---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Trust policies"
description: "The `trust_policies` collection of Sylphx Broker: A TrustPolicy grants a set of subjects the right to exchange their identity for a provider credential on one Connection, never wider than the policy's permissions and repositories."
type: reference
product: platform
summary: "A TrustPolicy grants a set of subjects the right to exchange their identity for a provider credential on one Connection, never wider than…"
updated: 2026-09-28
order: 900
---

> **This method is not served on the public API.** `api.sylphx.com` does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

A TrustPolicy grants a set of subjects the right to exchange their identity for a provider credential on one Connection, never wider than the policy's permissions and repositories.

**Service** Sylphx Broker · **Resource type** `broker.sylphx.com/TrustPolicy` · **Name pattern** `orgs/{org}/trust_policies/{trust_policy}` · **Shape** `spec_status`

**Not available yet.** Sylphx Broker is declared in the registry but no backend serves it: every call answers `501` with the problem code `UNIMPLEMENTED`.

## Fields

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/trust_policies/{trust_policy}`. |
| `uid` | `string` | `trp_<cell><ulid>`. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `spec` | `TrustPolicySpec` | Desired state. Required. |
| `status` | `TrustPolicyStatus` | Observed state. Output only. |

## Methods

Every method of the collection, in the registry's order, with the scope it
needs. The full request, response and examples are one link away.

| Method | Call | What it does |
| --- | --- | --- |
| `GET` | [`get`](/docs/api/trust_policies#get) | Gets a trust policy. |
| `GET` | [`list`](/docs/api/trust_policies#list) | Lists an org's trust policies. |
| `POST` | [`create`](/docs/api/trust_policies#create) | Creates a trust policy. |
| `PATCH` | [`update`](/docs/api/trust_policies#update) | Updates a trust policy. |
| `DELETE` | [`delete`](/docs/api/trust_policies#delete) | Deletes a trust policy. |
| `POST` | [`exchange_token`](/docs/api/trust_policies#exchange-token) | Exchanges the caller's workload identity for a short-lived provider credential under a trust policy (RFC 8693 token exchange). The credential is narrowed to the request and cached per installation and permission set; a permission the Connection lacks is PERMISSION_DENIED with reason `CapabilityMissing`, never an outage. |

## get

Gets a trust policy.

`GET https://api.sylphx.com/v1/orgs/acme/trust_policies/trust-policy` · scope `broker:read` · effect `read` · not available yet · [Request, response and examples](/docs/api/trust_policies/get)

## list

Lists an org's trust policies.

`GET https://api.sylphx.com/v1/orgs/acme/trust_policies` · scope `broker:read` · effect `read` · not available yet · paginated · [Request, response and examples](/docs/api/trust_policies/list)

## create

Creates a trust policy.

`POST https://api.sylphx.com/v1/orgs/acme/trust_policies` · scope `broker:admin` · effect `write` · not available yet · [Request, response and examples](/docs/api/trust_policies/create)

## update

Updates a trust policy.

`PATCH https://api.sylphx.com/v1/orgs/acme/trust_policies/trust-policy` · scope `broker:admin` · effect `write` · not available yet · [Request, response and examples](/docs/api/trust_policies/update)

## delete

Deletes a trust policy.

`DELETE https://api.sylphx.com/v1/orgs/acme/trust_policies/trust-policy` · scope `broker:admin` · effect `destructive` · not available yet · [Request, response and examples](/docs/api/trust_policies/delete)

## exchange_token

Exchanges the caller's workload identity for a short-lived provider credential under a trust policy (RFC 8693 token exchange). The credential is narrowed to the request and cached per installation and permission set; a permission the Connection lacks is PERMISSION_DENIED with reason `CapabilityMissing`, never an outage.

`POST https://api.sylphx.com/v1/orgs/acme/trust_policies/trust-policy:exchangeToken` · scope `broker:exchange` · effect `write` · not available yet · [Request, response and examples](/docs/api/trust_policies/exchange_token)
