Appearance
Onboarding Setup API
API endpoints for the Policy Setup Wizard.
Endpoints
GET /api/v1/onboarding/setup
Returns the current onboarding configuration state for the authenticated user's company.
Authentication: Required (ACCOUNT_OWNER, ACCOUNT_ADMIN, ADMIN, SUPER_ADMIN)
Response (200):
json
{
"success": true,
"isConfigured": true,
"company": {
"gdprCompliant": true,
"encryptionEnabled": true,
"hipaaModeEnabled": false,
"dataRetentionDays": 7,
"promptLogRetentionDays": 14,
"defaultResponseRetentionDays": 7
},
"routingPolicy": {
"id": "clx...",
"policyJson": { "..." }
},
"hasProviderAccessPolicy": true,
"accessProfiles": [
{ "id": "clx...", "name": "Company Admin" },
{ "id": "clx...", "name": "Developer" }
],
"hasGeofencingPolicy": true
}Response (401/403): Unauthorized — user role not permitted.
POST /api/v1/onboarding/setup
Applies the full onboarding configuration in a single database transaction.
Authentication: Required (ACCOUNT_OWNER, ACCOUNT_ADMIN, ADMIN, SUPER_ADMIN)
Request Body:
| Field | Type | Required | Description |
|---|---|---|---|
useCases | string[] | Yes | At least one of: compliant_access, prompt_libraries, ai_development, routing_gateway, api_execution, data_protection |
organizationType | string | Yes | One of: tech, finance, healthcare, government, legal, education, other |
complianceFrameworks | string[] | Yes | Array of: GDPR, HIPAA, SOC2, ISO27001, PCI_DSS, none |
geoProcessing | object | Yes | `{ mode: "allow" |
teamSize | string | Yes | One of: individual, small, department, enterprise |
enableProjects | boolean | Yes | Whether to enable project-based organization |
roles | string[] | Yes | Array of: admins, developers, business_users, security |
providerAccess | string | Yes | One of: platform, byok, mixed |
routingPriority | string | Yes | One of: cost, quality, speed, security, balanced |
providerRestriction | string | Yes | One of: all, major, custom |
customAllowedProviders | string[] | No | Required when providerRestriction is custom |
sanitizationMode | string | Yes | One of: automatic, manual, disabled |
encryptionEnabled | boolean | Yes | Enable AES-256 encryption at rest |
dataRetention | string | Yes | One of: 7, 30, 90, custom |
customRetention | object | No | Required when dataRetention is custom: { dataRetentionDays, promptLogRetentionDays, responseRetentionDays } |
budgetMode | string | Yes | One of: per_user, company, none |
budgetAmount | number | No | Monthly budget amount (positive number) |
Response (200):
json
{
"success": true,
"created": {
"routingPolicyId": "clx...",
"providerAccessPolicyId": "clx...",
"accessProfileIds": ["clx...", "clx..."],
"chatRolePolicyCount": 3,
"geofencingPolicyId": "clx..."
},
"warnings": []
}Response (422): Validation failed.
json
{
"error": "Validation failed",
"details": {
"useCases": ["Array must contain at least 1 element(s)"]
}
}Response (400): Invalid JSON body.
POST /api/v1/onboarding/setup/skip
Records that the user skipped the onboarding wizard. Creates an audit log entry.
Authentication: Required (ACCOUNT_OWNER, ACCOUNT_ADMIN, ADMIN, SUPER_ADMIN)
Response (200):
json
{ "success": true }Example: cURL
bash
# Check onboarding state
curl -H "Cookie: next-auth.session-token=YOUR_TOKEN" \
https://app.veriprompt.tech/api/v1/onboarding/setup
# Apply configuration
curl -X POST \
-H "Cookie: next-auth.session-token=YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"useCases": ["compliant_access"],
"organizationType": "tech",
"complianceFrameworks": ["none"],
"geoProcessing": {"mode":"allow","regions":[],"countries":[]},
"teamSize": "small",
"enableProjects": false,
"roles": ["admins","developers"],
"providerAccess": "platform",
"routingPriority": "balanced",
"providerRestriction": "all",
"sanitizationMode": "manual",
"encryptionEnabled": false,
"dataRetention": "30",
"budgetMode": "none"
}' \
https://app.veriprompt.tech/api/v1/onboarding/setup