> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usefini.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List guardrail policies

> List guardrail policies through the workspace-scoped public API.

Returns all policies for the agent, including disabled ones, ordered by creation time. The response is an array, not a paginated envelope. It can be empty when no policies exist.

See the [Guardrails overview](/en/api-reference/guardrails) for shared schemas and runtime limitations.

<ParamField header="Authorization" type="string" required>Bearer workspace API key. The key needs `read` scope.</ParamField>
<ParamField query="botId" type="string" required>Agent UUID in the authenticated workspace.</ParamField>

## Response

<ResponseField name="id" type="string">Policy UUID.</ResponseField>
<ResponseField name="companyId" type="string">Owning workspace UUID.</ResponseField>
<ResponseField name="botId" type="string">Agent UUID.</ResponseField>
<ResponseField name="checkType" type="string">Check type from the catalogue.</ResponseField>
<ResponseField name="config" type="object">Check-specific definition. See the [configuration schemas](/en/api-reference/guardrails#configuration-schemas).</ResponseField>
<ResponseField name="enabled" type="boolean">Whether the policy is enabled.</ResponseField>
<ResponseField name="sources" type="array">Channel names, or `null` for all channels.</ResponseField>
<ResponseField name="createdAt" type="datetime">Creation timestamp.</ResponseField>
<ResponseField name="updatedAt" type="datetime">Last update timestamp.</ResponseField>

<RequestExample>
  ```bash cURL theme={null}
  curl --request GET \
    --url "https://api-prod.usefini.com/v2/guardrail-policies/public?botId=11111111-1111-4111-8111-111111111111" \
    --header "Authorization: Bearer $FINI_API_KEY"
  ```

  ```javascript Node.js theme={null}
  const response = await fetch("https://api-prod.usefini.com/v2/guardrail-policies/public?botId=11111111-1111-4111-8111-111111111111", {
    method: "GET",
    headers: { Authorization: `Bearer ${process.env.FINI_API_KEY}` },
  });
  if (!response.ok) throw new Error(`HTTP ${response.status}`);
  console.log(await response.json());
  ```

  ```python Python theme={null}
  import os
  import requests

  response = requests.get(
      "https://api-prod.usefini.com/v2/guardrail-policies/public?botId=11111111-1111-4111-8111-111111111111",
      headers={"Authorization": f"Bearer {os.environ['FINI_API_KEY']}"},
      timeout=30,
  )
  response.raise_for_status()
  print(response.json())
  ```
</RequestExample>

<ResponseExample>
  ```json 200 theme={null}
  [
    {
      "id": "22222222-2222-4222-8222-222222222222",
      "companyId": "33333333-3333-4333-8333-333333333333",
      "botId": "11111111-1111-4111-8111-111111111111",
      "checkType": "banned_terms",
      "config": {
        "terms": [
          "guaranteed approval"
        ]
      },
      "enabled": true,
      "sources": [
        "widget"
      ],
      "createdAt": "2026-10-01T08:00:00.000Z",
      "updatedAt": "2026-10-01T08:00:00.000Z"
    }
  ]
  ```
</ResponseExample>


## Related topics

- [Overview](/en/api-reference/guardrails.md)
- [List guardrail runs](/en/api-reference/list-guardrail-runs.md)
- [Update guardrail policy](/en/api-reference/update-guardrail-policy.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.