Vigilfield Docs
API referenceInstallations

`POST /installations/{id}/permissions` — approve some of the permissions the App declares that this installation does not hold yet (ADR-0079).

POST/installations/{id}/permissions

The body is an install's: (scope, target) pairs, bounded the same way. Only the installing team, acting as it, approves.

Path Parameters

id*string

Installation id (inst-…)

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

POST /apps/{id}/installations body.

⚠️ There is no team_id field, and adding one would reopen a check this design removes. The installing team is auth.acting_team_id, which the extractor has already validated is one of the caller's own teams (extractor.rs:63-66) — so there is no field in which to name somebody else's team, and no membership check to forget. export/logic.rs:56-62 is the shipped precedent for reading the acting team this way.

Response Body

application/json

curl -X POST "https://example.com/installations/string/permissions" \  -H "Content-Type: application/json" \  -d '{}'
{  "app_id": "string",  "created_at": "string",  "id": "string",  "installed_by": "string",  "pending_permissions": [    "string"  ],  "permissions": [    {      "grant_id": "string",      "scope": "string",      "target": "string"    }  ],  "team_id": "string"}