---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# API access policy

# API access policy {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

API access policy defines the permissions and duration of access to an API.

API access policy enables you to restrict access to inbound ServiceNow® APIs based on the authentication type and the specified filter criteria of the access policy.

Following are the three level auth policy support for the non-interactive sessions:

* REST API: Admin can define a global API auth policy or API specific auth policy.
* SOAP API: Admin can define a global API auth policy or API specific auth policy.
* System/Export Processor: Admin can define five base system auth profiles, which can be used to apply auth profile to processors API auth policy or processor specific auth policy.

{#api-access-policy__ul_pbt_ysq_dyb}  
Hinweis:  
If you add a global auth policy, then the policy applies for all the REST APIs, SOAP APIs, or System/Export Processors.

Following are the plugins auto-installed for API policies and authentication scope:

* com.glide.rest.policy
* com.glide.soap.policy
* com.glide.processor.policy
* com.glide.rest.auth.scope

{#api-access-policy__ul_jfn_cb1_b1c}

You can configure the default Global Blocking Policy or create a custom API access policy according to your security requirements. And apply filter criteria that contain filter conditions or queries that are used as policy inputs
for an authentication policy.

The following API access policies are supported in ServiceNow®:

* [REST API access policies](https://servicenow-prod.fluidtopics.net/002u62CFr18p4d3zwiyGlQ "REST API access policies allow you to restrict access to inbound REST APIs based on the authentication type and the specified filter criteria of the access policy.")
* [SOAP API access
  policies](https://servicenow-prod.fluidtopics.net/YjYUIM7SdM_edAiQfsQMIg "SOAP API access policies allow you to restrict access to inbound SOAP APIs based on the authentication type and the specified filter criteria of the access policy.")

{#api-access-policy__ul_a21_dnc_lvb}

For information about policies related to export processors, see [Access policy for System or Export Processors](https://servicenow-prod.fluidtopics.net/4BdJWGmXxvaDxWbFbSCfXQ "Ability for System or Export Processors to leverage processor access policy to secure all the export endpoints.").

