Get a demo approval (sandbox only)
Sandbox only. Returns an approval signed by the sandbox’s demo approver, so you can try an approved request from a browser.
curl -X POST https://parmana-sandbox.vercel.app/sandbox/approvals -H "Authorization: Bearer $PARMANA_API_KEY" -H "Content-Type: application/json" -d '{
"capability": "sandbox:receipt",
"resourceId": "demo-order-1"
}'// Sandbox only, and not in the SDK: a demo for trying Parmana, not part of
// the product API. Call the route directly.
const response = await fetch(
"https://parmana-sandbox.vercel.app/sandbox/approvals",
{
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PARMANA_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
capability: "sandbox:receipt",
resourceId: "demo-order-1",
}),
},
);
// Send it as signals.approvalArtifact within 5 minutes.
const approval: unknown = await response.json();
console.log(response.status, approval);# Sandbox only, and not in the SDK: a demo for trying Parmana, not part of
# the product API. Call the route directly.
import os
import requests
response = requests.post(
"https://parmana-sandbox.vercel.app/sandbox/approvals",
headers={"Authorization": f"Bearer {os.environ['PARMANA_API_KEY']}"},
json={"capability": "sandbox:receipt", "resourceId": "demo-order-1"},
timeout=30,
)
# Send it as signals.approvalArtifact within 5 minutes.
approval = response.json()
print(response.status_code, approval)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({capability: 'sandbox:receipt', resourceId: '<string>'})
};
fetch('https://parmana-api-real.vercel.app/sandbox/approvals', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://parmana-api-real.vercel.app/sandbox/approvals",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'capability' => 'sandbox:receipt',
'resourceId' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://parmana-api-real.vercel.app/sandbox/approvals"
payload := strings.NewReader("{\n \"capability\": \"sandbox:receipt\",\n \"resourceId\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://parmana-api-real.vercel.app/sandbox/approvals")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"capability\": \"sandbox:receipt\",\n \"resourceId\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://parmana-api-real.vercel.app/sandbox/approvals")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"capability\": \"sandbox:receipt\",\n \"resourceId\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"payload": {
"version": 1,
"approvalId": "f328a67e-a527-4119-8617-1eadead9367d",
"issuer": {
"approverId": "sandbox-demo-approver",
"keyId": "sandbox-demo-approver-key-1"
},
"issuedAt": "2026-10-01T11:10:57.825Z",
"expiresAt": "2026-10-01T11:15:57.825Z",
"capability": "sandbox:receipt",
"resourceId": "demo-order-1",
"scope": {
"field": "resourceId",
"comparator": "eq",
"value": "demo-order-1"
},
"nonce": "9c199e50-746d-409f-98f4-26c319af22ae"
},
"signature": {
"algorithm": "ed25519",
"keyId": "sandbox-demo-approver-key-1",
"value": "H5Anvojj4J3325IkJnL/SD50WEDJxhv7AafGgkSauSyQKQ6y3Fw5d+ZoC0k2BUfDDJvR0jn1IDgZ/1I+nx6ZAQ==",
"signedAt": "2026-10-01T11:10:57.825Z"
}
}Authorizations
Caller API key issued by scripts/generate-api-key.ts. Sent as Authorization: Bearer . Verified against a stored SHA-256 hash in constant time by packages/api/src/auth/StaticKeyAuthenticator.ts. Required on every route not listed as exempt in this document's top-level description. See /api-reference/authentication.
Body
Response
The signed approval. Send it as signals.approvalArtifact within 5 minutes; it is accepted once.
A person's approval of one action, signed with their approver key. A request carries it in signals.approvalArtifact when its policy declares approvalSignals. The server checks the issuer is a trusted approver key, the signature, the capability, the resource, the scope and the expiry, and consumes the nonce, so an approval is used once.
curl -X POST https://parmana-sandbox.vercel.app/sandbox/approvals -H "Authorization: Bearer $PARMANA_API_KEY" -H "Content-Type: application/json" -d '{
"capability": "sandbox:receipt",
"resourceId": "demo-order-1"
}'// Sandbox only, and not in the SDK: a demo for trying Parmana, not part of
// the product API. Call the route directly.
const response = await fetch(
"https://parmana-sandbox.vercel.app/sandbox/approvals",
{
method: "POST",
headers: {
Authorization: `Bearer ${process.env.PARMANA_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({
capability: "sandbox:receipt",
resourceId: "demo-order-1",
}),
},
);
// Send it as signals.approvalArtifact within 5 minutes.
const approval: unknown = await response.json();
console.log(response.status, approval);# Sandbox only, and not in the SDK: a demo for trying Parmana, not part of
# the product API. Call the route directly.
import os
import requests
response = requests.post(
"https://parmana-sandbox.vercel.app/sandbox/approvals",
headers={"Authorization": f"Bearer {os.environ['PARMANA_API_KEY']}"},
json={"capability": "sandbox:receipt", "resourceId": "demo-order-1"},
timeout=30,
)
# Send it as signals.approvalArtifact within 5 minutes.
approval = response.json()
print(response.status_code, approval)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({capability: 'sandbox:receipt', resourceId: '<string>'})
};
fetch('https://parmana-api-real.vercel.app/sandbox/approvals', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://parmana-api-real.vercel.app/sandbox/approvals",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'capability' => 'sandbox:receipt',
'resourceId' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://parmana-api-real.vercel.app/sandbox/approvals"
payload := strings.NewReader("{\n \"capability\": \"sandbox:receipt\",\n \"resourceId\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://parmana-api-real.vercel.app/sandbox/approvals")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"capability\": \"sandbox:receipt\",\n \"resourceId\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://parmana-api-real.vercel.app/sandbox/approvals")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"capability\": \"sandbox:receipt\",\n \"resourceId\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"payload": {
"version": 1,
"approvalId": "f328a67e-a527-4119-8617-1eadead9367d",
"issuer": {
"approverId": "sandbox-demo-approver",
"keyId": "sandbox-demo-approver-key-1"
},
"issuedAt": "2026-10-01T11:10:57.825Z",
"expiresAt": "2026-10-01T11:15:57.825Z",
"capability": "sandbox:receipt",
"resourceId": "demo-order-1",
"scope": {
"field": "resourceId",
"comparator": "eq",
"value": "demo-order-1"
},
"nonce": "9c199e50-746d-409f-98f4-26c319af22ae"
},
"signature": {
"algorithm": "ed25519",
"keyId": "sandbox-demo-approver-key-1",
"value": "H5Anvojj4J3325IkJnL/SD50WEDJxhv7AafGgkSauSyQKQ6y3Fw5d+ZoC0k2BUfDDJvR0jn1IDgZ/1I+nx6ZAQ==",
"signedAt": "2026-10-01T11:10:57.825Z"
}
}