Skip to main content
POST
Send method: eip712_signature with the external owner’s signerAddress and signature, or method: managed_email_otp with the managed Vault’s email code. Idempotency-Key is required. For an external-signer Vault, the signature alone does not change the Vault’s on-chain spending policy. Get an account Vault then returns an execute_safe_transaction action, and the owner, or the owner multisig, executes the returned transaction. Record it with Submit an external Vault action transaction. Stableyard verifies the transaction receipt and the policy on chain, then marks the policy active.

Authorizations

Authorization
string
header
required

HTTP Basic auth. Username is the Stableyard app ID. Password is the app secret. The optional Stableyard-Version request header must match the environment pin.

Headers

Idempotency-Key
string
required

Retry key. Reuse a key only with the identical request; different input returns a conflict.

Example:

"request-key-001"

Stableyard-Version
enum<string>

Optional contract-version assertion. Omit it to use the app environment's pinned version. A different supported version is accepted only after that environment is explicitly migrated.

Available options:
2026-09-09

Path Parameters

accountId
string
required

Canonical account id returned by the Accounts API.

Example:

"acct_123"

policyId
string
required

Body

application/json
method
enum<string>
required
Available options:
eip712_signature
signerAddress
string
required
Example:

"0x3333333333333333333333333333333333333333"

signature
string
required
Example:

"0x..."

Response

Authorized policy

id
string
required
Example:

"vault_policy_123"

vaultId
string
required
Example:

"vault_123"

version
integer
required
Required range: x >= 1
policySchemaVersion
integer
required
Required range: x >= 1
status
enum<string>
required
Available options:
draft,
pending_authorization,
authorized,
installing,
active,
superseded,
revoked,
failed
ownershipMode
enum<string>
required
Available options:
external,
stableyard
allowedTokens
object[]
required
spendLimits
object
required
yieldRules
object
required
resourceVersion
integer
required
Required range: x >= 1
createdAt
string<date-time>
required
updatedAt
string<date-time>
required
authorization
object

Present on single-policy responses while authorization is pending.

nextAction
Vault action required · object | null
reason
string | null
failureCode
string | null