Skip to main content
Creating or changing certain resources through the API opens a change request. The change does not take effect until your API user approves it. Every change request uses the same two endpoints: Get Approval Message and Submit Approval Action.

What needs approval

For each change below, pass the id from the create or update response as entityId.

Transactions

A new transaction comes back with status: "PENDING". If your policy approves on creation, it comes back in a later status and needs no action.

Approval flow

1

Create or update the entity

Call the endpoint from What needs approval and keep the id from the response.
2

Get the approval message

Call Get Approval Message with entityId set to that id. Save the approvalId and message.
3

Sign the message

Sign the exact message with your API user’s private key, the same key that signs your requests (ECDSA with SHA-256), and hex-encode the signature.
4

Submit the action

Call Submit Approval Action with the approvalId, action: "approve" (or "reject"), and the signature.
5

Confirm the result

Fetch the entity. Track a transaction with Retrieve a Transaction or webhooks until it reaches COMPLETED, FAILED, or DECLINED. Check a vault with Retrieve a Vault. Check that a contact or bank account status moved from PENDING to APPROVED with Retrieve Contact or Retrieve Bank Account.

Approve with the SDK

approveChangeRequest() gets the approval message, signs it with the client’s configured key (a private key or AWS KMS), and submits the action. It works for any entityId in the table above. The ...WithApproval() helpers call it for you.

Get Approval Message

The message to sign for a pending change request.

Submit Approval Action

Approve or reject with the signed message.