> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usefini.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create guardrail policy

> Create guardrail policy through the workspace-scoped public API.

Creates a saved policy directly. It is enabled by default; use `enabled: false` to configure it without enabling evaluation. Duplicate built-in types return 409; exceeding 10 custom rules returns 400.

See the [Guardrails overview](/en/api-reference/guardrails) for shared schemas and runtime limitations.

<ParamField header="Authorization" type="string" required>Bearer workspace API key. The key needs `write` scope.</ParamField>
<ParamField body="botId" type="string" required>Agent UUID.</ParamField>
<ParamField body="checkType" type="string" required>One of the six [check types](/en/api-reference/guardrails#configuration-schemas).</ParamField>
<ParamField body="config" type="object" required>Complete check-specific configuration. See [configuration schemas](/en/api-reference/guardrails#configuration-schemas).</ParamField>
<ParamField body="enabled" type="boolean">Defaults to `true` on creation.</ParamField>
<ParamField body="sources" type="array">Unique supported channel names. Omit or send an empty array on creation for all channels.</ParamField>

## Response

<ResponseField name="id" type="string">Policy UUID.</ResponseField>
<ResponseField name="companyId" type="string">Owning workspace UUID.</ResponseField>
<ResponseField name="botId" type="string">Agent UUID.</ResponseField>
<ResponseField name="checkType" type="string">Check type from the catalogue.</ResponseField>
<ResponseField name="config" type="object">Check-specific definition. See the [configuration schemas](/en/api-reference/guardrails#configuration-schemas).</ResponseField>
<ResponseField name="enabled" type="boolean">Whether the policy is enabled.</ResponseField>
<ResponseField name="sources" type="array">Channel names, or `null` for all channels.</ResponseField>
<ResponseField name="createdAt" type="datetime">Creation timestamp.</ResponseField>
<ResponseField name="updatedAt" type="datetime">Last update timestamp.</ResponseField>

<RequestExample>
  ```bash cURL theme={null}
  curl --request POST \
    --url "https://api-prod.usefini.com/v2/guardrail-policies/public" \
    --header "Authorization: Bearer $FINI_API_KEY" \
    --header "Content-Type: application/json" \
    --data '{"botId": "11111111-1111-4111-8111-111111111111", "checkType": "banned_terms", "config": {"terms": ["guaranteed approval"]}, "enabled": true, "sources": ["widget"]}'
  ```

  ```javascript Node.js theme={null}
  const response = await fetch("https://api-prod.usefini.com/v2/guardrail-policies/public", {
    method: "POST",
    headers: { Authorization: `Bearer ${process.env.FINI_API_KEY}`, "Content-Type": "application/json" },
    body: JSON.stringify({"botId": "11111111-1111-4111-8111-111111111111", "checkType": "banned_terms", "config": {"terms": ["guaranteed approval"]}, "enabled": true, "sources": ["widget"]}),
  });
  if (!response.ok) throw new Error(`HTTP ${response.status}`);
  console.log(await response.json());
  ```

  ```python Python theme={null}
  import os
  import requests

  response = requests.post(
      "https://api-prod.usefini.com/v2/guardrail-policies/public",
      headers={"Authorization": f"Bearer {os.environ['FINI_API_KEY']}"},
      json={'botId': '11111111-1111-4111-8111-111111111111', 'checkType': 'banned_terms', 'config': {'terms': ['guaranteed approval']}, 'enabled': True, 'sources': ['widget']},
      timeout=30,
  )
  response.raise_for_status()
  print(response.json())
  ```
</RequestExample>

<ResponseExample>
  ```json 201 theme={null}
  {
    "id": "22222222-2222-4222-8222-222222222222",
    "companyId": "33333333-3333-4333-8333-333333333333",
    "botId": "11111111-1111-4111-8111-111111111111",
    "checkType": "banned_terms",
    "config": {
      "terms": [
        "guaranteed approval"
      ]
    },
    "enabled": true,
    "sources": [
      "widget"
    ],
    "createdAt": "2026-10-01T08:00:00.000Z",
    "updatedAt": "2026-10-01T08:00:00.000Z"
  }
  ```
</ResponseExample>


## Related topics

- [Overview](/en/api-reference/guardrails.md)
- [Update guardrail policy](/en/api-reference/update-guardrail-policy.md)
- [Get guardrail policy](/en/api-reference/get-guardrail-policy.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.