Skip to main content
POST
cURL

Authorizations

Authorization
string
header
default:2VfYWCzt_cBAPK-8uufX6ordfY2JuQhFPsohuEumKME
required

Caller API key issued by scripts/generate-api-key.ts. Sent as Authorization: Bearer . Verified against a stored SHA-256 hash in constant time by packages/api/src/auth/StaticKeyAuthenticator.ts. Required on every route not listed as exempt in this document's top-level description. See /api-reference/authentication.

Body

application/json

Request body for POST /authority-grants/changes. A grant carries validUntil and optionally limits and validFrom; a revoke carries none of them.

action
enum<string>
required
Available options:
grant,
revoke
callerId
string
required

The callerId of the API key the grant is for. Not your own.

Pattern: ^\S{1,256}$
capability
string
required
Maximum string length: 128
Pattern: ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*:[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$
reason
string
required
Required string length: 1 - 2000
limits
object

Optional, grant only. Limits on the request, by Intent path: target or parameters.. min and max (inclusive) apply to a number there; oneOf lists the only values allowed there. A request whose value is missing, of another type, or outside a limit is NOT_AUTHORIZED.

validFrom
string<date-time>

Optional, grant only.

validUntil
string<date-time>

Required for grant. In the future, after validFrom, and at most 366 days after it.

Response

Proposed and waiting for a checker. Keep the changeId.

Response of POST /authority-grants/changes (201) and of approve and reject (200). A bare Authority Grant Change, no wrapper.

changeId
string
required

Unique id of the change, a UUID. The step up authorization for approve or reject names it in payload.pendingPolicyChangeId. An approved grant change's id is also the grantId.

action
enum<string>
required
Available options:
grant,
revoke
callerId
string
required
capability
string
required
Pattern: ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*:[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$
reason
string
required
Maximum string length: 2000
proposedBy
string
required

The proposer's caller id. Always a human credential, never the grantee.

proposedAt
string<date-time>
required
status
enum<string>
required
Available options:
PENDING_APPROVAL,
APPROVED,
REJECTED
limits
object

grant only, optional. Limits on the request, by Intent path: target or parameters.. min and max (inclusive) apply to a number there; oneOf lists the only values allowed there. A request whose value is missing, of another type, or outside a limit is NOT_AUTHORIZED.

validFrom
string<date-time>

grant only, optional. Without it the grant starts when it is approved.

validUntil
string<date-time>

grant only, required. At most 366 days after validFrom (or the proposal).

resolvedBy
string

Who approved or rejected it. Never the proposer or the grantee.

resolvedAt
string<date-time>
rejectionReason
string

Present when REJECTED.