> This page is for mk.io.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://mediakind.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://mediakind.ferndocs.com/_mcp/server.

# List Content Key Policies

GET https://app.mk.io/api/v1/projects/{project_name}/media/contentKeyPolicies

## Listing, Sorting and Filtering Content Key Policies

This endpoint returns the list of content key policies in the specified project.

### Sorting

The results from this endpoint can be ordered using the `$orderby` query parameter. Specify a list of field names, separated by commas
where each one can optionally specify `asc` or `desc`.

Sorting is valid on the following fields: `created`, `createdBy`, `id`, `name`, `properties/created`, `properties/lastModified`, `properties/policyId`, `updated`, `updatedBy`

### Filtering



The `$filter` query parameter allows for content key policies to be filtered on the basis of fields in the schema using OData query syntax.
See [this document](https://learn.microsoft.com/en-us/odata/concepts/queryoptions-overview#filter) for more details on the syntax used.

Filters are valid on the following fields: `created`, `createdBy`, `createdByEmail`, `createdByName`, `id`, `name`, `properties/created`, `properties/lastModified`, `properties/policyId`, `updated`, `updatedBy`, `updatedByEmail`, `updatedByName`

### Examples:

`?$top=10` - Returns only the first 10 content key policies from the list.

`?$orderby=name desc` - Sorts content key policies by name in descending order.

`?$filter=name eq 'descriptive name'` - Returns content key policies that match the provided name.


`?$orderby=created desc` - Sorts content key policies by creation date in descending order.

`?$filter=created ge 2021-01-01T00:00:00Z` - Returns content key policies created after January 1, 2021.

RBAC Capability Required: `ams.contentkeypolicy.get`

Reference: https://mediakind.ferndocs.com/mkio/api/media/content-key-policies/list-content-key-policies

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Request

### Path parameters

- `project_name` (string, required)

### Query parameters

- `$orderby` (string, optional) — Specifies the key by which the result collection should be ordered.
- `$filter` (string, optional) — Restricts the set of items returned.
- `$top` (string, optional) — Specifies a non-negative integer `n` that limits the number of items returned from a collection. The service returns the number of available items up to but not greater than the specified value `n`.
- `$skiptoken` (string, optional) — Specifies a start offset to support paginated results. Use `@odata.nextLink` in the result object to enumerate the collection - it will be present only if there's more than one page of entities.

## Response

### 200

A list of content key policies.

- `supplemental` (ListResponseSupplementalSchema, required) — Supplemental info
- `value` (list of ContentKeyPolicySchema, required) — A list of content key policies.
- `@odata.nextLink` (string, optional) — @odata.nextLink URL if the page length and number of items match.

## Errors

### 400 Bad Request Error

Bad Request

- `error` (ErrorDetail, required) — Pertinent information about the error
- `ref` (string, required) — A reference to the request that caused the error.
- `status` (integer, required) — The HTTP status code

### 401 Unauthorized Error

Unauthorized

- `error` (ErrorDetail, required) — Pertinent information about the error
- `ref` (string, required) — A reference to the request that caused the error.
- `status` (integer, required) — The HTTP status code

### 403 Forbidden Error

Forbidden

- `error` (ErrorDetail, required) — Pertinent information about the error
- `ref` (string, required) — A reference to the request that caused the error.
- `status` (integer, required) — The HTTP status code

### 404 Not Found Error

Not Found

- `error` (ErrorDetail, required) — Pertinent information about the error
- `ref` (string, required) — A reference to the request that caused the error.
- `status` (integer, required) — The HTTP status code

### 429 Too Many Requests Error

Too Many Requests

- `error` (ErrorDetail, required) — Pertinent information about the error
- `ref` (string, required) — A reference to the request that caused the error.
- `status` (integer, required) — The HTTP status code

### 500 Internal Server Error

Internal Server Error

- `error` (ErrorDetail, required) — Pertinent information about the error
- `ref` (string, required) — A reference to the request that caused the error.
- `status` (integer, required) — The HTTP status code

## Types

### ListResponseSupplementalSchema

- `count` (integer, required) — Number of items returned
- `kind` (string, required) — Type of items in the list
- `operation` (string, required) — Operation type. Should always say 'list'
- `pagination` (PaginationInfoSchema, required) — Pagination info
- `subscription` (ProjectInfoSchema, optional) — Project info

### ContentKeyPolicySchema

- `properties` (ContentKeyPolicyProperties, required) — The key policy
- `id` (string, optional) — Fully qualified resource ID for the resource. Ex - /subscriptions/\{subscriptionId}/resourceGroups/\{resourceGroupName}/providers/\{resourceProviderNamespace}/\{resourceType}/\{resourceName}
- `name` (string, optional) — The name of the resource
- `systemData` (SystemDataSchema, optional) — Metadata pertaining to creation and last modification of the resource.
- `type` (string, optional) — The type of the resource. E.g. "Microsoft.Media/mediaservices/assets"

### ErrorDetail

- `code` (string, required) — The error code.
- `detail` (string, required) — The error message.
- `extraDetail` (map from string to any, optional) — Extra information regarding this error.

### PaginationInfoSchema

- `end` (integer, required) — Position of the last item in the list
- `records` (integer, required) — Total number of items returned in the list
- `start` (integer, required) — Position of the first item in the list
- `total` (integer, required) — Total number of items in the project

### ProjectInfoSchema

- `id` (string, required) — Project ID
- `name` (string, required) — Project name

### ContentKeyPolicyProperties

The properties of the Content Key Policy.

- `options` (list of ContentKeyPolicyOption, required) — The Key Policy options.
- `created` (datetime, optional) — The creation date of the Policy
- `description` (string, optional) — A description for the Policy.
- `fairPlayAmsCompatibility` (boolean, optional) — FairPlay AMS compatibility enabled.
- `lastModified` (datetime, optional) — The last modified date of the Policy
- `policyId` (string, optional) — The legacy Policy ID.

### SystemDataSchema

- `createdAt` (datetime, required) — The timestamp of resource creation (UTC).
- `createdBy` (string, required) — The identity that created the resource.
- `createdByType` (enum, required) — The type of identity that created the resource.
  - Allowed values: `User`, `Application`, `ManagedIdentity`, `Key`
- `internalId` (string, required) — The internal ID of the resource.
- `lastModifiedAt` (datetime, required) — The timestamp of resource last modification (UTC).
- `lastModifiedBy` (string, required) — The identity that last modified the resource.
- `lastModifiedByType` (enum, required) — The type of identity that last modified the resource.
  - Allowed values: `User`, `Application`, `ManagedIdentity`, `Key`

### ContentKeyPolicyOption

Represents a policy option.

- `configuration` (ContentKeyPolicyOptionConfiguration, required) — The key delivery configuration.
- `restriction` (ContentKeyPolicyOptionRestriction, required) — The requirements that must be met to deliver keys with this configuration
- `name` (string, optional) — The Policy Option description.
- `policyOptionId` (string, optional) — The legacy Policy Option ID.

### ContentKeyPolicyOptionConfiguration

The key delivery configuration.

### ContentKeyPolicyOptionRestriction

The requirements that must be met to deliver keys with this configuration

### ContentKeyPolicyClearKeyConfiguration

Represents a configuration for non-DRM keys.

- `@odata.type` (string, required) — The discriminator for derived types.

### ContentKeyPolicyFairPlayConfiguration

Specifies a configuration for FairPlay licenses.

- `@odata.type` (string, required) — The discriminator for derived types.
- `ask` (string, required, nullable) — The key that must be used as FairPlay Application Secret key. This needs to be base64 encoded.
- `fairPlayPfx` (string, required, nullable) — The Base64 representation of FairPlay certificate in PKCS 12 (pfx) format (including private key).
- `fairPlayPfxPassword` (string, required, nullable) — The password encrypting FairPlay certificate in PKCS 12 (pfx) format.
- `rentalAndLeaseKeyType` (enum, required) — The rental and lease key type.
  - Allowed values: `Unknown`, `Undefined`, `DualExpiry`, `PersistentUnlimited`, `PersistentLimited`
- `rentalDuration` (long, required) — The rental duration. Must be greater than or equal to 0.
- `offlineRentalConfiguration` (ContentKeyPolicyFairPlayOfflineRentalConfiguration, optional) — Offline rental policy

### ContentKeyPolicyPlayReadyConfiguration

Specifies a configuration for PlayReady licenses.

- `@odata.type` (string, required) — The discriminator for derived types.
- `licenses` (list of ContentKeyPolicyPlayReadyLicense, required) — The PlayReady licenses.
- `responseCustomData` (string, optional) — The custom response data.

### ContentKeyPolicyUnknownConfiguration

Represents a ContentKeyPolicyConfiguration that is unavailable in the current API version.

- `@odata.type` (string, required) — The discriminator for derived types.

### ContentKeyPolicyWidevineConfiguration

Specifies a configuration for Widevine licenses.

- `@odata.type` (string, required) — The discriminator for derived types.
- `widevineTemplate` (string, required) — The Widevine template.

### ContentKeyPolicyOpenRestriction

Represents an open restriction. License or key will be delivered on every request.

- `@odata.type` (string, required) — The discriminator for derived types.

### ContentKeyPolicyTokenRestriction

Represents a token restriction. Provided token must match these requirements for successful license or key delivery.

- `@odata.type` (string, required) — The discriminator for derived types.
- `audience` (string, required) — The audience for the token.
- `issuer` (string, required) — The token issuer.
- `primaryVerificationKey` (ContentKeyPolicyTokenRestrictionPrimaryVerificationKey, required, nullable) — The primary verification key.
- `restrictionTokenType` (enum, required) — The type of token.
  - Allowed values: `Unknown`, `Swt`, `Jwt`
- `alternateVerificationKeys` (list of ContentKeyPolicyTokenRestrictionAlternateVerificationKeysItems, optional) — A list of alternative verification keys.
- `openIdConnectDiscoveryDocument` (string, optional) — The OpenID connect discovery document.
- `requiredClaims` (list of ContentKeyPolicyTokenClaim, optional) — A list of required token claims.

### ContentKeyPolicyUnknownRestriction

Represents a ContentKeyPolicyRestriction that is unavailable in the current API version.

- `@odata.type` (string, required) — The discriminator for derived types.

### ContentKeyPolicyFairPlayOfflineRentalConfiguration

- `playbackDurationSeconds` (long, required) — Playback duration
- `storageDurationSeconds` (long, required) — Storage duration

### ContentKeyPolicyPlayReadyLicense

The PlayReady license

- `allowTestDevices` (boolean, required) — A flag indicating whether test devices can use the license.
- `contentKeyLocation` (ContentKeyPolicyPlayReadyLicenseContentKeyLocation, required) — The content key location.
- `contentType` (enum, required) — The PlayReady content type.
  - Allowed values: `Unknown`, `Unspecified`, `UltraVioletDownload`, `UltraVioletStreaming`
- `licenseType` (enum, required) — The license type.
  - Allowed values: `Unknown`, `NonPersistent`, `Persistent`
- `beginDate` (datetime, optional) — The begin date of license
- `expirationDate` (datetime, optional) — The expiration date of license.
- `gracePeriod` (string, optional) — The grace period of license.
- `playRight` (ContentKeyPolicyPlayReadyPlayRight, optional) — The license PlayRight
- `relativeBeginDate` (string, optional) — The relative begin date of license.
- `relativeExpirationDate` (string, optional) — The relative expiration date of license.
- `securityLevel` (enum, optional) — The security level.
  - Allowed values: `Unknown`, `SL150`, `SL2000`, `SL3000`

### ContentKeyPolicyTokenRestrictionPrimaryVerificationKey

The primary verification key.

### ContentKeyPolicyTokenRestrictionAlternateVerificationKeysItems

### ContentKeyPolicyTokenClaim

Represents a token claim.

- `claimType` (string, optional) — Token claim type.
- `claimValue` (string, optional) — Token claim value.

### ContentKeyPolicyPlayReadyLicenseContentKeyLocation

The content key location.

### ContentKeyPolicyPlayReadyPlayRight

Configures the Play Right in the PlayReady license.

- `allowPassingVideoContentToUnknownOutput` (enum, required) — Configures Unknown output handling settings of the license.
  - Allowed values: `Unknown`, `NotAllowed`, `Allowed`, `AllowedWithVideoConstriction`
- `digitalVideoOnlyContentRestriction` (boolean, required) — Enables the Image Constraint For Analog Component Video Restriction in the license.
- `imageConstraintForAnalogComponentVideoRestriction` (boolean, required) — Enables the Image Constraint For Analog Component Video Restriction in the license.
- `imageConstraintForAnalogComputerMonitorRestriction` (boolean, required) — Enables the Image Constraint For Analog Component Video Restriction in the license.
- `agcAndColorStripeRestriction` (integer, optional) — Configures Automatic Gain Control (AGC) and Color Stripe in the license. Must be between 0 and 3 inclusive.
- `analogVideoOpl` (integer, optional) — Specifies the output protection level for compressed digital audio.
- `compressedDigitalAudioOpl` (integer, optional) — Specifies the output protection level for compressed digital audio.
- `compressedDigitalVideoOpl` (integer, optional) — Specifies the output protection level for compressed digital video.
- `explicitAnalogTelevisionOutputRestriction` (ContentKeyPolicyPlayReadyExplicitAnalogTelevisionRestriction, optional) — Configures the Explicit Analog Television Output Restriction in the license. Configuration data must be between 0 and 3 inclusive.
- `firstPlayExpiration` (string, optional) — The amount of time that the license is valid after the license is first used to play content.
- `scmsRestriction` (integer, optional) — Configures the Serial Copy Management System (SCMS) in the license. Must be between 0 and 3 inclusive.
- `uncompressedDigitalAudioOpl` (integer, optional) — Specifies the output protection level for uncompressed digital audio.
- `uncompressedDigitalVideoOpl` (integer, optional) — Specifies the output protection level for uncompressed digital video.

### ContentKeyPolicyRsaTokenKey

Specifies a RSA key for token validation

- `@odata.type` (string, required) — The discriminator for derived types.
- `exponent` (string, required, nullable) — The RSA Parameter exponent
- `modulus` (string, required, nullable) — The RSA Parameter modulus

### ContentKeyPolicySymmetricTokenKey

Specifies a symmetric key for token validation.

- `@odata.type` (string, required) — The discriminator for derived types.
- `keyValue` (string, required, nullable) — The key value of the key

### ContentKeyPolicyX509CertificateTokenKey

Specifies a certificate for token validation.

- `@odata.type` (string, required) — The discriminator for derived types.
- `rawBody` (string, required, nullable) — The raw data field of a certificate in PKCS 12 format (X509Certificate2 in .NET)

### ContentKeyPolicyPlayReadyContentEncryptionKeyFromHeader

Specifies that the content key ID is in the PlayReady header.

- `@odata.type` (string, required) — The discriminator for derived types.

### ContentKeyPolicyPlayReadyContentEncryptionKeyFromKeyIdentifier

Specifies that the content key ID is specified in the PlayReady configuration.

- `@odata.type` (string, required) — The discriminator for derived types.
- `keyId` (string, required, nullable) — The content key ID.

### ContentKeyPolicyPlayReadyExplicitAnalogTelevisionRestriction

Configures the Explicit Analog Television Output Restriction control bits. For further details see the PlayReady Compliance Rules.

- `bestEffort` (boolean, required) — Indicates whether this restriction is enforced on a Best Effort basis.
- `configurationData` (integer, required) — Configures the restriction control bits. Must be between 0 and 3 inclusive.

## Examples

**Response**

```json
{
  "supplemental": {
    "count": 1,
    "kind": "string",
    "operation": "string",
    "pagination": {
      "end": 1,
      "records": 1,
      "start": 1,
      "total": 1
    },
    "subscription": {
      "id": "string",
      "name": "string"
    }
  },
  "value": [
    {
      "properties": {
        "options": [
          {
            "configuration": {
              "@odata.type": "string"
            },
            "restriction": {
              "@odata.type": "string"
            },
            "name": "string",
            "policyOptionId": "string"
          }
        ],
        "created": "2024-01-15T09:30:00Z",
        "description": "string",
        "fairPlayAmsCompatibility": true,
        "lastModified": "2024-01-15T09:30:00Z",
        "policyId": "string"
      },
      "id": "string",
      "name": "name",
      "systemData": {
        "createdAt": "2024-01-15T09:30:00Z",
        "createdBy": "string",
        "createdByType": "User",
        "internalId": "string",
        "lastModifiedAt": "2024-01-15T09:30:00Z",
        "lastModifiedBy": "string",
        "lastModifiedByType": "User"
      },
      "type": "string"
    }
  ],
  "@odata.nextLink": "string"
}
```

**SDK Code**

```python
import requests

url = "https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies"

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers)

print(response.json())
```

```javascript
const url = 'https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies");
var request = new RestRequest(Method.GET);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://app.mk.io/api/v1/projects/project_name/media/contentKeyPolicies")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```