> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neo.projectdiscovery.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a standing policy rule

> Creates a rule in the caller's own scope, or in their workspace when they
administer it. Repository and thread rules are read-only through this API.




## OpenAPI

````yaml /openapi/neo.public.openapi.json post /api/v1/hooks
openapi: 3.1.0
info:
  contact:
    name: ProjectDiscovery
    url: https://neo.projectdiscovery.io
  description: Neo API Server - Security agent orchestration platform
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Neo API
  version: 1.0.0
servers:
  - description: Production
    url: https://neo.api.projectdiscovery.io
  - description: Development
    url: https://neo.api.dev.projectdiscovery.io
  - description: Local development
    url: http://localhost:8080
security: []
tags:
  - description: Task execution and management
    name: Tasks
  - description: Agent listing and management
    name: Agents
  - description: Public agent directory
    name: Agent Directory
  - description: User file storage management
    name: Files
  - description: User working memory management
    name: Memory
  - description: Scheduled and recurring task management
    name: Schedules
  - description: Knowledge base and semantic search
    name: Knowledge
  - description: Encrypted user credentials and API keys
    name: Secrets
  - description: Neo API key management for programmatic access
    name: API Keys
  - description: User profile and account information
    name: User
  - description: Task and LLM usage tracking
    name: Usage
  - description: Bring Your Own Key provider management
    name: BYOK
  - description: Connect personal AI provider accounts and select them as a model source
    name: AI Connections
  - description: Model discovery and capabilities
    name: Models
  - description: Third-party integrations
    name: Integrations
  - description: Skill knowledge documents for agent prompts
    name: Skills
  - description: User-authored tools and toolkit management
    name: Dynamic Tools
  - description: Team management and member invitations
    name: Teams
  - description: Prompt library management and discovery
    name: Prompts
  - description: Slack bot integration for workspace installation and OAuth
    name: Slack
  - description: GitHub integration for PR reviews and repository management
    name: GitHub
  - description: Vulnerability issue tracking and management
    name: Issues
  - description: Subscription billing and plans
    name: Billing
  - description: Project management and member assignments
    name: Projects
  - description: SSH key pair generation and management for remote server access
    name: SSH Keys
  - description: Codebase structural analysis and mapping
    name: Codemaps
  - description: AI-generated codebase documentation and security analysis
    name: CodeWiki
  - description: Captured HTTP traffic query and replay
    name: Network Events
  - description: User and team API activity metadata
    name: Audit Logs
  - description: Vulnerability triage for HackerOne, GitHub, and Security Inbox
    name: Triage
paths:
  /api/v1/hooks:
    post:
      tags:
        - Hooks
      summary: Create a standing policy rule
      description: >
        Creates a rule in the caller's own scope, or in their workspace when
        they

        administer it. Repository and thread rules are read-only through this
        API.
      operationId: post-v1-hooks
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/HookCreateRequest'
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Hook'
          description: Rule created
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: The rule is not valid
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Authentication required
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Not allowed to write policy in that scope
        '409':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: The scope already holds the maximum number of rules
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
          description: Internal error
      security:
        - BearerAuth: []
        - ApiKeyAuth: []
components:
  schemas:
    HookCreateRequest:
      properties:
        action:
          $ref: '#/components/schemas/HookAction'
        event:
          $ref: '#/components/schemas/HookEvent'
        matcher:
          $ref: '#/components/schemas/HookMatcher'
        scope:
          $ref: '#/components/schemas/HookScope'
        scope_id:
          description: >-
            Defaults to the caller for a user rule, or their workspace for an
            org rule.
          type: string
      required:
        - scope
        - event
        - action
      type: object
    Hook:
      properties:
        action:
          $ref: '#/components/schemas/HookAction'
        created_at:
          format: date-time
          type: string
        editable:
          description: >-
            Whether this caller may change or delete the rule. Reads are wider
            than writes.
          type: boolean
        enabled:
          type: boolean
        event:
          $ref: '#/components/schemas/HookEvent'
        id:
          format: uuid
          type: string
        locked:
          description: Locked workspace policy cannot be changed through this API.
          type: boolean
        matcher:
          $ref: '#/components/schemas/HookMatcher'
        scope:
          $ref: '#/components/schemas/HookScope'
        scope_id:
          type: string
        updated_at:
          format: date-time
          type: string
      required:
        - id
        - scope
        - scope_id
        - event
        - matcher
        - action
        - enabled
        - locked
        - created_at
        - updated_at
      type: object
    ErrorResponse:
      properties:
        code:
          description: >
            Stable machine-readable error code — branch on this rather than

            matching the human `error`/`message` strings. Domain codes include

            `user_spending_cap_reached`, `project_spending_cap_reached`, and

            `insufficient_neo_credits`; Free/usage codes include

            `free_grant_challenge_required`, `free_usage_exhausted`,

            `free_task_budget_exhausted`, `model_not_available_on_free`,

            `sandbox_not_available_on_free` (cloud sandbox surfaces are not

            available on the Free plan; task files remain available from the

            task), `free_cannot_continue_managed_task` (a task that ran on the

            standard cloud sandbox cannot be continued on the Free plan; start

            a new task), `free_origin_not_supported` (integration-originated

            tasks are not available on the Free plan),

            `weekly_usage_limit_reached`, `billing_period_usage_limit_reached`,

            `topup_required`, `subscription_required`, and

            `isolated_workspace_purged`. Otherwise it mirrors the error kind

            (e.g. `forbidden`, `invalid_request`, `not_exists`,
            `already_exists`).
          example: user_spending_cap_reached
          type: string
        error:
          example: Bad request
          type: string
        error_id:
          description: Correlation id for a specific error instance, when present.
          type: string
        kind:
          description: Coarse error category (e.g. "forbidden request", "invalid request").
          example: forbidden request
          type: string
        message:
          description: |
            Human-readable detail (the kind prefixed to the error). For display,
            not for branching.
          type: string
        turnstile_site_key:
          description: |
            Public Cloudflare Turnstile site key returned only with
            `free_grant_challenge_required`, so the client can complete the
            invisible verification before retrying the request.
          type: string
      required:
        - error
      type: object
    HookAction:
      description: >
        What happens when the matcher matches. Each action only runs on the
        events

        that read it, and a pairing outside that is refused.
      properties:
        max_denials:
          description: How many times a Stop or SubagentStop rule may send the agent back.
          type: integer
        on_yes:
          enum:
            - allow
            - deny
          type: string
        question:
          type: string
        reason:
          description: Shown to the agent when a call is denied or held for approval.
          type: string
        set:
          additionalProperties: true
          description: Replacement arguments, for update_input.
          type: object
        text:
          description: Context added to the run, for additional_context.
          type: string
        type:
          enum:
            - allow
            - deny
            - ask
            - additional_context
            - update_input
            - judge
          type: string
      required:
        - type
      type: object
    HookEvent:
      description: The moment in a task where the rule is checked.
      enum:
        - PreToolUse
        - PostToolUse
        - PostToolUseFailure
        - PermissionRequest
        - SessionStart
        - SubagentStop
        - Stop
      type: string
    HookMatcher:
      description: >
        Which calls the rule covers. An absent field matches anything, so an
        empty

        matcher covers everything within its scope. Prefer `path` for anything

        about a file or directory: it is checked against every string in the
        call,

        so one rule covers a read, a write, and a shell command alike.
      properties:
        args:
          description: Conditions on named argument fields.
          items:
            properties:
              op:
                enum:
                  - equals
                  - contains
                  - glob
                  - in
                  - is_secret
                type: string
              path:
                type: string
              value: {}
            required:
              - path
              - op
            type: object
          type: array
        path:
          description: >-
            Glob checked against every string in the call. A trailing slash
            covers the directory and everything under it.
          type: string
        source:
          description: >-
            Restricts the rule to tasks that arrived from these sources — chat,
            slack, or github.
          items:
            type: string
          type: array
        tool:
          description: Exact tool name or glob, e.g. github_*
          type: string
      type: object
    HookScope:
      description: Who the rule applies to. Rules from every scope are evaluated together.
      enum:
        - org
        - repo
        - user
        - thread
      type: string
  securitySchemes:
    BearerAuth:
      bearerFormat: JWT
      description: JWT authentication token
      scheme: bearer
      type: http
    ApiKeyAuth:
      description: Neo API key (neo_sk_* prefix)
      in: header
      name: X-Api-Key
      type: apiKey

````