Skip to content
Français

signWorkflowDecision

import { signWorkflowDecision } from "@elie-laloum/outpost";

Sign one exact decision with an application-owned Ed25519 private key and return a frozen copy carrying its proof. It neither submits the decision nor stores the key. Throws on a non-Ed25519 key, a blank decision field or key identifier, or an expiresAt that is not in the future.

Complete example and detailed rules.

  • optionsRequired
    WorkflowDecisionSigningOptions
    Exact decision, Ed25519 private key, key identifier and future expiration to sign.
  • options.decisionRequired
    Omit<WorkflowDecision, "proof">
    Exact execution, pending request, task, actor, action and reason to sign, without an existing proof.
  • options.keyIdRequired
    string
    Identifier of the matching trusted public key, nonblank and at most 512 characters; signed with the decision and copied into the proof.
  • options.privateKeyRequired
    KeyObject
    Ed25519 private KeyObject owned by your application; any other key type throws. Outpost never stores it.
  • options.expiresAtRequired
    string
    Proof expiry, parseable by Date.parse and later than now; the exact string is signed.

WorkflowDecision

export declare function signWorkflowDecision(
  options: WorkflowDecisionSigningOptions,
): WorkflowDecision;