typescript/src/client/ParmanaClient.ts and python/parmana/client.py. A method added to either client appears here the next time the reference is generated, and a test fails until it is. Configuration, retries and errors: TypeScript and Python.
TypeScript: ParmanaClient (@parmana/sdk)
| Signature | What it does |
|---|---|
endpoint(): string | Returns the configured Runtime endpoint. |
health(): Promise<HealthStatus> | Performs a Runtime health check. |
version(): Promise<unknown> | Returns the Runtime name, version, and API version. |
execute(transaction: BusinessTransaction): Promise<ExecutionTrustRecord> | Executes a Business Transaction. |
verify(businessTransactionId: string): Promise<Verification> | Runs a fresh verification of an Execution Trust Record, appending a new Verification to its history. Distinct from getLatestVerification(), which reads the most recent one without re-verifying. |
getLatestVerification(businessTransactionId: string): Promise<Verification> | Returns the latest Verification. |
replay(businessTransactionId: string): Promise<ReplayResult> | Performs deterministic replay. |
receipt(businessTransactionId: string): Promise<Receipt> | Generates an execution receipt. |
createTransaction(transaction: BusinessTransaction): Promise<ExecutionTrustRecord> | Creates (executes) a Business Transaction via POST /transactions, a second, independent entry point into the identical execution pipeline as execute() (POST /execute). See TransactionApi.create. |
transaction(businessTransactionId: string): Promise<BusinessTransaction> | Retrieves a Business Transaction. |
transactions(page = 1, pageSize = 25): Promise<BusinessTransaction[]> | Lists Business Transactions. |
latestReceipt(businessTransactionId: string): Promise<Receipt> | Retrieves the most recent receipt without generating a new one. |
trustRecord(businessTransactionId: string): Promise<ExecutionTrustRecord> | Retrieves an Execution Trust Record. |
trustRecords(page = 1, pageSize = 25, options: { readonly since?: string; readonly until?: string } = {}): Promise<ExecutionTrustRecord[]> | Lists Execution Trust Records of this caller’s transactions, newest first. See TrustRecordApi.list. |
caller(): Promise<CallerIdentity> | Who this API key belongs to and what it may do (GET /callers/me). |
publicKey(keyId = "default"): Promise<PublicKeyInfo> | A signing public key of the deployment (GET /keys/), for the offline verifiers. Records are signed with default. |
policyInEffect(capability: string): Promise<PolicyInEffect> | The policy a request for capability must declare right now, and what the request must carry (GET /policies/in-effect). Call it before every request and declare policy exactly as returned. |
validatePolicy(policyId: string, policyVersion: string): Promise<PolicyValidationResult> | Confirms that a policy (name + version) is loadable by the Runtime. |
refusalRecord(businessTransactionId: string): Promise<RefusalRecord> | Retrieves a Refusal Record by Business Transaction ID. |
verifyRefusalRecord(record: RefusalRecord): Promise<boolean> | Verifies a Refusal Record’s signature. |
executionIntent(businessTransactionId: string): Promise<ExecutionIntentView> | Retrieves an Execution Intent and its status by Business Transaction ID (ADR-0012). The intent is the signed statement, stored before an action is released, of what was about to be released. |
verifyExecutionIntent(intent: ExecutionIntent): Promise<boolean> | Verifies an Execution Intent’s hash and signature. Needs no credential. true proves the intent is genuine and unaltered. It does not prove the action was released, or what its result was. |
unfinalizedExecutionIntents(limit?: number): Promise<UnfinalizedExecutionIntents> | Lists Execution Intents that never reached a signed Trust Record and were not closed by hand, oldest first. Needs a credential provisioned as a verified human. |
finalizeExecutionIntent(businessTransactionId: string): Promise<FinalizeExecutionIntentResult> | Rebuilds the signed Trust Record for a released action whose record was never produced. Never calls a connector. Safe to run twice. Needs a credential provisioned as a verified human. |
resolveExecutionIntent(businessTransactionId: string, input: ResolveExecutionIntentInput): Promise<ResolveExecutionIntentResult> | Closes a PREPARED or ERRORED intent that a verified human reconciled at the connector. The note is required. The resolution is an attributed operator statement in unsigned status, not a Trust Record. |
verifyAuditEvent(event: AuditEvent, signature: Signature): Promise<boolean> | Verifies a signed caller-authentication audit event’s signature. |
proposePolicyChange(name: string, version: string, input: ProposePolicyChangeInput): Promise<ProposedPolicyChange> | Proposes a policy change. See PolicyApi.proposeChange. |
policyChanges(status?: PendingPolicyChangeStatus): Promise<PolicyChangeForReview[]> | Lists policy changes for review. See PolicyApi.listChanges. |
approvePolicyChange(pendingPolicyChangeId: string, stepUpAuthorization: PolicyChangeStepUpAuthorization): Promise<PendingPolicyChange> | Approves a policy change with a signed step up authorization. See PolicyApi.approveChange and signPolicyChangeStepUp(). |
rejectPolicyChange(pendingPolicyChangeId: string, rejectionReason: string, stepUpAuthorization: PolicyChangeStepUpAuthorization): Promise<PendingPolicyChange> | Rejects a policy change with a reason and a signed step up authorization. See PolicyApi.rejectChange. |
approvers(): Promise<ApprovalIssuer[]> | Every approver key the server trusts or trusted. See ApproverApi.list. |
proposeApproverChange(input: ProposeApproverChangeInput): Promise<ApprovalIssuerChange> | Proposes adding or revoking an approver key. See ApproverApi.proposeChange. |
approverChanges(status?: PendingPolicyChangeStatus): Promise<ApprovalIssuerChange[]> | Lists approver changes. See ApproverApi.listChanges. |
approveApproverChange(changeId: string, stepUpAuthorization: PolicyChangeStepUpAuthorization): Promise<ApprovalIssuerChange> | Approves and applies an approver change. See ApproverApi.approveChange. |
rejectApproverChange(changeId: string, rejectionReason: string, stepUpAuthorization: PolicyChangeStepUpAuthorization): Promise<ApprovalIssuerChange> | Rejects an approver change. See ApproverApi.rejectChange. |
TypeScript: functions exported next to the client
They make no request.| Signature | What it does |
|---|---|
verifyExecutionTrustRecordOffline(trustRecord: unknown, publicKeys: PublicKeys): OfflineVerificationResult | Verifies an Execution Trust Record with only public keys. |
verifyExecutionIntentOffline(intent: unknown, publicKeys: PublicKeys): OfflineVerificationResult | Verifies an Execution Intent with only public keys. |
signPolicyChangeStepUp(input: SignPolicyChangeStepUpInput): PolicyChangeStepUpAuthorization | Signs a step up authorization for one decision (approve or reject) on one change: a policy, an approver or an external connector. Valid for ttlSeconds (default 120) and usable once. Run by the checker, with their own step up private key. |
signApproval(input: SignApprovalInput): SignedApproval | Signs an approval for one action on one resource, optionally up to an amount, valid for ttlSeconds (default 900, at most 86400) and usable once. Run by the approver, with their own private key. |
verifyParmanaRelease(body: unknown, options: VerifyParmanaReleaseOptions): Promise<ParmanaReleaseVerification> | Checks, in order: the body’s shape, the signature over the canonical JSON of release with the key named in signature.keyId, that release.audience equals audience, and that release.expiresAt has not passed (with the clock skew allowance). Only then does it ask isAlreadyExecuted. Never throws for a bad body; returns { valid: false, errors }. |
Python: ParmanaClient (parmana)
| Signature | What it does |
|---|---|
endpoint() -> str | Parmana Runtime endpoint. |
version() -> str | Parmana SDK version. |
health() -> dict[str, Any] | Returns the Runtime health status. |
execute(transaction: BusinessTransaction) -> ExecutionTrustRecord | Execute a Business Transaction. |
verify(business_transaction_id: str) -> Verification | Run a fresh verification of an Execution Trust Record, appending a new Verification to its history. Distinct from get_latest_verification(), which reads the most recent one without re-verifying. |
get_latest_verification(business_transaction_id: str) -> Verification | Returns the latest Verification, without performing a fresh one. |
create_transaction(transaction: BusinessTransaction) -> ExecutionTrustRecord | Creates (executes) a Business Transaction via POST /transactions, a second, independent entry point into the identical execution pipeline as execute() (POST /execute). |
transaction(business_transaction_id: str) -> BusinessTransaction | Retrieves a Business Transaction. |
trust_record(business_transaction_id: str) -> ExecutionTrustRecord | Retrieves an Execution Trust Record. |
policy_in_effect(capability: str) -> PolicyInEffect | The policy a request for capability must declare right now, and what the request must carry (GET /policies/in-effect). Call it before every request and declare policy exactly as returned. |
validate_policy(policy_id: str, policy_version: str) -> dict[str, Any] | Validates that a policy (name + version) is loadable. |
refusal_record(business_transaction_id: str) -> RefusalRecord | Retrieves a Refusal Record by Business Transaction ID. |
verify_refusal_record(record: RefusalRecord) -> bool | Verifies a Refusal Record’s signature. |
execution_intent(business_transaction_id: str) -> ExecutionIntentView | Retrieves an Execution Intent and its status (ADR-0012). The intent is the signed statement, stored before an action is released, of what was about to be released. |
verify_execution_intent(intent: ExecutionIntent) -> bool | Verifies an Execution Intent’s hash and signature. Needs no credential. True proves the intent is genuine and unaltered. It does not prove the action was released, or what its result was. |
unfinalized_execution_intents(limit: int | None = None) -> UnfinalizedExecutionIntents | Lists Execution Intents that never reached a signed Trust Record and were not closed by hand, oldest first. Needs a credential provisioned as a verified human. |
finalize_execution_intent(business_transaction_id: str) -> FinalizeExecutionIntentResult | Rebuilds the signed Trust Record for a released action whose record was never produced. Never calls a connector. Safe to run twice. Needs a credential provisioned as a verified human. |
resolve_execution_intent(business_transaction_id: str, *, resolution: ExecutionIntentResolution | str, note: str) -> ResolveExecutionIntentResult | Closes a PREPARED or ERRORED intent that a verified human reconciled at the connector. The note is required. The resolution is an attributed operator statement in unsigned status, not a Trust Record. |
verify_audit_event(event: dict[str, Any], signature: Signature) -> bool | Verifies a signed caller-authentication or Razorpay-webhook audit event’s signature. |
latest_receipt(business_transaction_id: str) -> Receipt | Retrieve the most recent receipt without generating a new one. See ReceiptApi.get_latest. |
caller() -> CallerIdentity | Who this API key belongs to and what it may do (GET /callers/me). |
public_key(key_id: str = "default") -> PublicKeyInfo | A signing public key of the deployment (GET /keys/), for the offline verifiers. Records are signed with “default”. |
propose_policy_change(name: str, version: str, *, proposed_content: dict[str, Any], reason: str) -> ProposedPolicyChange | Propose a policy change. See PolicyApi.propose_change. |
policy_changes(status: str | None = None) -> list[PolicyChangeForReview] | List policy changes for review. See PolicyApi.list_changes. |
approve_policy_change(pending_policy_change_id: str, step_up_authorization: dict[str, Any]) -> PendingPolicyChange | Approve a policy change with a signed step up authorization. See PolicyApi.approve_change and parmana.crypto.sign_policy_change_step_up. |
reject_policy_change(pending_policy_change_id: str, rejection_reason: str, step_up_authorization: dict[str, Any]) -> PendingPolicyChange | Reject a policy change with a reason and a signed step up authorization. See PolicyApi.reject_change. |
list_approvers() -> list[ApprovalIssuer] | Every approver key the server trusts or trusted. See ApproverApi.list. |
approver_changes(status: str | None = None) -> list[ApprovalIssuerChange] | List approver changes. See ApproverApi.list_changes. |
approve_approver_change(change_id: str, step_up_authorization: dict[str, Any]) -> ApprovalIssuerChange | Approve and apply an approver change. See ApproverApi.approve_change. |
reject_approver_change(change_id: str, rejection_reason: str, step_up_authorization: dict[str, Any]) -> ApprovalIssuerChange | Reject an approver change. See ApproverApi.reject_change. |
Python: functions in parmana.crypto
They make no request. Install with pip install "parmana[verify]".
| Signature | What it does |
|---|---|
verify_execution_trust_record_offline(trust_record: Any, public_keys: dict[str, str]) -> OfflineVerificationResult | trust_record is a plain dict, exactly as json.load() would produce from a Trust Record JSON file or API response body, or the ExecutionTrustRecord that client.trust_record() returns. public_keys maps keyId -> PEM-encoded public key text. |
verify_execution_intent_offline(intent: Any, public_keys: dict[str, str]) -> OfflineVerificationResult | Python counterpart to verifyExecutionIntentOffline() in packages/crypto/src/OfflineVerifier.ts (ADR-0012). No network call, no database, no environment variable: only the intent and the public key(s). |
sign_policy_change_step_up(*, pending_policy_change_id: str, action: str, private_key_pem: str, key_id: str, ttl_seconds: float = DEFAULT_TTL_SECONDS) -> dict[str, Any] | Sign a step up authorization for one action on one policy change. |
sign_approval(*, private_key_pem: str, approver_id: str, key_id: str, capability: str, resource_id: str, max_amount: float | None = None, ttl_seconds: int = DEFAULT_APPROVAL_TTL_SECONDS) -> dict[str, Any] | Sign an approval of one action on one resource. |
verify_parmana_release(body: Any, *, public_keys: dict[str, str], audience: str, is_already_executed: Callable[[str], bool], now: datetime | None = None, clock_skew_seconds: float = DEFAULT_RELEASE_CLOCK_SKEW_SECONDS) -> ParmanaReleaseVerification | Checks, in order: the body’s shape, the signature over the canonical JSON of release with the key named in signature.keyId, that release.audience equals audience (this endpoint’s URL exactly as Parmana stored it at registration), and that release.expiresAt has not passed, allowing clock_skew_seconds. Only then does it call is_already_executed(businessTransactionId). |
canonical_serialize(value: Any) -> bytes | Serializes an already-JSON-decoded value into the same canonical UTF-8 bytes CanonicalSerializer.ts would produce for the equivalent JavaScript value. |