openapi: 3.0.1 info: title: Blaxel Control Plane Agents Policies API description: Representative specification of the Blaxel (formerly Beamlit) control plane REST API. The control plane manages agents, MCP/function servers, models, sandboxes, jobs, policies, integrations, and workspaces. Authenticate with a Bearer API key (Authorization or X-Blaxel-Authorization header) or an OAuth 2.0 short-lived JWT. Requests may include a Blaxel-Version header (YYYY-MM-DD) and, for multi-workspace accounts, an X-Blaxel-Workspace header. termsOfService: https://blaxel.ai/terms-of-service contact: name: Blaxel Support email: support@blaxel.ai version: v0 servers: - url: https://api.blaxel.ai/v0 security: - apiKey: [] - bearerAuth: [] tags: - name: Policies paths: /policies: get: operationId: listPolicies tags: - Policies summary: List all policies in the workspace. responses: '200': description: A list of policies. content: application/json: schema: type: array items: $ref: '#/components/schemas/Policy' post: operationId: createPolicy tags: - Policies summary: Create a new policy. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Policy' responses: '200': description: The created policy. content: application/json: schema: $ref: '#/components/schemas/Policy' /policies/{policy_name}: parameters: - name: policy_name in: path required: true schema: type: string get: operationId: getPolicy tags: - Policies summary: Get a policy by name. responses: '200': description: The requested policy. put: operationId: updatePolicy tags: - Policies summary: Update a policy by name. responses: '200': description: The updated policy. delete: operationId: deletePolicy tags: - Policies summary: Delete a policy by name. responses: '200': description: The deleted policy. components: schemas: Policy: type: object properties: metadata: $ref: '#/components/schemas/Metadata' spec: type: object properties: type: type: string locations: type: array items: type: object flavors: type: array items: type: object Metadata: type: object properties: name: type: string displayName: type: string workspace: type: string createdAt: type: string format: date-time updatedAt: type: string format: date-time labels: type: object additionalProperties: type: string securitySchemes: apiKey: type: apiKey in: header name: X-Blaxel-Authorization description: API key supplied as "Bearer YOUR-API-KEY". bearerAuth: type: http scheme: bearer bearerFormat: JWT description: OAuth 2.0 short-lived JWT access token.