Policies API v1

REST reference for the Policies service v1 API: policy reports, policy exceptions, and compliance.

Applies to: Nirmata Control Hub 4.0 and later

The Policies API v1 is a JSON REST API for the policy and compliance data in Nirmata Control Hub. Use it to read policy reports and findings, manage policy exceptions and exception requests, and work with compliance standards, controls, and compliance reports.

Unlike the model-based platform API, the v1 API uses fixed resource paths and plain JSON request and response bodies. The URL parameters (fields, filter, query, and so on) and common endpoints do not apply to v1 endpoints.

Base URL

All endpoints are served under:

https://<your-nirmata-host>/policies/api/v1

For Nirmata Control Hub SaaS, <your-nirmata-host> is nirmata.io.

Authentication

Every request needs an Authorization header. Two schemes are supported:

Authorization: NIRMATA-API <api-token>
Authorization: Bearer <jwt>

To create an API token, see API Tokens. Requests run as the user who owns the token, scoped to that user’s tenant. You never pass a tenant ID explicitly.

export NIRMATA_URL=https://nirmata.io
export NIRMATA_TOKEN=<api-token>

curl -s -H "Authorization: NIRMATA-API $NIRMATA_TOKEN" \
  "$NIRMATA_URL/policies/api/v1/policy-reports?limit=10"

Roles

Access is controlled by the user roles in Nirmata Control Hub (see Users and Roles). Each endpoint lists the roles allowed to call it. The table below summarizes the default permissions for the resources in this reference:

Resourceadmin, platformsecuritydevops
Policy reports and findingsRead, write, deleteRead, write, deleteRead
Compliance standards, controls, and reportsRead, write, deleteRead, write, deleteRead
Policy exceptionsRead, write, deleteRead, write, deleteRead, write, delete (own only)
Policy exception requestsRead, write, deleteRead, write, deleteRead, write, delete (own only)

An endpoint’s role list can be narrower than this table. For example, approving an exception request may be limited to specific roles. A request from a user whose role is not allowed returns 403 Forbidden.

Pagination

List endpoints accept limit and offset query parameters and return a page envelope:

{
  "items": [ ... ],
  "total": 132,
  "limit": 50,
  "offset": 0
}
ParameterDefaultDescription
limit50Maximum number of items to return.
offset0Number of items to skip.

Some endpoints use a different envelope or extra filter parameters. Each endpoint’s reference documents its own response shape.

Errors

Errors return a standard HTTP status code and a JSON body with an error message:

{ "error": "Policy exception not found" }
StatusMeaning
400The request is malformed or failed validation.
401, 403The credentials are missing or invalid, or the caller’s role is not allowed to perform the operation.
404The resource does not exist in the caller’s tenant.
500Unexpected server error.

Endpoint groups

GroupWhat it covers
Policy ReportsPolicy reports, scan findings, and publishing scan results
Policy ExceptionsKyverno policy exceptions and the resources they cover
Policy Exception RequestsException requests submitted for approval (read only)
Compliance StandardsAvailable standards, enablement, rescans, and custom standards
Compliance ReportsCompliance reports, control findings, history, and namespace compliance
Compliance ScansScheduled and on-demand compliance scans
Compliance Audit ReportsGenerating and downloading audit report artifacts
Compliance PublishingPublishing compliance snapshots and evidence packages
Compliance CatalogThe compliance standards and controls catalog

Policy Reports

Policies API v1 endpoints for policy reports, scan findings, and publishing scan results.

Policy Exceptions

Policies API v1 endpoints for reading Kyverno policy exceptions.

Policy Exception Requests

Policies API v1 endpoints for reading policy exception requests.

Compliance Standards

Policies API v1 endpoints for compliance standards, enablement, and custom standards.

Compliance Reports

Policies API v1 endpoints for compliance reports, history, and namespace compliance.

Compliance Scans

Policies API v1 endpoints for compliance scan schedules and on-demand scans.

Compliance Audit Reports

Policies API v1 endpoints for generating and downloading compliance audit reports.

Compliance Publishing

Policies API v1 endpoints for publishing compliance snapshots and evidence packages.

Compliance Catalog

Policies API v1 endpoints for the compliance standards and controls catalog.