Creates an Authorization allowing a Person or ServiceAccount principal to exercise a set of scopes against the selected Account context. The grantor Account is resolved from the caller's account context (X-Wingspan-Account or an account-bound session) and is the protected resource, not an authenticating actor. Accounts are intentionally excluded as grantees: Account-to-Account access is hierarchy / Organization policy, not an Authorization. Idempotent via Idempotency-Key.
Requires a session with recent MFA step-up for HighRiskWriteAction. If step-up is missing or expired, this operation returns 403 StepUpMfaRequired; create and verify an MFA challenge at /v3/platform/mfa-challenges with requiredFor: "HighRiskWriteAction", then retry.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||