POST
cURL
Roles: approver, compliance, operator, risk.

Authorizations

Authorization
string
header
required

A JWT from the deployment's identity provider, whose roles claim names the caller's roles and whose holder claim names an investor's holder.

Headers

X-Signature-Key
string

A signed request's key id, as venue.api.signing.clients configures it for the bearer's subject.

X-Signature-Timestamp
string

Seconds since the epoch, within venue.api.signing.window of the engine's clock, 5 minutes by default.

Pattern: ^[0-9]+$
X-Signature-Nonce
string

At least 16 random bytes in base64url, never reused within twice the window.

Required string length: 22 - 128
Pattern: ^[A-Za-z0-9_-]+={0,2}$
X-Signature
string

The base64 HMAC-SHA256, under the key's secret, of the method, the path and query, the timestamp, the nonce and the body's SHA-256.

X-Request-Id
string

Your id for this request, 1 to 128 printable characters, repeated in the answer; absent, the engine makes one.

Maximum string length: 128
Pattern: ^[\x21-\x7E]+$
traceparent
string

A W3C trace context, which the engine joins and passes on.

Pattern: ^[0-9a-f]{2}-[0-9a-f]{32}-[0-9a-f]{16}-[0-9a-f]{2}$

Path Parameters

actionKey
string
required

The four-eyes action's key, as its maker's call and GET /v1/approvals name it.

Body

application/json

The rejection's reason.

reason
string
required

Why, 1 to 512 characters.

Response

The action, rejected.

A four-eyes action, with the request it is and where it stands.

actionKey
string
required

The four-eyes action's key.

kind
enum<string>
required

The operation kind the action runs as.

Available options:
instrument.record,
policy.set,
admission-consent.propose,
instrument.pause,
holder.register,
holder.onboard,
holder.close,
holder.register-successor,
holder.set-attributes,
admission.offer,
admission.withdraw,
accepted-terms.accept,
subscription.claim,
subscription.withdraw,
subscription.deliver,
subscription.settle,
subscription.release,
primary-market.propose,
redemption.claim,
redemption.withdraw,
redemption.release,
redemption.settle,
dealing-cycle.open,
dealing-cycle.settle,
dealing-cycle.release,
standing-settlement.open,
standing-settlement.settle,
standing-settlement.pause,
standing-settlement.resume,
standing-settlement.close,
reserve.propose,
reserve.close,
lock-agreement.propose,
lock-agreement.release,
mint.start,
mint.cancel,
reserve-redemption.start,
reserve-redemption.cancel,
reserve-report.create,
amendment.propose,
amendment.withdraw,
provision-settlement.propose,
distribution.execute,
distribution.roll,
standing-approval.grant,
standing-approval.revoke,
holder.restrict,
holder.restrict-batch,
restriction.lift,
issuer-powers-agreement.propose,
issuer-powers-consent.offer,
holder.force-transfer,
holder.recover,
instrument.force-transfer,
instrument.recover,
hold.release,
external-account.map,
webhook.register,
webhook.remove,
webhook.test
resource
object
required

The record it acts on, and, once it succeeds, the record it created or changed.

maker
string
required

Who made the action, by sub.

makerName
string | null
required

The name claim of the maker's bearer; null where it carried none.

makerEmail
string | null
required

The email claim of the maker's bearer; null where it carried none.

makerRole
enum<string>
required

The role the maker acted in.

Available options:
operator,
approver,
risk,
compliance,
auditor,
investor,
app,
monitor,
feed,
registrar
madeAt
string
required

When the maker made the action.

state
enum<string>
required

Where the action stands.

Available options:
awaiting,
approved,
rejected
checker
string | null
required

Who decided it, the approver, or on a rejection the approver or the maker withdrawing it; null while it awaits.

checkerName
string | null
required

The name claim of the checker's bearer; null while it awaits, or where it carried none.

checkerEmail
string | null
required

The email claim of the checker's bearer; null while it awaits, or where it carried none.

checkedAt
string | null
required

When the action was decided; null while it awaits.

operationId
string | null
required

The operation the approved action ran as.

reason
string | null
required

Why it was rejected.

method
string
required

The request's method.

path
string
required

The concrete path the maker sent.

body
any
required

The request the action runs with, as its route opened it; an approval by key sends the maker's own body.

required
integer<int32>
required

How many distinct approvers the action needs.

signedBy
string[]
required

The approvers who have signed it so far; all of them once approved.

signers
object[]
required

Each sign-off so far, in order: who signed, with the name and email claims of their bearer, and when.