Skip to main content
POST
Approve an approver change

Authorizations

Authorization
string
header
required

Caller API key issued by scripts/generate-api-key.ts. Sent as Authorization: Bearer . Verified against a stored SHA-256 hash in constant time by packages/api/src/auth/StaticKeyAuthenticator.ts. Required on every route not listed as exempt in this document's top-level description. See /api-reference/authentication.

Path Parameters

id
string
required

The changeId.

Body

application/json

Request body for POST /policies/pending-changes/{id}/approve.

stepUpAuthorization
Policy Change Step-Up Authorization · object
required

Signed envelope proving a checker's explicit, fresh intent to approve or reject one specific Pending Policy Change (Policy Governance, Layer 4). Produced by PolicyChangeStepUpAuthorizationSigner (@parmana/crypto) using the checker's own step-up private key, never the bearer API key. Verified server-side against: the checker's registered stepUpPublicKey, payload.pendingPolicyChangeId matching the URL's {id}, payload.action matching the endpoint (approve vs reject), payload.expiresAt not yet passed, and payload.nonce not previously seen (single-use, replay-rejected on a second attempt with the same envelope).

Example:

Response

Approved and applied.

A proposal to add an approver key, or to revoke one added this way, and its resolution. One person proposes it; a different person approves or rejects it with a step up authorization. Only an approved change affects which approvals verify.

changeId
string
required

Unique id of the change, a UUID. The step up authorization for approve or reject names it in payload.pendingPolicyChangeId.

action
enum<string>
required

add trusts a new key; revoke stops trusting a key added this way, and every approval it ever signed.

Available options:
add,
revoke
approverId
string
required

The approver, as named in the payload.issuer.approverId of the approvals they sign.

Pattern: ^[A-Za-z0-9._-]{1,128}$
keyId
string
required

The approver's key, as named in payload.issuer.keyId. A key id is used once: a revoked key id cannot be added again.

Pattern: ^[A-Za-z0-9._-]{1,128}$
reason
string
required

Why, from the proposer.

Maximum string length: 2000
proposedBy
string
required

The proposer's caller id. Always a human credential.

proposedAt
string<date-time>
required
status
enum<string>
required

PENDING_APPROVAL until a second person approves or rejects it; then APPROVED or REJECTED, once.

Available options:
PENDING_APPROVAL,
APPROVED,
REJECTED
publicKeyPem
string

The approver's Ed25519 public key, PEM (SPKI), as the server stored it. Present on add, absent on revoke.

resolvedBy
string

Who approved or rejected it. Never the proposer.

resolvedAt
string<date-time>
rejectionReason
string

Present when REJECTED.