Propose granting or revoking an agent's authority
Proposes per-agent authority (RFC-0023 phase 3): grant says the API key with callerId may have requests for capability decided, within limits on the request, until validUntil (at most 366 days); revoke ends the active grant.
Authorizations
Caller API key issued by scripts/generate-api-key.ts. Sent as Authorization: Bearer . Verified against a stored SHA-256 hash in constant time by packages/api/src/auth/StaticKeyAuthenticator.ts. Required on every route not listed as exempt in this document's top-level description. See /api-reference/authentication.
Body
Request body for POST /authority-grants/changes. A grant carries validUntil and optionally limits and validFrom; a revoke carries none of them.
grant, revoke The callerId of the API key the grant is for. Not your own.
^\S{1,256}$128^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*:[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$1 - 2000Optional, grant only. Limits on the request, by Intent path: target or parameters.. min and max (inclusive) apply to a number there; oneOf lists the only values allowed there. A request whose value is missing, of another type, or outside a limit is NOT_AUTHORIZED.
Optional, grant only.
Required for grant. In the future, after validFrom, and at most 366 days after it.
Response
Proposed and waiting for a checker. Keep the changeId.
Response of POST /authority-grants/changes (201) and of approve and reject (200). A bare Authority Grant Change, no wrapper.
Unique id of the change, a UUID. The step up authorization for approve or reject names it in payload.pendingPolicyChangeId. An approved grant change's id is also the grantId.
grant, revoke ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*:[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$2000The proposer's caller id. Always a human credential, never the grantee.
PENDING_APPROVAL, APPROVED, REJECTED grant only, optional. Limits on the request, by Intent path: target or parameters.. min and max (inclusive) apply to a number there; oneOf lists the only values allowed there. A request whose value is missing, of another type, or outside a limit is NOT_AUTHORIZED.
grant only, optional. Without it the grant starts when it is approved.
grant only, required. At most 366 days after validFrom (or the proposal).
Who approved or rejected it. Never the proposer or the grantee.
Present when REJECTED.