Skip to main content
Parmana authority grants (RFC-0023 phase 3): which API key may have which capability decided, within which limits, until when, made through maker checker. They matter for a policy with requireAuthorityGrant; GET /policies/in-effect says so with authority_grant_required. Hand-maintained: the response bodies of the /authority-grants routes (packages/api/src/routes/authority-grants.ts).

AuthorityGrant Objects

A grant, active or revoked.

grant_id

The change_id of the approved grant change that created it.

caller_id

The callerId of the API key the grant is for.

valid_until

After this, requests are refused as AUTHORITY_EXPIRED.

status

“active” or “revoked”. At most one active grant per caller and capability.

limits

By Intent path (“target”, “parameters.<name>”): “min”, “max” and “oneOf”, as sent.

AuthorityGrantChange Objects

A proposal to grant or revoke authority, and its resolution. Sign the step up authorization for approve or reject with change_id as pending_policy_change_id.

action

“grant” or “revoke”.