approvalSignals accepts an action only with a signed approval from a trusted
approver key, such as a manager approving a refund. This guide shows how to trust a new
approver key, rotate one, and revoke one, through the API. Each change is proposed by one
person and approved by a different person with a step up signature, and it takes effect on
the next request. Nothing is deployed.
Approvers added this way are stored in the
approval_issuers table. Approvers
listed in the server code (createApprovalIssuerRegistry.ts) still work, and
are shown by the same list call, but they change only with a pull request and
a deploy.How it works
Before you begin
You need three people, or at least three roles:- The new approver, who will sign approvals. They make their own key pair and never share the private key.
- A proposer with an API key added as a human.
- A checker, a different person, with an API key added as a human and a registered step up key. This is the same setup policy approvals use: see Policy lifecycle and approvals.
20260929120000_add_approval_issuers.sql. Self hosted
deployments apply it on start. Otherwise run npm run db:migrate -- apply before deploying
this version, as in Production deployment, step 2.
Step 1: The approver makes a key pair
On the approver’s own machine:manager-priya__manager-priya-key-1.private.pem, which stays on that machine, and
manager-priya__manager-priya-key-1.public.pem, which they send to the proposer. Any Ed25519
key works; openssl genpkey -algorithm ed25519 makes one too.
approverId and keyId are the names the approver will put in every approval they sign. Use
letters, digits, ., _ and -, at most 128 characters. Put a number in the key id, so a
later key can have the next one.
Step 2: Propose adding the key
201 Created
400.
Step 3: The checker reviews it
Step 4: The checker approves it
The checker signs a step up authorization on their own machine, naming this change and the action, and sends it with the approval. It is the same step up authorization policy changes use: the change id goes inpendingPolicyChangeId.
200 OK
manager-priya-key-1 verify.
Step 5: Confirm the key is trusted
200 OK
scripts/sign-approval.ts, signApproval() or
parmana.crypto.sign_approval(). See Human approval.
Rotate a key
Key ids are used once, so a rotation is two changes:- The approver makes a new key pair with the next key id, such as
manager-priya-key-2. - Propose and approve adding it (Steps 2 to 4).
- The approver signs new approvals with the new key.
- Propose and approve revoking the old key (below).
Revoke a key
Revoke when an approver leaves the role, or a private key may be exposed. Once the revocation is approved, every approval the key ever signed is refused, including ones not used yet.revoked: true there and
deploying.
Reject a change
rejectionReason.
Errors
Reference
- API: List approver keys, Propose, List changes, Approve, Reject.
- Tables:
approval_issuersandapproval_issuer_changes. - The server logs
approval_issuer_change_approvedfor every approved change, andapproval_issuer_lookup_failedwhen the table could not be read during a check.