How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Fortanix Approval Requests API

The Approval_requests API from Fortanix — 6 operation(s) for approval_requests.

Fortanix Approval Requests API is one of 51 APIs that Fortanix publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Approval Requests. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 8 operations across 6 paths, and defines 42 schemas. It is described by OpenAPI 3.2.0, at version 0.1.0-20260710.

Requests are made against a single base URL, {dsmEndpoint}.

8 operations 6 paths 42 schemas 1 DELETE2 GET5 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
0.1.0-20260710
Base URL
https://amer.smartkey.io
Authentication
HTTP Basic, API Key, HTTP Bearer
License
Terms of Service
Resource Areas
1

Authentication & Security 3

Fortanix Approval Requests API declares 3 security schemes for authenticating requests. It accepts HTTP basic authentication (basicAuth). An API key is passed in the header as Authorization (apiKeyAuth). It accepts HTTP bearer tokens (JWT) (bearerToken).

  • apiKeyAuth — Please enter your token prefixed with 'Basic ' (e.g., 'Basic yourtokenhere')

Paths & Operations 8

Across 6 paths, the API surfaces 8 operations — 1 DELETE, 2 GET, 5 POST. Each is listed below with its method, path, parameters, and response codes.

Approval_requests 8
POST
/sys/v1/approval_requests/{req_id}/approve
Approve an approval request.
ApproveRequest 1 param body → 2XX
POST
/sys/v1/approval_requests
Create a new approval request.
CreateApprovalRequest body → 2XX
GET
/sys/v1/approval_requests
Get all approval requests.
ListApprovalRequests 1 param → 2XX
DELETE
/sys/v1/approval_requests/{req_id}
Delete an approval request.
DeleteApprovalRequest 1 param → 204
GET
/sys/v1/approval_requests/{req_id}
Lookup a specific approval request.
GetApprovalRequest 1 param → 2XX
POST
/sys/v1/approval_requests/{req_id}/deny
Deny an approval request.
DenyRequest 1 param body → 2XX
POST
/sys/v1/approval_requests/{req_id}/result
Get the result for an approved or failed request.
GetApprovalRequestResult 1 param → 2XX
POST
/sys/v1/approval_requests/{req_id}/challenge
Creates a challenge for the FIDO2/U2F device to sign.
MfaChallenge 2 params → 2XX

Schemas 42

The contract defines 42 schemas that model the data the API accepts and returns. The most detailed is ApprovableResult (2 properties). Each schema is shown below with its type and property counts.

U2fRegisteredKey
COSEAlgorithmIdentifier
string
https://www.w3.org/TR/webauthn-2/typedefdef-cosealgorithmidentifier Signing algorithms from [IANA COSE Algorithms registry] that are supported on DSM side for…
PublicKeyCredentialEntityForRp
PrincipalUserViaApp
UserVerificationRequirement
string
https://www.w3.org/TR/webauthn-2/enum-userVerificationRequirement https://www.w3.org/TR/webauthn-2/user-verification
PublicKeyCredentialUserEntity
ListApprovalRequestsParams
DenyRequest
Fido2MfaChallengeResponse
Fido2 options when requesting assertion or attestation to a device
ApprovableResult
object
2 properties 2 required
Base64UrlSafe
string
U2fAuthRequest
OauthScope
string
OAuth scope.
MfaProtocol
string
Protocols for MFA.
PublicKeyCredentialAuthenticatorAssertionResponse
PublicKeyCredentialDescriptor
Reviewer
ApprovalStatus
string
Approval request status.
PublicKeyCredentialRpEntity
ApprovalSubject
Identifies an object acted upon by an approval request.
AuthenticatorTransportInner
string
See [AuthenticatorTransport] type.
ResidentKeyRequirement
string
Tells Relying Party's requirement about client side discoverable creds (formely known as resident keys). If client side discoverable creds are there, it means…
PublicKeyCredentialEntityForUser
PublicKeyCredentialType
string
https://www.w3.org/TR/webauthn-2/enum-credentialType This enum defines valid cred types.
AuthenticatorAttachment
string
Principal
A security principal.
AuthenticationExtensionsClientOutputs
U2fMfaChallengeResponse
AttestationConveyancePreference
string
If you really want to understand attestation, read the following: This enum just specified how the attestation should be conveyed to the RP. You can see doc of…
AuthenticatorTransport
Hints by relying party on how client should communicate with the authenticator. https://www.w3.org/TR/webauthn-2/enum-transport
AuthenticatorAssertionResponse
ApprovalRequestRequest
MfaChallengeParams
ApproveRequest
PublicKeyCredentialRequestOptions
AuthenticatorSelectionCriteria
PublicKeyCredentialParameters
MfaChallengeResponse
PublicKeyCredentialCreationOptions
AuthenticationExtensionsClientInputs
ReviewerPrincipal
A Principal who can approve or deny an approval request.
ApprovalRequest

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

fortanix-approval-requests-api-openapi.yml Raw ↑

Other APIs Fortanix publishes across the network.

Fortanix Confidential Computing Manager REST API
Fortanix Account Extensions API
Fortanix Accounts API
Fortanix Admin API
Fortanix App API
Fortanix Application Config API
Fortanix Approval Requests API
Fortanix Apps API
Fortanix Auth API
Fortanix Authentication API
Fortanix Batch API
Fortanix Build API
Where this information came from

This is an independent, third-party profile of Fortanix Approval Requests API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.