# Policy evaluation based on external rest api call

**URL:** <https://forum.keycloak.org/t/policy-evaluation-based-on-external-rest-api-call/2903>\
**Category:** Securing applications\
**Created:** [May 22, 2020, 1:03pm UTC](https://forum.keycloak.org/t/policy-evaluation-based-on-external-rest-api-call/2903 "2020-05-22T13:03:10Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rajendra.kotulkar](https://avatars.discourse-cdn.com/v4/letter/r/b782af/32.png) [@rajendra.kotulkar](https://forum.keycloak.org/u/rajendra.kotulkar)\
**Post date:** [May 22, 2020, 1:03pm UTC](https://forum.keycloak.org/t/policy-evaluation-based-on-external-rest-api-call/2903/1 "2020-05-22T13:03:10Z")

</div>

I want to evaluate a policy based on external api call response.i explored javascript based policy  
as per below link -  
[https://www.keycloak.org/docs/latest/authorization\_services/index.html#\_policy\_js](https://www.keycloak.org/docs/latest/authorization_services/index.html#_policy_js)  
tried below example but not working  
fetch(‘[https://ghibliapi.herokuapp.com/films](https://ghibliapi.herokuapp.com/films)’)  
.then(function() {  
$evaluation.grant();  
})  
.catch(function() {  
$evaluation.deny();  
});
