Skip to content

Policy Override

Overview

Policy Override lets you override the configuration of a gateway policy that is already attached to an API endpoint, for a specific gateway environment, without changing the catalog policy definition for every environment.

With this feature, you can:

  • Create overrides at API Level for a selected API, endpoint, policy, and environment.
  • Edit override configuration (including routing and transformation editors when applicable).
  • Search, edit, or delete existing overrides from a single list.

Path: API Manager → Gateway Control → Policy Override


Why This Matters

  • Apply environment-specific policy settings while keeping the same attached policy.
  • Change runtime config for one endpoint and environment without editing the shared catalog policy.
  • Do not use this page to attach a policy for the first time — attach under Gateway Policies or endpoint details first.
  • It is applicable only for non-default Environments.
  • Create gateway Environments before you create overrides.

Prerequisites

Required Access and Permissions

  • API Manager access.
  • Permission to manage Gateway Control features.

System / Technical Requirements

  • Valid organization context in the API Manager.
  • At least one published or onboarded API with endpoints.
  • At least one gateway policy already attached to the target endpoint.
  • At least one gateway environment.

Policy Override List

Search: Matches policy name, API name, or environment name.

Click Create Policy Override to open Policy Override / Create Policy Override.

Column Description
Policy Override Name Name of the attached policy (not a separate override title)
Control Level API Level or Subscription Level
Environment Gateway environment for the override
Status Active or Inactive
Created Date When the override was created
Edit Opens Policy Override / Edit Policy Override
Delete Opens Delete Policy Override

There is no View column and no API Name column on the list. API Name appears in search and in the delete modal.

Status values

Status Meaning
Active Override is enabled for the selected environment (default when status is missing)
Inactive Override is not currently applied

Step-by-Step Implementation

Creating a Policy Override

Step 1: Navigate to Policy Override

  • From the left navigation panel, open Gateway Control → Policy Override.

Step 2: Open Create

  • Click Create Policy Override to open Policy Override / Create Policy Override.

Step 3: Enter Basic Information

  1. Select Control Level → API Level (the only option on create).
  2. Select Select API.
  3. Select Select Endpoints.
  4. Select Policy (only policies attached to that endpoint appear).
  5. Select Environment.

Changing Control Level clears Policy. Changing API clears Endpoints and Policy. Changing Endpoints clears Policy.

Until you select a Policy, Override Configuration shows: Select a policy to load its override configuration.

Step 4: Configure Override Configuration

  • Complete the Override Configuration section for the selected policy type.
  • Routing, transformation, caching, throttling, CORS, and other supported types load dedicated editors.
  • Unsupported types use the Policy configuration text area.

Create stays disabled until all Basic Information fields are set and Override Configuration is non-empty.

Step 5: Save

  • Click Create.
  • Or click Cancel to return to the list without saving.

Success

The override appears in the list. Policy Override Name shows the attached policy name. Status is Active by default.

Editing a Policy Override

  1. On the Policy Override list, click Edit to open Policy Override / Edit Policy Override.
  2. Basic Information selectors are read-only. Update Override Configuration only.
  3. Click Update (enabled after you change the configuration).

Deleting a Policy Override

  1. On the Policy Override list, click Delete to open Delete Policy Override.
  2. Review Policy Override Name, Control Level, API Name, and Environment.
  3. Confirm with Delete, or choose Cancel.

Best Practices

Practice Reason
Attach the policy before creating an override The Policy selector lists only policies attached to the endpoint
Create environments first Each override requires a gateway environment
Prefer overrides for environment-specific differences Keep the catalog policy unchanged for other environments
Use Edit only for configuration changes Basic Information cannot be changed after create

Troubleshooting

Issue Possible Cause Resolution
No policies in the selector No policies attached to the endpoint Attach a policy to the endpoint first (No policies attached to selected endpoint)
Create disabled Incomplete Basic Information or empty Override Configuration Complete all required fields and Override Configuration
No endpoints found API has no endpoints Add endpoints under My APIs
No APIs found No APIs available in the organization Onboard or publish an API first
No environments found No gateway environments Create one in Environments
Update disabled No configuration changes yet Change Override Configuration before Update
No lists available for Policy override No overrides created yet Create the first override
No Policy overrides match your search Search or filters are too narrow Clear search or broaden the query

Frequently Asked Questions

Does a policy override replace attaching a policy?

No. The policy must already be attached to the endpoint. The override changes how that attachment is configured for the selected environment.

Can I create a subscription-level override?

The create form currently offers API Level as the Control Level. Existing rows may still show Subscription Level if present in the data.

What is Policy Override Name?

It is the name of the attached gateway policy, not a separate title you type when creating the override.

How does this relate to Environments?

Each override applies to one gateway environment. Create the environment first, then create the override.

Tip

Attach the policy to the endpoint first, create Environments as needed, then use Policy Override for environment-specific configuration without changing the catalog policy.