Skip to main content
POST
cURL

Authorizations

Authorization
string
header
default:2VfYWCzt_cBAPK-8uufX6ordfY2JuQhFPsohuEumKME
required

Caller API key issued by scripts/generate-api-key.ts. Sent as Authorization: Bearer . Verified against a stored SHA-256 hash in constant time by packages/api/src/auth/StaticKeyAuthenticator.ts. Required on every route not listed as exempt in this document's top-level description. See /api-reference/authentication.

Path Parameters

id
string
required

The changeId from the proposal.

Body

application/json

Request body for POST /policies/pending-changes/{id}/reject.

rejectionReason
string
required

Free-text reason. Required, non-empty.

stepUpAuthorization
Policy Change Step-Up Authorization · object
required

Signed envelope proving a checker's explicit, fresh intent to approve or reject one specific Pending Policy Change (Policy Governance, Layer 4). Produced by PolicyChangeStepUpAuthorizationSigner (@parmana/crypto) using the checker's own step-up private key, never the bearer API key. Verified server-side against: the checker's registered stepUpPublicKey, payload.pendingPolicyChangeId matching the URL's {id}, payload.action matching the endpoint (approve vs reject), payload.expiresAt not yet passed, and payload.nonce not previously seen (single-use, replay-rejected on a second attempt with the same envelope).

Example:

Response

Rejected. No grant changed.

Response of POST /authority-grants/changes (201) and of approve and reject (200). A bare Authority Grant Change, no wrapper.

changeId
string
required

Unique id of the change, a UUID. The step up authorization for approve or reject names it in payload.pendingPolicyChangeId. An approved grant change's id is also the grantId.

action
enum<string>
required
Available options:
grant,
revoke
callerId
string
required
capability
string
required
Pattern: ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*:[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$
reason
string
required
Maximum string length: 2000
proposedBy
string
required

The proposer's caller id. Always a human credential, never the grantee.

proposedAt
string<date-time>
required
status
enum<string>
required
Available options:
PENDING_APPROVAL,
APPROVED,
REJECTED
limits
object

grant only, optional. Limits on the request, by Intent path: target or parameters.. min and max (inclusive) apply to a number there; oneOf lists the only values allowed there. A request whose value is missing, of another type, or outside a limit is NOT_AUTHORIZED.

validFrom
string<date-time>

grant only, optional. Without it the grant starts when it is approved.

validUntil
string<date-time>

grant only, required. At most 366 days after validFrom (or the proposal).

resolvedBy
string

Who approved or rejected it. Never the proposer or the grantee.

resolvedAt
string<date-time>
rejectionReason
string

Present when REJECTED.