Approve short-lived WalletD vendor-support access (partner admin only)
Approves one named WalletD support engineer to touch this tenant's production data for a bounded window, against a ticket reference and a stated reason.
/v1/support_access_grantsApproves one named WalletD support engineer to touch this tenant's production data for a bounded window, against a ticket reference and a stated reason. Requires a partner administrator: a staff session that is neither a platform nor a WalletD vendor-support principal and that holds support_access:manage; anyone else is refused partner_admin_required (403). A missing body or an expiry the service will not accept gives invalid_request (400), and a second grant for an engineer who already holds a live one support_access_already_active (409). While the grant stands, every request that engineer makes is recorded against it.
Console-only. This path is not routed at the public API gateway: it is reachable from the partner administration console and from inside the deployment, never with a tenant API key over the internet. It additionally requires a partner administrator — a staff principal that is neither a platform nor a WalletD vendor-support identity.
Authorization
bearerAuth A tenant API key (sk_{env}_{id}_{secret}), a wallet user token, or an IdP access token. Which principal the credential resolves to decides the scopes it carries; see the authentication guide.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/problem+json
curl -X POST "https://example.com/v1/support_access_grants" \ -H "Content-Type: application/json" \ -d '{ "staff_id": "string", "reason": "string", "ticket_reference": "string", "expires_at": "2019-08-24T14:15:22Z" }'{ "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "tenant_id": "34f5c98e-f430-457b-a812-92637d0c6fd0", "staff_id": "string", "reason": "string", "ticket_reference": "string", "created_by_type": "string", "created_by_id": "string", "created_at": "2019-08-24T14:15:22Z", "expires_at": "2019-08-24T14:15:22Z", "revoked_at": "2019-08-24T14:15:22Z", "revoked_by_type": "string", "revoked_by_id": "string"}List WalletD vendor-support approvals (partner admin only)
Expired and revoked grants remain in the response as operational and audit evidence.
Get the calling WalletD vendor-support identity's active grant
This is the only tenant endpoint a WalletD vendor-support identity may call without an active grant.