Skip to main content
PUT
Create or update the transaction review config for an environment

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

environmentId
string
required

ID of the environment

Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

Body

application/json
webhookUrl
string<uri>
required

URL that receives transaction review requests before signing.

enabled
boolean

Whether transaction review is active. Defaults to true.

webhookFailurePolicy
enum<string>

Determines what happens when the review webhook is unreachable or times out. ALLOW proceeds with signing; DENY blocks the transaction. Defaults to DENY when omitted from a configuration request.

Available options:
ALLOW,
DENY
webhookPublicKey
string | null

Optional Ed25519 public key (PEM format) used to verify the response signature from the webhook. When configured, the webhook must include an x-dynamic-response-signature header containing a base64-encoded Ed25519 signature over the raw response body. Pass null to remove.

webhookSecret
string | null

Optional secret used to sign webhook requests via HMAC-SHA256. Sent as the x-dynamic-signature header. Pass null to remove.

webhookTimeoutMs
integer

Milliseconds to wait for a webhook response. Defaults to 5000.

Required range: 500 <= x <= 30000

Response

Transaction review config saved

enabled
boolean
required
environmentId
string
required
Required string length: 36
Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$
Example:

"95b11417-f18f-457f-8804-68e361f9164f"

webhookFailurePolicy
enum<string>
required

Determines what happens when the review webhook is unreachable or times out. ALLOW proceeds with signing; DENY blocks the transaction. Defaults to DENY when omitted from a configuration request.

Available options:
ALLOW,
DENY
webhookSecretSet
boolean
required

True iff a webhook secret is stored. The secret itself is never returned.

webhookTimeoutMs
integer
required
webhookUrl
string<uri>
required
webhookPublicKey
string

Ed25519 public key (PEM format) configured for response signature verification, if any.

Last modified on July 20, 2026