Skip to main content
POST
Create a posture

Authorizations

Authorization
string
header
required

Supabase JWT token in Authorization: Bearer header

Headers

Idempotency-Key
string
required

Client-supplied idempotency token (required). Replays within 24 hours return the stored result; reusing a key with a different body returns 409. See ADR-023.

Body

application/json
slug
string
required

URL-safe identifier for the posture, unique within its scope (lowercase letters, digits, and hyphens).

name
string
required

Human-readable display name for the posture.

scope
enum<string>
required

Ownership scope: platform (Mnemom-default, staff only) or org (tenant-owned; requires org_id).

Available options:
platform,
org
body
object
required

Trust posture body (PostureBody v1.0): the sideband, fleet_identification, and fan_out configuration this posture enforces.

description
string

Optional human-readable summary of what this posture enforces.

org_id
string

Required when scope=org.

Response

Posture.

Trust posture row (mig 173). Library row; revisions are versioned bodies stored separately.

posture_id
string
required
Pattern: ^tp-[a-z0-9-]{1,64}$
slug
string
required

URL-safe identifier (e.g., 'standard', 'banking-core').

name
string
required
scope
enum<string>
required
Available options:
platform,
org
is_default
boolean
required

True for Mnemom-shipped platform defaults.

current_revision_id
string | null
required

FK to trust_posture_revisions; NULL only mid-create.

created_at
string<date-time>
required
updated_at
string<date-time>
required
description
string | null
org_id
string | null

NULL for platform-scope postures.

owner_user_id
string<uuid> | null
deleted_at
string<date-time> | null

Soft-delete timestamp; NULL = live.