> ## Documentation Index
> Fetch the complete documentation index at: https://docs.useanima.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Put agents policy



## OpenAPI

````yaml /openapi.json put /agents/{agentId}/policy
openapi: 3.1.1
info:
  title: Anima API
  version: 0.1.0
  description: >-
    The Anima API provides programmatic access to unified infrastructure for AI
    agents: create and manage agents; send and receive email; place phone calls
    and send/receive SMS and voice; store and retrieve vault credentials; manage
    agent identity; and configure webhooks for real-time events. Authenticate
    using a Bearer token or an API key passed via the X-API-Key header.
  contact:
    name: Anima Labs
    url: https://useanima.sh
    email: support@useanima.sh
  license:
    name: MIT
    url: https://opensource.org/licenses/MIT
servers:
  - url: https://api.useanima.sh/v1
    description: Production
security:
  - BearerAuth: []
  - ApiKeyAuth: []
paths:
  /agents/{agentId}/policy:
    put:
      operationId: agent.updatePolicy
      parameters:
        - name: agentId
          in: path
          required: true
          schema:
            type: string
            pattern: ^[cC][^\s-]{8,}$
            description: Agent identifier to update policy for
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                policy:
                  type: object
                  properties:
                    email:
                      type: object
                      properties:
                        allowedRecipientDomains:
                          default: []
                          type: array
                          items:
                            type: string
                            minLength: 1
                          description: If non-empty, agent may ONLY send to these domains
                        blockedRecipientDomains:
                          default: []
                          type: array
                          items:
                            type: string
                            minLength: 1
                          description: Agent may NEVER send to these domains
                        maxPerHour:
                          type: integer
                          minimum: 0
                          description: Override emails-per-hour rate limit for this agent
                      additionalProperties: false
                      description: Email capability constraints
                    contentSafety:
                      type: object
                      properties:
                        scanLevel:
                          default: 'off'
                          enum:
                            - 'off'
                            - basic
                            - strict
                          type: string
                          description: Outbound content scanning intensity
                        injectionScanEnabled:
                          default: false
                          type: boolean
                          description: >-
                            Whether prompt-injection detection runs on outgoing
                            messages
                        autoApproveBelow:
                          default: medium
                          enum:
                            - none
                            - medium
                            - high
                          type: string
                          description: >-
                            Auto-approve flagged messages at or below this risk
                            threshold
                        blockedPatterns:
                          default: []
                          type: array
                          items:
                            type: string
                          description: Regex patterns blocked in outgoing messages
                      additionalProperties: false
                      description: >-
                        Outbound content-safety constraints (formerly the
                        separate Security Policy)
                    vault:
                      type: object
                      properties:
                        readOnly:
                          default: false
                          type: boolean
                          description: >-
                            Agent can read vault items but cannot create,
                            update, or delete
                        blocked:
                          default: false
                          type: boolean
                          description: Completely disable vault access for this agent
                      additionalProperties: false
                      description: Vault capability constraints
                    phone:
                      type: object
                      properties:
                        allowedCountries:
                          default: []
                          type: array
                          items:
                            type: string
                            minLength: 2
                            maxLength: 2
                          description: >-
                            ISO 3166-1 alpha-2 country codes. If non-empty,
                            agent may only call/text these.
                        maxSmsPerHour:
                          type: integer
                          minimum: 0
                          description: Override SMS-per-hour rate limit for this agent
                        blocked:
                          default: false
                          type: boolean
                          description: >-
                            Completely disable phone/SMS capabilities for this
                            agent
                      additionalProperties: false
                      description: Phone/SMS capability constraints
                    voice:
                      type: object
                      properties:
                        allowedCountries:
                          default: []
                          type: array
                          items:
                            type: string
                            minLength: 2
                            maxLength: 2
                          description: >-
                            ISO 3166-1 alpha-2 country codes. If non-empty,
                            agent may only call these.
                        blocked:
                          default: false
                          type: boolean
                          description: >-
                            Completely disable outbound voice calls for this
                            agent
                      additionalProperties: false
                      description: Voice-call capability constraints
                  additionalProperties: false
                  description: New policy to apply
              required:
                - policy
              description: Input for updating an agent's capability policy
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  agentId:
                    type: string
                    description: Agent identifier
                  policy:
                    type: object
                    properties:
                      email:
                        type: object
                        properties:
                          allowedRecipientDomains:
                            default: []
                            type: array
                            items:
                              type: string
                              minLength: 1
                            description: If non-empty, agent may ONLY send to these domains
                          blockedRecipientDomains:
                            default: []
                            type: array
                            items:
                              type: string
                              minLength: 1
                            description: Agent may NEVER send to these domains
                          maxPerHour:
                            type: integer
                            minimum: 0
                            description: Override emails-per-hour rate limit for this agent
                        additionalProperties: false
                        description: Email capability constraints
                      contentSafety:
                        type: object
                        properties:
                          scanLevel:
                            default: 'off'
                            enum:
                              - 'off'
                              - basic
                              - strict
                            type: string
                            description: Outbound content scanning intensity
                          injectionScanEnabled:
                            default: false
                            type: boolean
                            description: >-
                              Whether prompt-injection detection runs on
                              outgoing messages
                          autoApproveBelow:
                            default: medium
                            enum:
                              - none
                              - medium
                              - high
                            type: string
                            description: >-
                              Auto-approve flagged messages at or below this
                              risk threshold
                          blockedPatterns:
                            default: []
                            type: array
                            items:
                              type: string
                            description: Regex patterns blocked in outgoing messages
                        additionalProperties: false
                        description: >-
                          Outbound content-safety constraints (formerly the
                          separate Security Policy)
                      vault:
                        type: object
                        properties:
                          readOnly:
                            default: false
                            type: boolean
                            description: >-
                              Agent can read vault items but cannot create,
                              update, or delete
                          blocked:
                            default: false
                            type: boolean
                            description: Completely disable vault access for this agent
                        additionalProperties: false
                        description: Vault capability constraints
                      phone:
                        type: object
                        properties:
                          allowedCountries:
                            default: []
                            type: array
                            items:
                              type: string
                              minLength: 2
                              maxLength: 2
                            description: >-
                              ISO 3166-1 alpha-2 country codes. If non-empty,
                              agent may only call/text these.
                          maxSmsPerHour:
                            type: integer
                            minimum: 0
                            description: Override SMS-per-hour rate limit for this agent
                          blocked:
                            default: false
                            type: boolean
                            description: >-
                              Completely disable phone/SMS capabilities for this
                              agent
                        additionalProperties: false
                        description: Phone/SMS capability constraints
                      voice:
                        type: object
                        properties:
                          allowedCountries:
                            default: []
                            type: array
                            items:
                              type: string
                              minLength: 2
                              maxLength: 2
                            description: >-
                              ISO 3166-1 alpha-2 country codes. If non-empty,
                              agent may only call these.
                          blocked:
                            default: false
                            type: boolean
                            description: >-
                              Completely disable outbound voice calls for this
                              agent
                        additionalProperties: false
                        description: Voice-call capability constraints
                    additionalProperties: false
                    description: Current capability policy
                required:
                  - agentId
                  - policy
                description: Agent policy response
components:
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        JWT Bearer token obtained from authentication. Pass as: Authorization:
        Bearer <token>
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key
      description: 'API key for programmatic access. Pass as: X-API-Key: <your-key>'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.