Save the KYC policy editor draft for a programme and flow
/v1/kyc/policy/draftRequires an API client bearer token.
Upserts the SCRATCH policy-editor draft for a (tenant, mode, programme, flow) — no policy version is minted and no audit trail records draft activity; only `PolicyDraftStore`'s own row is upserted in place. Idempotent by overwrite (no Idempotency-Key required). Validation runs BEFORE the draft is stored, using the same compose-layer codes `POST /v1/kyc/policy` uses (`eligibility_rules_owned`, `unknown_detail_field`, `field_in_both_lists`, `invalid_rule`, `invalid_field_config`), plus `unknown_flow` for a `flow_key` naming no flow and `flow_archived` for one naming a retired flow — an invalid draft is never saved. One pair is judged only at publish: a nationality dropdown offering no nationality `rules.allowed_nationalities` accepts (400 `invalid_field_config`), because either half may carry forward from an active policy that moved after the draft was saved. The response includes `composed`/`flow`, a live preview of exactly what publishing this draft would mint against the current active policy. Send `expect_updated_at` (the `updated_at` you last saw) for optimistic concurrency: if the draft changed in another session since then the save is refused with 409 `draft_conflict`, whose body carries the CURRENT draft in `draft` (or `null` if it was discarded) so you can reload or overwrite deliberately. Omit it to keep the last-write-wins behaviour. Requires the programme_admin role.
Request body
+ show properties− hide properties
+ show properties− hide properties
No properties.
+ show properties− hide properties
Example
curl -X PUT https://api.rigid.fi/v1/kyc/policy/draft \
-H "Authorization: Bearer $RIGID_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"programme_id": "uuid",
"definition": {
"required_signals": [
"string"
]
}
}'Responses
200The saved draft, composed against the current active policy.
+ show properties− hide properties
+ show properties− hide properties
No properties.
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
No properties.
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
No properties.
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
+ show properties− hide properties
400Validation error
401Authentication required
403Forbidden
409The draft changed in another session since `expect_updated_at` (code `draft_conflict`; the body carries the current draft in `draft`, or `null` if it was discarded). On this path `draft.composed`/`draft.flow` may be absent — if the stored draft can no longer be composed the preview is omitted rather than the conflict being reported as something else
500Internal server error