<!-- https://cutedyno.com/docs/api/update-policy -->

# Update profile policy

`PUT https://api.cutedyno.com/v1/policy`

Sets the guardrails on a profile. Only the fields you send change.



Required permission: `posts:write`

Accepts `profileId` to target a specific profile. Omit it to use the key’s home profile.

Required permission: `posts:write`

MCP tool: `update_policy`

## Body

- `profileId` (string) — Profile to act on. Defaults to the profile the API key was created in.
- `requireApproval` (boolean)
- `allowedPlatforms` (enum[])
- `maxPostsPerDay` (integer) — Cap on posts per UTC day for this profile. null removes the cap.

## Request

```bash
curl -X PUT "https://api.cutedyno.com/v1/policy" \
  -H "Authorization: Bearer $CUTEDYNO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "profileId": "profile_a1b2c3d4",
  "requireApproval": false,
  "allowedPlatforms": [
    "facebook"
  ],
  "maxPostsPerDay": 0
}'
```

```typescript
import { CuteDyno } from '@cutedyno/node';

const cutedyno = new CuteDyno();

const result = await cutedyno.policy.update({
  profileId: "profile_a1b2c3d4",
  requireApproval: false,
  allowedPlatforms: [
    "facebook"
  ],
  maxPostsPerDay: 0
});
console.log(result);
```

```python
import os
import requests

url = "https://api.cutedyno.com/v1/policy"
headers = {"Authorization": f"Bearer {os.environ['CUTEDYNO_API_KEY']}"}

payload = {
    "profileId": "profile_a1b2c3d4",
    "requireApproval": False,
    "allowedPlatforms": [
        "facebook"
    ],
    "maxPostsPerDay": 0
}

response = requests.put(url, json=payload, headers=headers)
response.raise_for_status()
print(response.json())
```

## Response 200

- `policy` (Policy, required)
- `profileId` (string, required)

```json
{
  "policy": {
    "requireApproval": false,
    "allowedPlatforms": [
      "facebook"
    ],
    "maxPostsPerDay": 0
  },
  "profileId": "profile_a1b2c3d4"
}
```

## Errors

- `invalid_request` (400) — The request body or query string failed validation. The message names the offending field.
- `invalid_api_key` (401) — The key does not exist, was revoked, or is malformed. Keys start with cdyn_live_.
- `profile_not_accessible` (403) — The requested profile is outside this key’s scope, or belongs to another account.
- `rate_limit_exceeded` (429) — Too many requests for this key. Honour the Retry-After header before retrying.
- `internal_error` (500) — Something failed on our side. Retry with the same Idempotency-Key; report the requestId if it persists.