Skip to main content
PATCH
Update a PII redaction policy
Partial update. Omitted fields are left as they are. A change takes effect on the data plane within the recognizer cache’s short TTL — the cache is invalidated on write, so it is effectively immediate. Requires the update capability on ai_gateway. See the control-plane overview for authentication, the {data, meta} envelope, pagination and error types.

Authorizations

Authorization
string
header
required

OAuth 2.1 authentication — recommended for new integrations. Access tokens (kc_ prefix) are minted at the root-host token endpoint https://api.knoxcall.com/oauth/token and passed as Authorization: Bearer <access_token>. Public clients must use PKCE with the authorization_code grant; confidential clients may use client_credentials. The first-party SDKs and the knoxcall login CLI handle token minting, caching, refresh, and DPoP for you.

Path Parameters

id
string<uuid>
required

Body

application/json
recognizer_ids
string<uuid>[]
default_action
enum<string>
Available options:
redact,
tokenize,
whitelist,
warn
description
string

Response

The updated policy.

data
object

A tenant-scoped bundle of PII recognizers plus a default action, attached to an agent through pii_redact_policy_id.

meta
object

Metadata included with every API response.