> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sahlfinancial.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List scoring policies

> **Who can call it:** Any signed-in member of the workspace.

Policies for one `path` (`kyc` or `kyb`) and one country (default: the workspace's, else `MA`). Also returns the country's factor catalogue and rules.

**Auth:** dashboard session (`Authorization: Bearer <access token>`). Not available with a partner API key.



## OpenAPI

````yaml /openapi-console.json get /v1/scoring/policies
openapi: 3.1.0
info:
  title: Sahl Console API
  version: 0.1.0
  description: >-
    **Used by the Sahl console. Not available with partner API keys. Contact
    Sahl if you need programmatic access.**


    These are the routes the Sahl console calls with a signed-in user's session.
    They are documented so that a developer or a workspace admin can see what
    the console does, with the real request and response models. They are
    **not** part of the [Partner API](/api-reference/introduction): an API key
    is refused here (401), there is no try-it, and the shapes can change with
    the console.


    Authentication: `Authorization: Bearer <access token>`, the JWT the console
    gets from `POST /v1/auth/login` (30 minutes; renewed with `POST
    /v1/auth/refresh`, refresh token valid 7 days). There is no cookie. The role
    of the user is read from the user's record on every call, not from the
    token. Every call is scoped to the workspace of the user.


    Common answers: 401 (no or bad session), 403 `Insufficient permissions`
    (role), 422 (validation), 429 (100 requests per minute and IP). Error bodies
    have the same three shapes as the Partner API: see [Errors](/errors).
servers:
  - url: https://app.sahlfinancial.com/api
    description: Console host. Same host as the Partner API.
security:
  - dashboardSession: []
tags:
  - name: Bank connections
    description: Simulated in the Sandbox; 409 `bank_connect_unavailable` elsewhere.
  - name: Cases
    description: Client files that group documents, a score and a decision.
  - name: Documents
    description: Upload, status, result and download.
  - name: Webhooks
    description: Manage the endpoints that receive events.
  - name: API keys
    description: Create, rotate and revoke the keys used with the Partner API.
  - name: Scoring policies
    description: Weights and thresholds of the credit score.
  - name: Flows
    description: Verification flows (graphs) and their simulation.
paths:
  /v1/scoring/policies:
    get:
      tags:
        - Scoring policies
      summary: List scoring policies
      description: >-
        **Who can call it:** Any signed-in member of the workspace.


        Policies for one `path` (`kyc` or `kyb`) and one country (default: the
        workspace's, else `MA`). Also returns the country's factor catalogue and
        rules.


        **Auth:** dashboard session (`Authorization: Bearer <access token>`).
        Not available with a partner API key.
      operationId: listScoringPolicies
      parameters:
        - name: path
          in: query
          required: false
          schema:
            type: string
            default: kyc
            title: Path
        - name: country
          in: query
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: Country
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyListResponse'
              example:
                path: kyc
                country: MA
                factors:
                  - key: income_stability
                    label: Income stability
                    description: Regularity and level of income.
                    default_weight: 0.3
                    block: null
                regime: {}
                items:
                  - id: 2f8c1d5a-7b3e-4e96-8a4d-0c6b9e1f3d72
                    path: kyc
                    country: MA
                    name: Standard 2026
                    description: Default thresholds
                    weights:
                      income_stability: 0.3
                      debt_ratio: 0.3
                      bank_behaviour: 0.2
                      documents: 0.2
                    approve_threshold: 700
                    refuse_threshold: 500
                    dti_cap_pct: 40
                    require_cnss: true
                    require_domiciliation: false
                    gds_cap_pct: null
                    tds_cap_pct: null
                    min_bureau_score: null
                    is_active: false
                countries_with_policies:
                  - MA
                active_country: MA
        '400':
          description: '`path` is not `kyc` or `kyb`, or `country` is not an ISO code.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                detail: path must be 'kyc' or 'kyb'
        '401':
          description: No session, expired token, ended session or inactive account.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                detail: Invalid or expired token
        '403':
          description: >-
            The role is not allowed, MFA enrolment is pending, or the
            environment is refused.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                detail: Insufficient permissions
        '422':
          description: Validation error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                detail:
                  - type: missing
                    loc:
                      - body
                      - bank_code
                    msg: Field required
                    input: {}
        '429':
          description: >-
            More than 100 requests per minute from one IP address. The body has
            no `detail`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RateLimitError'
              example:
                code: rate_limit_exceeded
                message: Too many requests. Please slow down.
          headers:
            Retry-After:
              schema:
                type: integer
              description: Seconds to wait.
components:
  schemas:
    PolicyListResponse:
      properties:
        path:
          type: string
        country:
          type: string
        factors:
          items:
            $ref: '#/components/schemas/FactorMeta'
          type: array
        regime:
          additionalProperties: true
          type: object
        items:
          items:
            $ref: '#/components/schemas/PolicyResponse'
          type: array
        countries_with_policies:
          items:
            type: string
          type: array
          default: []
        active_country:
          anyOf:
            - type: string
            - type: 'null'
      type: object
      required:
        - path
        - country
        - factors
        - regime
        - items
    Error:
      type: object
      description: >-
        FastAPI error body. `detail` is a string, a list (422), or an object
        with `code` and `message` (extra keys possible).
      properties:
        detail:
          oneOf:
            - type: string
            - items:
                additionalProperties: true
                type: object
              type: array
            - type: object
              additionalProperties: true
              properties:
                code:
                  type: string
                message:
                  type: string
      required:
        - detail
    RateLimitError:
      type: object
      description: Top-level `code` and `message`, no `detail`.
      properties:
        code:
          type: string
        message:
          type: string
      required:
        - code
        - message
    FactorMeta:
      properties:
        key:
          type: string
        label:
          type: string
        description:
          type: string
        default_weight:
          type: number
        block:
          anyOf:
            - type: string
            - type: 'null'
      type: object
      required:
        - key
        - label
        - description
        - default_weight
    PolicyResponse:
      properties:
        id:
          type: string
        path:
          type: string
        country:
          anyOf:
            - type: string
            - type: 'null'
        name:
          type: string
        description:
          anyOf:
            - type: string
            - type: 'null'
        weights:
          additionalProperties:
            type: number
          type: object
        approve_threshold:
          type: integer
        refuse_threshold:
          type: integer
        dti_cap_pct:
          type: integer
        require_cnss:
          type: boolean
        require_domiciliation:
          type: boolean
        gds_cap_pct:
          anyOf:
            - type: integer
            - type: 'null'
        tds_cap_pct:
          anyOf:
            - type: integer
            - type: 'null'
        min_bureau_score:
          anyOf:
            - type: integer
            - type: 'null'
        is_active:
          type: boolean
      type: object
      required:
        - id
        - path
        - name
        - weights
        - approve_threshold
        - refuse_threshold
        - dti_cap_pct
        - require_cnss
        - require_domiciliation
        - is_active
  securitySchemes:
    dashboardSession:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        The access token (JWT) of a signed-in console user, from `POST
        /v1/auth/login`. It lasts 30 minutes. It is not an API key: a partner
        API key is refused here. There is no cookie.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.