curl --request POST \
--url https://app.vumasign.com/api/v1/standing-authorisations/{authorisationId}/cancel \
--header 'Authorization: Bearer <token>' \
--header 'Idempotency-Key: <idempotency-key>'import requests
url = "https://app.vumasign.com/api/v1/standing-authorisations/{authorisationId}/cancel"
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>"
}
response = requests.post(url, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Idempotency-Key': '<idempotency-key>', Authorization: 'Bearer <token>'}
};
fetch('https://app.vumasign.com/api/v1/standing-authorisations/{authorisationId}/cancel', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.vumasign.com/api/v1/standing-authorisations/{authorisationId}/cancel"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"id": "0b9a5c1e-7d42-4f8a-9e13-5c6d7e8f9a0b",
"number": "SA-0012",
"status": "cancelled",
"sandbox": false,
"brand": {
"id": "9d4f2a6b-1c3e-4d5f-8a7b-6c5d4e3f2a1b",
"name": "NTT DATA"
},
"legal_entity": {
"name": "NTT DATA South Africa (Pty) Ltd",
"registration_number": "1990/001234/07"
},
"grantor": {
"name": "Naledi Mokoena",
"email": "naledi@example.test",
"job_title": "HR Director"
},
"intended_use": "Salary adjustment letters and employment confirmations",
"valid_from": "2026-10-14T22:00:00.000Z",
"valid_until": "2027-10-13T22:00:00.000Z",
"invite_expires_at": "2026-10-28T22:00:00.000Z",
"granted_at": null,
"cancellation": {
"at": "2026-10-15T08:00:00.000Z",
"reason": "requested"
},
"revocation": null,
"invalidation": null,
"reference": "ntt-signatory-2026",
"applied_count": 0,
"created_at": "2026-10-14T06:00:00.000Z"
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}Cancel a pending standing authorisation request.
Withdraws an invited request: the mandate link stops working, the grantor is told in your organisation’s name, and the status becomes cancelled with cancellation.reason requested. Takes no body. Cancelling a cancelled request returns it unchanged. Once the grantor has signed it can no longer be cancelled (409 authorisation_not_pending): wait for authorisation.granted, then revoke.
curl --request POST \
--url https://app.vumasign.com/api/v1/standing-authorisations/{authorisationId}/cancel \
--header 'Authorization: Bearer <token>' \
--header 'Idempotency-Key: <idempotency-key>'import requests
url = "https://app.vumasign.com/api/v1/standing-authorisations/{authorisationId}/cancel"
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>"
}
response = requests.post(url, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Idempotency-Key': '<idempotency-key>', Authorization: 'Bearer <token>'}
};
fetch('https://app.vumasign.com/api/v1/standing-authorisations/{authorisationId}/cancel', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.vumasign.com/api/v1/standing-authorisations/{authorisationId}/cancel"
req, _ := http.NewRequest("POST", url, nil)
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"id": "0b9a5c1e-7d42-4f8a-9e13-5c6d7e8f9a0b",
"number": "SA-0012",
"status": "cancelled",
"sandbox": false,
"brand": {
"id": "9d4f2a6b-1c3e-4d5f-8a7b-6c5d4e3f2a1b",
"name": "NTT DATA"
},
"legal_entity": {
"name": "NTT DATA South Africa (Pty) Ltd",
"registration_number": "1990/001234/07"
},
"grantor": {
"name": "Naledi Mokoena",
"email": "naledi@example.test",
"job_title": "HR Director"
},
"intended_use": "Salary adjustment letters and employment confirmations",
"valid_from": "2026-10-14T22:00:00.000Z",
"valid_until": "2027-10-13T22:00:00.000Z",
"invite_expires_at": "2026-10-28T22:00:00.000Z",
"granted_at": null,
"cancellation": {
"at": "2026-10-15T08:00:00.000Z",
"reason": "requested"
},
"revocation": null,
"invalidation": null,
"reference": "ntt-signatory-2026",
"applied_count": 0,
"created_at": "2026-10-14T06:00:00.000Z"
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}Authorizations
Authorization: Bearer vsk_live_…. Chosen over a bespoke X-API-KEY header because every client, proxy and log-redaction rule already knows this one. What a key may DO is its scopes — see x-scopes at the root of this document and x-required-scope on each operation. The scope list is not written here because OpenAPI reserves a requirement’s scope array for oauth2 and openIdConnect and requires it to be empty for an http scheme.
Headers
Any string that identifies this request, at most 255 characters. The caller’s own request identifier.
"01960000-0000-4000-8000-00000000ffff"
Path Parameters
The authorisation’s id, from the invitation’s answer or the list. A live authorisation’s id answers not_found to a test key.
An authorisation id.
"0b9a5c1e-7d42-4f8a-9e13-5c6d7e8f9a0b"
Response
The authorisation, cancelled; or, cancelled before, unchanged.
The authorisation.
The authorisation’s id.
Its number in your organisation, as printed on the mandate.
"SA-0012"
invited until the signed mandate is sealed, then active. An invite ends declined, expired_unsigned or cancelled; an active one ends revoked, expired or invalidated.
invited, active, declined, expired_unsigned, cancelled, revoked, expired, invalidated Requested with a test key: it binds nobody, and applies only to sandbox envelopes.
The brand it covers, as granted.
Show child attributes
Show child attributes
The legal entity the grantor signs for.
Show child attributes
Show child attributes
The person who signs the mandate.
Show child attributes
Show child attributes
Your description, printed on the mandate as yours. Not enforced.
The start, or null for "from the grant".
The end.
When the mandate lapses unsigned.
When the signed mandate was sealed and the authorisation took effect.
Set when the request ended without a grant.
Show child attributes
Show child attributes
Set when an active authorisation was revoked.
Show child attributes
Show child attributes
Set when the brand changed under it.
Show child attributes
Show child attributes
Your own reference, as you set it.
How many documents it pre-signed.
When it was requested.