{"type":"video","version":"1.0","html":"<iframe src=\"https://www.loom.com/embed/bfb4a8ca84d3416db5ae7ce0c2661874\" frameborder=\"0\" width=\"1660\" height=\"1245\" webkitallowfullscreen mozallowfullscreen allowfullscreen></iframe>","height":1245,"width":1660,"provider_name":"Loom","provider_url":"https://www.loom.com","thumbnail_height":1245,"thumbnail_width":1660,"thumbnail_url":"https://cdn.loom.com/sessions/thumbnails/bfb4a8ca84d3416db5ae7ce0c2661874-98c4b23b47b118cd.gif","duration":663.891,"title":"Fine Grained API Token Policies in Beta","description":"This Loom introduces a new beta Policy API token feature for fine-grained access control to infrastructure. It explains that tokens are validated by an Open Policy Agent to allow or deny specific API endpoint interactions at a defined capability level, including allowing deploy actions while disallowing delete operations. The example shows an agent successfully deploying a service, then receiving a 401 response when attempting to delete the application. This is presented as a way to close a real gap in how teams grant infrastructure access as agents increasingly use infrastructure directly."}