Skip to main content
Parmana Approver API. Approvers managed without a deploy: list the keys trusted to sign approvals, propose adding or revoking one, and approve or reject a proposal with a signed step up authorization. Every call needs an API key that belongs to a verified human.

ApproverApi Objects

Approver API.

list

Every approver key the server trusts or trusted, revoked ones marked. Maps to GET /approval-issuers.

propose_add

Propose trusting a new approver key. Maps to POST /approval-issuers/changes with action “add”. public_key_pem is the .public.pem file scripts/generate-approver-key.ts writes. Nothing changes until a different person approves it.

propose_revoke

Propose revoking an approver key added through approver changes. Maps to POST /approval-issuers/changes with action “revoke”. Once approved, every approval the key ever signed is refused.

list_changes

List approver changes, newest first. Maps to GET /approval-issuers/changes.

Parameters

status: “PENDING_APPROVAL”, “APPROVED” or “REJECTED”. Omit for all.

approve_change

Approve and apply an approver change. Maps to POST /approval-issuers/changes/{id}/approve. The caller must not be the proposer and must have a registered step up key. Make step_up_authorization with parmana.crypto.sign_policy_change_step_up(), change_id as pending_policy_change_id, and action “approve”.

reject_change

Reject an approver change. Maps to POST /approval-issuers/changes/{id}/reject. Same caller rules as approve_change(); sign with action “reject”.