> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-leet-slack-mcp-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Create

> Create a recovery policy.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/recovery-policies
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/recovery-policies:
    post:
      tags:
        - Recovery Policy
      summary: Create
      description: Create a recovery policy.
      operationId: c1.api.credential_inventory.v1.RecoveryPolicyService.Create
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyServiceCreateRequest
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicyServiceCreateResponse
          description: Successful response
      x-codeSamples:
        - lang: go
          label: Create
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.RecoveryPolicy.Create(ctx, nil)\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.RecoveryPolicyServiceCreateResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    c1.api.credential_inventory.v1.RecoveryPolicyServiceCreateRequest:
      description: The RecoveryPolicyServiceCreateRequest message.
      properties:
        allowedRecoveryTypes:
          description: The credential types a user may use to recover access.
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_PASSKEY
              - CREDENTIAL_TYPE_PASSWORD
              - CREDENTIAL_TYPE_TOTP
              - CREDENTIAL_TYPE_EMAIL_OTP
              - CREDENTIAL_TYPE_RECOVERY_CODE
              - CREDENTIAL_TYPE_DELEGATED_GOOGLE
              - CREDENTIAL_TYPE_DELEGATED_MICROSOFT
              - CREDENTIAL_TYPE_UPSTREAM_IDP
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        displayName:
          description: A human-readable name for the policy.
          type: string
        minRecoveryAuthLevel:
          description: The minimum assurance level a recovery ceremony must reach.
          enum:
            - AUTH_LEVEL_UNSPECIFIED
            - AUTH_LEVEL_NONE
            - AUTH_LEVEL_SINGLE_FACTOR
            - AUTH_LEVEL_MULTI_FACTOR
            - AUTH_LEVEL_PHR
            - AUTH_LEVEL_PHRH
          type: string
          x-speakeasy-unknown-values: allow
        priority:
          description: >-
            When a user matches more than one policy, the policy with the
            highest
             priority applies.
          format: int32
          type: integer
        revokeOnRecovery:
          description: >-
            When true, a successful recovery revokes existing credentials and
            forces
             re-enrollment.
          type: boolean
      required:
        - displayName
      title: Recovery Policy Service Create Request
      type: object
      x-speakeasy-entity: RecoveryPolicy
      x-speakeasy-name-override: RecoveryPolicyServiceCreateRequest
    c1.api.credential_inventory.v1.RecoveryPolicyServiceCreateResponse:
      description: The RecoveryPolicyServiceCreateResponse message.
      properties:
        recoveryPolicy:
          oneOf:
            - $ref: >-
                #/components/schemas/c1.api.credential_inventory.v1.RecoveryPolicy
            - type: 'null'
      title: Recovery Policy Service Create Response
      type: object
      x-speakeasy-name-override: RecoveryPolicyServiceCreateResponse
    c1.api.credential_inventory.v1.RecoveryPolicy:
      description: |-
        RecoveryPolicy defines how users recover access when they lose their
         credentials.
      properties:
        allowedRecoveryTypes:
          description: >-
            The credential types a user may use to recover access under this
            policy.
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_PASSKEY
              - CREDENTIAL_TYPE_PASSWORD
              - CREDENTIAL_TYPE_TOTP
              - CREDENTIAL_TYPE_EMAIL_OTP
              - CREDENTIAL_TYPE_RECOVERY_CODE
              - CREDENTIAL_TYPE_DELEGATED_GOOGLE
              - CREDENTIAL_TYPE_DELEGATED_MICROSOFT
              - CREDENTIAL_TYPE_UPSTREAM_IDP
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        createdAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        deletedAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        displayName:
          description: A human-readable name for the policy.
          type: string
        id:
          description: Unique identifier for the policy.
          readOnly: true
          type: string
        isBuiltin:
          description: >-
            True for built-in policies provided by ConductorOne. Built-in
            policies
             cannot be edited or deleted.
          readOnly: true
          type: boolean
        minRecoveryAuthLevel:
          description: >-
            The minimum assurance level a recovery ceremony must reach for this
            policy.
          enum:
            - AUTH_LEVEL_UNSPECIFIED
            - AUTH_LEVEL_NONE
            - AUTH_LEVEL_SINGLE_FACTOR
            - AUTH_LEVEL_MULTI_FACTOR
            - AUTH_LEVEL_PHR
            - AUTH_LEVEL_PHRH
          type: string
          x-speakeasy-unknown-values: allow
        priority:
          description: >-
            When a user matches more than one policy, the policy with the
            highest
             priority applies.
          format: int32
          type: integer
        revokeOnRecovery:
          description: >-
            When true, a successful recovery revokes the user's existing
            credentials
             and forces re-enrollment. When false, recovery adds to the existing set.
          type: boolean
        updatedAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
      title: Recovery Policy
      type: object
      x-speakeasy-entity: RecoveryPolicy
      x-speakeasy-name-override: RecoveryPolicy
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````