `/developer/account/repositories/{repository_id}/policy`
{ .endpoint }

`PUT`{ .put } `/developer/account/repositories/{repository_id}/policy`
{ .endpoint }

An override is **sparse**: it holds only the fields the repository changes.
The response shows both the override and the merged result.

```jsonc title="200 OK · DeveloperRepositoryPolicyRead"
{
  "repository_id": "9c2d…",
  "override": {
    "scope": "repository",
    "version": 2,
    "policy": { "delivery_mode": "draft_pr" }   // only what this repo changes
  },
  "effective": {
    "scope": "effective",
    "policy": { /* complete, merged with the account policy */ }
  }
}
```

Present `effective` as what will apply, and `override` as what this repository
changes. `override` is `null` when the repository inherits everything.

To write an override, send only the fields to change:

```json title="Request"
{ "policy": { "package_installs": "allow" }, "expected_version": 2 }
```

Errors: `404` for an unknown repository, `409` for a stale version, `422` for an
invalid value.
