Approve an application
const url = 'https://example.com/api/v1/onboarding/applications/example/approve';const options = { method: 'POST', headers: { cookie: 'bl_authority_session=<bl_authority_session>', 'Content-Type': 'application/json' }, body: '{"roles":["example"],"kvk_verified":true,"note":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/api/v1/onboarding/applications/example/approve \ --header 'Content-Type: application/json' \ --cookie bl_authority_session=<bl_authority_session> \ --data '{ "roles": [ "example" ], "kvk_verified": true, "note": "example" }'After the signatory signed, the reviewer confirms in the KvK register that the signer may represent the organisation (kvk_verified). The participant enters the registry and is offered its membership credential over DCP. The authority must have witnessed the participant’s did:webvh log.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”The id of the application.
Request Bodyrequired
Section titled “Request Bodyrequired”object
The roles to grant, within the signed mandate; default: all of them.
The reviewer confirms that the signer is authorised to represent the organisation according to the KvK register.
Example generated
{ "roles": [ "example" ], "kvk_verified": true, "note": "example"}Responses
Section titled “Responses”OK.
An application as the API shows it: documents the JSON built in
[application_json].
object
Ignored with an invite: its roles count.
Person authorised to sign on behalf of the organisation (KvK).
awaiting_signature, pending, approved or rejected.
The roles asked for, or those of the invite; after approval the granted ones.
Approved only.
Why it was rejected.
The check of the reviewer: kvk_verified, verified_by, verified_at, note, signer.
The latest signing request of the signatory.
Example generated
{ "did": "example", "slug": "example", "name": "example", "legal_name": "example", "kvk_number": "example", "contact_email": "example", "requested_roles": [ "example" ], "dsp_endpoint": "example", "dataplane_url": "example", "color": "example", "invite_code": "example", "signatory_name": "example", "signatory_email": "example", "key_storage": { "source": "example", "non_exportable": true }, "id": "example", "state": "example", "roles": [ "example" ], "granted_roles": [ "example" ], "reason": "example", "decided_by": "example", "decided_at": "2026-04-15T12:00:00Z", "created_at": "2026-04-15T12:00:00Z", "submitted_at": "2026-04-15T12:00:00Z", "review": "example", "signing": "example"}Not confirmed in the KvK register, a role outside the mandate, or a key that can be exported for a write role.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}No valid session, DPoP-bound token or API key.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}Not found.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}Not signed yet, not pending, or the did:webvh log is not witnessed yet.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}