curl --request GET \
--url https://app.vumasign.com/api/v1/standing-authorisations \
--header 'Authorization: Bearer <token>'import requests
url = "https://app.vumasign.com/api/v1/standing-authorisations"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.vumasign.com/api/v1/standing-authorisations', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.vumasign.com/api/v1/standing-authorisations"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"data": [
{
"id": "0b9a5c1e-7d42-4f8a-9e13-5c6d7e8f9a0b",
"number": "SA-0012",
"status": "active",
"sandbox": false,
"brand": {
"id": "9d4f2a6b-1c3e-4d5f-8a7b-6c5d4e3f2a1b",
"name": "NTT DATA"
},
"legal_entity": {
"name": "NTT DATA South Africa (Pty) Ltd",
"registration_number": "1990/001234/07"
},
"grantor": {
"name": "Naledi Mokoena",
"email": "naledi@example.test",
"job_title": "HR Director"
},
"intended_use": "Salary adjustment letters and employment confirmations",
"valid_from": "2026-10-14T22:00:00.000Z",
"valid_until": "2027-10-13T22:00:00.000Z",
"invite_expires_at": "2026-10-28T22:00:00.000Z",
"granted_at": "2026-10-16T07:12:44.000Z",
"cancellation": null,
"revocation": null,
"invalidation": null,
"reference": "ntt-signatory-2026",
"applied_count": 0,
"created_at": "2026-10-14T06:00:00.000Z"
}
],
"has_more": false,
"next_cursor": null
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}List standing authorisations, newest first, optionally filtered.
Every standing authorisation of your organisation, by keyset cursor as GET /api/v1/envelopes pages, filtered by status, brand_id or your reference. ⚠️ A TEST KEY LISTS ONLY SANDBOX AUTHORISATIONS. Each row is the full resource; it never carries the signature, the mandate or any grant evidence.
curl --request GET \
--url https://app.vumasign.com/api/v1/standing-authorisations \
--header 'Authorization: Bearer <token>'import requests
url = "https://app.vumasign.com/api/v1/standing-authorisations"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.vumasign.com/api/v1/standing-authorisations', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.vumasign.com/api/v1/standing-authorisations"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}{
"data": [
{
"id": "0b9a5c1e-7d42-4f8a-9e13-5c6d7e8f9a0b",
"number": "SA-0012",
"status": "active",
"sandbox": false,
"brand": {
"id": "9d4f2a6b-1c3e-4d5f-8a7b-6c5d4e3f2a1b",
"name": "NTT DATA"
},
"legal_entity": {
"name": "NTT DATA South Africa (Pty) Ltd",
"registration_number": "1990/001234/07"
},
"grantor": {
"name": "Naledi Mokoena",
"email": "naledi@example.test",
"job_title": "HR Director"
},
"intended_use": "Salary adjustment letters and employment confirmations",
"valid_from": "2026-10-14T22:00:00.000Z",
"valid_until": "2027-10-13T22:00:00.000Z",
"invite_expires_at": "2026-10-28T22:00:00.000Z",
"granted_at": "2026-10-16T07:12:44.000Z",
"cancellation": null,
"revocation": null,
"invalidation": null,
"reference": "ntt-signatory-2026",
"applied_count": 0,
"created_at": "2026-10-14T06:00:00.000Z"
}
],
"has_more": false,
"next_cursor": null
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}{
"error": {
"code": "unauthenticated",
"message": "<string>"
}
}Authorizations
Authorization: Bearer vsk_live_…. Chosen over a bespoke X-API-KEY header because every client, proxy and log-redaction rule already knows this one. What a key may DO is its scopes — see x-scopes at the root of this document and x-required-scope on each operation. The scope list is not written here because OpenAPI reserves a requirement’s scope array for oauth2 and openIdConnect and requires it to be empty for an http scheme.
Query Parameters
How many to return. A value outside the range is refused, not clamped. How many authorisations to return.
1 <= x <= 100The next_cursor from the previous page. Opaque.
Where to resume.
Only authorisations in this status. An unknown value is refused, not answered with an empty page. One status.
invited, active, declined, expired_unsigned, cancelled, revoked, expired, invalidated Only authorisations covering this brand. A brand id.
Only authorisations whose reference is exactly this, compared in Unicode NFC.
Your reference.
1 - 255"ntt-signatory-2026"
Response
A page of authorisations, newest first, with the cursor for the next.