Skip to content

Onboarding Setup API ​

API endpoints for the Policy Setup Wizard.

Endpoints ​

GET /api/v1/onboarding/setup ​

Returns the current onboarding configuration state for the authenticated user's company.

Authentication: Required (ACCOUNT_OWNER, ACCOUNT_ADMIN, ADMIN, SUPER_ADMIN)

Response (200):

json
{
  "success": true,
  "isConfigured": true,
  "company": {
    "gdprCompliant": true,
    "encryptionEnabled": true,
    "hipaaModeEnabled": false,
    "dataRetentionDays": 7,
    "promptLogRetentionDays": 14,
    "defaultResponseRetentionDays": 7
  },
  "routingPolicy": {
    "id": "clx...",
    "policyJson": { "..." }
  },
  "hasProviderAccessPolicy": true,
  "accessProfiles": [
    { "id": "clx...", "name": "Company Admin" },
    { "id": "clx...", "name": "Developer" }
  ],
  "hasGeofencingPolicy": true
}

Response (401/403): Unauthorized — user role not permitted.


POST /api/v1/onboarding/setup ​

Applies the full onboarding configuration in a single database transaction.

Authentication: Required (ACCOUNT_OWNER, ACCOUNT_ADMIN, ADMIN, SUPER_ADMIN)

Request Body:

FieldTypeRequiredDescription
useCasesstring[]YesAt least one of: compliant_access, prompt_libraries, ai_development, routing_gateway, api_execution, data_protection
organizationTypestringYesOne of: tech, finance, healthcare, government, legal, education, other
complianceFrameworksstring[]YesArray of: GDPR, HIPAA, SOC2, ISO27001, PCI_DSS, none
geoProcessingobjectYes`{ mode: "allow"
teamSizestringYesOne of: individual, small, department, enterprise
enableProjectsbooleanYesWhether to enable project-based organization
rolesstring[]YesArray of: admins, developers, business_users, security
providerAccessstringYesOne of: platform, byok, mixed
routingPrioritystringYesOne of: cost, quality, speed, security, balanced
providerRestrictionstringYesOne of: all, major, custom
customAllowedProvidersstring[]NoRequired when providerRestriction is custom
sanitizationModestringYesOne of: automatic, manual, disabled
encryptionEnabledbooleanYesEnable AES-256 encryption at rest
dataRetentionstringYesOne of: 7, 30, 90, custom
customRetentionobjectNoRequired when dataRetention is custom: { dataRetentionDays, promptLogRetentionDays, responseRetentionDays }
budgetModestringYesOne of: per_user, company, none
budgetAmountnumberNoMonthly budget amount (positive number)

Response (200):

json
{
  "success": true,
  "created": {
    "routingPolicyId": "clx...",
    "providerAccessPolicyId": "clx...",
    "accessProfileIds": ["clx...", "clx..."],
    "chatRolePolicyCount": 3,
    "geofencingPolicyId": "clx..."
  },
  "warnings": []
}

Response (422): Validation failed.

json
{
  "error": "Validation failed",
  "details": {
    "useCases": ["Array must contain at least 1 element(s)"]
  }
}

Response (400): Invalid JSON body.


POST /api/v1/onboarding/setup/skip ​

Records that the user skipped the onboarding wizard. Creates an audit log entry.

Authentication: Required (ACCOUNT_OWNER, ACCOUNT_ADMIN, ADMIN, SUPER_ADMIN)

Response (200):

json
{ "success": true }

Example: cURL ​

bash
# Check onboarding state
curl -H "Cookie: next-auth.session-token=YOUR_TOKEN" \
  https://app.veriprompt.tech/api/v1/onboarding/setup

# Apply configuration
curl -X POST \
  -H "Cookie: next-auth.session-token=YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "useCases": ["compliant_access"],
    "organizationType": "tech",
    "complianceFrameworks": ["none"],
    "geoProcessing": {"mode":"allow","regions":[],"countries":[]},
    "teamSize": "small",
    "enableProjects": false,
    "roles": ["admins","developers"],
    "providerAccess": "platform",
    "routingPriority": "balanced",
    "providerRestriction": "all",
    "sanitizationMode": "manual",
    "encryptionEnabled": false,
    "dataRetention": "30",
    "budgetMode": "none"
  }' \
  https://app.veriprompt.tech/api/v1/onboarding/setup