Grant scoped Account access to a principal

Creates an Authorization allowing a Person or ServiceAccount principal to exercise a set of scopes against the selected Account context. The grantor Account is resolved from the caller's account context (X-Wingspan-Account or an account-bound session) and is the protected resource, not an authenticating actor. Accounts are intentionally excluded as grantees: Account-to-Account access is hierarchy / Organization policy, not an Authorization. Idempotent via Idempotency-Key.

Requires a session with recent MFA step-up for HighRiskWriteAction. If step-up is missing or expired, this operation returns 403 StepUpMfaRequired; create and verify an MFA challenge at /v3/platform/mfa-challenges with requiredFor: "HighRiskWriteAction", then retry.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
string
enum
required

The authenticated principal kind receiving an Authorization. Both Person and ServiceAccount grants are enforced at request time.

Allowed:
string
required

ID of the grantee Person or ServiceAccount principal.

scopes
array of strings
required

Base scope names (for example payments.payable). Use actions for Read/Write; do not append :read or :write.

scopes*
string
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Select one id returned by GET /platform/scope-groups. Mutually exclusive with scopes.

actions
array of strings
required
actions*
Allowed:
scopeModifications
object
boolean
Defaults to false

Explicitly opt the Authorization into descendant Account access. Omit or send false for a leaf-only grant on the selected grantor Account.

date-time
metadata
object

Free-form key-value pairs. Max 50 keys; key length at most 40 characters; value length at most 500 characters. Where a list endpoint declares metadata filtering, it uses the QueryQL namespace via filter[metadata.{key}][eq]=value or filter[metadata.{key}][in][]=value. Endpoints that do not declare the dynamic Metadata filter do not support Metadata filtering.

Headers
string
length between 1 and 255
^[\x21-\x7e]{1,255}$

Optional idempotency token for authenticated POST and PATCH requests. Reusing the same key and body returns the cached response for 24 hours, except credential operations that explicitly document a 409 because one-time secret material is never cached; reusing it with a different body returns 409 IdempotencyKeyConflict. Use 1-255 printable ASCII characters.

string
^(?:[A-Za-z0-9_.]{22}|[a-f0-9]{24})$

Select the Account for an Account-scoped operation. A direct ServiceAccount API key MUST supply this header, and the target must be within the ServiceAccount owner's or Authorization grant's Account boundary. A Person bearer may select an Account on which it has an active Stakeholder, and an Account session may select its bound Account (or a descendant only when the session explicitly includes descendants).

string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json