## Retrieve

**get** `/policy/bundle`

Returns the effective Policy Bundle for the user identified by the
zone-issued resource-scoped token. When no user-scope binding exists,
one will be generated from the default set.

The response body is a binary archive in the codec selected via the
`Accept` header. The only codec supported today is
`application/vnd.keycard.policy-bundle.v1+tar+gzip`. Clients SHOULD send
an explicit `Accept` header; absent one, the server defaults to the
tar+gzip codec.

Supports conditional fetch via `If-None-Match`: when the supplied ETag
matches the current bundle, the server responds `304 Not Modified` with
no body.

### Header Parameters

- `"If-None-Match": optional string`

- `"X-Client-Request-ID": optional string`

### Example

```http
curl https://api.keycard.ai/policy/bundle \
    -H "Authorization: Bearer $KEYCARD_API_API_KEY"
```
