Propose registering or revoking a business signal source
Proposes connecting a business system, any system that owns facts a policy needs (an ERP, an order system, a CRM, a ledger), so Parmana can ask it instead of trusting the agent’s claim.
Authorizations
Caller API key issued by scripts/generate-api-key.ts. Sent as Authorization: Bearer . Verified against a stored SHA-256 hash in constant time by packages/api/src/auth/StaticKeyAuthenticator.ts. Required on every route not listed as exempt in this document's top-level description. See /api-reference/authentication.
Body
Request body for POST /business-signal-sources/changes. A register carries endpointUrl and optionally timeoutMs, publicKeyPem and keyId; a revoke carries none of them.
register, revoke ^[a-z0-9][a-z0-9-]{0,62}$1 - 2000Required for register. https only, a public host name.
20481000 <= x <= 30000Optional, register only. An Ed25519 public key in PEM. Recommended: without it, Parmana trusts the answer on the strength of the pinned HTTPS connection alone.
1000Optional, register only, and only with publicKeyPem.
^[A-Za-z0-9._-]{1,128}$Response
Proposed and waiting for a checker. Keep the changeId.
Response of POST /business-signal-sources/changes (201) and of approve and reject (200). A bare Business Signal Source Change, no wrapper.
Unique id of the change, a UUID. The step up authorization for approve or reject names it in payload.pendingPolicyChangeId. An approved register change's id is also the registrationId.
register names a source and its endpoint; revoke ends the active registration for the name.
register, revoke The name a policy's signalSources uses in source.
^[a-z0-9][a-z0-9-]{0,62}$Why, from the proposer.
2000The proposer's caller id. Always a human credential.
PENDING_APPROVAL until a second person approves or rejects it; then APPROVED or REJECTED, once.
PENDING_APPROVAL, APPROVED, REJECTED register only. The endpoint as the server stored it, normalized by URL parsing: https, a host name with a domain, no IP literal, no localhost, no user name, password or fragment, resolving only to public addresses.
register only. How long Parmana waits for the source's answer. Defaults to 10000.
1000 <= x <= 30000register only, optional. The Ed25519 public key the source signs its answers with, as the server stored it (SPKI PEM).
register only, optional, and only with publicKeyPem.
^[A-Za-z0-9._-]{1,128}$Who approved or rejected it. Never the proposer.
Present when REJECTED.