Reject an authority grant change
Rejects an authority grant change.
Authorizations
Caller API key issued by scripts/generate-api-key.ts. Sent as Authorization: Bearer . Verified against a stored SHA-256 hash in constant time by packages/api/src/auth/StaticKeyAuthenticator.ts. Required on every route not listed as exempt in this document's top-level description. See /api-reference/authentication.
Path Parameters
The changeId from the proposal.
Body
Request body for POST /policies/pending-changes/{id}/reject.
Free-text reason. Required, non-empty.
Signed envelope proving a checker's explicit, fresh intent to approve or reject one specific Pending Policy Change (Policy Governance, Layer 4). Produced by PolicyChangeStepUpAuthorizationSigner (@parmana/crypto) using the checker's own step-up private key, never the bearer API key. Verified server-side against: the checker's registered stepUpPublicKey, payload.pendingPolicyChangeId matching the URL's {id}, payload.action matching the endpoint (approve vs reject), payload.expiresAt not yet passed, and payload.nonce not previously seen (single-use, replay-rejected on a second attempt with the same envelope).
Response
Rejected. No grant changed.
Response of POST /authority-grants/changes (201) and of approve and reject (200). A bare Authority Grant Change, no wrapper.
Unique id of the change, a UUID. The step up authorization for approve or reject names it in payload.pendingPolicyChangeId. An approved grant change's id is also the grantId.
grant, revoke ^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*:[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$2000The proposer's caller id. Always a human credential, never the grantee.
PENDING_APPROVAL, APPROVED, REJECTED grant only, optional. Limits on the request, by Intent path: target or parameters.. min and max (inclusive) apply to a number there; oneOf lists the only values allowed there. A request whose value is missing, of another type, or outside a limit is NOT_AUTHORIZED.
grant only, optional. Without it the grant starts when it is approved.
grant only, required. At most 366 days after validFrom (or the proposal).
Who approved or rejected it. Never the proposer or the grantee.
Present when REJECTED.