Proteside Docs
Endpoint referenceScripts

Authorize a script (PCI 6.4.3 justification required)

POST
/scripts/{id}/authorize

Sets status = authorized, authorization_method = api, authorized_by = api:<prefix>, records a review and deactivates any block rule matching the script. expires_days sets expires_at / review_due_at.

Authorization

bearerAuth
headerAuthorizationBearer <token>

API token created in Settings → API. Scopes are attached to the token; each operation lists its required scope in x-scope.

Path Parameters

id*string
Formatuuid

Query Parameters

org_id?string

Partners only (orgs:manage): act on this child organization. May also be sent as org_id in JSON bodies.

Formatuuid

Header Parameters

Idempotency-Key?string

Replays the original response for 24 h

Length1 <= length <= 255

Request Body

application/json
  1. body
justification*string
Length10 <= length <= 2000
expires_days?integer
Range1 <= value <= 3650

Response Body

Authorized script

application/json
  1. response
id?string
Formatuuid
store_id?string
Formatuuid
src?string
type?|
Value in"first_party""known_third""unknown"null
category?string|null
status?string
Value in"trusted""needs_review""suspicious""malicious""authorized""blocked"
integrity_status?|
Value in"match""mismatch""pending""monitored""blocked"null
current_hash?string|null
authorized_hash?string|null
hash_source?string|null
sri_hash?string|null
integrity_attr?boolean|null
size_bytes?integer|null
vendor_id?string|null
gtm_container?string|null
authorization_method?|
Value in"manual""auto""policy""ai_assisted""import""api""expiry""integrity""system"null
authorized_by?string|null
justification?string|null
policy_id?|
Formatuuid
policy_version?integer|null
reviewed_at?|
Formatdate-time
expires_at?|
Formatdate-time
review_due_at?|
Formatdate-time
first_seen_at?string
Formatdate-time
last_seen_at?string
Formatdate-time
last_verified_at?|
Formatdate-time
last_hash_change_at?|
Formatdate-time
block_rules_deactivated?boolean
curl -X POST "https://example.com/scripts/497f6eca-6276-4993-bfeb-53cbbbba6f08/authorize" \  -H "Content-Type: application/json" \  -d '{    "justification": "Google Tag Manager container owned by the marketing team; no access to payment fields.",    "expires_days": 90  }'
{  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",  "store_id": "7fe87115-950c-4ae8-bd7e-970406bc9ac0",  "src": "string",  "type": "first_party",  "category": "string",  "status": "trusted",  "integrity_status": "match",  "current_hash": "string",  "authorized_hash": "string",  "hash_source": "string",  "sri_hash": "string",  "integrity_attr": true,  "size_bytes": 0,  "vendor_id": "string",  "gtm_container": "string",  "authorization_method": "manual",  "authorized_by": "string",  "justification": "string",  "policy_id": "ee9b03e0-6495-427a-85a5-34444d24ae04",  "policy_version": 0,  "reviewed_at": "2019-08-24T14:15:22Z",  "expires_at": "2019-08-24T14:15:22Z",  "review_due_at": "2019-08-24T14:15:22Z",  "first_seen_at": "2019-08-24T14:15:22Z",  "last_seen_at": "2019-08-24T14:15:22Z",  "last_verified_at": "2019-08-24T14:15:22Z",  "last_hash_change_at": "2019-08-24T14:15:22Z",  "block_rules_deactivated": true}