Skip to content

Retrieve a policy branch rule

Request

Early AccessIdentity Engine
OAuth 2.0 scope:
  • okta.policies.read

Retrieves a specific rule from a policy branch by rule ID.

Only applicable to ACCESS_POLICY type policies.

Path
policyIdstringrequired

id of the ACCESS_POLICY

Example:rst1d7xus97faIAgmti0
branchIdstringrequired

id of the policy branch

Example:rsb1d7xus97faIAgmti
ruleIdstringrequired

id of the policy rule

Example:ruld3hJ7jZh4fn0st0g3
GET
/api/v1/policies/{policyId}/branches/{branchId}/rules/{ruleId}
curl -i -X GET \
  https://subdomain.okta.com/api/v1/policies/rst1d7xus97faIAgmti0/branches/rsb1d7xus97faIAgmti/rules/ruld3hJ7jZh4fn0st0g3

Responses

Success

Bodyapplication/json
actionsobject(AccessPolicyRuleActions)

Specifies actions to be taken, or operations that may be allowed, if the rule conditions are satisfied.

branchInformationobjectread-only

Information about the branch this rule belongs to

conditionsobject(AccessPolicyRuleConditions)

Specifies conditions that must be met during policy evaluation to apply the rule. All policy conditions, as well as conditions for at least one rule must be met to apply the settings specified in the policy and the associated rule.

createdstring or null, (date-time)read-only

Timestamp when the policy branch rule was created

idstringread-only

Identifier for the rule

lastUpdatedstring or null, (date-time)read-only

Timestamp when the policy branch rule was last modified

namestring

Name of the rule

priorityinteger or null

Priority of the rule

statusstring(LifecycleStatus)

Whether or not the rule is active. Use the activate query parameter to set the status of a rule.

Enum:"ACTIVE""INACTIVE"
systemboolean

Specifies whether Okta created the policy rule (system=true). You can't delete policy rules that have system set to true.

Default:false
typestring

Policy rule type. Branch rules are only supported for ACCESS_POLICY policies.

Value:"ACCESS_POLICY"
Response
{ "id": "rul5o1bcd47keNFq2xm", "status": "ACTIVE", "name": "Require MFA for high-risk sign-ins", "priority": 1, "created": "2026-04-02T11:00:00.000Z", "lastUpdated": "2026-04-10T09:30:00.000Z", "system": false, "conditions": { "riskScore": {}, "network": {} }, "actions": { "appSignOn": {} }, "_links": { "self": {} }, "type": "ACCESS_POLICY" }