- Create a policy branch rule
Creates a new rule in a policy branch.
Only applicable to ACCESS_POLICY type policies.
Specifies actions to be taken, or operations that may be allowed, if the rule conditions are satisfied.
Specifies conditions that must be met during policy evaluation to apply the rule. All policy conditions, as well as conditions for at least one rule must be met to apply the settings specified in the policy and the associated rule.
Whether or not the rule is active. Use the activate query parameter to set the status of a rule.
Specifies whether Okta created the policy rule (system=true). You can't delete policy rules that have system set to true.
- ASSURANCE
- AUTH_METHOD_CHAIN
- ID_PROOFING
curl -i -X POST \
https://subdomain.okta.com/api/v1/policies/rst1d7xus97faIAgmti0/branches/rsb1d7xus97faIAgmti/rules \
-H 'Content-Type: application/json' \
-d '{
"type": "ACCESS_POLICY",
"name": "Require step-up auth for sensitive resources",
"conditions": {
"app": {
"include": [
{
"type": "APP",
"id": "0oa8r4uvw59mgQIt5d7"
}
]
},
"network": {
"connection": "ANYWHERE"
}
},
"actions": {
"appSignOn": {
"access": "ALLOW",
"verificationMethod": {
"type": "ASSURANCE",
"reauthenticateIn": "PT1H",
"constraints": [
{
"knowledge": {
"types": [
"PASSWORD"
]
},
"reauthenticateIn": "PT1H"
},
{
"possession": {
"userPresence": "REQUIRED"
}
}
]
}
}
}
}'Created
Specifies actions to be taken, or operations that may be allowed, if the rule conditions are satisfied.
Specifies conditions that must be met during policy evaluation to apply the rule. All policy conditions, as well as conditions for at least one rule must be met to apply the settings specified in the policy and the associated rule.
Timestamp when the policy branch rule was last modified
Whether or not the rule is active. Use the activate query parameter to set the status of a rule.
Specifies whether Okta created the policy rule (system=true). You can't delete policy rules that have system set to true.
Policy rule type. Branch rules are only supported for ACCESS_POLICY policies.
- ASSURANCE
- AUTH_METHOD_CHAIN
- ID_PROOFING
{ "id": "rul7s3efg69mgPIt6ao", "status": "ACTIVE", "name": "Require step-up auth for sensitive resources", "priority": 1, "created": "2026-05-06T16:30:00.000Z", "lastUpdated": "2026-05-06T16:30:00.000Z", "system": false, "conditions": { "app": { … }, "network": { … } }, "actions": { "appSignOn": { … } }, "_links": { "self": { … } }, "type": "ACCESS_POLICY" }