How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

AppOmni Policies API

Create, read, update and delete AppOmni security policies and the rules inside them, run and inspect policy assessments, and handle rule events — closing them, converting them to exceptions, or bulk deleting rules.

AppOmni Policies API is one of 9 APIs that AppOmni publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Policies, Governance, and Posture Management. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 23 operations across 22 paths, organized into 2 resource areas, and defines 1 schema. It is described by OpenAPI 3.1.0, at version 1.0.0.

Requests are made against a single base URL, https://{instance}.appomni.com.

23 operations 22 paths 1 schemas 2 DELETE15 GET3 PATCH3 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
1.0.0
Base URL
https://{instance}.appomni.com
Authentication
HTTP Bearer
Contact
Resource Areas
2

Authentication & Security 1

AppOmni Policies API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (bearerAuth). By default, every request must be authenticated.

  • bearerAuth — AppOmni API access token, created and managed in the AppOmni platform under Settings API Settings. Sent as Authorization: Bearer .

Paths & Operations 23

Across 22 paths, the API surfaces 23 operations — 2 DELETE, 15 GET, 3 PATCH, 3 POST. They span 2 resource areas: Policies, [Beta] Policy Assessment Stats. Each is listed below with its method, path, parameters, and response codes.

Policies 22
GET
/api/v1/core/policy/
Retrieve Posture Policies
retrievePosturePolicies 1 param → 200401403
GET
/api/v1/core/policy/{id}/
Get Policy
getPolicy 1 param → 200401403
PATCH
/api/v1/core/policy/{id}/
Assign Target Tags to Policy
assignTargetTagsToPolicy 1 param body → 200401403
POST
/api/v1/core/policy/{id}/scan/
Start Policy Scan
startPolicyScan 1 param → 201401403
GET
/api/v1/core/policyassessment/check_status/
Check Policy Scan Status and Results
checkPolicyScanStatusAndResults → 200401403
GET
/api/v1/core/ruleevent/
List Open Policy Issues
listOpenPolicyIssues → 200401403
GET
/api/v1/compliance/evaluated_controls/
List Compliance Controls for Policy Rule
listComplianceControlsForPolicyRule 1 param → 200401403
GET
/api/v1/{service_type}/rule/
Retrieve Selected Posture Policy Rule Options
retrieveSelectedPosturePolicyRuleOptions 2 params → 200401403
GET
/api/v1/{policy_type}/rule/
Retrieve Rules for Policy
retrieveRulesForPolicy 2 params → 200401403
PATCH
/api/v1/{service_type}/rule/{rule_id}/
Update Policy Rule
updatePolicyRule 2 params body → 200401403
GET
/api/v1/core/tag/
Retrieve Impact Tags
retrieveImpactTags 1 param → 200401403
GET
/api/v1/{service_type}/ruleevent/{id}/list_instances/
List open policy violations
listOpenPolicyViolations 2 params → 200401403
GET
/api/v1/{service_type}/ruleevent/meta/
Get current user's permissions for policy issues
getCurrentUserSPermissionsForPolicyIssues 1 param → 200401403
POST
/api/v1/{service_type}/ruleevent/convert_to_exception/
Allow rule event violation
allowRuleEventViolation 1 param body → 200401403
PATCH
/api/v1/{service_type}/ruleevent/close/
Close rule event violation
closeRuleEventViolation 1 param body → 200401403
DELETE
/api/v1/{service_type}/rule/{id}/
Delete an individual rule within a policy
deleteAnIndividualRuleWithinAPolicy 2 params → 204401403
DELETE
/api/v1/{service_type}/rule/bulk_delete/
Bulk delete rules within a policy
bulkDeleteRulesWithinAPolicy 1 param body → 204401403
GET
/api/v1/core/monitoredservice/{id}/last_successful_policy_assessments/
List the last successful scan time for the active policies in a given monitored service
listTheLastSuccessfulScanTimeForTheActivePoliciesInAGivenMonitor 1 param → 200401403
GET
/api/v1/core/policy/{id}/last_successful_policy_assessments/
List the last successful scan time for all monitored services on a given active policy
listTheLastSuccessfulScanTimeForAllMonitoredServicesOnAGivenActi 1 param → 200401403
GET
/api/v1/{serviceType}/svcexp/{serviceId}/servicesettings/
List MS Service Settings
listMSServiceSettings 2 params → 200401403
GET
/api/v1/o365/svcexp/{serviceId}/policy/
List Policy Settings - M365 Only
listPolicySettingsM365Only 1 param → 200401403
POST
/api/v1/core/policy/snapshot/
Create a Posture Policy Snapshot
createAPosturePolicySnapshot body → 200401403
[Beta] Policy Assessment Stats 1

THIS FEATURE IS IN BETA - Please contact Customer Success to enable this early access API Provides a granular breakdown of policy assessments across monitored services, allowing y…

GET
/api/v1/core/monitoredservice/score/policycomponents/{policy_id}/
Get policy stats
getPolicyStats 1 param → 200401403

Schemas 1

The contract defines 1 schema that model the data the API accepts and returns. The most detailed is Error (1 property). Each schema is shown below with its type and property counts.

Error
object
Standard Django REST Framework error envelope returned by the AppOmni API.
1 property

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

appomni-policies-api-openapi.yml Raw ↑

Other APIs AppOmni publishes across the network.

AppOmni Posture Findings API
AppOmni Compliance and Reports API
AppOmni Monitored Services API
AppOmni Identity and Access API
AppOmni SCIM 2.0 API
AppOmni Discovery, Insights and Audit API
AppOmni Developer Platform API
AppOmni AI API
Where this information came from

This is an independent, third-party profile of AppOmni Policies API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.