Description
Delete an access policy in PAM Core. The operation is a soft delete.
A policy that's still linked to one or more user groups can't be deleted, the request is rejected with 409. Remove the policy from every user group that references it before calling this endpoint.
Deleting a policy removes the access it grants. Before deleting, confirm that no user still depends on the policy for privileged access. To suspend a policy temporarily instead, use POST | Deactivate access policy.
Prerequisites
- An application with the Access Policy (V2) authorization granted by the administrator in A2A, and its PAM resource permission set to Read and write. For more information, access How to manage authorizations in A2A.
- A valid OAuth 2.0 access token. For more information, access How to authenticate an application in A2A.
- The current
ETagvalue of the access policy, returned by GET | List an access policy by [id] and by every write operation on the policy. - No user group may still reference the access policy.
An access token carries only the authorizations that existed when it was generated. After the administrator enables Access Policy (V2), generate a new token for the application, an existing token won't gain the new authorization.
Request
DELETE /api/v2/pam/access-policies/{id}
Path parameters
| Field | Type | Required | Description |
|---|---|---|---|
id |
integer | Yes | Unique identification code of the access policy. Note: this value is assigned by Segura® in POST | Create access policy. |
Example request
DELETE {{url}}/api/v2/pam/access-policies/3001
Headers
If-Match: "v3"
Response
HTTP/1.1 204 No Content
The response has no body.
Errors
| HTTP code | Message | Possible cause | Solution |
|---|---|---|---|
401 |
api.auth.token.invalid |
The access token is missing or has expired. | Request a new access token. |
403 |
api.permission.denied |
The authorization doesn't have permission to delete access policies. | Ask the administrator to check the Access Policy (V2) authorization and the PAM resource permission in A2A, then generate a new token. |
404 |
api.resource.not_found |
The access policy doesn't exist, or it's outside the scope of the authorization. | Check the identification code sent in the path. |
409 |
api.resource.in_use |
The access policy is still linked to one or more user groups. | Remove the policy from every user group that references it, then resend the request. |
412 |
api.precondition.failed |
The If-Match value doesn't match the policy's current version, which means the policy changed after it was read. |
Retrieve the policy again with GET | List an access policy by [id], review the changes, and resend the request with the new ETag. |
429 |
rate_limit_exceeded |
The request rate limit was exceeded. | Reduce the request rate and try again. |
500 |
api.internal.error |
Internal server error. | Contact the Segura® support team. |
Example error response
409 the policy is still linked to user groups:
{
"error": {
"code": "api.resource.in_use",
"message": "Access policy is linked to user groups and cannot be deleted."
}
}
For authentication error messages and the 403 versus 404 policy, access API v2 - Conventions and shared behaviors.