> For the complete documentation index, see [llms.txt](https://hinkal-team.gitbook.io/hinkal/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hinkal-team.gitbook.io/hinkal/hinkal-waas/api-reference/update-policy.md).

# Update Policy

## POST /waas/update-policy

> Update an existing policy

```json
{"openapi":"3.0.3","info":{"title":"Hinkal WaaS API","version":"1.0.0"},"tags":[{"name":"Update Policy"}],"servers":[{"url":"https://api.hinkal.io","description":"Production"}],"security":[{"XStamp":[]}],"components":{"securitySchemes":{"XStamp":{"type":"apiKey","in":"header","name":"X-Stamp","description":"Base64URL-encoded JSON: `{ \"publicKey\": \"<hex ed25519 pubkey>\", \"signature\": \"<hex ed25519 sig>\" }`.\nThe signature covers `JSON.stringify([binding, Object.entries(params)])`, where `binding`\nis `\"<METHOD> <routePath>\"` (the server's route pattern, e.g. `\"POST /waas/create-wallet\"`)\nand `params` is the request body (POST) or query params (GET). This binds the stamp to\nits own route so it cannot be replayed against a different endpoint. The one parameterized\nroute, `GET /waas/scheduled-transaction/{scheduleId}`, binds to the literal\n`\"GET /waas/scheduled-transaction/:scheduleId\"`, not the concrete ID. See the Signing\nRequests guide for runnable examples.\n"}},"schemas":{"PolicyInput":{"type":"object","properties":{"userIds":{"type":"array","items":{"type":"string"}},"actionType":{"type":"string"}},"required":["userIds","actionType"]},"SuccessResponse":{"type":"object","properties":{"status":{"type":"string","enum":["success"]}},"required":["status"]},"Policy":{"type":"object","properties":{"policyId":{"type":"string"},"userIds":{"type":"array","items":{"type":"string"}},"actionType":{"type":"string","description":"AdminTransactionType — e.g. PayPublicToPublicSend, PayPrivateToPublicSend"}},"required":["policyId","userIds","actionType"]},"ErrorResponse":{"type":"object","properties":{"status":{"type":"string","enum":["error"]},"message":{"type":"string"}},"required":["status","message"]}},"responses":{"PoliciesResponse":{"description":"Policies list","content":{"application/json":{"schema":{"allOf":[{"$ref":"#/components/schemas/SuccessResponse"},{"type":"object","properties":{"data":{"type":"object","properties":{"organizationId":{"type":"string"},"policies":{"type":"array","items":{"$ref":"#/components/schemas/Policy"}}}}}}]}}}},"BadRequest":{"description":"Bad request","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"Unauthorized":{"description":"Invalid or missing X-Stamp","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"Forbidden":{"description":"Insufficient permissions","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}},"ServerError":{"description":"Internal server error","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ErrorResponse"}}}}}},"paths":{"/waas/update-policy":{"post":{"operationId":"updatePolicy","summary":"Update an existing policy","tags":["Update Policy"],"requestBody":{"required":true,"content":{"application/json":{"schema":{"type":"object","properties":{"organizationId":{"type":"string"},"policyId":{"type":"string"},"newPolicy":{"$ref":"#/components/schemas/PolicyInput"},"nonce":{"type":"string"}},"required":["organizationId","policyId","newPolicy","nonce"]}}}},"responses":{"200":{"$ref":"#/components/responses/PoliciesResponse"},"400":{"$ref":"#/components/responses/BadRequest"},"401":{"$ref":"#/components/responses/Unauthorized"},"403":{"$ref":"#/components/responses/Forbidden"},"500":{"$ref":"#/components/responses/ServerError"}}}}}}
```
