> ## Documentation Index
> Fetch the complete documentation index at: https://developers.fireblocks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Approve configuration changes

## Configuration Approval Callback

`POST /v2/config_change_sign_request`

This request expects a [CallbackResponse](/cosigners/callback-handler/response-object) object from the callback handler. If the callback handler does not respond within 30 seconds, Fireblocks fails the request. If your callback handler can't respond within 30 seconds, you can use the [retry mechanism](/cosigners/callback-handler/response-object) by responding with `RETRY`.

***

## Request parameters

<ResponseField name="requestId" type="string">
  A unique identifier of this request. It must be returned in the response.
</ResponseField>

<ResponseField name="signerId" type="string">
  (Optional) The Fireblocks API user ID associated with the cosigner device that's signing this approval.
</ResponseField>

<ResponseField name="type" type="string">
  The type of configuration request. See [Configuration types](#configuration-types) for the full list of values and their fields.
</ResponseField>

<ResponseField name="extraInfo" type="object">
  Additional information about the request. The shape depends on `type`. See [Configuration types](#configuration-types).
</ResponseField>

***

## Configuration types

Each type below lists the fields Fireblocks sends in `extraInfo` for that specific configuration change.

### Wallets and external accounts

#### UNMANAGED\_WALLET

An event that involves address whitelisting. This type also covers the `UNMANAGED_V2` internal request type — both surface as `UNMANAGED_WALLET` in the callback.

<ResponseField name="subType" type="string">
  `INTERNAL` - Internal Wallets are addresses you control outside your Fireblocks workspace. Internal addresses display their current balance and are included in your workspace's total billable address count.

  `EXTERNAL` - External Wallets are addresses managed by your clients and counterparties.

  `CONTRACT` - Contract Wallets are addresses of smart contracts you want to interact with. Currently, this only applies to smart contracts on EVM-compatible blockchains.
</ResponseField>

<ResponseField name="walletName" type="string">
  The name of the internal, external, or contract wallet you want to approve adding an address to.
</ResponseField>

<ResponseField name="walletId" type="string">
  The ID of the internal, external, or contract wallet that you want to approve adding an address to.
</ResponseField>

<ResponseField name="asset" type="string">
  The ID of the asset to add to this wallet. Use [GET supported assets](/api-reference/blockchains-&-assets/list-assets-legacy) request to retrieve more information about an asset.
</ResponseField>

<ResponseField name="address" type="string">
  The asset deposit address requested to be added to the wallet.
</ResponseField>

<ResponseField name="tag" type="string">
  Destination address tag for Ripple; destination memo for EOS, Stellar, Hedera, & DigitalBits; destination note for Algorand; bank transfer description for fiat providers.

  **Note:** For Stellar, the memo must be a string representation of an integer between "0" and "2147483647". Setting the memo to other values for Stellar assets will result in a failed request with an error message.
</ResponseField>

<ResponseField name="additionalInfo" type="object">
  (Optional) Extra address metadata, present only when the whitelisting request originated from certain workspace flows.
</ResponseField>

#### UNMANAGED\_DAPP

An event that involves adding an unmanaged dApp connection to your workspace.

<ResponseField name="dappContainerName" type="string">
  The name of the dApp connection's wallet container.
</ResponseField>

<ResponseField name="walletContainerId" type="string">
  The ID of the dApp connection's wallet container.
</ResponseField>

<ResponseField name="dappName" type="string">
  The name of the dApp.
</ResponseField>

<ResponseField name="dappUrl" type="string">
  The URL of the dApp.
</ResponseField>

<ResponseField name="subType" type="string">
  The dApp connection subtype.
</ResponseField>

#### EXCHANGE, FIAT\_ACCOUNT, and CONNECTED\_ACCOUNT

An event that involves adding an exchange account, fiat account, or connected account to your workspace. All three types share the same fields.

<ResponseField name="subType" type="string">
  The specific exchange, fiat account, or connected account provider.
</ResponseField>

<ResponseField name="accountName" type="string">
  The account's name.
</ResponseField>

<ResponseField name="accountId" type="string">
  The account's ID.
</ResponseField>

<ResponseField name="apiKey" type="string">
  The third-party service's API key. Blank for certain provider subtypes.
</ResponseField>

<ResponseField name="addresses" type="string">
  (Optional) A JSON-formatted "key":"value" string, where "key" is an asset symbol and "value" is its address. There can be multiple entries in the JSON. Only populated for `FIAT_ACCOUNT`. Use [supported\_assets](/api-reference/blockchains-&-assets/list-assets-legacy) to retrieve asset symbols.
</ResponseField>

### Users and devices

#### ADD\_USER

An event that involves adding a user to your workspace.

<ResponseField name="userId" type="string">
  The UUID of the user being added.
</ResponseField>

<ResponseField name="type" type="string">
  The type of the added user: `CONSOLE` or `API`.
</ResponseField>

<ResponseField name="role" type="string">
  The user's assigned role.
</ResponseField>

<ResponseField name="fullName" type="string">
  The user's first and last name.
</ResponseField>

<ResponseField name="email" type="string">
  The user's email address.
</ResponseField>

#### DELETE\_USER

An event that involves removing a user from your workspace.

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="tenantId" type="string">
  The workspace ID.
</ResponseField>

<ResponseField name="type" type="string">
  The configuration request type.
</ResponseField>

<ResponseField name="id" type="string">
  The ID of the user being removed.
</ResponseField>

<ResponseField name="firstName" type="string">
  The user's first name.
</ResponseField>

<ResponseField name="lastName" type="string">
  The user's last name.
</ResponseField>

<ResponseField name="email" type="string">
  The user's email address.
</ResponseField>

<ResponseField name="role" type="string">
  The user's role.
</ResponseField>

<ResponseField name="alerts" type="string">
  A newline-separated list of alerts related to deleting this user (for example, pending requests or owned resources), if any.
</ResponseField>

#### EDIT\_USER\_INFO

An event that involves editing a user's name, email, or role.

<ResponseField name="beforeChangedFirstName" type="string">
  The user's first name before the change.
</ResponseField>

<ResponseField name="beforeChangedLastName" type="string">
  The user's last name before the change.
</ResponseField>

<ResponseField name="beforeChangedEmail" type="string">
  The user's email before the change.
</ResponseField>

<ResponseField name="beforeChangedRole" type="string">
  The user's role before the change.
</ResponseField>

<ResponseField name="requestedFirstName" type="string">
  The requested first name.
</ResponseField>

<ResponseField name="requestedLastName" type="string">
  The requested last name.
</ResponseField>

<ResponseField name="requestedEmail" type="string">
  The requested email.
</ResponseField>

<ResponseField name="requestedRole" type="string">
  The requested role.
</ResponseField>

#### RE\_ENROLL\_DEVICE

An event where an admin re-enrolls a mobile device for one of the users. Unlike `ADD_USER`, this type has no CONSOLE/API field: the `role` value here is deliberately stripped of the `API USER:` prefix, so you can't recover whether the user is a console or API user from this payload.

<ResponseField name="userId" type="string">
  The UUID of the user whose device is being reset.
</ResponseField>

<ResponseField name="role" type="string">
  The user's role, without any console/API user prefix.
</ResponseField>

<ResponseField name="fullName" type="string">
  The user's first and last name.
</ResponseField>

<ResponseField name="email" type="string">
  The user's email address.
</ResponseField>

### Cosigner and device pairing

#### COSIGNER\_CHANGE\_CALLBACK and PAIR\_VIRTUAL\_DEVICE

`COSIGNER_CHANGE_CALLBACK` changes the callback configuration (URL, certificate, JWT public key) of a device that's already paired. `PAIR_VIRTUAL_DEVICE` pairs a new virtual (non-mobile) device using a pairing token.

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="tenantId" type="string">
  The workspace ID.
</ResponseField>

<ResponseField name="userId" type="string">
  The ID of the API user being paired.
</ResponseField>

<ResponseField name="userType" type="string">
  The type of the paired user: `CONSOLE` or `API`.
</ResponseField>

<ResponseField name="name" type="string">
  The paired user's first name.
</ResponseField>

<ResponseField name="role" type="string">
  The paired user's role, including any console/API user prefix.
</ResponseField>

<ResponseField name="pairingToken" type="string" post={["PAIR_VIRTUAL_DEVICE only"]}>
  Always `null` in this payload for both types. The actual pairing token is generated after approval and delivered separately.
</ResponseField>

<ResponseField name="customerServerURL" type="string">
  Your customer server URL to pair with.
</ResponseField>

<ResponseField name="customerServerCert" type="string">
  Your customer server certificate.
</ResponseField>

<ResponseField name="customerJWTPubkey" type="string">
  Your customer JWT public key.
</ResponseField>

<ResponseField name="physicalDeviceId" type="string">
  The physical device identifier.
</ResponseField>

<ResponseField name="deviceId" type="string" post={["COSIGNER_CHANGE_CALLBACK only"]}>
  The device identifier.
</ResponseField>

<ResponseField name="requestId" type="string">
  Always `null` in this payload for both types. Use the callback's top-level `requestId` instead.
</ResponseField>

### Quorum and MPC configuration

#### CHANGE\_QUORUM\_THRESHOLD

An event where the admin updates the quorum threshold.

<ResponseField name="oldThreshold" type="number">
  The quorum threshold before the change.
</ResponseField>

<ResponseField name="newThreshold" type="number">
  The requested quorum threshold.
</ResponseField>

#### CONFIGURE\_OWNER\_IN\_ADMIN\_QUORUM

An event that changes whether the workspace owner counts toward the admin quorum.

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="tenantId" type="string">
  The workspace ID.
</ResponseField>

<ResponseField name="ownerInQuorum" type="boolean">
  Whether the workspace owner counts toward the admin quorum.
</ResponseField>

#### SET\_MPC\_PROVISIONER

An event that designates a user as an MPC provisioner.

<ResponseField name="userId" type="string">
  Always `null` in this payload — no producer currently populates it.
</ResponseField>

<ResponseField name="isMPCProvisioner" type="boolean">
  Whether the user is set as an MPC provisioner.
</ResponseField>

### IP allow list

#### ACTIVATE\_IP\_ALLOW\_LIST

An event that turns the IP allow list on or off.

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="tenantId" type="string">
  The workspace ID.
</ResponseField>

<ResponseField name="type" type="string">
  The configuration request type.
</ResponseField>

<ResponseField name="activate" type="boolean">
  Whether the IP allow list is being turned on or off.
</ResponseField>

<ResponseField name="ruleId" type="string">
  The ID of the allow list rule.
</ResponseField>

#### ADD\_IP\_ADDRESS

An event that adds an IP address to the allow list.

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="tenantId" type="string">
  The workspace ID.
</ResponseField>

<ResponseField name="type" type="string">
  The configuration request type.
</ResponseField>

<ResponseField name="name" type="string">
  The label for this IP address entry.
</ResponseField>

<ResponseField name="ipAddress" type="string">
  The IP address being added.
</ResponseField>

<ResponseField name="id" type="string">
  The ID of this IP address entry.
</ResponseField>

<ResponseField name="ruleId" type="string">
  The ID of the allow list rule.
</ResponseField>

<ResponseField name="createdAt" type="string">
  When this entry was created.
</ResponseField>

<ResponseField name="updatedAt" type="string">
  When this entry was last updated.
</ResponseField>

#### DELETE\_IP\_ADDRESS

An event that removes an IP address from the allow list.

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="tenantId" type="string">
  The workspace ID.
</ResponseField>

<ResponseField name="type" type="string">
  The configuration request type.
</ResponseField>

<ResponseField name="name" type="string">
  The label for this IP address entry.
</ResponseField>

<ResponseField name="ipAddress" type="string">
  The IP address being removed.
</ResponseField>

<ResponseField name="id" type="string">
  The ID of this IP address entry.
</ResponseField>

<ResponseField name="ruleId" type="string">
  The ID of the allow list rule.
</ResponseField>

<ResponseField name="createdAt" type="string">
  When this entry was created.
</ResponseField>

<ResponseField name="updatedAt" type="string">
  When this entry was last updated.
</ResponseField>

<ResponseField name="ipId" type="string">
  The ID of the removed IP address.
</ResponseField>

#### UPDATE\_IP\_ADDRESS

An event that updates an existing IP address on the allow list.

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="tenantId" type="string">
  The workspace ID.
</ResponseField>

<ResponseField name="type" type="string">
  The configuration request type.
</ResponseField>

<ResponseField name="name" type="string">
  The current label for this IP address entry.
</ResponseField>

<ResponseField name="newName" type="string">
  The requested label for this IP address entry.
</ResponseField>

<ResponseField name="ipAddress" type="string">
  The current IP address.
</ResponseField>

<ResponseField name="newAddress" type="string">
  The requested IP address.
</ResponseField>

<ResponseField name="id" type="string">
  The ID of this IP address entry.
</ResponseField>

<ResponseField name="ruleId" type="string">
  The ID of the allow list rule.
</ResponseField>

<ResponseField name="createdAt" type="string">
  When this entry was created.
</ResponseField>

<ResponseField name="updatedAt" type="string">
  When this entry was last updated.
</ResponseField>

<ResponseField name="ipId" type="string">
  The ID of the updated IP address.
</ResponseField>

### dApp connections and MEV protection

#### ENABLE\_ONE\_TIME\_ADDRESS

An event which involves enabling a particular transaction to a one-time address in the workspace. This type has no `extraInfo` fields.

#### ENABLE\_NON\_EVM\_DAPPS\_CONNECTIONS

An event that enables dApp connections for non-EVM blockchains.

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="tenantId" type="string">
  The workspace ID.
</ResponseField>

<ResponseField name="type" type="string">
  The configuration request type.
</ResponseField>

#### ENABLE\_MEV\_DAPPS, DISABLE\_MEV\_DAPPS, ENABLE\_MEV\_API, and DISABLE\_MEV\_API

An event that enables or disables MEV protection for dApp connections or API-initiated transactions. All four types share the same fields.

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="tenantId" type="string">
  The workspace ID.
</ResponseField>

<ResponseField name="type" type="string">
  The configuration request type.
</ResponseField>

### Fireblocks Network

#### ADD\_NETWORK\_CONNECTION

An event of adding a Fireblocks Network new connection.

<ResponseField name="networkConnectionId" type="string">
  ID of network connection
</ResponseField>

<ResponseField name="note" type="string">
  Connection note
</ResponseField>

<ResponseField name="localNetworkId" type="string">
  ID of local networkId
</ResponseField>

<ResponseField name="remoteNetworkId" type="string">
  ID of the remote peer's networkId
</ResponseField>

<ResponseField name="remoteTenantId" type="string">
  ID of remote peer tenantId
</ResponseField>

<ResponseField name="routingPolicy" type="string">
  (Optional) JSON representation of routing policy object. Only included in the payload sent to the connection's initiating tenant, not the receiving tenant.
</ResponseField>

#### SET\_NETWORK\_CONNECTION\_ROUTING\_POLICY

An event where the admin configures the routing policy for each network connection.

<ResponseField name="connectionId" type="string">
  ID of network connection
</ResponseField>

<ResponseField name="routingPolicy" type="string">
  JSON representation of routing policy object
</ResponseField>

#### SET\_NETWORK\_ID\_POLICY

An event of setting up the Fireblocks Network *Network ID* in case its profile is not discoverable.

<ResponseField name="networkId" type="string">
  ID of networkID
</ResponseField>

<ResponseField name="routingPolicy" type="string">
  JSON representation of routing policy object
</ResponseField>

### Policies and approval groups

#### POLICY\_APPROVAL

An event that involves updating the Transaction Authorization Policy.

<ResponseField name="origEditorId" type="string">
  The ID of the user who originally edited the policy.
</ResponseField>

<ResponseField name="origEditor" type="string">
  The name of the user who originally edited the policy.
</ResponseField>

<ResponseField name="editorId" type="string">
  The ID of the user who most recently edited the policy.
</ResponseField>

<ResponseField name="editor" type="string">
  The name of the user who most recently edited the policy.
</ResponseField>

<ResponseField name="editTime" type="number">
  When the policy was edited, in Unix epoch time.
</ResponseField>

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="publisher" type="string">
  The name of the user who published the policy.
</ResponseField>

<ResponseField name="publishTime" type="number">
  When the policy was published, in Unix epoch time.
</ResponseField>

<ResponseField name="allowRules" type="number">
  (Optional) The number of allow rules in the policy.
</ResponseField>

<ResponseField name="blockRules" type="number">
  (Optional) The number of block rules in the policy.
</ResponseField>

<ResponseField name="twoTierRules" type="number">
  (Optional) The number of two-tier approval rules in the policy.
</ResponseField>

#### POLICY\_CHANGE

An event that involves a pending edit to the Transaction Authorization Policy before it's published.

<ResponseField name="origEditorId" type="string">
  The ID of the user who originally edited the policy.
</ResponseField>

<ResponseField name="origEditor" type="string">
  The name of the user who originally edited the policy.
</ResponseField>

<ResponseField name="editorId" type="string">
  The ID of the user who most recently edited the policy.
</ResponseField>

<ResponseField name="editor" type="string">
  The name of the user who most recently edited the policy.
</ResponseField>

<ResponseField name="editTime" type="number">
  When the policy was edited, in Unix epoch time.
</ResponseField>

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="publisher" type="string">
  The name of the user who published the policy.
</ResponseField>

<ResponseField name="publishTime" type="number">
  When the policy was published, in Unix epoch time.
</ResponseField>

<ResponseField name="actionCounters" type="object">
  (Optional) A summary of pending rule changes. Keys combine the rule type and verdict action (for example, `transferALLOWRules`); values are display strings such as `"3 Rules"`, not numeric counts. For a change spanning multiple policies, only the last policy's counters are present.
</ResponseField>

#### UPDATE\_APPROVAL\_GROUP\_MAPPING

An event involving gathering a list of approvers for a particular admin operation.

<ResponseField name="creatorFirstName" type="string">
  The first name of the user who initiated the request.
</ResponseField>

<ResponseField name="creatorLastName" type="string">
  The last name of the user who initiated the request.
</ResponseField>

<ResponseField name="ccrType" type="string">
  The admin operation type this approval group mapping applies to.
</ResponseField>

<ResponseField name="isOwnerMandatory" type="boolean">
  Whether the workspace owner must be included in the approval group.
</ResponseField>

<ResponseField name="newGroupId" type="string">
  The ID of the requested approval group.
</ResponseField>

<ResponseField name="newThreshold" type="number">
  The requested approval threshold.
</ResponseField>

<ResponseField name="newGroupName" type="string">
  The name of the requested approval group.
</ResponseField>

<ResponseField name="groupMembersCount" type="number">
  The number of members in the requested approval group.
</ResponseField>

<ResponseField name="timestamp" type="number">
  When the request was created, in Unix epoch seconds.
</ResponseField>

#### USERS\_GROUP\_APPROVAL

An event that involves creating, editing, or deleting a user group in your workspace. The fields included depend on the `subType`.

<ResponseField name="subType" type="string">
  `CREATE_USERS_GROUP`, `EDIT_USERS_GROUP`, or `DELETE_USERS_GROUP`.
</ResponseField>

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="groupId" type="string">
  The ID of the user group.
</ResponseField>

<ResponseField name="groupName" type="string">
  The name of the user group.
</ResponseField>

<ResponseField name="pendingChanges" type="array">
  A list of the pending changes to the group.

  <Expandable title="entry object">
    <ResponseField name="type" type="string">
      `RENAMED_TITLE`, `ADDED_USER`, `REMOVED_USER`, or `DELETE_GROUP`.
    </ResponseField>

    <ResponseField name="title" type="string">
      (Optional) The new group name. Present when `type` is `RENAMED_TITLE`.
    </ResponseField>

    <ResponseField name="userId" type="string">
      (Optional) The affected user's ID. Present when `type` is `ADDED_USER` or `REMOVED_USER`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="membersSummary" type="array">
  A breakdown of the group's members by role, plus a `total` entry.

  <Expandable title="entry object">
    <ResponseField name="key" type="string">
      A role name, or `total` for the overall member count.
    </ResponseField>

    <ResponseField name="value" type="number">
      The number of members for this `key`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="newGroupName" type="string">
  (Optional) The requested group name. Included when `subType` is `EDIT_USERS_GROUP`.
</ResponseField>

<ResponseField name="addedUsers" type="array">
  (Optional) Users added to the group. Included when `subType` is `CREATE_USERS_GROUP` or `EDIT_USERS_GROUP`.

  <Expandable title="entry object">
    <ResponseField name="fullName" type="string">
      The user's first and last name.
    </ResponseField>

    <ResponseField name="role" type="string">
      The user's role.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="removedUsers" type="array">
  (Optional) Users removed from the group. Included when `subType` is `EDIT_USERS_GROUP`. Same entry shape as `addedUsers`.
</ResponseField>

<ResponseField name="membersIds" type="array">
  (Optional) The IDs of the group's members, as strings. Included when `subType` is `CREATE_USERS_GROUP` or `EDIT_USERS_GROUP`.
</ResponseField>

<ResponseField name="groupMembers" type="array">
  (Optional) The group's members. Included when `subType` is `DELETE_USERS_GROUP`. Same entry shape as `addedUsers`.
</ResponseField>

#### REGISTER\_EXTERNAL\_KEYS\_VALIDATOR\_KEY

An event that registers a validator key for External Keys.

<ResponseField name="creatorFirstName" type="string">
  The first name of the user who initiated the request.
</ResponseField>

<ResponseField name="creatorLastName" type="string">
  The last name of the user who initiated the request.
</ResponseField>

<ResponseField name="validatorKey" type="string">
  The validator key being registered.
</ResponseField>

### Automation rules

#### ADD\_ACTIVE\_AUTOMATION\_RULE, ADD\_INACTIVE\_AUTOMATION\_RULE, EDIT\_AUTOMATION\_RULE, DELETE\_AUTOMATION\_RULE, ACTIVATE\_AUTOMATION\_RULE, and DEACTIVATE\_AUTOMATION\_RULE

An event that adds, edits, deletes, activates, or deactivates an automation rule. All six types share the same fields.

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="tenantId" type="string">
  The workspace ID.
</ResponseField>

<ResponseField name="type" type="string">
  The configuration request type.
</ResponseField>

<ResponseField name="request" type="object">
  The full automation rule definition submitted for this change. Its schema is defined by the Automation Rules API.
</ResponseField>

### Protected tags

Editing, deleting, attaching, and detaching a [protected tag](/docs/tags#protected-tags-and-the-approval-flow) requires quorum approval. These events carry those changes.

#### EDIT\_PROTECTED\_TAG

An event that edits a protected tag.

<ResponseField name="tagId" type="string">
  The ID of the protected tag.
</ResponseField>

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="operationData" type="object">
  The requested changes to the tag, as `newTag` and `previousTag` objects with the same shape.

  <Expandable title="properties">
    <ResponseField name="newTag" type="object">
      The tag's state after the edit.

      <Expandable title="properties">
        <ResponseField name="tagId" type="string">
          The tag's ID.
        </ResponseField>

        <ResponseField name="label" type="string">
          The tag's label.
        </ResponseField>

        <ResponseField name="color" type="string">
          The tag's color.
        </ResponseField>

        <ResponseField name="description" type="string">
          The tag's description.
        </ResponseField>

        <ResponseField name="isProtected" type="boolean">
          Whether the tag is protected.
        </ResponseField>

        <ResponseField name="tagType" type="string">
          The tag's type.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="previousTag" type="object">
      The tag's state before the edit. Same fields as `newTag`.
    </ResponseField>
  </Expandable>
</ResponseField>

#### DELETE\_PROTECTED\_TAG

An event that deletes a protected tag.

<ResponseField name="tagId" type="string">
  The ID of the protected tag.
</ResponseField>

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="protectedTag" type="object">
  (Optional) The tag being deleted.

  <Expandable title="properties">
    <ResponseField name="label" type="string">
      The tag's label.
    </ResponseField>

    <ResponseField name="description" type="string">
      The tag's description.
    </ResponseField>

    <ResponseField name="color" type="string">
      The tag's color.
    </ResponseField>

    <ResponseField name="tagType" type="string">
      The tag's type.
    </ResponseField>

    <ResponseField name="typeName" type="string">
      The tag type's display name.
    </ResponseField>
  </Expandable>
</ResponseField>

#### ATTACH\_AND\_DETACH\_PROTECTED\_TAGS

An event that attaches or detaches protected tags on one or more entities.

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="entities" type="array">
  (Optional) The entities being tagged or untagged.

  <Expandable title="entry object">
    <ResponseField name="text" type="string">
      The entity's display name.
    </ResponseField>

    <ResponseField name="id" type="string">
      The entity's ID.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="attachedTags" type="array">
  (Optional) The tags being attached.

  <Expandable title="entry object">
    <ResponseField name="label" type="string">
      The tag's label.
    </ResponseField>

    <ResponseField name="description" type="string">
      The tag's description.
    </ResponseField>

    <ResponseField name="color" type="string">
      The tag's color.
    </ResponseField>

    <ResponseField name="tagId" type="string">
      The tag's ID.
    </ResponseField>

    <ResponseField name="tagType" type="string">
      The tag's type.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="detachedTags" type="array">
  (Optional) The tags being detached. Same entry shape as `attachedTags`.
</ResponseField>

#### CREATE\_ENTITIES\_WITH\_TAG\_ATTACHMENTS

An event that creates entities with protected tags attached.

<ResponseField name="creator" type="string">
  The ID of the user who initiated the request.
</ResponseField>

<ResponseField name="tenantId" type="string">
  The workspace ID.
</ResponseField>

<ResponseField name="tagIds" type="array">
  (Optional) The IDs of the tags being attached.
</ResponseField>

<ResponseField name="entityType" type="number">
  (Optional) The type of entity being created: `1` for a vault account, `2` for a contact.
</ResponseField>

<ResponseField name="entityCount" type="number">
  (Optional) The number of entities being created.
</ResponseField>

<ResponseField name="maxEntityId" type="number">
  (Optional) The highest existing vault account ID at request time, used as a floor for the newly created IDs. Only present when `entityType` is `1` (vault account).
</ResponseField>

<ResponseField name="tags" type="object">
  (Optional) The tags being attached. Unlike `ATTACH_AND_DETACH_PROTECTED_TAGS`, this field isn't unwrapped to a plain array before being sent — the tag list is nested under `values`.

  <Expandable title="properties">
    <ResponseField name="arrayTitle" type="object">
      A display label for this list, for Fireblocks' own UI. Not something a callback handler needs to act on.

      <Expandable title="properties">
        <ResponseField name="singular" type="string">
          Singular form of the label. Always `"Tag"`.
        </ResponseField>

        <ResponseField name="plural" type="string">
          Plural form of the label. Always `"Tags"`.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="values" type="array">
      The tags being attached.

      <Expandable title="tag object">
        <ResponseField name="label" type="string">
          The tag's label.
        </ResponseField>

        <ResponseField name="description" type="string">
          The tag's description.
        </ResponseField>

        <ResponseField name="color" type="string">
          The tag's color.
        </ResponseField>

        <ResponseField name="tagId" type="string">
          The tag's ID.
        </ResponseField>

        <ResponseField name="tagType" type="string">
          The tag's type.
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>
