Reference
/- Create or update a category / subcategory policy
List all business policy groups
Fetch all policy groups with their policies
Get business policies by policy group ID
Get a single business policy by ID
Get full business policy summary
Get category or subcategory policies
Update a category or subcategory policy
Delete a category or subcategory policy
List policy approval workflows for the selected currency
Create a policy approval workflow for a currency
Create a new business policy
Update a business policy
Delete a business policy
Create or update a catego...
🔒 Private label — contact sales. Requires a private-label entitlement on your API client.
Upserts a business policy under the SUBCATEGORY or CATEGORY policy group.
- Without
_id: initializes a new policy then applies the full payload in one call. - With
_id: updates the existing policy directly.
The policy group is resolved automatically from the type query param.
Security
oauth2ClientCredentials(Required scopes: business-policies:write)
Business policy MongoDB ObjectId. When present the policy is updated; omit to create.
Example:"6a3ebb7893bb2649e19cb8a6"
Policy status. INACTIVE is accepted as an alias for DISABLED.
Enum:"ACTIVE""DISABLED""INACTIVE""DELETED"
Example:"ACTIVE"
- Mock serverhttps://developer.boyahq.com/_mock/v2/openapi/business-policies/category-policies
- Productionhttps://api.boyahq.com/v2/business-policies/category-policies
- Sandboxhttps://sandbox.api.boyahq.com/v2/business-policies/category-policies
curl -i -X PUT \
'https://developer.boyahq.com/_mock/v2/openapi/business-policies/category-policies?type=subcategory' \
-H 'Authorization: Bearer <YOUR_TOKEN_HERE>' \
-H 'Content-Type: application/json' \
-H 'business_id: string' \
-d '{
"_id": "6a3ebb7893bb2649e19cb8a6",
"name": "Company Travel spend limits",
"type": "business",
"status": "ACTIVE",
"description": "string",
"priority": 1,
"workflow": {},
"employees": [
"string"
],
"teams": [
"string"
],
"budgets": [
"string"
],
"rules": [
{
"conditions": [
{
"field": "string",
"operator": "string",
"value": {},
"value_id": "string"
}
],
"action": "string",
"period_unit": "TRANSACTION",
"period": 0,
"kick_off_date": "string",
"target": "string",
"target_employees": [
"string"
],
"exempt_employees": [
"string"
],
"target_teams": [
"string"
],
"exempt_teams": [
"string"
],
"target_sub_categories": [
"string"
],
"exempt_sub_categories": [
"string"
],
"target_channels": [
"string"
],
"target_roles": [
"string"
],
"require_tax_compliant_receipt": true,
"funding_source_strategy": "string",
"exempt_wallet_types": [
"string"
]
}
],
"require_tax_compliant_receipt": true
}'Business policy created or updated successfully
Parent policy group — either a MongoDB ObjectId string or an expanded PolicyRefV1Dto object
Response
{ "_id": "string", "status": "ACTIVE", "policy": { "_id": "string", "status": "ACTIVE", "description": "string", "policy_code": "string" }, "business": "string", "policy_type": "string", "policy_code": "string", "employees": [ "string" ], "teams": [ "string" ], "budgets": [ "string" ], "priority": 0, "workflow": {}, "rules": [ { … } ], "name": "string", "description": "string", "createdAt": "string", "updatedAt": "string" }