Skip to main content
POST
cURL

Authorizations

Authorization
string
header
required

Caller API key issued by scripts/generate-api-key.ts. Sent as Authorization: Bearer . Verified against a stored SHA-256 hash in constant time by packages/api/src/auth/StaticKeyAuthenticator.ts. Required on every route not listed as exempt in this document's top-level description. See /api-reference/authentication.

Body

application/json

Asks the sandbox's demo approver to approve one sandbox:receipt request.

capability
string
required

The only capability the demo approver signs for.

Allowed value: "sandbox:receipt"
resourceId
string
required

The target of the request you will send, its intent.target.

Required string length: 1 - 200

Response

The signed approval. Send it as signals.approvalArtifact within 5 minutes; it is accepted once.

A person's approval of one action, signed with their approver key. A request carries it in signals.approvalArtifact when its policy declares approvalSignals. The server checks the issuer is a trusted approver key, the signature, the capability, the resource, the scope and the expiry, and consumes the nonce, so an approval is used once.

payload
object
required
signature
object
required