> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-leet-slack-mcp-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Update

> Update a sign-in policy. Supply the policy object and an update mask
 listing the fields to change; omitted fields are left as-is.



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples post /api/v1/sign-in-policies/{id}
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/sign-in-policies/{id}:
    post:
      tags:
        - Sign-In Policy
      summary: Update
      description: |-
        Update a sign-in policy. Supply the policy object and an update mask
         listing the fields to change; omitted fields are left as-is.
      operationId: c1.api.sign_in_policy.v1.SignInPolicyService.Update
      parameters:
        - in: path
          name: id
          required: true
          schema:
            description: Unique identifier for the policy.
            readOnly: true
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceUpdateRequestInput
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.sign_in_policy.v1.SignInPolicyServiceUpdateResponse
          description: Successful response
      x-codeSamples:
        - lang: go
          label: Update
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/operations\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.SignInPolicy.Update(ctx, operations.C1APISignInPolicyV1SignInPolicyServiceUpdateRequest{\n        ID: \"<id>\",\n    })\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.SignInPolicyServiceUpdateResponse != nil {\n        // handle response\n    }\n}"
components:
  schemas:
    c1.api.sign_in_policy.v1.SignInPolicyServiceUpdateRequestInput:
      description: The SignInPolicyServiceUpdateRequest message.
      properties:
        signInPolicy:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy'
            - type: 'null'
        updateMask:
          type:
            - string
            - 'null'
      title: Sign In Policy Service Update Request
      type: object
      x-speakeasy-name-override: SignInPolicyServiceUpdateRequest
    c1.api.sign_in_policy.v1.SignInPolicyServiceUpdateResponse:
      description: The SignInPolicyServiceUpdateResponse message.
      properties:
        signInPolicy:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.SignInPolicy'
            - type: 'null'
      title: Sign In Policy Service Update Response
      type: object
      x-speakeasy-name-override: SignInPolicyServiceUpdateResponse
    c1.api.sign_in_policy.v1.SignInPolicy:
      description: SignInPolicy defines how users sign in.
      properties:
        allowedMfaTypes:
          description: >-
            The credential types accepted as a second factor. Must be a subset
            of the
             credential types their inventory policy permits.
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_PASSKEY
              - CREDENTIAL_TYPE_PASSWORD
              - CREDENTIAL_TYPE_TOTP
              - CREDENTIAL_TYPE_EMAIL_OTP
              - CREDENTIAL_TYPE_RECOVERY_CODE
              - CREDENTIAL_TYPE_DELEGATED_GOOGLE
              - CREDENTIAL_TYPE_DELEGATED_MICROSOFT
              - CREDENTIAL_TYPE_UPSTREAM_IDP
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        allowedPrimaryTypes:
          description: >-
            The primary credential types users may sign in with. Must be a
            subset of
             the credential types their inventory policy permits.
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_PASSKEY
              - CREDENTIAL_TYPE_PASSWORD
              - CREDENTIAL_TYPE_TOTP
              - CREDENTIAL_TYPE_EMAIL_OTP
              - CREDENTIAL_TYPE_RECOVERY_CODE
              - CREDENTIAL_TYPE_DELEGATED_GOOGLE
              - CREDENTIAL_TYPE_DELEGATED_MICROSOFT
              - CREDENTIAL_TYPE_UPSTREAM_IDP
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
        createdAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        defaultOutcome:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome'
            - type: 'null'
        deletedAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        displayName:
          description: A human-readable name for the policy.
          type: string
        id:
          description: Unique identifier for the policy.
          readOnly: true
          type: string
        isBuiltin:
          description: >-
            True for built-in policies provided by ConductorOne. Built-in
            policies
             cannot be edited or deleted.
          readOnly: true
          type: boolean
        priority:
          description: >-
            When a user matches more than one policy, the policy with the
            highest
             priority applies.
          format: int32
          type: integer
        rules:
          description: The ordered rule cascade, evaluated top to bottom.
          items:
            $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyRule'
          type:
            - array
            - 'null'
        updatedAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
      title: Sign In Policy
      type: object
      x-speakeasy-entity: SignInPolicy
      x-speakeasy-name-override: SignInPolicy
    c1.api.sign_in_policy.v1.PolicyOutcome:
      description: >
        PolicyOutcome is the effect of a matched rule. Exactly one kind is set.


        This message contains a oneof named kind. Only a single field of the
        following list may be set at a time:
          - allow
          - deny
          - stepUpRequired
          - challengeRequired
          - enrollmentRequired
      properties:
        allow:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.Allow'
            - type: 'null'
        challengeRequired:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.ChallengeRequired'
            - type: 'null'
        deny:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.Deny'
            - type: 'null'
        enrollmentRequired:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.EnrollmentRequired'
            - type: 'null'
        stepUpRequired:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.StepUpRequired'
            - type: 'null'
      title: Policy Outcome
      type: object
      x-speakeasy-name-override: PolicyOutcome
    c1.api.sign_in_policy.v1.PolicyRule:
      description: >-
        PolicyRule is one rung of the ordered sign-in cascade. Rules are
        evaluated
         top to bottom; the first enforced rule whose condition matches supplies the
         outcome.
      properties:
        description:
          description: A human-readable description shown in the admin UI.
          type: string
        id:
          description: A stable identifier for the rule, surfaced in audit.
          type: string
        matchCel:
          description: >-
            A boolean condition expression evaluated against the sign-in
            context.
          type: string
        mode:
          description: Whether the rule is live, evaluated-only, or skipped.
          enum:
            - POLICY_RULE_MODE_UNSPECIFIED
            - POLICY_RULE_MODE_ENFORCE
            - POLICY_RULE_MODE_OBSERVE
            - POLICY_RULE_MODE_DISABLED
          type: string
          x-speakeasy-unknown-values: allow
        outcome:
          oneOf:
            - $ref: '#/components/schemas/c1.api.sign_in_policy.v1.PolicyOutcome'
            - type: 'null'
      title: Policy Rule
      type: object
      x-speakeasy-name-override: PolicyRule
    c1.api.sign_in_policy.v1.Allow:
      description: Allow permits the sign-in.
      properties:
        floorLevel:
          description: >-
            The minimum assurance level that satisfies this rule. Required on
            enforced
             Allow rules.
          enum:
            - AUTH_LEVEL_UNSPECIFIED
            - AUTH_LEVEL_NONE
            - AUTH_LEVEL_SINGLE_FACTOR
            - AUTH_LEVEL_MULTI_FACTOR
            - AUTH_LEVEL_PHR
            - AUTH_LEVEL_PHRH
          type: string
          x-speakeasy-unknown-values: allow
      title: Allow
      type: object
      x-speakeasy-name-override: Allow
    c1.api.sign_in_policy.v1.ChallengeRequired:
      description: >-
        ChallengeRequired asks for an additional factor before the sign-in
        completes.
      properties:
        types:
          description: The credential types that may satisfy the challenge.
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_PASSKEY
              - CREDENTIAL_TYPE_PASSWORD
              - CREDENTIAL_TYPE_TOTP
              - CREDENTIAL_TYPE_EMAIL_OTP
              - CREDENTIAL_TYPE_RECOVERY_CODE
              - CREDENTIAL_TYPE_DELEGATED_GOOGLE
              - CREDENTIAL_TYPE_DELEGATED_MICROSOFT
              - CREDENTIAL_TYPE_UPSTREAM_IDP
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
      title: Challenge Required
      type: object
      x-speakeasy-name-override: ChallengeRequired
    c1.api.sign_in_policy.v1.Deny:
      description: Deny rejects the sign-in.
      properties:
        reasonAdmin:
          description: Reason shown in admin-only audit.
          type: string
        reasonUser:
          description: Reason safe to show the end user.
          type: string
      title: Deny
      type: object
      x-speakeasy-name-override: Deny
    c1.api.sign_in_policy.v1.EnrollmentRequired:
      description: >-
        EnrollmentRequired tells the user to enroll a credential before
        continuing.
      properties:
        credentialTypes:
          description: >-
            The credential types the user may enroll. Empty means "complete
            identity
             verification first".
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_PASSKEY
              - CREDENTIAL_TYPE_PASSWORD
              - CREDENTIAL_TYPE_TOTP
              - CREDENTIAL_TYPE_EMAIL_OTP
              - CREDENTIAL_TYPE_RECOVERY_CODE
              - CREDENTIAL_TYPE_DELEGATED_GOOGLE
              - CREDENTIAL_TYPE_DELEGATED_MICROSOFT
              - CREDENTIAL_TYPE_UPSTREAM_IDP
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
      title: Enrollment Required
      type: object
      x-speakeasy-name-override: EnrollmentRequired
    c1.api.sign_in_policy.v1.StepUpRequired:
      description: >-
        StepUpRequired demands a stronger re-authentication before access is
        granted.
      properties:
        level:
          description: The assurance level the step-up must reach.
          enum:
            - AUTH_LEVEL_UNSPECIFIED
            - AUTH_LEVEL_NONE
            - AUTH_LEVEL_SINGLE_FACTOR
            - AUTH_LEVEL_MULTI_FACTOR
            - AUTH_LEVEL_PHR
            - AUTH_LEVEL_PHRH
          type: string
          x-speakeasy-unknown-values: allow
        maxAgeSeconds:
          description: How fresh the step-up must be, in seconds.
          format: int32
          type: integer
        types:
          description: The credential types that may satisfy the step-up.
          items:
            enum:
              - CREDENTIAL_TYPE_UNSPECIFIED
              - CREDENTIAL_TYPE_PASSKEY
              - CREDENTIAL_TYPE_PASSWORD
              - CREDENTIAL_TYPE_TOTP
              - CREDENTIAL_TYPE_EMAIL_OTP
              - CREDENTIAL_TYPE_RECOVERY_CODE
              - CREDENTIAL_TYPE_DELEGATED_GOOGLE
              - CREDENTIAL_TYPE_DELEGATED_MICROSOFT
              - CREDENTIAL_TYPE_UPSTREAM_IDP
            type: string
            x-speakeasy-unknown-values: allow
          type:
            - array
            - 'null'
      title: Step Up Required
      type: object
      x-speakeasy-name-override: StepUpRequired
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````