Reject an external connector change
Rejects an external connector change.
Authorizations
Caller API key issued by scripts/generate-api-key.ts. Sent as Authorization: Bearer . Verified against a stored SHA-256 hash in constant time by packages/api/src/auth/StaticKeyAuthenticator.ts. Required on every route not listed as exempt in this document's top-level description. See /api-reference/authentication.
Path Parameters
The changeId.
Body
Request body for POST /policies/pending-changes/{id}/reject.
Free-text reason. Required, non-empty.
Signed envelope proving a checker's explicit, fresh intent to approve or reject one specific Pending Policy Change (Policy Governance, Layer 4). Produced by PolicyChangeStepUpAuthorizationSigner (@parmana/crypto) using the checker's own step-up private key, never the bearer API key. Verified server-side against: the checker's registered stepUpPublicKey, payload.pendingPolicyChangeId matching the URL's {id}, payload.action matching the endpoint (approve vs reject), payload.expiresAt not yet passed, and payload.nonce not previously seen (single-use, replay-rejected on a second attempt with the same envelope).
Response
Rejected.
A proposal to register an external connector, or to revoke the active one for a capability, and its resolution (ADR-0013). One person proposes it; a different person approves or rejects it with a step up authorization. Only an approved change affects which external connectors are registered.
Unique id of the change, a UUID. The step up authorization for approve or reject names it in payload.pendingPolicyChangeId. An approved register change's id is also the registrationId.
register binds the capability to the endpoint; revoke ends the active registration for the capability.
register, revoke namespace:verb. Never in a built in connector's namespace (paytm, hubspot, github, slack, test).
128^[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*:[a-z][a-z0-9]*(?:[-_][a-z0-9]+)*$Why, from the proposer.
2000The proposer's caller id. Always a human credential.
PENDING_APPROVAL until a second person approves or rejects it; then APPROVED or REJECTED, once.
PENDING_APPROVAL, APPROVED, REJECTED register only. The endpoint as the server stored it, normalized by URL parsing: https, a host name with a domain, no IP literal, no localhost, no user name, password or fragment, resolving only to public addresses. It is the audience of every release to this endpoint.
register only. The name of the policy that governs the capability. The version in effect is decided by policy governance.
^[a-z0-9][a-z0-9-]{0,127}$register only. The only parameter names Parmana will forward to the endpoint.
64^[A-Za-z_][A-Za-z0-9_]{0,63}$register only. How long Parmana waits for the endpoint's answer. Defaults to 10000.
1000 <= x <= 30000Who approved or rejected it. Never the proposer.
Present when REJECTED.