---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Create REST API access policy

# Create REST API access policy {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 Minuten Lesedauer

Create an API access policy and map an authentication profile to restrict the
authentication type for a REST API. For example, you can create an API access policy that
allows only ID token authentication for a REST API.

## Vorbereitungen

Make sure that an authentication profile is created. For more information, see [Create an authentication profile](https://servicenow-prod.fluidtopics.net/12DG5ultj90ynl51RBPO4w "Create an authentication profile and add one or more authentication policies to the profile. You can also configure the ID Token and OAuth Token authentication profiles that are available by default.").

Role required: api_service_admin, adaptive_auth_policy_admin

## Prozedur

1. Navigate to AllSystem Web ServicesREST API Access Policies.
2. Select New.
3. On the form, fill in the mandatory fields and submit.  
   Hinweis:  
   You must reopen the submitted form to populate additional fields.
   {#create-api-access-policy__table_d4x_w45_d4b__entry__2}

   | Field | Description |
   |-|-|
   | Name | Unique name of the API access policy. |
   | Active | Option to make the API access policy active. |
   | REST API | The REST API to which the access policy is applied. For example, Attachment API. |
   | REST API PATH | API path of the REST API. This field is auto-populated based on the selected REST API. For example, now/attachment. |
   | HTTP Method | Method used for interacting with the API. This field is auto-populated based on the selected REST API. |
   | Version | Version of the API. For example, v1. This field is auto-populated based on the selected REST API. Hinweis: If you want to create an authentication policy for all versions of a REST API, you must create individual policies for each version. |
   | Resource | Child resource of the REST API. This field is auto-populated based on the selected REST API. For example, /now/attachment |
   | Table | The tables to which the API access policy applies. This option only applies to policies for the Table API. |
   | Application | Scope of the application. |
   | Global | Option to apply the policy to all methods, versions, and resources for the API. |
   | Apply to all methods | Option to apply the policy to all the methods, versions, and resources for the API. |
   | Apply to all resources | Option to apply the policy to all or the API resources. |
   | Apply to all versions | Option to apply the policy to all or the API versions. |
   | Apply to all tables | Option to apply the policy to all tables. This option only applies to policies for the Table API. |
   | [Advertise all auth schemes](https://servicenow-prod.fluidtopics.net/12DG5ultj90ynl51RBPO4w "Create an authentication profile and add one or more authentication policies to the profile. You can also configure the ID Token and OAuth Token authentication profiles that are available by default.") | Determines whether the `WWW-Authenticate` header includes all configured authentication schemes. When set to `false` (default), the header includes only the most recently configured authentication profile in the policy. When set to `true`, the header lists all configured authentication schemes. |
   [Tabelle : 1. API Access Policies]

   {#create-api-access-policy__table_d4x_w45_d4b}  
   Hinweis:  
   To understand more about the API access policy prioritization, see [API access policy prioritization](https://servicenow-prod.fluidtopics.net/fYY10JgGZY8gT67EFkh~oQ "Learn about the policy prioritization logic if there are multiple API access policy configured for your ServiceNow instance.").
4. Double-click Insert a new row.
5. Select an inbound authentication profile from the list and select the save icon ![save icon]().  
   For example, you can add Basic Auth, ID Token, Certificate based Auth, OAuth or WSSE Auth.
   1. To add one or more inbound authentication profiles, select New to create a new profile.
   2. Choose What Kind of authentication profiles?.  
      * Create standard http authentication profiles
      * Create WSSE authentication profiles
      * Create API Key authentication profiles
      * Create HMAC authentication profiles

      {#create-api-access-policy__ul_bnj_gpr_2wb}
   3. After creating the authentication profile, save the record.
   {#create-api-access-policy__substeps_vvx_qvx_2wb}
6. Select Submit to submit the REST API access policy.

