POST
cURL
Roles: operator. Four eyes: it runs once an approver other than the maker approves it.

Authorizations

Authorization
string
header
required

A JWT from the deployment's identity provider, whose roles claim names the caller's roles and whose holder claim names an investor's holder.

Headers

Idempotency-Key
string

Names this write, so a retry answers the same operation; absent, the write is keyed on its body.

X-Signature-Key
string

A signed request's key id, as venue.api.signing.clients configures it for the bearer's subject.

X-Signature-Timestamp
string

Seconds since the epoch, within venue.api.signing.window of the engine's clock, 5 minutes by default.

Pattern: ^[0-9]+$
X-Signature-Nonce
string

At least 16 random bytes in base64url, never reused within twice the window.

Required string length: 22 - 128
Pattern: ^[A-Za-z0-9_-]+={0,2}$
X-Signature
string

The base64 HMAC-SHA256, under the key's secret, of the method, the path and query, the timestamp, the nonce and the body's SHA-256.

X-Request-Id
string

Your id for this request, 1 to 128 printable characters, repeated in the answer; absent, the engine makes one.

Maximum string length: 128
Pattern: ^[\x21-\x7E]+$
traceparent
string

A W3C trace context, which the engine joins and passes on.

Pattern: ^[0-9a-f]{2}-[0-9a-f]{32}-[0-9a-f]{16}-[0-9a-f]{2}$

Body

application/json

The webhook to create.

webhookId
string
required

The webhook's id, 1 to 64 of A-Z a-z 0-9 . _ -.

url
string
required

The https URL the engine posts to. It leads to a public address, or to one in a network the venue allows.

secretFile
string
required

The absolute path of a file in the engine's webhook secret directory holding the HMAC key, at least 32 bytes.

events
enum<string>[]

The control event types it receives; empty, every type.

What an event announces: the record and what happened to it, <record>.<event>.

Available options:
reconciliation.run,
reconciliation.finding,
reconciliation.hold,
hold.released,
statement.received,
statement.overdue,
distribution.payable,
distribution.held,
distribution.paid,
holder.restricted,
holder.unrestricted,
holder.forced-transfer,
holder.recovered,
instrument.paused,
distribution.rate-changed,
distribution.carried,
distribution.due,
standing-approval.granted,
standing-approval.revoked,
reserve.minted,
reserve.redeemed,
reserve.cover-low,
reserve.reported,
reserve.amended,
retention.pruned,
operation.succeeded,
operation.failed,
approval.requested,
approval.signed,
approval.approved,
approval.rejected,
subscription.priced,
subscription.delivered,
subscription.ended,
redemption.priced,
redemption.funded,
redemption.burned,
redemption.settled,
redemption.withdrawn,
dealing-cycle.settled,
dealing-cycle.released

Response

The same write again, with the same key and body; the operation it already is.

What every write answers: an operation, or an action awaiting approval, told apart by state.

state
required

Where the write stands: an operation's state, or awaiting for an action awaiting its approvers.

Available options:
queued,
running,
succeeded,
failed
operationId
string

The operation's id.

kind
enum<string>

What the operation does.

Available options:
instrument.record,
policy.set,
admission-consent.propose,
instrument.pause,
holder.register,
holder.onboard,
holder.close,
holder.register-successor,
holder.set-attributes,
admission.offer,
admission.withdraw,
accepted-terms.accept,
subscription.claim,
subscription.withdraw,
subscription.deliver,
subscription.settle,
subscription.release,
primary-market.propose,
redemption.claim,
redemption.withdraw,
redemption.release,
redemption.settle,
dealing-cycle.open,
dealing-cycle.settle,
dealing-cycle.release,
standing-settlement.open,
standing-settlement.settle,
standing-settlement.pause,
standing-settlement.resume,
standing-settlement.close,
reserve.propose,
reserve.close,
lock-agreement.propose,
lock-agreement.release,
mint.start,
mint.cancel,
reserve-redemption.start,
reserve-redemption.cancel,
reserve-report.create,
amendment.propose,
amendment.withdraw,
provision-settlement.propose,
distribution.execute,
distribution.roll,
standing-approval.grant,
standing-approval.revoke,
holder.restrict,
holder.restrict-batch,
restriction.lift,
issuer-powers-agreement.propose,
issuer-powers-consent.offer,
holder.force-transfer,
holder.recover,
instrument.force-transfer,
instrument.recover,
hold.release,
external-account.map,
webhook.register,
webhook.remove,
webhook.test
resource
object

The record it acts on, and, once it succeeds, the record it created or changed.

request
any | null

The body the operation was opened with, beside the ids its path named.

result
any | null

What the operation came to, once succeeded; null otherwise.

problem
any | null

The problem the operation failed with; null otherwise.

actor
string

Who asked, by sub.

actorName
string | null

The name claim of the bearer that asked; null where it carried none, and for an operation the engine opened itself.

actorEmail
string | null

The email claim of the bearer that asked; null where it carried none, and for an operation the engine opened itself.

role
enum<string> | null

The role the operation ran under; null for an operation the engine opened itself, whose actor names it.

Available options:
operator,
approver,
risk,
compliance,
auditor,
investor,
app,
monitor,
feed,
registrar
createdAt
string

When the operation was opened.

startedAt
string | null

When the operation started running; null while queued.

finishedAt
string | null

When the operation finished; null until it does.

updateId
string | null

The ledger update the operation committed; null until it commits.

offset
integer<int64> | null

The offset the operation's transaction committed at; null until it commits.

actionKey
string

The four-eyes action's key.

maker
string

Who made the action, by sub.

makerRole
enum<string>

The role the maker acted in.

Available options:
operator,
approver,
risk,
compliance,
auditor,
investor,
app,
monitor,
feed,
registrar
madeAt
string

When the maker made the action.

required
integer<int32>

How many distinct approvers the action needs.

signedBy
string[]

The approvers who have signed it so far.

recovery
string

What completes the action awaiting approval.