WalletD developers
Operations and audit

Approve short-lived WalletD vendor-support access (partner admin only)

Approves one named WalletD support engineer to touch this tenant's production data for a bounded window, against a ticket reference and a stated reason.

POST/v1/support_access_grants

Approves one named WalletD support engineer to touch this tenant's production data for a bounded window, against a ticket reference and a stated reason. Requires a partner administrator: a staff session that is neither a platform nor a WalletD vendor-support principal and that holds support_access:manage; anyone else is refused partner_admin_required (403). A missing body or an expiry the service will not accept gives invalid_request (400), and a second grant for an engineer who already holds a live one support_access_already_active (409). While the grant stands, every request that engineer makes is recorded against it.

Console-only. This path is not routed at the public API gateway: it is reachable from the partner administration console and from inside the deployment, never with a tenant API key over the internet. It additionally requires a partner administrator — a staff principal that is neither a platform nor a WalletD vendor-support identity.

Authorization

bearerAuth
AuthorizationBearer <token>

A tenant API key (sk_{env}_{id}_{secret}), a wallet user token, or an IdP access token. Which principal the credential resolves to decides the scopes it carries; see the authentication guide.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/problem+json

curl -X POST "https://example.com/v1/support_access_grants" \  -H "Content-Type: application/json" \  -d '{    "staff_id": "string",    "reason": "string",    "ticket_reference": "string",    "expires_at": "2019-08-24T14:15:22Z"  }'
{  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",  "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0",  "staff_id": "string",  "reason": "string",  "ticket_reference": "string",  "created_by_type": "string",  "created_by_id": "string",  "created_at": "2019-08-24T14:15:22Z",  "expires_at": "2019-08-24T14:15:22Z",  "revoked_at": "2019-08-24T14:15:22Z",  "revoked_by_type": "string",  "revoked_by_id": "string"}