Returns the list of compliance rules associated with a compliance profile.
get /bsp/api/v1/bmp/compliance/{compliance_id}/rules
https://{server-hostname}:8383/bsp/api/v1/bmp/compliance/{compliance_id}/rules
BrowserManager.READCopied!
Authorization: d92d4xxxxxxxxxxxxx15f52
Compliance profile ID from List Compliance Profiles response (profileid field)
curl --request GET \
--url https://appdomain/bsp/api/v1/bmp/compliance/{compliance_id}/rules \
--header 'Accept: application/json' \
--header 'Authorization: d92d4xxxxxxxxxxxxx15f52'Compliance rule details
Unique identifier of the compliance rule
Internal name of the rule (e.g., disable_autofill)
User-facing display name of the rule
Description of what the compliance rule enforces
Category name the rule belongs to (e.g., Security, Privacy)
Unauthorized error code returned when authentication credentials are missing, expired, or invalid (authentication=required)
Authentication failure reason
Forbidden error code returned when the authenticated user does not have the required uem-roles (e.g., DataEncryption_Admin or DataEncryptionRecoveryKey_Admin)
Message indicating insufficient privileges to access this resource
Rate limit error code returned when the API call threshold (configured via threshold/duration in security XML) is exceeded; client is locked out for lock-period minutes
Rate limit exceeded message with retry guidance
Message describing the server-side failure
Internal server error code
Rules attached to the specified profile
{
"compliance": [
{
"rule_id": 1,
"rule_name": "disable_autofill",
"rule_description": "Disables browser autofill functionality",
"categories": "Security",
"rule_display_name": "Disable Autofill"
},
{
"rule_id": 2,
"rule_name": "disable_password_save",
"rule_description": "Prevents browser from saving passwords",
"categories": "Privacy",
"rule_display_name": "Disable Password Save"
}
]
}
Unauthorized
{
"errorCode": "UNAUTHORIZED",
"errorMsg": "You are not authorized to perform this action"
}
Forbidden
{
"errorCode": "FORBIDDEN",
"errorMsg": "You do not have permission to access this resource"
}
Rate limit exceeded
{
"errorCode": "RATE_LIMIT_EXCEEDED",
"errorMsg": "You have exceeded the maximum number of API calls. Please try again later."
}
Server error
{
"error_description": "Internal Server error, Please try again in a moment.",
"error_code": "COM0004"
}
![]()
Duration: 1 minute | Threshold: 60 | Lock period: 5 minutes
Duration - Time window for the threshold.
Threshold - Number of API calls allowed within the specified duration.
Lock Period - Wait time before consecutive API requests.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.
© 2026, Zoho Corporation Pvt. Ltd. All Rights Reserved.