Create a tag rule

Note: This endpoint is in preview and is subject to change. If you have any feedback, contact Datadog support.

POST https://api.ap1.datadoghq.com/api/v2/governance/tag_ruleshttps://api.ap2.datadoghq.com/api/v2/governance/tag_ruleshttps://api.datadoghq.eu/api/v2/governance/tag_ruleshttps://api.ddog-gov.com/api/v2/governance/tag_ruleshttps://api.us2.ddog-gov.com/api/v2/governance/tag_ruleshttps://api.uk1.datadoghq.com/api/v2/governance/tag_ruleshttps://api.datadoghq.com/api/v2/governance/tag_ruleshttps://api.us3.datadoghq.com/api/v2/governance/tag_ruleshttps://api.us5.datadoghq.com/api/v2/governance/tag_rules

Overview

Create a new tag rule for the organization. The caller’s organization is derived from the authenticated user; cross-organization creation is not supported. Fields such as rule_id, version, and the timestamp/audit fields are assigned by the server. This endpoint requires the telemetry_rules_create permission.

Request

Body Data (required)

Expand All

Field

Type

Description

data [required]

object

Data object for creating a tag rule.

attributes [required]

object

Attributes that can be supplied when creating a tag rule.

enabled

boolean

Whether the rule is currently enforced. Defaults to true for newly created rules.

name [required]

string

Human-readable name for the tag rule.

negated

boolean

When true, the rule matches tag values that do NOT match any of the supplied patterns. Defaults to false.

required

boolean

When true, telemetry without this tag is treated as a violation. Defaults to false.

rule_type [required]

enum

The rule type allowed when creating a tag rule. Only surfacing is accepted at creation time. Allowed enum values: surfacing

scope [required]

string

The scope the rule applies within. Typically an environment, team, or organization-level identifier used to limit where the rule is enforced.

source [required]

enum

The telemetry source that a tag rule applies to. Allowed enum values: logs,spans,metrics,rum,feed

tag_key [required]

string

The tag key that the rule governs (for example, service).

tag_value_patterns [required]

[string]

One or more patterns that valid values for the tag key must match. At least one pattern is required.

type [required]

enum

JSON:API resource type for a tag rule. Allowed enum values: tag_rule

{
  "data": {
    "attributes": {
      "enabled": true,
      "name": "Service tag must be one of api or web",
      "negated": false,
      "required": true,
      "rule_type": "surfacing",
      "scope": "env",
      "source": "logs",
      "tag_key": "service",
      "tag_value_patterns": [
        "api",
        "web"
      ]
    },
    "type": "tag_rule"
  }
}

Response

Created

A single tag rule.

Expand All

Field

Type

Description

data [required]

object

A tag rule resource.

attributes [required]

object

The attributes of a tag rule resource.

created_at [required]

date-time

The RFC 3339 timestamp at which the rule was created.

created_by [required]

string

The identifier of the user who created the rule.

deleted_at

date-time

The RFC 3339 timestamp at which the rule was soft-deleted. null if the rule has not been deleted. Only present when include_deleted=true is requested.

deleted_by

string

The identifier of the user who soft-deleted the rule. null if the rule has not been deleted.

enabled [required]

boolean

Whether the rule is currently enforced.

modified_at [required]

date-time

The RFC 3339 timestamp at which the rule was last modified.

modified_by [required]

string

The identifier of the user who last modified the rule.

name [required]

string

Human-readable name for the tag rule.

negated [required]

boolean

When true, the rule matches tag values that do NOT match any of the supplied patterns.

required [required]

boolean

When true, telemetry without this tag is treated as a violation.

rule_type [required]

enum

How the rule is enforced. blocking rejects telemetry that violates the rule. surfacing only highlights non-compliant telemetry without blocking it. Allowed enum values: blocking,surfacing

scope [required]

string

The scope the rule applies within.

source [required]

enum

The telemetry source that a tag rule applies to. Allowed enum values: logs,spans,metrics,rum,feed

tag_key [required]

string

The tag key that the rule governs.

tag_value_patterns [required]

[string]

The patterns that valid values for the tag key must match.

version [required]

int64

A monotonically increasing version counter that is incremented on each update.

id [required]

string

The unique identifier of the tag rule.

relationships

object

Related resources for a tag rule. Only present when the corresponding include query parameter is supplied.

score

object

A relationship to the compliance score resource for this rule.

data [required]

object

Identifier of the related compliance score resource.

id [required]

string

The unique identifier of the related compliance score resource.

type [required]

enum

JSON:API resource type for a tag rule compliance score. Allowed enum values: tag_rule_score

type [required]

enum

JSON:API resource type for a tag rule. Allowed enum values: tag_rule

included

[object]

Related resources fetched alongside the primary tag rules. Populated when an include query parameter is supplied.

attributes [required]

object

Attributes of a tag rule compliance score.

score [required]

double

The compliance score for the rule over the requested time window, as a percentage between 0 and 100. null indicates that no relevant telemetry was found.

ts_end [required]

int64

End of the time window the score was computed over, as a Unix timestamp in milliseconds.

ts_start [required]

int64

Start of the time window the score was computed over, as a Unix timestamp in milliseconds.

version [required]

int64

The version of the tag rule that the score was computed against.

id [required]

string

The unique identifier of the compliance score resource.

type [required]

enum

JSON:API resource type for a tag rule compliance score. Allowed enum values: tag_rule_score

{
  "data": {
    "attributes": {
      "created_at": "2026-05-21T22:11:06.108696Z",
      "created_by": "test-user",
      "deleted_at": "2019-09-19T10:00:00.000Z",
      "deleted_by": "string",
      "enabled": true,
      "modified_at": "2026-05-21T22:11:06.108696Z",
      "modified_by": "test-user",
      "name": "Service tag must be one of api or web",
      "negated": false,
      "required": true,
      "rule_type": "surfacing",
      "scope": "env",
      "source": "logs",
      "tag_key": "service",
      "tag_value_patterns": [
        "api",
        "web"
      ],
      "version": 1
    },
    "id": "123",
    "relationships": {
      "score": {
        "data": {
          "id": "123-v1-1779315066097-1779401466097",
          "type": "tag_rule_score"
        }
      }
    },
    "type": "tag_rule"
  },
  "included": [
    {
      "attributes": {
        "score": 80,
        "ts_end": 1779401466097,
        "ts_start": 1779315066097,
        "version": 1
      },
      "id": "123-v1-1779315066097-1779401466097",
      "type": "tag_rule_score"
    }
  ]
}

Bad Request

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Unauthorized

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Forbidden

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Conflict

API error response.

Expand All

Field

Type

Description

errors [required]

[object]

A list of errors.

detail

string

A human-readable explanation specific to this occurrence of the error.

meta

object

Non-standard meta-information about the error

source

object

References to the source of the error.

header

string

A string indicating the name of a single request header which caused the error.

parameter

string

A string indicating which URI query parameter caused the error.

pointer

string

A JSON pointer to the value in the request document that caused the error.

status

string

Status code of the response.

title

string

Short human-readable summary of the error.

{
  "errors": [
    {
      "detail": "Missing required attribute in body",
      "meta": {},
      "source": {
        "header": "Authorization",
        "parameter": "limit",
        "pointer": "/data/attributes/title"
      },
      "status": "400",
      "title": "Bad Request"
    }
  ]
}

Too many requests

API error response.

Expand All

Field

Type

Description

errors [required]

[string]

A list of errors.

{
  "errors": [
    "Bad Request"
  ]
}

Code Example

                  ## default
# 

# Curl command
curl -X POST "https://api.ap1.datadoghq.com"https://api.ap2.datadoghq.com"https://api.datadoghq.eu"https://api.ddog-gov.com"https://api.us2.ddog-gov.com"https://api.uk1.datadoghq.com"https://api.datadoghq.com"https://api.us3.datadoghq.com"https://api.us5.datadoghq.com/api/v2/governance/tag_rules" \ -H "Accept: application/json" \ -H "Content-Type: application/json" \ -H "DD-API-KEY: ${DD_API_KEY}" \ -H "DD-APPLICATION-KEY: ${DD_APP_KEY}" \ -d @- << EOF { "data": { "attributes": { "enabled": true, "name": "Service tag must be one of api or web", "negated": false, "required": true, "rule_type": "surfacing", "scope": "env", "source": "logs", "tag_key": "service", "tag_value_patterns": [ "api", "web" ] }, "type": "tag_rule" } } EOF
"""
Create a tag rule returns "Created" response
"""

from datadog_api_client import ApiClient, Configuration
from datadog_api_client.v2.api.tag_rules_api import TagRulesApi
from datadog_api_client.v2.model.tag_rule_create_attributes import TagRuleCreateAttributes
from datadog_api_client.v2.model.tag_rule_create_data import TagRuleCreateData
from datadog_api_client.v2.model.tag_rule_create_request import TagRuleCreateRequest
from datadog_api_client.v2.model.tag_rule_create_type import TagRuleCreateType
from datadog_api_client.v2.model.tag_rule_resource_type import TagRuleResourceType
from datadog_api_client.v2.model.tag_rule_source import TagRuleSource

body = TagRuleCreateRequest(
    data=TagRuleCreateData(
        attributes=TagRuleCreateAttributes(
            enabled=True,
            name="Service tag must be one of api or web",
            negated=False,
            required=True,
            rule_type=TagRuleCreateType.SURFACING,
            scope="env",
            source=TagRuleSource.LOGS,
            tag_key="service",
            tag_value_patterns=[
                "api",
                "web",
            ],
        ),
        type=TagRuleResourceType.TAG_RULE,
    ),
)

configuration = Configuration()
configuration.unstable_operations["create_tag_rule"] = True
with ApiClient(configuration) as api_client:
    api_instance = TagRulesApi(api_client)
    response = api_instance.create_tag_rule(body=body)

    print(response)

Instructions

First install the library and its dependencies and then save the example to example.py and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" python3 "example.py"
# Create a tag rule returns "Created" response

require "datadog_api_client"
DatadogAPIClient.configure do |config|
  config.unstable_operations["v2.create_tag_rule".to_sym] = true
end
api_instance = DatadogAPIClient::V2::TagRulesAPI.new

body = DatadogAPIClient::V2::TagRuleCreateRequest.new({
  data: DatadogAPIClient::V2::TagRuleCreateData.new({
    attributes: DatadogAPIClient::V2::TagRuleCreateAttributes.new({
      enabled: true,
      name: "Service tag must be one of api or web",
      negated: false,
      required: true,
      rule_type: DatadogAPIClient::V2::TagRuleCreateType::SURFACING,
      scope: "env",
      source: DatadogAPIClient::V2::TagRuleSource::LOGS,
      tag_key: "service",
      tag_value_patterns: [
        "api",
        "web",
      ],
    }),
    type: DatadogAPIClient::V2::TagRuleResourceType::TAG_RULE,
  }),
})
p api_instance.create_tag_rule(body)

Instructions

First install the library and its dependencies and then save the example to example.rb and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" rb "example.rb"
// Create a tag rule returns "Created" response

package main

import (
	"context"
	"encoding/json"
	"fmt"
	"os"

	"github.com/DataDog/datadog-api-client-go/v2/api/datadog"
	"github.com/DataDog/datadog-api-client-go/v2/api/datadogV2"
)

func main() {
	body := datadogV2.TagRuleCreateRequest{
		Data: datadogV2.TagRuleCreateData{
			Attributes: datadogV2.TagRuleCreateAttributes{
				Enabled:  datadog.PtrBool(true),
				Name:     "Service tag must be one of api or web",
				Negated:  datadog.PtrBool(false),
				Required: datadog.PtrBool(true),
				RuleType: datadogV2.TAGRULECREATETYPE_SURFACING,
				Scope:    "env",
				Source:   datadogV2.TAGRULESOURCE_LOGS,
				TagKey:   "service",
				TagValuePatterns: []string{
					"api",
					"web",
				},
			},
			Type: datadogV2.TAGRULERESOURCETYPE_TAG_RULE,
		},
	}
	ctx := datadog.NewDefaultContext(context.Background())
	configuration := datadog.NewConfiguration()
	configuration.SetUnstableOperationEnabled("v2.CreateTagRule", true)
	apiClient := datadog.NewAPIClient(configuration)
	api := datadogV2.NewTagRulesApi(apiClient)
	resp, r, err := api.CreateTagRule(ctx, body)

	if err != nil {
		fmt.Fprintf(os.Stderr, "Error when calling `TagRulesApi.CreateTagRule`: %v\n", err)
		fmt.Fprintf(os.Stderr, "Full HTTP response: %v\n", r)
	}

	responseContent, _ := json.MarshalIndent(resp, "", "  ")
	fmt.Fprintf(os.Stdout, "Response from `TagRulesApi.CreateTagRule`:\n%s\n", responseContent)
}

Instructions

First install the library and its dependencies and then save the example to main.go and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" go run "main.go"
// Create a tag rule returns "Created" response

import com.datadog.api.client.ApiClient;
import com.datadog.api.client.ApiException;
import com.datadog.api.client.v2.api.TagRulesApi;
import com.datadog.api.client.v2.model.TagRuleCreateAttributes;
import com.datadog.api.client.v2.model.TagRuleCreateData;
import com.datadog.api.client.v2.model.TagRuleCreateRequest;
import com.datadog.api.client.v2.model.TagRuleCreateType;
import com.datadog.api.client.v2.model.TagRuleResourceType;
import com.datadog.api.client.v2.model.TagRuleResponse;
import com.datadog.api.client.v2.model.TagRuleSource;
import java.util.Arrays;

public class Example {
  public static void main(String[] args) {
    ApiClient defaultClient = ApiClient.getDefaultApiClient();
    defaultClient.setUnstableOperationEnabled("v2.createTagRule", true);
    TagRulesApi apiInstance = new TagRulesApi(defaultClient);

    TagRuleCreateRequest body =
        new TagRuleCreateRequest()
            .data(
                new TagRuleCreateData()
                    .attributes(
                        new TagRuleCreateAttributes()
                            .enabled(true)
                            .name("Service tag must be one of api or web")
                            .negated(false)
                            .required(true)
                            .ruleType(TagRuleCreateType.SURFACING)
                            .scope("env")
                            .source(TagRuleSource.LOGS)
                            .tagKey("service")
                            .tagValuePatterns(Arrays.asList("api", "web")))
                    .type(TagRuleResourceType.TAG_RULE));

    try {
      TagRuleResponse result = apiInstance.createTagRule(body);
      System.out.println(result);
    } catch (ApiException e) {
      System.err.println("Exception when calling TagRulesApi#createTagRule");
      System.err.println("Status code: " + e.getCode());
      System.err.println("Reason: " + e.getResponseBody());
      System.err.println("Response headers: " + e.getResponseHeaders());
      e.printStackTrace();
    }
  }
}

Instructions

First install the library and its dependencies and then save the example to Example.java and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" java "Example.java"
// Create a tag rule returns "Created" response
use datadog_api_client::datadog;
use datadog_api_client::datadogV2::api_tag_rules::TagRulesAPI;
use datadog_api_client::datadogV2::model::TagRuleCreateAttributes;
use datadog_api_client::datadogV2::model::TagRuleCreateData;
use datadog_api_client::datadogV2::model::TagRuleCreateRequest;
use datadog_api_client::datadogV2::model::TagRuleCreateType;
use datadog_api_client::datadogV2::model::TagRuleResourceType;
use datadog_api_client::datadogV2::model::TagRuleSource;

#[tokio::main]
async fn main() {
    let body = TagRuleCreateRequest::new(TagRuleCreateData::new(
        TagRuleCreateAttributes::new(
            "Service tag must be one of api or web".to_string(),
            TagRuleCreateType::SURFACING,
            "env".to_string(),
            TagRuleSource::LOGS,
            "service".to_string(),
            vec!["api".to_string(), "web".to_string()],
        )
        .enabled(true)
        .negated(false)
        .required(true),
        TagRuleResourceType::TAG_RULE,
    ));
    let mut configuration = datadog::Configuration::new();
    configuration.set_unstable_operation_enabled("v2.CreateTagRule", true);
    let api = TagRulesAPI::with_config(configuration);
    let resp = api.create_tag_rule(body).await;
    if let Ok(value) = resp {
        println!("{:#?}", value);
    } else {
        println!("{:#?}", resp.unwrap_err());
    }
}

Instructions

First install the library and its dependencies and then save the example to src/main.rs and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" cargo run
/**
 * Create a tag rule returns "Created" response
 */

import { client, v2 } from "@datadog/datadog-api-client";

const configuration = client.createConfiguration();
configuration.unstableOperations["v2.createTagRule"] = true;
const apiInstance = new v2.TagRulesApi(configuration);

const params: v2.TagRulesApiCreateTagRuleRequest = {
  body: {
    data: {
      attributes: {
        enabled: true,
        name: "Service tag must be one of api or web",
        negated: false,
        required: true,
        ruleType: "surfacing",
        scope: "env",
        source: "logs",
        tagKey: "service",
        tagValuePatterns: ["api", "web"],
      },
      type: "tag_rule",
    },
  },
};

apiInstance
  .createTagRule(params)
  .then((data: v2.TagRuleResponse) => {
    console.log(
      "API called successfully. Returned data: " + JSON.stringify(data)
    );
  })
  .catch((error: any) => console.error(error));

Instructions

First install the library and its dependencies and then save the example to example.ts and run following commands:

    
DD_SITE="datadoghq.comus3.datadoghq.comus5.datadoghq.comdatadoghq.euap1.datadoghq.comap2.datadoghq.comuk1.datadoghq.comddog-gov.comus2.ddog-gov.com" DD_API_KEY="<DD_API_KEY>" DD_APP_KEY="<DD_APP_KEY>" tsc "example.ts"