Skip to content

Mobile and push

Step up to approve

POST/api/mobile/v1/w/:wid/approvals/:apid/step-up

Above the line (the workspace’s chat line, or £100 when it sets none), approving needs a fresh proof from the device’s biometric-held key, or a TOTP code. Denying never does.

#Authentication

Device token

A bearer token issued to one phone after its owner signs in through the browser, sent as Authorization: Bearer. The rules are the console's rules; approving above a line needs a fresh step-up proof from the device. Writes carry x-immiscible-csrf: 1.

#Path parameters

widstringrequired

Workspace id

apidstringrequired

Approval id