Skip to main content
POST
Renew a standing authorisation: send its grantor a new mandate that starts when it ends.

Authorizations

Authorization
string
header
required

Authorization: Bearer vsk_live_…. Chosen over a bespoke X-API-KEY header because every client, proxy and log-redaction rule already knows this one. What a key may DO is its scopes — see x-scopes at the root of this document and x-required-scope on each operation. The scope list is not written here because OpenAPI reserves a requirement’s scope array for oauth2 and openIdConnect and requires it to be empty for an http scheme.

Headers

Idempotency-Key
string
required

Any string that identifies this request, at most 255 characters. ⚠️ REQUIRED: a retry with the same key returns the same renewal instead of sending a second mandate. The caller’s own request identifier.

Example:

"01960000-0000-4000-8000-00000000ffff"

Path Parameters

authorisationId
string<uuid>
required

The id of the authorisation to renew. A live authorisation’s id answers not_found to a test key. An authorisation id.

Example:

"0b9a5c1e-7d42-4f8a-9e13-5c6d7e8f9a0b"

Body

application/json

Optional. Send no body to renew for the longest span allowed.

The request.

valid_until
string<date-time> | null

The renewal’s end: after its start, at most 12 months after it, and at least 2 days from now. Omit it for exactly 12 months after the start.

invite_expires_at
string<date-time> | null

As on the invitation. Omit it for the default.

Response

The renewal, invited, with renews naming the authorisation it renews.

The renewal.

id
string<uuid>
required

The authorisation’s id.

number
string
required

Its number in your organisation, as printed on the mandate.

Example:

"SA-0012"

status
enum<string>
required

invited until the signed mandate is sealed, then active. An invite ends declined, expired_unsigned or cancelled; an active one ends revoked, expired or invalidated.

Available options:
invited,
active,
declined,
expired_unsigned,
cancelled,
revoked,
expired,
invalidated
sandbox
boolean
required

Requested with a test key: it binds nobody, and applies only to sandbox envelopes.

brand
object
required

The brand it covers, as granted.

The legal entity the grantor signs for.

grantor
object
required

The person who signs the mandate.

intended_use
string | null
required

Your description, printed on the mandate as yours. Not enforced.

valid_from
string<date-time> | null
required

The start, or null for "from the grant".

valid_until
string<date-time>
required

The end.

invite_expires_at
string<date-time>
required

When the mandate lapses unsigned.

granted_at
string<date-time> | null
required

When the signed mandate was sealed and the authorisation took effect.

cancellation
object | null
required

Set when the request ended without a grant.

revocation
object | null
required

Set when an active authorisation was revoked.

invalidation
object | null
required

Set when the brand changed under it.

reference
string | null
required

Your own reference, as you set it.

renews
string<uuid> | null
required

The authorisation this one renews (POST /standing-authorisations/{id}/renew), or null. The old one stays in force until its own valid_until; name the new one on sends from then. Vumasign never chooses an authorisation for you.

renewal_requested_at
string<date-time> | null
required

When the grantor asked, through the renew link in their own email, to be asked again. Null if they have not. It grants nothing; renewing is your call.

applied_count
integer
required

How many documents it pre-signed.

created_at
string<date-time>
required

When it was requested.