Approve an approver change
Approves an approver change and applies it in one step: add trusts the key from the next approval checked, revoke refuses every approval the key ever signed from the next request on.
Authorizations
Caller API key issued by scripts/generate-api-key.ts. Sent as Authorization: Bearer . Verified against a stored SHA-256 hash in constant time by packages/api/src/auth/StaticKeyAuthenticator.ts. Required on every route not listed as exempt in this document's top-level description. See /api-reference/authentication.
Path Parameters
The changeId.
Body
Request body for POST /policies/pending-changes/{id}/approve.
Signed envelope proving a checker's explicit, fresh intent to approve or reject one specific Pending Policy Change (Policy Governance, Layer 4). Produced by PolicyChangeStepUpAuthorizationSigner (@parmana/crypto) using the checker's own step-up private key, never the bearer API key. Verified server-side against: the checker's registered stepUpPublicKey, payload.pendingPolicyChangeId matching the URL's {id}, payload.action matching the endpoint (approve vs reject), payload.expiresAt not yet passed, and payload.nonce not previously seen (single-use, replay-rejected on a second attempt with the same envelope).
Response
Approved and applied.
A proposal to add an approver key, or to revoke one added this way, and its resolution. One person proposes it; a different person approves or rejects it with a step up authorization. Only an approved change affects which approvals verify.
Unique id of the change, a UUID. The step up authorization for approve or reject names it in payload.pendingPolicyChangeId.
add trusts a new key; revoke stops trusting a key added this way, and every approval it ever signed.
add, revoke The approver, as named in the payload.issuer.approverId of the approvals they sign.
^[A-Za-z0-9._-]{1,128}$The approver's key, as named in payload.issuer.keyId. A key id is used once: a revoked key id cannot be added again.
^[A-Za-z0-9._-]{1,128}$Why, from the proposer.
2000The proposer's caller id. Always a human credential.
PENDING_APPROVAL until a second person approves or rejects it; then APPROVED or REJECTED, once.
PENDING_APPROVAL, APPROVED, REJECTED The approver's Ed25519 public key, PEM (SPKI), as the server stored it. Present on add, absent on revoke.
Who approved or rejected it. Never the proposer.
Present when REJECTED.