Policy Override¶
Overview¶
Policy Override lets you override the configuration of a gateway policy that is already attached to an API endpoint, for a specific gateway environment, without changing the catalog policy definition for every environment.
With this feature, you can:
- Create overrides at API Level for a selected API, endpoint, policy, and environment.
- Edit override configuration (including routing and transformation editors when applicable).
- Search, edit, or delete existing overrides from a single list.
Path: API Manager → Gateway Control → Policy Override
Why This Matters¶
- Apply environment-specific policy settings while keeping the same attached policy.
- Change runtime config for one endpoint and environment without editing the shared catalog policy.
- Do not use this page to attach a policy for the first time — attach under Gateway Policies or endpoint details first.
- It is applicable only for non-default Environments.
- Create gateway Environments before you create overrides.
Prerequisites¶
Required Access and Permissions¶
- API Manager access.
- Permission to manage Gateway Control features.
System / Technical Requirements¶
- Valid organization context in the API Manager.
- At least one published or onboarded API with endpoints.
- At least one gateway policy already attached to the target endpoint.
- At least one gateway environment.
Policy Override List¶
Search: Matches policy name, API name, or environment name.
Click Create Policy Override to open Policy Override / Create Policy Override.
| Column | Description |
|---|---|
Policy Override Name |
Name of the attached policy (not a separate override title) |
Control Level |
API Level or Subscription Level |
Environment |
Gateway environment for the override |
Status |
Active or Inactive |
Created Date |
When the override was created |
Edit |
Opens Policy Override / Edit Policy Override |
Delete |
Opens Delete Policy Override |
There is no View column and no API Name column on the list. API Name appears in search and in the delete modal.
Status values¶
| Status | Meaning |
|---|---|
| Active | Override is enabled for the selected environment (default when status is missing) |
| Inactive | Override is not currently applied |
Step-by-Step Implementation¶
Creating a Policy Override¶
Step 1: Navigate to Policy Override¶
- From the left navigation panel, open
Gateway Control → Policy Override.
Step 2: Open Create¶
- Click
Create Policy Overrideto open Policy Override / Create Policy Override.
Step 3: Enter Basic Information¶
- Select
Control Level→API Level(the only option on create). - Select
Select API. - Select
Select Endpoints. - Select
Policy(only policies attached to that endpoint appear). - Select
Environment.
Changing Control Level clears Policy. Changing API clears Endpoints and Policy. Changing Endpoints clears Policy.
Until you select a Policy, Override Configuration shows: Select a policy to load its override configuration.
Step 4: Configure Override Configuration¶
- Complete the Override Configuration section for the selected policy type.
- Routing, transformation, caching, throttling, CORS, and other supported types load dedicated editors.
- Unsupported types use the Policy configuration text area.
Create stays disabled until all Basic Information fields are set and Override Configuration is non-empty.
Step 5: Save¶
- Click
Create. - Or click
Cancelto return to the list without saving.
Success
The override appears in the list. Policy Override Name shows the attached policy name. Status is Active by default.
Editing a Policy Override¶
- On the Policy Override list, click
Editto open Policy Override / Edit Policy Override. - Basic Information selectors are read-only. Update Override Configuration only.
- Click
Update(enabled after you change the configuration).
Deleting a Policy Override¶
- On the Policy Override list, click
Deleteto open Delete Policy Override. - Review
Policy Override Name,Control Level,API Name, andEnvironment. - Confirm with
Delete, or chooseCancel.
Best Practices¶
| Practice | Reason |
|---|---|
| Attach the policy before creating an override | The Policy selector lists only policies attached to the endpoint |
| Create environments first | Each override requires a gateway environment |
| Prefer overrides for environment-specific differences | Keep the catalog policy unchanged for other environments |
| Use Edit only for configuration changes | Basic Information cannot be changed after create |
Troubleshooting¶
| Issue | Possible Cause | Resolution |
|---|---|---|
| No policies in the selector | No policies attached to the endpoint | Attach a policy to the endpoint first (No policies attached to selected endpoint) |
| Create disabled | Incomplete Basic Information or empty Override Configuration | Complete all required fields and Override Configuration |
| No endpoints found | API has no endpoints | Add endpoints under My APIs |
| No APIs found | No APIs available in the organization | Onboard or publish an API first |
| No environments found | No gateway environments | Create one in Environments |
| Update disabled | No configuration changes yet | Change Override Configuration before Update |
| No lists available for Policy override | No overrides created yet | Create the first override |
| No Policy overrides match your search | Search or filters are too narrow | Clear search or broaden the query |
Frequently Asked Questions¶
Does a policy override replace attaching a policy?
No. The policy must already be attached to the endpoint. The override changes how that attachment is configured for the selected environment.
Can I create a subscription-level override?
The create form currently offers API Level as the Control Level. Existing rows may still show Subscription Level if present in the data.
What is Policy Override Name?
It is the name of the attached gateway policy, not a separate title you type when creating the override.
How does this relate to Environments?
Each override applies to one gateway environment. Create the environment first, then create the override.
Tip
Attach the policy to the endpoint first, create Environments as needed, then use Policy Override for environment-specific configuration without changing the catalog policy.