Create a compliance catalog entry

posthttps://api.expiryedge.com/v1/createCompliance
editor or admin60/minIdempotency-KeyAny method
Request
curl -X POST 'https://api.expiryedge.com/v1/createCompliance' \
  -H "Authorization: Bearer $EXPIRYEDGE_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "name": "HIPAA Security Risk Assessment",
  "description": "Annual security risk analysis required under the HIPAA Security Rule.",
  "category": "Data Privacy",
  "renewalFrequency": "Annually",
  "notes": "Keep the signed report for six years.",
  "status": "Active",
  "customFields": {
    "regulator": "HHS OCR"
  }
}'
Response
{
  "message": "Compliance created successfully.",
  "compliance": {
    "id": "cm_9Pq4zR",
    "name": "HIPAA Security Risk Assessment",
    "description": "Annual security risk analysis required under the HIPAA Security Rule.",
    "category": "Data Privacy",
    "customCategory": "",
    "renewalFrequency": "Annually",
    "notes": "Keep the signed report for six years.",
    "status": "Active",
    "customFields": {
      "regulator": "HHS OCR"
    },
    "isArchived": false,
    "archivedAt": null,
    "organization_id": "org_northwind",
    "user_id": "u_71bXq",
    "createdAt": "2026-09-27T14:05:00.000Z",
    "updatedAt": "2026-09-27T14:05:00.000Z"
  }
}

No plan limit applies.

Headers

  • Idempotency-Keystring
    Optional client-generated key (1-255 characters of letters, digits, - _ : .).
    pattern: ^[A-Za-z0-9_\-:.]{1,255}$

Body parameters

application/json
  • namestringrequired
    Required on create; cannot be blank on update.
  • descriptionstring
  • categorystring
    Any other value is stored as Other.
    AllowedData PrivacySafetyFinancialEnvironmentalLaborQualitySecurityRegulatoryOther
  • customCategorystring
    Only kept when category is Other.
  • renewalFrequencystring
    Any other value is stored as One-Time.
    AllowedOne-TimeMonthlyQuarterlyAnnuallyBiennially
  • notesstring
  • statusstring
    Any other value is stored as Active.
    AllowedActiveInactive
  • customFieldsmap of string
    Free-form key/value pairs. Keys are trimmed; values are stored as strings.

Returns

201
Created.
  • messagestring
  • complianceobject
    A compliance requirement in the organization catalog.

Errors

400
The request is missing required fields or contains invalid values.
401
Missing, expired or invalid bearer token.
403
Authenticated, but your role or organization does not allow this action.
409
A request with the same Idempotency-Key is still being processed. Retry after Retry-After seconds.
422
The Idempotency-Key was already used with a different request body.
429
Too many requests for this endpoint from your IP. Wait Retry-After seconds.
500
Unexpected server error. Retry later; quote requestId to support.