Skip to navigation

Approve a credential

Concludes the pending proposal (credentials:approve, not its proposer): an activation, amendment, reactivation, rotation or revocation. Nothing pending refuses 409 NOTHING_PENDING.

Authentication

AuthorizationBearer

Bearer authentication of the form Bearer <token>, where token is your auth token.

Path parameters

idintegerRequired

The record's id — a positive 32-bit integer the platform minted.

Headers

Idempotency-KeystringRequired

Required on every write: a URL-safe string of 1 to 64 characters from [A-Za-z0-9._~-] (a UUID fits), scoped to you. It names one operation on one record, ever: a retry replays the stored outcome (Idempotent-Replay: true) or attaches to the live one, and reuse on another record refuses 409 IDEMPOTENCY_KEY_REUSED. Missing or malformed, 400.

If-MatchstringOptional

The ETag the read minted, quoted or bare; absent or * is unconditional; a weak validator refuses 400 INVALID_IF_MATCH. A stale value answers 412 VERSION_CONFLICT with currentVersion and a fresh ETag: re-read, reapply, retry. Send it — every write restates the whole record, so an unconditional write overwrites every field from your copy, and an amend against a pending proposal replaces that proposal.

Request

This endpoint expects an object.
credentialIdintegerOptional
expectedVersionstring or nullOptionalformat: "^-?[0-9]+$"
int64 as a decimal JSON string

Response

The credential as the platform now holds it after the write — the same row the read serves, with the answering change's position, the row's ETag and, on a replayed key, Idempotent-Replay.

credentialIdinteger
Sticky entity key.
globalSequencestringformat: "^[0-9]+$"

The position as a decimal string — the last change this member had applied, orders and balance readings included.

keyFingerprintstring

The credential's fingerprint as the intake computed it — fp- and the first 16 hex characters of SHA-256 over the canonical payload — the pin a connector adopts the material at: enough to prove a cutover, never enough to sign. Empty on a row seeded before the intake.

namestring

Natural key — per-org unique among live credentials.

orgIdinteger

Owner-stamped.

pendingTransitionenum

ACTIVATE, AMEND (capabilities/secretRef), REACTIVATE, REVOKE or ROTATE; NONE otherwise. NONE is the unset sentinel: outputs only — as input, omit the field instead; explicit NONE refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as NONE, never as an error; as input an unknown name refuses 400 — the parse is strict

providerKindenum

UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

secretRefstring

LOGICAL credential name (okx-account-prod) — never a store path or provider URI; resolution happens only at the owning connector's edge.

statusenum

UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

venueKeyIdstring

The venue's identifier for the key — metadata, not material.

versionstringformat: "^-?[0-9]+$"
Monotonic per entity. int64 as a decimal JSON string
allowlistDetailstringOptional

The venue's own allowlist, verbatim (IP addresses are not secrets); empty when none or no probe answered.

appGroupstringOptional

The connector app group serving this credential (desk 5-as-amended, okx-oe D-E17): the assignment rides the row — one group per credential by construction, empty = unassigned (no connector serves it; fail-safe). Replaces the compile-time CredentialAssignments table.

canExecuteTransfersbooleanOptional

Whether the key may execute transfers. a boolean; absent reads false

canReadBalancesbooleanOptional

Whether the key may read balances. a boolean; absent reads false

canServeAddressesbooleanOptional

Whether the key may serve deposit addresses. a boolean; absent reads false

canTradebooleanOptional

Capability boolean: an order routes through its account's trading pipe — the account's designated tradingCredentialId, else its own credential — which must be ACTIVE and carry canTrade. Any number of trading credentials may share one (org × venue) — one venue key per sub-account. a boolean; absent reads false

exchangeIdinteger or nullOptional

The refdata exchange for an EXCHANGE-kind credential — carried, not resolved here; a credential that can trade must name one (MISSING_VENUE); 0 = no venue.

keyCreatedAtNsstring or nullOptionalformat: "^-?[0-9]+$"

Key metadata: when the venue key was minted; 0 = not stated. int64 as a decimal JSON string

observedAllowlistenumOptional

The probe's allowlist verdict against the cluster's egress set; UNKNOWN until a probe answers. UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

Allowed values:
observedKeyCreatedAtNsstring or nullOptionalformat: "^-?[0-9]+$"

The key creation time the venue stated to the probe; 0 = the venue states none, or never probed. int64 as a decimal JSON string

observedKeyFingerprintstringOptional

The fingerprint of the material the probe adopted — compare with keyFingerprint, the intake's pin; empty until a probe answers.

observedKeyIdstringOptional

The venue-facing key identifier the probing connector resolved (the public half, never the secret); empty until a probe answers.

observedPermissionslist of enumsOptional

The observed axis: the key scopes the venue stated to the probing connector, parsed by name; empty until a probe answers. a set (SBE bit-set) served as the array of its set choice names in declared order; empty = none set, never null. The choice set is append-only: a consumer READING this field skips an unknown name, never errors; as input an unknown or repeated name refuses 400 — the parse is strict

Allowed values:
pendingByUserIdinteger or nullOptional

The user whose proposal is pending, so an approver is checked to be someone else; 0 when nothing is pending.

permissionDetailstringOptional

The venue's own permission string, verbatim (not a secret); empty until a probe answers.

probeDetailstringOptional

Redacted diagnostic text for a non-NONE probe outcome; empty-not-null.

probeOutcomeenumOptional

UNKNOWN = never probed; NONE = the venue's key-restrictions read answered; else the probe's own failure in the credential or gate band. UNKNOWN is the unset sentinel: outputs only — as input, omit the field instead; explicit UNKNOWN refuses 400. The value set is append-only: a consumer READING this field treats an unknown name as UNKNOWN, never as an error; as input an unknown name refuses 400 — the parse is strict

probedAtNsstring or nullOptionalformat: "^-?[0-9]+$"

Consensus time of the probe report this row records — owner-stamped; 0 = never probed. int64 as a decimal JSON string

rotateByNsstring or nullOptionalformat: "^-?[0-9]+$"

Governance deadline for rotation; a breach is an ops alert; 0 = none. int64 as a decimal JSON string

venueAccountRefstringOptional

The venue's account identifier behind the key (OKX uid); empty when the venue states none or no probe answered.

unscaledbooleanOptionalDeprecated

Never present since 0.3.3: every money value on this API states its own scale on the wire — a policy amount or cap since 0.3.3, an order's and an execution's since 0.3.2, a balance's since 0.3.1 — so a row is never served raw, whether or not this member holds the asset or instrument it references. Kept, deprecated, so a client generated from 0.3.2 still compiles; it goes at the next major.

Errors

400
Approve Credentials Request Bad Request Error
401
Approve Credentials Request Unauthorized Error
403
Approve Credentials Request Forbidden Error
404
Approve Credentials Request Not Found Error
409
Approve Credentials Request Conflict Error
412
Approve Credentials Request Precondition Failed Error
413
Approve Credentials Request Content Too Large Error
422
Approve Credentials Request Unprocessable Entity Error
429
Approve Credentials Request Too Many Requests Error
500
Approve Credentials Request Internal Server Error
503
Approve Credentials Request Service Unavailable Error