Replace a project's prompt injection settings
Replaces the override as a whole. Fields you omit inherit the organization value; send a field as null to clear it back to inheritance. An empty body means inherit everything, the same as DELETE. A project pinned to an API key uses this policy as written. A project named per request (project_id body field or X-Project-Id header) may only tighten the organization policy; anything that loosens it is ignored at request time.
Authentication
A management key (prefixed mgmt_), created on the dashboard’s API keys page under Management keys. Distinct from a regular gateway API key, and never used to call models.
Path parameters
Request
Direct-injection enforcement mode: off, alert, or block
Direct-injection block threshold. Must be at least the organization’s pi_pass_threshold, which is not overridable per project
Indirect-injection enforcement mode, a separate axis from pi_mode
Indirect-injection heuristic-confidence threshold
Indirect-injection embedding-similarity threshold
What to do when the response-side check fires