approval.needed event to a URL you choose, with exactly what the approver needs to sign.
When an event is sent
Parmana sends one event when all of these hold:- The request was refused by the policy’s own rules, or because an attached approval did not verify.
- The policy declares
approvalSignals. - Evaluating the same policy, with every declared approval signal set to
true, authorizes the request.
Set it up
1
Create an endpoint
Any HTTPS endpoint that accepts a JSON
POST and answers 2xx within 3 seconds: a small
function of your own, a Slack workflow webhook behind a relay, or an automation service.2
Generate a secret
3
Configure Parmana
Set both variables on the deployment, then redeploy:With
PARMANA_SECRETS_PROVIDER=aws-secrets-manager, APPROVAL_WEBHOOK_SECRET is the name or
ARN of the secret instead of its value. Setting only one of the two stops the server at
startup. The URL must be https outside NODE_ENV=test and development.4
Send a test request
Send a request the policy refuses only for want of an approval, for example a refund with
managerApproved: false and every other fact true. Your endpoint receives an event.The event
string
required
Always
approval.needed.string
required
When the request was refused, ISO 8601 UTC.
string
required
The refused request. Its Refusal Record has the full decision.
string
required
The refusal decision.
string
required
The action that needs approval, such as
paytm:refund. Sign with this as
capability.string
required
The request’s target.
string
required
The policy that refused it.
string
required
Its version.
string
The refusal reason from the policy.
string
The caller that sent the request, when known.
object[]
required
One entry per approval the policy declares.
businessTransactionId if you need them.
Verify the signature
Every event has two headers:
Verify against the raw request body, before parsing it, compare in constant time, and refuse a
timestamp more than 5 minutes old so a captured event cannot be replayed later.
From event to approval
The approver signs exactly what the event names:businessTransactionId, the approval signal set
to true, and the approval in signals.approvalArtifact. See
Human approval.
Delivery
Because delivery is best effort, the Refusal Records remain the complete list of waiting
requests. For a daily sweep, see Review refused requests.
Test locally
Point the webhook at a local listener and run Parmana in development:http is accepted only in development and test.
Reference
See also Environment variables.