- Who will initiate transactions?
- Who will approve transactions?
- Who will sign off on transactions?
Which API roles can initiate vs. sign transactions
Signing is a distinct step from initiating a transaction. A Non-Signing Admin or Editor API user can still callPOST /transactions to create a transaction, provided the Transaction Authorization Policy (TAP) permits it. An Approver cannot initiate transactions, only approve them. A separate Signing API user (typically paired with an API Co-signer) then signs the initiated request based on the TAP rule.
This lets you split responsibilities across API users. For example, an application server can use an Editor API key to initiate a transaction, while an API Co-signer paired with a Signer API user handles the actual signing.
The TAP rule that matches the transaction ultimately controls whether a specific initiator, source, destination, and signer combination is allowed. Confirm your TAP rules include the initiator you intend to use.