> ## Documentation Index
> Fetch the complete documentation index at: https://openworklabs.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Apply desktop-policies by stable key

> Creates or replaces an organization-scoped resource. Names do not identify resources; existing unkeyed resources are never adopted automatically. Assignments are replaced. Omitted write-only secrets are preserved. Concurrent writes are last-write-wins; conditional headers are not supported on this route.



## OpenAPI

````yaml /openapi.json put /v1/desktop-policies/by-key/{externalKey}
openapi: 3.1.0
info:
  title: Den API
  description: >-
    OpenAPI spec for the Den control plane API.


    Authentication:

    - Use `Authorization: Bearer <session-token>` for user-authenticated routes
    that require a Den session.

    - Use `x-api-key: <den-api-key>` for organization API-key calls. API keys
    resolve to the issuing user and the organization member they were scoped to
    when created, so they can call ordinary user and organization routes without
    a separate signed-in session.
      Example: `curl https://api.openworklabs.com/v1/me -H "x-api-key: den_..."`.
    - Session-only flows still require a signed-in user session, including
    organization creation, invitation acceptance, active-organization switching,
    and MCP token minting.

    - Public routes like health and documentation do not require authentication.


    Swagger tip: use the security schemes in the Authorize dialog to set either
    `bearerAuth` or `denApiKey` before trying protected endpoints.
  version: dev
servers:
  - url: http://api.den.local
security: []
tags:
  - name: System
    description: Service health and operational routes.
  - name: Organizations
    description: Top-level organization creation and context routes.
  - name: Invitations
    description: Invitation preview, acceptance, creation, and cancellation routes.
  - name: API Keys
    description: Organization API key management routes.
  - name: SCIM
    description: Organization SCIM connector management routes.
  - name: SSO
    description: Organization single sign-on connector management routes.
  - name: Members
    description: Organization member management routes.
  - name: Roles
    description: Organization custom role management routes.
  - name: Teams
    description: Organization team management routes.
  - name: Templates
    description: Organization shared template routes.
  - name: LLM Providers
    description: Organization LLM provider catalog, configuration, and access routes.
  - name: Workers
    description: Worker lifecycle, billing, and runtime routes.
  - name: Worker Runtime
    description: Worker runtime inspection and upgrade routes.
  - name: Worker Activity
    description: Worker heartbeat and activity reporting routes.
  - name: Telemetry
    description: Telemetry event ingestion and adoption analytics.
  - name: Admin
    description: Administrative reporting routes.
  - name: Users
    description: Current user and membership routes.
  - name: Bootstrap
    description: Agent-first provisional workspace setup routes.
paths:
  /v1/desktop-policies/by-key/{externalKey}:
    put:
      tags:
        - Desktop Policies
      summary: Apply desktop-policies by stable key
      description: >-
        Creates or replaces an organization-scoped resource. Names do not
        identify resources; existing unkeyed resources are never adopted
        automatically. Assignments are replaced. Omitted write-only secrets are
        preserved. Concurrent writes are last-write-wins; conditional headers
        are not supported on this route.
      operationId: putV1DesktopPoliciesByKeyByExternalKey
      parameters:
        - in: path
          name: externalKey
          schema:
            type: string
            pattern: ^[a-z0-9][a-z0-9._-]{0,127}$
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                policyName:
                  type: string
                  minLength: 1
                  maxLength: 255
                policy:
                  $ref: '#/components/schemas/DenDesktopPolicyDocumentWrite'
                priority:
                  type: integer
                  minimum: 0
                  maximum: 1000000
                isEnabled:
                  type: boolean
                memberIds:
                  maxItems: 500
                  type: array
                  items:
                    description: >-
                      Den TypeID with 'om_' prefix and a 26-character base32
                      suffix.
                    format: typeid
                    type: string
                    minLength: 29
                    maxLength: 29
                teamIds:
                  maxItems: 500
                  type: array
                  items:
                    description: >-
                      Den TypeID with 'tem_' prefix and a 26-character base32
                      suffix.
                    format: typeid
                    type: string
                    minLength: 30
                    maxLength: 30
                roles:
                  default: []
                  maxItems: 10
                  type: array
                  items:
                    type: string
                    enum:
                      - owner
                      - admin
                      - member
              required:
                - policyName
                - policy
      responses:
        '200':
          description: The existing resource was replaced.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DesktopPolicyResponse'
        '201':
          description: The resource was created.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DesktopPolicyResponse'
        '400':
          description: Invalid declarative request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/InvalidRequestError'
        '401':
          description: Authentication required.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedError'
        '403':
          description: Resource management permission required.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ForbiddenError'
        '404':
          description: A referenced resource was not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NotFoundError'
        '409':
          description: A name or identity conflict requires reconciliation.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                  message:
                    type: string
                required:
                  - error
components:
  schemas:
    DenDesktopPolicyDocumentWrite:
      type: object
      properties:
        allowCustomProviders:
          type: boolean
        allowZenModel:
          type: boolean
        allowMultipleWorkspaces:
          type: boolean
        allowControlSettings:
          type: boolean
        allowManageExtensions:
          type: boolean
        allowBuiltInExtensions:
          type: boolean
        allowAlphaUpdates:
          type: boolean
        showWelcomePage:
          type: boolean
        onboardingPrompts:
          anyOf:
            - minItems: 2
              maxItems: 3
              type: array
              items:
                type: string
                minLength: 1
                maxLength: 500
            - type: 'null'
        onboardingPromptDescriptions:
          anyOf:
            - minItems: 2
              maxItems: 3
              type: array
              items:
                type: string
                maxLength: 120
            - type: 'null'
    DesktopPolicyResponse:
      type: object
      properties:
        desktopPolicy:
          type: object
          properties: {}
          additionalProperties: {}
      required:
        - desktopPolicy
    InvalidRequestError:
      type: object
      properties:
        error:
          type: string
          const: invalid_request
        details:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
              path:
                type: array
                items:
                  anyOf:
                    - type: string
                    - type: number
            required:
              - message
            additionalProperties: {}
        capability:
          type: string
      required:
        - error
        - details
    UnauthorizedError:
      type: object
      properties:
        error:
          type: string
          const: unauthorized
      required:
        - error
    ForbiddenError:
      type: object
      properties:
        error:
          type: string
          enum:
            - forbidden
            - reauth
        reason:
          type: string
        message:
          type: string
      required:
        - error
    NotFoundError:
      type: object
      properties:
        error:
          type: string
        message:
          type: string
      required:
        - error

````