> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://mediakind.ferndocs.com/mkio/api/media/content-key-policies/create/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://mediakind.ferndocs.com/_mcp/server. # Create PUT https://app.mk.io/api/v1/projects/{project_name}/media/contentKeyPolicies/{policy_name} Content-Type: application/json Create a Content Key Policy RBAC Capability Required: `ams.contentkeypolicy.create` Reference: https://mediakind.ferndocs.com/mkio/api/media/content-key-policies/create ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. ## Request ### Path parameters - `project_name` (string, required) - `policy_name` (string, required) ### Body (application/json) This endpoint expects a ContentKeyPolicyPutSchema. - `properties` (ContentKeyPolicyPutProperties, required) — The key policy ## Response ### 201 Create a Content Key Policy - `properties` (ContentKeyPolicyProperties, required) — The key policy - `id` (string, optional) — Fully qualified resource ID for the resource. Ex - /subscriptions/\{subscriptionId}/resourceGroups/\{resourceGroupName}/providers/\{resourceProviderNamespace}/\{resourceType}/\{resourceName} - `name` (string, optional) — The name of the resource - `systemData` (SystemDataSchema, optional) — Metadata pertaining to creation and last modification of the resource. - `type` (string, optional) — The type of the resource. E.g. "Microsoft.Media/mediaservices/assets" ## Errors ### 400 Bad Request Error Bad Request - `error` (ErrorDetail, required) — Pertinent information about the error - `ref` (string, required) — A reference to the request that caused the error. - `status` (integer, required) — The HTTP status code ### 401 Unauthorized Error Unauthorized - `error` (ErrorDetail, required) — Pertinent information about the error - `ref` (string, required) — A reference to the request that caused the error. - `status` (integer, required) — The HTTP status code ### 403 Forbidden Error Forbidden - `error` (ErrorDetail, required) — Pertinent information about the error - `ref` (string, required) — A reference to the request that caused the error. - `status` (integer, required) — The HTTP status code ### 404 Not Found Error Not Found - `error` (ErrorDetail, required) — Pertinent information about the error - `ref` (string, required) — A reference to the request that caused the error. - `status` (integer, required) — The HTTP status code ### 409 Conflict Error Conflict - `error` (ErrorDetail, required) — Pertinent information about the error - `ref` (string, required) — A reference to the request that caused the error. - `status` (integer, required) — The HTTP status code ### 429 Too Many Requests Error Too Many Requests - `error` (ErrorDetail, required) — Pertinent information about the error - `ref` (string, required) — A reference to the request that caused the error. - `status` (integer, required) — The HTTP status code ### 500 Internal Server Error Internal Server Error - `error` (ErrorDetail, required) — Pertinent information about the error - `ref` (string, required) — A reference to the request that caused the error. - `status` (integer, required) — The HTTP status code ## Types ### ContentKeyPolicyPutProperties The properties of the Content Key Policy. - `options` (list of ContentKeyPolicyOption, required) — The Key Policy options. - `description` (string, optional) — A description for the Policy. - `fairPlayAmsCompatibility` (boolean, optional) — FairPlay AMS compatibility enabled. ### ContentKeyPolicyProperties The properties of the Content Key Policy. - `options` (list of ContentKeyPolicyOption, required) — The Key Policy options. - `created` (datetime, optional) — The creation date of the Policy - `description` (string, optional) — A description for the Policy. - `fairPlayAmsCompatibility` (boolean, optional) — FairPlay AMS compatibility enabled. - `lastModified` (datetime, optional) — The last modified date of the Policy - `policyId` (string, optional) — The legacy Policy ID. ### SystemDataSchema - `createdAt` (datetime, required) — The timestamp of resource creation (UTC). - `createdBy` (string, required) — The identity that created the resource. - `createdByType` (enum, required) — The type of identity that created the resource. - Allowed values: `User`, `Application`, `ManagedIdentity`, `Key` - `internalId` (string, required) — The internal ID of the resource. - `lastModifiedAt` (datetime, required) — The timestamp of resource last modification (UTC). - `lastModifiedBy` (string, required) — The identity that last modified the resource. - `lastModifiedByType` (enum, required) — The type of identity that last modified the resource. - Allowed values: `User`, `Application`, `ManagedIdentity`, `Key` ### ErrorDetail - `code` (string, required) — The error code. - `detail` (string, required) — The error message. - `extraDetail` (map from string to any, optional) — Extra information regarding this error. ### ContentKeyPolicyOption Represents a policy option. - `configuration` (ContentKeyPolicyOptionConfiguration, required) — The key delivery configuration. - `restriction` (ContentKeyPolicyOptionRestriction, required) — The requirements that must be met to deliver keys with this configuration - `name` (string, optional) — The Policy Option description. - `policyOptionId` (string, optional) — The legacy Policy Option ID. ### ContentKeyPolicyOptionConfiguration The key delivery configuration. ### ContentKeyPolicyOptionRestriction The requirements that must be met to deliver keys with this configuration ### ContentKeyPolicyClearKeyConfiguration Represents a configuration for non-DRM keys. - `@odata.type` (string, required) — The discriminator for derived types. ### ContentKeyPolicyFairPlayConfiguration Specifies a configuration for FairPlay licenses. - `@odata.type` (string, required) — The discriminator for derived types. - `ask` (string, required, nullable) — The key that must be used as FairPlay Application Secret key. This needs to be base64 encoded. - `fairPlayPfx` (string, required, nullable) — The Base64 representation of FairPlay certificate in PKCS 12 (pfx) format (including private key). - `fairPlayPfxPassword` (string, required, nullable) — The password encrypting FairPlay certificate in PKCS 12 (pfx) format. - `rentalAndLeaseKeyType` (enum, required) — The rental and lease key type. - Allowed values: `Unknown`, `Undefined`, `DualExpiry`, `PersistentUnlimited`, `PersistentLimited` - `rentalDuration` (long, required) — The rental duration. Must be greater than or equal to 0. - `offlineRentalConfiguration` (ContentKeyPolicyFairPlayOfflineRentalConfiguration, optional) — Offline rental policy ### ContentKeyPolicyPlayReadyConfiguration Specifies a configuration for PlayReady licenses. - `@odata.type` (string, required) — The discriminator for derived types. - `licenses` (list of ContentKeyPolicyPlayReadyLicense, required) — The PlayReady licenses. - `responseCustomData` (string, optional) — The custom response data. ### ContentKeyPolicyUnknownConfiguration Represents a ContentKeyPolicyConfiguration that is unavailable in the current API version. - `@odata.type` (string, required) — The discriminator for derived types. ### ContentKeyPolicyWidevineConfiguration Specifies a configuration for Widevine licenses. - `@odata.type` (string, required) — The discriminator for derived types. - `widevineTemplate` (string, required) — The Widevine template. ### ContentKeyPolicyOpenRestriction Represents an open restriction. License or key will be delivered on every request. - `@odata.type` (string, required) — The discriminator for derived types. ### ContentKeyPolicyTokenRestriction Represents a token restriction. Provided token must match these requirements for successful license or key delivery. - `@odata.type` (string, required) — The discriminator for derived types. - `audience` (string, required) — The audience for the token. - `issuer` (string, required) — The token issuer. - `primaryVerificationKey` (ContentKeyPolicyTokenRestrictionPrimaryVerificationKey, required, nullable) — The primary verification key. - `restrictionTokenType` (enum, required) — The type of token. - Allowed values: `Unknown`, `Swt`, `Jwt` - `alternateVerificationKeys` (list of ContentKeyPolicyTokenRestrictionAlternateVerificationKeysItems, optional) — A list of alternative verification keys. - `openIdConnectDiscoveryDocument` (string, optional) — The OpenID connect discovery document. - `requiredClaims` (list of ContentKeyPolicyTokenClaim, optional) — A list of required token claims. ### ContentKeyPolicyUnknownRestriction Represents a ContentKeyPolicyRestriction that is unavailable in the current API version. - `@odata.type` (string, required) — The discriminator for derived types. ### ContentKeyPolicyFairPlayOfflineRentalConfiguration - `playbackDurationSeconds` (long, required) — Playback duration - `storageDurationSeconds` (long, required) — Storage duration ### ContentKeyPolicyPlayReadyLicense The PlayReady license - `allowTestDevices` (boolean, required) — A flag indicating whether test devices can use the license. - `contentKeyLocation` (ContentKeyPolicyPlayReadyLicenseContentKeyLocation, required) — The content key location. - `contentType` (enum, required) — The PlayReady content type. - Allowed values: `Unknown`, `Unspecified`, `UltraVioletDownload`, `UltraVioletStreaming` - `licenseType` (enum, required) — The license type. - Allowed values: `Unknown`, `NonPersistent`, `Persistent` - `beginDate` (datetime, optional) — The begin date of license - `expirationDate` (datetime, optional) — The expiration date of license. - `gracePeriod` (string, optional) — The grace period of license. - `playRight` (ContentKeyPolicyPlayReadyPlayRight, optional) — The license PlayRight - `relativeBeginDate` (string, optional) — The relative begin date of license. - `relativeExpirationDate` (string, optional) — The relative expiration date of license. - `securityLevel` (enum, optional) — The security level. - Allowed values: `Unknown`, `SL150`, `SL2000`, `SL3000` ### ContentKeyPolicyTokenRestrictionPrimaryVerificationKey The primary verification key. ### ContentKeyPolicyTokenRestrictionAlternateVerificationKeysItems ### ContentKeyPolicyTokenClaim Represents a token claim. - `claimType` (string, optional) — Token claim type. - `claimValue` (string, optional) — Token claim value. ### ContentKeyPolicyPlayReadyLicenseContentKeyLocation The content key location. ### ContentKeyPolicyPlayReadyPlayRight Configures the Play Right in the PlayReady license. - `allowPassingVideoContentToUnknownOutput` (enum, required) — Configures Unknown output handling settings of the license. - Allowed values: `Unknown`, `NotAllowed`, `Allowed`, `AllowedWithVideoConstriction` - `digitalVideoOnlyContentRestriction` (boolean, required) — Enables the Image Constraint For Analog Component Video Restriction in the license. - `imageConstraintForAnalogComponentVideoRestriction` (boolean, required) — Enables the Image Constraint For Analog Component Video Restriction in the license. - `imageConstraintForAnalogComputerMonitorRestriction` (boolean, required) — Enables the Image Constraint For Analog Component Video Restriction in the license. - `agcAndColorStripeRestriction` (integer, optional) — Configures Automatic Gain Control (AGC) and Color Stripe in the license. Must be between 0 and 3 inclusive. - `analogVideoOpl` (integer, optional) — Specifies the output protection level for compressed digital audio. - `compressedDigitalAudioOpl` (integer, optional) — Specifies the output protection level for compressed digital audio. - `compressedDigitalVideoOpl` (integer, optional) — Specifies the output protection level for compressed digital video. - `explicitAnalogTelevisionOutputRestriction` (ContentKeyPolicyPlayReadyExplicitAnalogTelevisionRestriction, optional) — Configures the Explicit Analog Television Output Restriction in the license. Configuration data must be between 0 and 3 inclusive. - `firstPlayExpiration` (string, optional) — The amount of time that the license is valid after the license is first used to play content. - `scmsRestriction` (integer, optional) — Configures the Serial Copy Management System (SCMS) in the license. Must be between 0 and 3 inclusive. - `uncompressedDigitalAudioOpl` (integer, optional) — Specifies the output protection level for uncompressed digital audio. - `uncompressedDigitalVideoOpl` (integer, optional) — Specifies the output protection level for uncompressed digital video. ### ContentKeyPolicyRsaTokenKey Specifies a RSA key for token validation - `@odata.type` (string, required) — The discriminator for derived types. - `exponent` (string, required, nullable) — The RSA Parameter exponent - `modulus` (string, required, nullable) — The RSA Parameter modulus ### ContentKeyPolicySymmetricTokenKey Specifies a symmetric key for token validation. - `@odata.type` (string, required) — The discriminator for derived types. - `keyValue` (string, required, nullable) — The key value of the key ### ContentKeyPolicyX509CertificateTokenKey Specifies a certificate for token validation. - `@odata.type` (string, required) — The discriminator for derived types. - `rawBody` (string, required, nullable) — The raw data field of a certificate in PKCS 12 format (X509Certificate2 in .NET) ### ContentKeyPolicyPlayReadyContentEncryptionKeyFromHeader Specifies that the content key ID is in the PlayReady header. - `@odata.type` (string, required) — The discriminator for derived types. ### ContentKeyPolicyPlayReadyContentEncryptionKeyFromKeyIdentifier Specifies that the content key ID is specified in the PlayReady configuration. - `@odata.type` (string, required) — The discriminator for derived types. - `keyId` (string, required, nullable) — The content key ID. ### ContentKeyPolicyPlayReadyExplicitAnalogTelevisionRestriction Configures the Explicit Analog Television Output Restriction control bits. For further details see the PlayReady Compliance Rules. - `bestEffort` (boolean, required) — Indicates whether this restriction is enforced on a Best Effort basis. - `configurationData` (integer, required) — Configures the restriction control bits. Must be between 0 and 3 inclusive. ## Examples **Request** ```json { "properties": { "options": [ { "configuration": { "@odata.type": "string" }, "restriction": { "@odata.type": "string" } } ] } } ``` **Response** ```json { "properties": { "options": [ { "configuration": { "@odata.type": "string" }, "restriction": { "@odata.type": "string" }, "name": "string", "policyOptionId": "string" } ], "created": "2024-01-15T09:30:00Z", "description": "string", "fairPlayAmsCompatibility": true, "lastModified": "2024-01-15T09:30:00Z", "policyId": "string" }, "id": "string", "name": "name", "systemData": { "createdAt": "2024-01-15T09:30:00Z", "createdBy": "string", "createdByType": "User", "internalId": "string", "lastModifiedAt": "2024-01-15T09:30:00Z", "lastModifiedBy": "string", "lastModifiedByType": "User" }, "type": "string" } ``` **SDK Code** ```python import requests url = "https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies/policy_name" payload = { "properties": { "options": [ { "configuration": { "@odata.type": "string" }, "restriction": { "@odata.type": "string" } } ] } } headers = { "Authorization": "Bearer ", "Content-Type": "application/json" } response = requests.put(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies/policy_name'; const options = { method: 'PUT', headers: {Authorization: 'Bearer ', 'Content-Type': 'application/json'}, body: '{"properties":{"options":[{"configuration":{"@odata.type":"string"},"restriction":{"@odata.type":"string"}}]}}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies/policy_name" payload := strings.NewReader("{\n \"properties\": {\n \"options\": [\n {\n \"configuration\": {\n \"@odata.type\": \"string\"\n },\n \"restriction\": {\n \"@odata.type\": \"string\"\n }\n }\n ]\n }\n}") req, _ := http.NewRequest("PUT", url, payload) req.Header.Add("Authorization", "Bearer ") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies/policy_name") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Put.new(url) request["Authorization"] = 'Bearer ' request["Content-Type"] = 'application/json' request.body = "{\n \"properties\": {\n \"options\": [\n {\n \"configuration\": {\n \"@odata.type\": \"string\"\n },\n \"restriction\": {\n \"@odata.type\": \"string\"\n }\n }\n ]\n }\n}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.put("https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies/policy_name") .header("Authorization", "Bearer ") .header("Content-Type", "application/json") .body("{\n \"properties\": {\n \"options\": [\n {\n \"configuration\": {\n \"@odata.type\": \"string\"\n },\n \"restriction\": {\n \"@odata.type\": \"string\"\n }\n }\n ]\n }\n}") .asString(); ``` ```php request('PUT', 'https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies/policy_name', [ 'body' => '{ "properties": { "options": [ { "configuration": { "@odata.type": "string" }, "restriction": { "@odata.type": "string" } } ] } }', 'headers' => [ 'Authorization' => 'Bearer ', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies/policy_name"); var request = new RestRequest(Method.PUT); request.AddHeader("Authorization", "Bearer "); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"properties\": {\n \"options\": [\n {\n \"configuration\": {\n \"@odata.type\": \"string\"\n },\n \"restriction\": {\n \"@odata.type\": \"string\"\n }\n }\n ]\n }\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "Authorization": "Bearer ", "Content-Type": "application/json" ] let parameters = ["properties": ["options": [ [ "configuration": ["@odata.type": "string"], "restriction": ["@odata.type": "string"] ] ]]] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies/policy_name")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "PUT" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```