# GET /api/rule/list

**URL:** <https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155>\
**Category:** Non-Public API Deprecations\
**Tags:** deprecated\
**Created:** [January 30, 2024, 3:30pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155 "2024-01-30T15:30:04Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![colin\_mckibben](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/colin_mckibben/32/37182_2.png) [@colin\_mckibben](https://developer.sailpoint.com/discuss/u/colin_mckibben)\
**Post date:** [January 30, 2024, 3:30pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/1 "2024-01-30T15:30:04Z")

</div>

There are two ways to get rules.

# Get rules via CLI

The latest release of the CLI ([2.1.4](https://github.com/sailpoint-oss/sailpoint-cli/releases/tag/2.1.4)) allows you to list rules from your tenant.

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/2/2af77bf8738ec972eb321d91dc6826f9001f33fe.jpeg)

# Get rules via API

The replacement for this endpoint is to use the SP Config API to export rules for your tenant.

[https://developer.sailpoint.com/idn/api/beta/sp-config](https://developer.sailpoint.com/idn/api/beta/sp-config)

This is a three step process.

1. Initiate a configuration export using [https://developer.sailpoint.com/idn/api/beta/export-sp-config](https://developer.sailpoint.com/idn/api/beta/export-sp-config). Use the following request body payload to export rules.

2. Check the status of the export job using [https://developer.sailpoint.com/idn/api/beta/get-sp-config-export-status](https://developer.sailpoint.com/idn/api/beta/get-sp-config-export-status). You will need to provide the `jobId` from the last step in the URL of this endpoint. Depending on the size of data that needs to be exported, this can take a few seconds to a few minutes. You will need to wait for the status to show `COMPLETE` before you can download the results.

3. Download the results using [https://developer.sailpoint.com/idn/api/beta/get-sp-config-export](https://developer.sailpoint.com/idn/api/beta/get-sp-config-export), inserting the `jobId` from step 1 into the URL. This will return a JSON response of all the rules in your tenant.

# Get rules via Config Hub

Using [Config Hub](https://documentation.sailpoint.com/saas/help/confighub/config_hub.htm), you can export rules from the user interface.

 ![image](https://global.discourse-cdn.com/sailpoint/original/2X/7/79e2d433edc4318cd2a380177f5df3519a96de5f.png)

---

<div class="post-metadata">

**Author:** ![adunker](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/adunker/32/2664_2.png) [@adunker](https://developer.sailpoint.com/discuss/u/adunker)\
**Post date:** [January 30, 2024, 3:43pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/2 "2024-01-30T15:43:24Z")

</div>

How would we be able to get a cloud rule name / ID to attach to sources? Would the expectation to be to use SP-Config to initiate an export of rules and the get an name / ID from there? That should work fine - just annoyingly cumbersome compared to having an endpoint for cloud rules.

---

<div class="post-metadata">

**Author:** ![jalexand](https://avatars.discourse-cdn.com/v4/letter/j/258eb7/32.png) [@jalexand](https://developer.sailpoint.com/discuss/u/jalexand)\
**Post date:** [January 30, 2024, 3:59pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/3 "2024-01-30T15:59:05Z")

</div>

We are currently going through an IDN implementation. This endpoint is crucial to troubleshooting cloud rules. Otherwise, we cannot view the rules to check the logic as far as I know. It’s rough enough we have to submit a ticket every time they need updated, but being unable to view them is going to be a big roadblock.

Is there another method of viewing the script the cloud rule is running? Can the deprecation simply be pushed until the replacement is available?

---

<div class="post-metadata">

**Author:** ![jallen](https://avatars.discourse-cdn.com/v4/letter/j/839c29/32.png) [@jallen](https://developer.sailpoint.com/discuss/u/jallen)\
**Post date:** [January 30, 2024, 4:17pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/4 "2024-01-30T16:17:59Z")

</div>

I agree, this feels like quite an important endpoint for troubleshooting rules. The description is very clear to me, when you say “There will not be a public replacement available before March 31st” does that mean that there will be a replacement on March 31st or that there’s no planned replacement or ETA for a replacement? As @jalexand says, it’s already a pain that we have to pay extra to get these updated, would be even worse if we had to pay just to see what the rules look like.

---

<div class="post-metadata">

**Author:** ![colin\_mckibben](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/colin_mckibben/32/37182_2.png) [@colin\_mckibben](https://developer.sailpoint.com/discuss/u/colin_mckibben)\
**Post date:** [January 30, 2024, 7:27pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/5 "2024-01-30T19:27:25Z")

</div>

Good news. Our SP config API can export all rules, including cloud rules. I have update the first post in this topic to demonstrate how to do this.

---

<div class="post-metadata">

**Author:** ![jalexand](https://avatars.discourse-cdn.com/v4/letter/j/258eb7/32.png) [@jalexand](https://developer.sailpoint.com/discuss/u/jalexand)\
**Post date:** [February 2, 2024, 2:51pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/6 "2024-02-02T14:51:08Z")

</div>

Excellent, I’ve confirmed I was able to retrieve the rules. It’s not as streamlined, but it solves the ask nonetheless. Thank you, Colin!

---

<div class="post-metadata">

**Author:** ![akasper](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/akasper/32/6973_2.png) [@akasper](https://developer.sailpoint.com/discuss/u/akasper)\
**Post date:** [February 6, 2024, 11:56pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/8 "2024-02-06T23:56:21Z")

</div>

Umm, HELP!! - This does NOT return any data, it just starts a background job.

Can you please advise how to update the ruby **I/O TOOL** (idnio-2.3.4b) to manage this?? (rules.rb) (We’ve been relying on this and have history for 3+ years as our fortnightly backup.)  
My ruby knowledge is only as far as I can google - or can AI rewrite it for us?? 😉

> #  
> # Exports Rule configurations.  
> #  
> def self.export( directory )
> 
> ```
> response = IDNAPI.get( "#{$url}/cc/api/rule/list", $token )
> 
> case response
> when Net::HTTPSuccess
> 
> rules = JSON.parse( response.body )
> 
> ```

etc…

---

<div class="post-metadata">

**Author:** ![colin\_mckibben](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/colin_mckibben/32/37182_2.png) [@colin\_mckibben](https://developer.sailpoint.com/discuss/u/colin_mckibben)\
**Post date:** [February 7, 2024, 3:31pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/9 "2024-02-07T15:31:51Z")

</div>

> [@akasper](#):
>
> Umm, HELP!! - This does NOT return any data, it just starts a background job.

Sorry about that. You are correct in that this a three step process. I have updated the post to describe each step needed to get the rules, as well as how to do this using Config Hub.

You will need to update your ruby script to follow the three step process mentioned above. I too would need to google the right ruby code 😉 but here is some pseudo code to help you update your script. This is not ruby code, just an example of the steps you would need to take in your code to accomplish exporting rules. You’ll need to google the correct ruby code to make this work.

```auto
payload = {
  "description": "Export all available rules",
  "excludeTypes": [],
  "includeTypes": [
    "RULE"
  ],
  "objectOptions": {}
}
# initiate the export job for all rules
response = IDNAPI.post("/beta/sp-config/export", payload)
jobId = response["jobId"] # Save the jobId

# Check the status of the job every 5 seconds until it is complete
exportStatusUrl = "/beta/sp-config/export/" + jobId
while (JSON.parse(IDNAPI.get(exportStatusUrl).body)["status"] != "COMPLETE")
    wait(5) # wait 5 seconds

# Get the results
exportDownloadUrl = "/beta/sp-config/export/" + jobId + "/download"
response = IDNAPI.get(exportDownloadUrl)
rules = JSON.parse(response.body)

```

---

<div class="post-metadata">

**Author:** ![reklawttocs](https://avatars.discourse-cdn.com/v4/letter/r/96bed5/32.png) [@reklawttocs](https://developer.sailpoint.com/discuss/u/reklawttocs)\
**Post date:** [February 15, 2024, 8:15pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/10 "2024-02-15T20:15:38Z")

</div>

Hi Colin.

The Visual Studio Code Extension for IDN included listing Rules (though just connector rules for whatever reason). We use that tool a large amount for our ongoing enhancements as we flesh out our IDN implementation from last year (2023). To your knowledge is the maintainer of that tool incorporating the new approach for Rules ?

---

<div class="post-metadata">

**Author:** ![colin\_mckibben](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/colin_mckibben/32/37182_2.png) [@colin\_mckibben](https://developer.sailpoint.com/discuss/u/colin_mckibben)\
**Post date:** [February 15, 2024, 8:58pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/11 "2024-02-15T20:58:16Z")

</div>

T

> [@reklawttocs](#):
>
> The Visual Studio Code Extension for IDN

The VS Code Extension is a community tool maintained by @yannick_beot .

---

<div class="post-metadata">

**Author:** ![reklawttocs](https://avatars.discourse-cdn.com/v4/letter/r/96bed5/32.png) [@reklawttocs](https://developer.sailpoint.com/discuss/u/reklawttocs)\
**Post date:** [February 15, 2024, 9:04pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/12 "2024-02-15T21:04:06Z")

</div>

Right, thanks. And I likely answered my own question as it looks like the VS Code rules management uses the Beta Connector Rule Managment APIs, so it should still be ok. And that explains why it just shows the Connector rules and not any Cloud rules.

---

<div class="post-metadata">

**Author:** ![reklawttocs](https://avatars.discourse-cdn.com/v4/letter/r/96bed5/32.png) [@reklawttocs](https://developer.sailpoint.com/discuss/u/reklawttocs)\
**Post date:** [February 15, 2024, 9:11pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/13 "2024-02-15T21:11:36Z")

</div>

One key difference I note in the new approach to retrieving Rules is that the beta/sp-config/export API response does not seem to include any of the default rules vs. the /cc/api/rule/list API which included the default/demo rules. i.e. only rules which have been customized in the target tenant are returned by beta/sp-config/export.

Pros and Cons to this difference. Is this on purpose ?

---

<div class="post-metadata">

**Author:** ![colin\_mckibben](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/colin_mckibben/32/37182_2.png) [@colin\_mckibben](https://developer.sailpoint.com/discuss/u/colin_mckibben)\
**Post date:** [February 15, 2024, 9:37pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/14 "2024-02-15T21:37:37Z")

</div>

> [@reklawttocs](#):
>
> One key difference I note in the new approach to retrieving Rules is that the beta/sp-config/export API response does not seem to include any of the default rules vs. the /cc/api/rule/list API which included the default/demo rules. i.e. only rules which have been customized in the target tenant are returned by beta/sp-config/export.

Possibly just an oversight. I don’t think it would be intentional to leave out rules.

---

<div class="post-metadata">

**Author:** ![yannick\_beot](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/yannick_beot/32/8985_2.png) [@yannick\_beot](https://developer.sailpoint.com/discuss/u/yannick_beot)\
**Post date:** [February 15, 2024, 9:42pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/15 "2024-02-15T21:42:12Z")

</div>

@reklawttocs  
Currently, the VSCode plugin can export all rules through the SPConfig.  
I have just tested and by selected all rules, cloud rules will also be exported.

Actually, I just learned from Colin’s answer that the SPConfig could be leveraged to get the cloud rules.

Not sure what I can do more.  
Cloud rules will not be “editable” as connector rules.  
Feel free to create an issue as an enhancement request and to write your expectation, expected behavior and all.

---

<div class="post-metadata">

**Author:** ![angelo\_mekenkamp](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/angelo_mekenkamp/32/3386_2.png) [@angelo\_mekenkamp](https://developer.sailpoint.com/discuss/u/angelo_mekenkamp)\
**Post date:** [June 5, 2024, 9:44am UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/16 "2024-06-05T09:44:50Z")

</div>

I hope there will be an API available similar to GET `/api/rule/list`.  
Now we are dependent on using the CLI, `sp-config` or the `config-hub`, all of which require additional steps, is less user friendly and is not consistent with all other objects that are easily available through GET `/v3/any_object_types`.

Something like GET `/v3/rules` that directly gives a JSON array of the rules would be consistent here. We already have GET `/beta/connector-rules`, which only shows the connector-rules. Instead of `/v3/rules` it would also be fine for me if an API like GET `/v3/cloud-rules` would become available. Then we can also use APIs to fetch all rules easily.

Kind regards,  
Angelo

---

<div class="post-metadata">

**Author:** ![awyss](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/awyss/32/37310_2.png) [@awyss](https://developer.sailpoint.com/discuss/u/awyss)\
**Post date:** [June 11, 2024, 2:21pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/17 "2024-06-11T14:21:04Z")

</div>

1000% agreed. Having to go through sp-config, config hub, or vs code is significantly less user friendly than having a direct API endpoint to get at the data.

Just look at my documentation tool from dev days. Having to engineer in a solution for sp-config instead of having a direct API call is a lot more overhead than what is necessary IMO

---

<div class="post-metadata">

**Author:** ![swcoleman](https://avatars.discourse-cdn.com/v4/letter/s/76d3ee/32.png) [@swcoleman](https://developer.sailpoint.com/discuss/u/swcoleman)\
**Post date:** [June 11, 2024, 3:22pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/18 "2024-06-11T15:22:03Z")

</div>

to save everyone else a “google” search.

> [@Tenant documentation done in the speed of Shell](https://developer.sailpoint.com/discuss/t/tenant-documentation-done-in-the-speed-of-shell/37591):
>
> [[Tenant documentation done in the speed of Shell] ](https://www.youtube.com/watch?v=bWBEhuiTmzM)Description Interested in generating real-time documentation of your current environment’s configuration? Expert community ambassador, Adam Wyss, shows off how he leverages the Identity Security Cloud APIs to automatically generate documentation for all configurable objects in his tenant.

---

<div class="post-metadata">

**Author:** ![awyss](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/awyss/32/37310_2.png) [@awyss](https://developer.sailpoint.com/discuss/u/awyss)\
**Post date:** [June 11, 2024, 3:31pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/19 "2024-06-11T15:31:44Z")

</div>

I appreciate you linking this. Still hoping we can release it to the community but no updates yet on that sadly.

---

<div class="post-metadata">

**Author:** ![justinrhaines](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/justinrhaines/32/16564_2.png) [@justinrhaines](https://developer.sailpoint.com/discuss/u/justinrhaines)\
**Post date:** [October 24, 2024, 3:56pm UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/20 "2024-10-24T15:56:10Z")

</div>

Similar to other posts, it would be good to be able to export all rules because, as it is currently working, we are not able to export any SDIM Integration BeforeProvisioning rules.

---

<div class="post-metadata">

**Author:** ![baoussounda](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/baoussounda/32/13095_2.png) [@baoussounda](https://developer.sailpoint.com/discuss/u/baoussounda)\
**Post date:** [December 23, 2024, 10:00am UTC](https://developer.sailpoint.com/discuss/t/get-api-rule-list/28155/21 "2024-12-23T10:00:58Z")

</div>

@colin_mckibben i’m agree with @justinrhaines. It not possible to export “Sample Before Provisioning Rule for SDIM” rule.
