Создать композитную заявку (цепочка шагов)
Цепочка counterparty-действий как ЕДИНАЯ сущность с одним флоу одобрения. Каждый шаг гейтится СВОЕЙ политикой; голос approve засчитывается шагам, где голосующий уполномочен; заявка APPROVED, когда каждый шаг набрал свой порог. Reject = вето всей цепочки.
Payload шага может ссылаться на результат предыдущего: "$step:N" (например, membership на созданных в цепочке контрагента и группу).
Все шаги allow/bypass → цепочка применяется сразу (200); любой шаг block/deny → 403 вся цепочка; иначе → заявка (202). При сбое шага в apply — best-effort откат созданного.
curl -X POST "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/approval-requests/composite" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN" \
-d '{
"steps": [
{
"action": "counterparty_create",
"payload": {},
"targetId": "example_string"
}
]
}'
import requests
import json
url = "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/approval-requests/composite"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
data = {
"steps": [
{
"action": "counterparty_create",
"payload": {},
"targetId": "example_string"
}
]
}
response = requests.post(url, headers=headers, json=data)
print(response.json())
const response = await fetch("https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/approval-requests/composite", {
method: "POST",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
},
body: JSON.stringify({
"steps": [
{
"action": "counterparty_create",
"payload": {},
"targetId": "example_string"
}
]
})
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
"bytes"
"encoding/json"
)
func main() {
data := []byte(`{
"steps": [
{
"action": "counterparty_create",
"payload": {},
"targetId": "example_string"
}
]
}`)
req, err := http.NewRequest("POST", "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/approval-requests/composite", bytes.NewBuffer(data))
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/approval-requests/composite')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Post.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
request.body = '{
"steps": [
{
"action": "counterparty_create",
"payload": {},
"targetId": "example_string"
}
]
}'
response = http.request(request)
puts response.body
{
"applied": true,
"results": [
{
"stepIndex": 42,
"action": "example_string",
"resultId": "example_string"
}
]
}
{
"request": {
"id": "cmr3f41z20001psp7phmyapw3",
"vaultId": "example_string",
"action": "example_string",
"status": "example_string",
"initiatorId": "example_string",
"targetType": "example_string",
"targetId": "example_string",
"baseVersion": "example_string",
"payload": "null",
"decisionPolicyId": "example_string",
"decisionPolicyCode": "example_string",
"approvalThreshold": 42,
"resolvedResultId": "example_string",
"resolvedAt": "2026-07-02T11:25:15.134Z",
"createdAt": "2026-07-02T11:25:15.134Z",
"updatedAt": "2026-07-02T11:25:15.134Z",
"approvers": [
{
"id": "example_string",
"userId": "example_string",
"decision": "approve",
"comment": "example_string",
"votedAt": "2026-07-02T11:25:15.134Z",
"stepIndexesJson": [
42
],
"createdAt": "2026-07-02T11:25:15.134Z",
"user": {
"id": "example_string",
"name": "John Doe",
"email": "user@example.com",
"username": "John Doe",
"image": "example_string",
"color": "#000",
"emoji": "🦊"
}
}
]
}
}
{
"error": "Bad Request",
"message": "The request contains invalid parameters or malformed data",
"code": 400,
"details": [
{
"field": "email",
"message": "Invalid email format"
}
]
}
{
"error": "Unauthorized",
"message": "Authentication required. Please provide a valid API token",
"code": 401
}
{
"error": "Forbidden",
"message": "You don't have permission to access this resource",
"code": 403
}
{
"error": "Not Found",
"message": "The requested resource was not found",
"code": 404
}
{
"error": "Conflict",
"message": "The request conflicts with the current state of the resource",
"code": 409,
"details": "Resource already exists"
}
{
"error": "Internal Server Error",
"message": "An unexpected error occurred on the server",
"code": 500,
"requestId": "req_1234567890"
}
/api/v1/vaults/{code}/approval-requests/compositeTarget server for requests. Edit to use your own host.
better-auth session token. Мобилка/сервисы. Веб использует cookie.
API key (sent in cookie)
Уникальный код Vault'а (slug)
The media type of the request body
Цепочка шагов, применяется по порядку как единое целое. Пример: [counterparty_create, counterparty_group_create, counterparty_group_add]
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token. better-auth session token. Мобилка/сервисы. Веб использует cookie.
API Key for authentication. Provide your API key in the cookie.
Path Parameters
Body
Цепочка шагов, применяется по порядку как единое целое. Пример: [counterparty_create, counterparty_group_create, counterparty_group_add]
Responses
Все шаги allow/bypass — цепочка применена сразу, без заявки