Sponsor allows one verb once

**Sponsor token** (`writ_sp_...`) required — not the API key. The human sponsor approves a single write: the grant is scoped to the sponsor's tenant and matches only checks from that tenant's keys on all five fields (sponsor, agent, verb, target, purpose). Grants are **single-use**: the first matching check spends the grant; a second identical check needs a new grant. `ttlSeconds` defaults to 90 and must be between 1 and 3600. This is the approval behind every STEP_UP decision — the agent stops, the sponsor grants, the agent re-checks.

Authentication

AuthorizationBearer
Your Writ API key (writ_...) as an Authorization Bearer header. The sponsor token (writ_sp_...) is a separate credential used only for grants, revokes, and reinstate — it goes in the same Authorization header on those endpoints. In the Fern docs playground, paste the key here; it is stored in this browser only.

Headers

AuthorizationstringRequired

Bearer <sponsor token> — the writ_sp_… token issued with the tenant’s first API key.

Request

This endpoint expects an object.
sponsorIdstringRequired

The human sponsor on whose behalf the agent acts (e.g. s_42).

agentIdstringRequired

The agent performing the write (e.g. support-agent-07).

verbstringRequired

The consequential action (e.g. refund, provision, admit).

targetstringRequired

What the action applies to (e.g. order #88412).

purposestringRequired

Why — the stated intent, bound into the auth token (e.g. Refund order #88412, close ticket #2210).

ttlSecondsintegerOptional

Grants only: how long the grant lives. Default 90, min 1, max 3600.

Response

Grant created. It is live until spent or until expiresAt.

Errors

400
Bad Request Error
401
Unauthorized Error