Home / Companies / Qovery / Blog / Post Details
Content Deep Dive

Full Control Over Permissions, Welcome API Policy Tokens

Blog post from Qovery

Post Details
Company
Date Published
Author
-
Word Count
927
Company Posts That Month
43
Language
English
Hacker News Points
-
Post removed?
No
Summary

Qovery has introduced API Policy Tokens, a new organization token type that uses Open Policy Agent and Rego policies to enforce fine-grained, request-level API authorization rather than relying on broader RBAC roles. Policies can assess the requested action, target resource, HTTP method, and request body, allowing teams to grant automated systems such as AI agents, Terraform runners, CI/CD pipelines, scripts, and CLI users only the capabilities they require. The feature addresses the risk of overprivileged automation by denying all actions by default and explicitly permitting specific operations, such as allowing a staging deployment-triage agent to redeploy or roll back an environment while preventing deletion. Policies are evaluated on every request, apply changes immediately, and provide distinct audit-log attribution for each token. Users can create a Policy API Token in Qovery’s organization settings, define a Rego policy from a provided template, securely save the token when it is displayed once, and use it through the standard Authorization header.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Agents 2 5,780 1,243 245 -15%
Platform Engineering 2 1,191 259 79 -17%
MCP 1 8,729 854 211 -20%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.