ApprovalsCreate a composite request (chain of steps)

Create a composite request (chain of steps)

A chain of counterparty actions as a SINGLE entity with one approval flow. Each step is gated by ITS OWN policy; an approve vote counts toward the steps the voter is authorized for; the request is APPROVED once every step reaches its own threshold. Reject = veto of the entire chain.

A step's payload can reference the result of a previous step: "$step:N" (for example, membership for a counterparty and group created earlier in the chain).

All steps allow/bypass → the chain is applied immediately (200); any step block/deny → 403 for the whole chain; otherwise → approval request (202). If a step fails during apply, whatever was created is rolled back on a best-effort basis.

curl -X POST "https://policy-engine-rest.ezig.workers.dev/api/v1/vaults/demo_vault/approval-requests/composite" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN" \
  -d '{
  "steps": [
    {
      "action": "counterparty_create",
      "payload": {},
      "targetId": "example_string"
    }
  ]
}'
{
  "applied": true,
  "results": [
    {
      "stepIndex": 42,
      "action": "example_string",
      "resultId": "example_string"
    }
  ]
}
POST
/api/v1/vaults/{code}/approval-requests/composite
POST
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token
Bearer Tokenstring
Required

Session token. Mobile/services. The web uses a cookie.

Session token. Mobile/services. The web uses a cookie.
API Key (cookie: session_token)
session_tokenstring
Required

API key (sent in cookie)

path
codestring
Required

Unique Vault code (slug)

Content-Typestring
Required

The media type of the request body

Options: application/json
stepsarray
Required

A chain of steps, applied in order as a single unit. Example: [counterparty_create, counterparty_group_create, counterparty_group_add]

Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token. Session token. Mobile/services. The web uses a cookie.

path
parameterstring
Required

API Key for authentication. Provide your API key in the cookie.

Path Parameters

codestring
Required

Unique Vault code (slug)

Example:
demo_vault

Body

application/json
stepsarray
Required

A chain of steps, applied in order as a single unit. Example: [counterparty_create, counterparty_group_create, counterparty_group_add]

Responses

appliedboolean
Required

All steps allow/bypass: the chain was applied immediately, without an approval request

resultsarray
Required