Create a tag policy

Note: This endpoint is in preview and is subject to change. If you have any feedback, contact Datadog support.

POST https://api.ap1.datadoghq.com/api/v2/tag-policieshttps://api.ap2.datadoghq.com/api/v2/tag-policieshttps://api.datadoghq.eu/api/v2/tag-policieshttps://api.ddog-gov.com/api/v2/tag-policieshttps://api.us2.ddog-gov.com/api/v2/tag-policieshttps://api.uk1.datadoghq.com/api/v2/tag-policieshttps://api.datadoghq.com/api/v2/tag-policieshttps://api.us3.datadoghq.com/api/v2/tag-policieshttps://api.us5.datadoghq.com/api/v2/tag-policies

Overview

Create a new tag policy for the organization. The caller’s organization is derived from the authenticated user; cross-organization creation is not supported. Fields such as policy_id, version, and the timestamp/audit fields are assigned by the server.

Request

Body Data (required)

Expand All

Field

Type

Description

data [required]

object

Data object for creating a tag policy.

attributes [required]

object

Attributes that can be supplied when creating a tag policy.

enabled

boolean

Whether the policy is currently enforced. Defaults to true for newly created policies.

negated

boolean

When true, the policy matches tag values that do NOT match any of the supplied patterns. Defaults to false.

policy_name [required]

string

Human-readable name for the tag policy.

policy_type [required]

enum

The policy type allowed when creating a tag policy. Only surfacing is accepted at creation time. Allowed enum values: surfacing

required

boolean

When true, telemetry without this tag is treated as a violation. Defaults to false.

scope [required]

string

The scope the policy applies within. Typically an environment, team, or organization-level identifier used to limit where the policy is enforced.

source [required]

enum

The telemetry source that a tag policy applies to. Allowed enum values: logs,spans,metrics,rum,feed

tag_key [required]

string

The tag key that the policy governs (for example, service).

tag_value_patterns [required]

[string]

One or more patterns that valid values for the tag key must match. At least one pattern is required.

type [required]

enum

JSON:API resource type for a tag policy. Allowed enum values: tag_policy

{
  "data": {
    "attributes": {
      "enabled": true,
      "negated": false,
      "policy_name": "Service tag must be one of api or web",
      "policy_type": "surfacing",
      "required": true,
      "scope": "env",
      "source": "logs",
      "tag_key": "service",
      "tag_value_patterns": [
        "api",
        "web"
      ]
    },
    "type": "tag_policy"
  }
}

Response

Created

A single tag policy.

Expand All

Field

Type

Description

data [required]

object

A tag policy resource.

attributes [required]

object

The attributes of a tag policy resource.

created_at [required]

date-time

The RFC 3339 timestamp at which the policy was created.

created_by [required]

string

The identifier of the user who created the policy.

deleted_at

date-time

The RFC 3339 timestamp at which the policy was soft-deleted. null if the policy has not been deleted. Only present when include_deleted=true is requested.

deleted_by

string

The identifier of the user who soft-deleted the policy. null if the policy has not been deleted.

enabled [required]

boolean

Whether the policy is currently enforced.

modified_at [required]

date-time

The RFC 3339 timestamp at which the policy was last modified.

modified_by [required]

string

The identifier of the user who last modified the policy.

negated [required]

boolean

When true, the policy matches tag values that do NOT match any of the supplied patterns.

policy_name [required]

string

Human-readable name for the tag policy.

policy_type [required]

enum

How the policy is enforced. blocking rejects telemetry that violates the policy. surfacing only highlights non-compliant telemetry without blocking it. Allowed enum values: blocking,surfacing

required [required]

boolean

When true, telemetry without this tag is treated as a violation.

scope [required]

string

The scope the policy applies within.

source [required]

enum

The telemetry source that a tag policy applies to. Allowed enum values: logs,spans,metrics,rum,feed

tag_key [required]

string

The tag key that the policy governs.

tag_value_patterns [required]

[string]

The patterns that valid values for the tag key must match.

version [required]

int64

A monotonically increasing version counter that is incremented on each update.

id [required]

string

The unique identifier of the tag policy.

relationships

object

Related resources for a tag policy. Only present when the corresponding include query parameter is supplied.

score

object

A relationship to the compliance score resource for this policy.

data [required]

object

Identifier of the related compliance score resource.

id [required]

string

The unique identifier of the related compliance score resource.

type [required]

enum

JSON:API resource type for a tag policy compliance score. Allowed enum values: tag_policy_score

type [required]

enum

JSON:API resource type for a tag policy. Allowed enum values: tag_policy

included

[object]

Related resources fetched alongside the primary tag policies. Populated when an include query parameter is supplied.

attributes [required]

object

Attributes of a tag policy compliance score.

score [required]

double

The compliance score for the policy over the requested time window, as a percentage between 0 and 100. null indicates that no relevant telemetry was found.

ts_end [required]

int64

End of the time window the score was computed over, as a Unix timestamp in milliseconds.

ts_start [required]

int64

Start of the time window the score was computed over, as a Unix timestamp in milliseconds.

version [required]

int64

The version of the tag policy that the score was computed against.

id [required]

string

The unique identifier of the compliance score resource.

type [required]

enum

JSON:API resource type for a tag policy compliance score. Allowed enum values: tag_policy_score

{
  "data": {
    "attributes": {
      "created_at": "2026-05-21T22:11:06.108696Z",
      "created_by": "test-user",
      "deleted_at": "2019-09-19T10:00:00.000Z",
      "deleted_by": "string",
      "enabled": true,
      "modified_at": "2026-05-21T22:11:06.108696Z",
      "modified_by": "test-user",
      "negated": false,
      "policy_name": "Service tag must be one of api or web",
      "policy_type": "surfacing",
      "required": true,
      "scope": "env",
      "source": "logs",
      "tag_key": "service",
      "tag_value_patterns": [
        "api",
        "web"
      ],
      "version": 1
    },
    "id": "123",
    "relationships": {
      "score": {
        "data": {
          "id": "123-v1-1779315066097-1779401466097",
          "type": "tag_policy_score"
        }
      }
    },
    "type": "tag_policy"
  },
  "included": [
    {
      "attributes": {
        "score": 80,
        "ts_end": 1779401466097,
        "ts_start": 1779315066097,
        "version": 1
      },
      "id": "123-v1-1779315066097-1779401466097",
      "type": "tag_policy_score"
    }
  ]
}

Bad Request

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Unauthorized

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Forbidden

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Conflict

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Too many requests

API error response.

Expand All

Field

Type

Description

errors [required]

[string]

A list of errors.

{
  "errors": [
    "Bad Request"
  ]
}

Code Example

                  ## default
# 

# Curl command
curl -X POST "https://api.ap1.datadoghq.com"https://api.ap2.datadoghq.com"https://api.datadoghq.eu"https://api.ddog-gov.com"https://api.us2.ddog-gov.com"https://api.uk1.datadoghq.com"https://api.datadoghq.com"https://api.us3.datadoghq.com"https://api.us5.datadoghq.com/api/v2/tag-policies" \ -H "Accept: application/json" \ -H "Content-Type: application/json" \ -H "DD-API-KEY: ${DD_API_KEY}" \ -H "DD-APPLICATION-KEY: ${DD_APP_KEY}" \ -d @- << EOF { "data": { "attributes": { "enabled": true, "negated": false, "policy_name": "Service tag must be one of api or web", "policy_type": "surfacing", "required": true, "scope": "env", "source": "logs", "tag_key": "service", "tag_value_patterns": [ "api", "web" ] }, "type": "tag_policy" } } EOF
"""
Create a tag policy returns "Created" response
"""

from datadog_api_client import ApiClient, Configuration
from datadog_api_client.v2.api.tag_policies_api import TagPoliciesApi
from datadog_api_client.v2.model.tag_policy_create_attributes import TagPolicyCreateAttributes
from datadog_api_client.v2.model.tag_policy_create_data import TagPolicyCreateData
from datadog_api_client.v2.model.tag_policy_create_request import TagPolicyCreateRequest
from datadog_api_client.v2.model.tag_policy_create_type import TagPolicyCreateType
from datadog_api_client.v2.model.tag_policy_resource_type import TagPolicyResourceType
from datadog_api_client.v2.model.tag_policy_source import TagPolicySource

body = TagPolicyCreateRequest(
    data=TagPolicyCreateData(
        attributes=TagPolicyCreateAttributes(
            enabled=True,
            negated=False,
            policy_name="Service tag must be one of api or web",
            policy_type=TagPolicyCreateType.SURFACING,
            required=True,
            scope="env",
            source=TagPolicySource.LOGS,
            tag_key="service",
            tag_value_patterns=[
                "api",
                "web",
            ],
        ),
        type=TagPolicyResourceType.TAG_POLICY,
    ),
)

configuration = Configuration()
configuration.unstable_operations["create_tag_policy"] = True
with ApiClient(configuration) as api_client:
    api_instance = TagPoliciesApi(api_client)
    response = api_instance.create_tag_policy(body=body)

    print(response)

Instructions

First install the library and its dependencies and then save the example to example.py and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<API-KEY>" DD_APP_KEY="<APP-KEY>" python3 "example.py"
# Create a tag policy returns "Created" response

require "datadog_api_client"
DatadogAPIClient.configure do |config|
  config.unstable_operations["v2.create_tag_policy".to_sym] = true
end
api_instance = DatadogAPIClient::V2::TagPoliciesAPI.new

body = DatadogAPIClient::V2::TagPolicyCreateRequest.new({
  data: DatadogAPIClient::V2::TagPolicyCreateData.new({
    attributes: DatadogAPIClient::V2::TagPolicyCreateAttributes.new({
      enabled: true,
      negated: false,
      policy_name: "Service tag must be one of api or web",
      policy_type: DatadogAPIClient::V2::TagPolicyCreateType::SURFACING,
      required: true,
      scope: "env",
      source: DatadogAPIClient::V2::TagPolicySource::LOGS,
      tag_key: "service",
      tag_value_patterns: [
        "api",
        "web",
      ],
    }),
    type: DatadogAPIClient::V2::TagPolicyResourceType::TAG_POLICY,
  }),
})
p api_instance.create_tag_policy(body)

Instructions

First install the library and its dependencies and then save the example to example.rb and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<API-KEY>" DD_APP_KEY="<APP-KEY>" rb "example.rb"
// Create a tag policy returns "Created" response

package main

import (
	"context"
	"encoding/json"
	"fmt"
	"os"

	"github.com/DataDog/datadog-api-client-go/v2/api/datadog"
	"github.com/DataDog/datadog-api-client-go/v2/api/datadogV2"
)

func main() {
	body := datadogV2.TagPolicyCreateRequest{
		Data: datadogV2.TagPolicyCreateData{
			Attributes: datadogV2.TagPolicyCreateAttributes{
				Enabled:    datadog.PtrBool(true),
				Negated:    datadog.PtrBool(false),
				PolicyName: "Service tag must be one of api or web",
				PolicyType: datadogV2.TAGPOLICYCREATETYPE_SURFACING,
				Required:   datadog.PtrBool(true),
				Scope:      "env",
				Source:     datadogV2.TAGPOLICYSOURCE_LOGS,
				TagKey:     "service",
				TagValuePatterns: []string{
					"api",
					"web",
				},
			},
			Type: datadogV2.TAGPOLICYRESOURCETYPE_TAG_POLICY,
		},
	}
	ctx := datadog.NewDefaultContext(context.Background())
	configuration := datadog.NewConfiguration()
	configuration.SetUnstableOperationEnabled("v2.CreateTagPolicy", true)
	apiClient := datadog.NewAPIClient(configuration)
	api := datadogV2.NewTagPoliciesApi(apiClient)
	resp, r, err := api.CreateTagPolicy(ctx, body)

	if err != nil {
		fmt.Fprintf(os.Stderr, "Error when calling `TagPoliciesApi.CreateTagPolicy`: %v\n", err)
		fmt.Fprintf(os.Stderr, "Full HTTP response: %v\n", r)
	}

	responseContent, _ := json.MarshalIndent(resp, "", "  ")
	fmt.Fprintf(os.Stdout, "Response from `TagPoliciesApi.CreateTagPolicy`:\n%s\n", responseContent)
}

Instructions

First install the library and its dependencies and then save the example to main.go and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<API-KEY>" DD_APP_KEY="<APP-KEY>" go run "main.go"
// Create a tag policy returns "Created" response

import com.datadog.api.client.ApiClient;
import com.datadog.api.client.ApiException;
import com.datadog.api.client.v2.api.TagPoliciesApi;
import com.datadog.api.client.v2.model.TagPolicyCreateAttributes;
import com.datadog.api.client.v2.model.TagPolicyCreateData;
import com.datadog.api.client.v2.model.TagPolicyCreateRequest;
import com.datadog.api.client.v2.model.TagPolicyCreateType;
import com.datadog.api.client.v2.model.TagPolicyResourceType;
import com.datadog.api.client.v2.model.TagPolicyResponse;
import com.datadog.api.client.v2.model.TagPolicySource;
import java.util.Arrays;

public class Example {
  public static void main(String[] args) {
    ApiClient defaultClient = ApiClient.getDefaultApiClient();
    defaultClient.setUnstableOperationEnabled("v2.createTagPolicy", true);
    TagPoliciesApi apiInstance = new TagPoliciesApi(defaultClient);

    TagPolicyCreateRequest body =
        new TagPolicyCreateRequest()
            .data(
                new TagPolicyCreateData()
                    .attributes(
                        new TagPolicyCreateAttributes()
                            .enabled(true)
                            .negated(false)
                            .policyName("Service tag must be one of api or web")
                            .policyType(TagPolicyCreateType.SURFACING)
                            .required(true)
                            .scope("env")
                            .source(TagPolicySource.LOGS)
                            .tagKey("service")
                            .tagValuePatterns(Arrays.asList("api", "web")))
                    .type(TagPolicyResourceType.TAG_POLICY));

    try {
      TagPolicyResponse result = apiInstance.createTagPolicy(body);
      System.out.println(result);
    } catch (ApiException e) {
      System.err.println("Exception when calling TagPoliciesApi#createTagPolicy");
      System.err.println("Status code: " + e.getCode());
      System.err.println("Reason: " + e.getResponseBody());
      System.err.println("Response headers: " + e.getResponseHeaders());
      e.printStackTrace();
    }
  }
}

Instructions

First install the library and its dependencies and then save the example to Example.java and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<API-KEY>" DD_APP_KEY="<APP-KEY>" java "Example.java"
// Create a tag policy returns "Created" response
use datadog_api_client::datadog;
use datadog_api_client::datadogV2::api_tag_policies::TagPoliciesAPI;
use datadog_api_client::datadogV2::model::TagPolicyCreateAttributes;
use datadog_api_client::datadogV2::model::TagPolicyCreateData;
use datadog_api_client::datadogV2::model::TagPolicyCreateRequest;
use datadog_api_client::datadogV2::model::TagPolicyCreateType;
use datadog_api_client::datadogV2::model::TagPolicyResourceType;
use datadog_api_client::datadogV2::model::TagPolicySource;

#[tokio::main]
async fn main() {
    let body = TagPolicyCreateRequest::new(TagPolicyCreateData::new(
        TagPolicyCreateAttributes::new(
            "Service tag must be one of api or web".to_string(),
            TagPolicyCreateType::SURFACING,
            "env".to_string(),
            TagPolicySource::LOGS,
            "service".to_string(),
            vec!["api".to_string(), "web".to_string()],
        )
        .enabled(true)
        .negated(false)
        .required(true),
        TagPolicyResourceType::TAG_POLICY,
    ));
    let mut configuration = datadog::Configuration::new();
    configuration.set_unstable_operation_enabled("v2.CreateTagPolicy", true);
    let api = TagPoliciesAPI::with_config(configuration);
    let resp = api.create_tag_policy(body).await;
    if let Ok(value) = resp {
        println!("{:#?}", value);
    } else {
        println!("{:#?}", resp.unwrap_err());
    }
}

Instructions

First install the library and its dependencies and then save the example to src/main.rs and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<API-KEY>" DD_APP_KEY="<APP-KEY>" cargo run
/**
 * Create a tag policy returns "Created" response
 */

import { client, v2 } from "@datadog/datadog-api-client";

const configuration = client.createConfiguration();
configuration.unstableOperations["v2.createTagPolicy"] = true;
const apiInstance = new v2.TagPoliciesApi(configuration);

const params: v2.TagPoliciesApiCreateTagPolicyRequest = {
  body: {
    data: {
      attributes: {
        enabled: true,
        negated: false,
        policyName: "Service tag must be one of api or web",
        policyType: "surfacing",
        required: true,
        scope: "env",
        source: "logs",
        tagKey: "service",
        tagValuePatterns: ["api", "web"],
      },
      type: "tag_policy",
    },
  },
};

apiInstance
  .createTagPolicy(params)
  .then((data: v2.TagPolicyResponse) => {
    console.log(
      "API called successfully. Returned data: " + JSON.stringify(data)
    );
  })
  .catch((error: any) => console.error(error));

Instructions

First install the library and its dependencies and then save the example to example.ts and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<API-KEY>" DD_APP_KEY="<APP-KEY>" tsc "example.ts"