Skip to content
Registry StackDocsDevelopment (unreleased)

Check current resource-bound task authority

GET
/v1/task-grants/{grant_id}/status
curl --request GET \
--url https://casework.example.test/v1/task-grants/2489E9AD-2EE2-8E00-8EC9-32D5F69181C0/status \
--header 'Authorization: Bearer <token>'

Requires a service token with casework:grants:status and the registered client for the grant resource. Returns fresh status after Directory and source checks. Consumers must compare every bound and enforce expiresAt. An unavailable check grants no authority.

grant_id
required
string format: uuid

Immutable task grant identifier.

traceparent
string

Optional W3C trace context continued in the response.

Success

Media typeapplication/json
object
active
required
boolean
grant
object
bounds
required
One of:
object
requirement
required
string
>= 1 characters <= 512 characters
type
required
Allowed value: evidence
client
required
string
>= 1 characters <= 512 characters
expiresAt
required
integer
grantId
required
string format: uuid
principal
required
string
>= 1 characters <= 512 characters
purpose
required
string
>= 1 characters <= 512 characters
resource
required
string
>= 1 characters <= 512 characters
sourceIssuer
required
string
>= 1 characters <= 512 characters
subjects
required
object
<= 32 properties
key
additional properties
string | integer | boolean
Example
{
"grant": {
"bounds": {
"type": "evidence"
}
}
}
traceparent
string

W3C trace context for the request and response.

Problem response: request.invalid

Media typeapplication/problem+json
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: request.invalid
detail
required
Allowed value: The Casework request is invalid.
status
required
Allowed value: 400
title
required
Allowed value: Invalid request
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/request/invalid
Example
{
"code": "request.invalid",
"detail": "The Casework request is invalid.",
"status": 400,
"title": "Invalid request",
"type": "https://id.registrystack.org/problems/registry-casework/request/invalid"
}
traceparent
string

W3C trace context for the request and response.

Problem response: authentication.refused

Media typeapplication/problem+json
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: authentication.refused
detail
required
Allowed value: The bearer credential is missing, invalid, or expired. Sign in again.
status
required
Allowed value: 401
title
required
Allowed value: Authentication refused
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/authentication/refused
Example
{
"code": "authentication.refused",
"detail": "The bearer credential is missing, invalid, or expired. Sign in again.",
"status": 401,
"title": "Authentication refused",
"type": "https://id.registrystack.org/problems/registry-casework/authentication/refused"
}
WWW-Authenticate
Allowed value: Bearer

Bearer authentication challenge.

traceparent
string

W3C trace context for the request and response.

Problem response: operation.not-authorized, profile.not-authorized, profile.not-human

Media typeapplication/problem+json
One of:
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: operation.not-authorized
detail
required
Allowed value: Your current Casework authority does not allow this operation.
status
required
Allowed value: 403
title
required
Allowed value: Operation not authorized
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/operation/not-authorized
Example
{
"code": "operation.not-authorized",
"detail": "Your current Casework authority does not allow this operation.",
"status": 403,
"title": "Operation not authorized",
"type": "https://id.registrystack.org/problems/registry-casework/operation/not-authorized"
}
traceparent
string

W3C trace context for the request and response.

Problem response: source.not-found, work-item.not-visible

Media typeapplication/problem+json
One of:
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: source.not-found
detail
required
Allowed value: The requested source is not registered.
status
required
Allowed value: 404
title
required
Allowed value: Source not found
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/source/not-found
Example
{
"code": "source.not-found",
"detail": "The requested source is not registered.",
"status": 404,
"title": "Source not found",
"type": "https://id.registrystack.org/problems/registry-casework/source/not-found"
}
traceparent
string

W3C trace context for the request and response.

Problem response: request.method-not-allowed

Media typeapplication/problem+json
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: request.method-not-allowed
detail
required
Allowed value: This route does not accept that HTTP method.
status
required
Allowed value: 405
title
required
Allowed value: Method not allowed
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/request/method-not-allowed
Example
{
"code": "request.method-not-allowed",
"detail": "This route does not accept that HTTP method.",
"status": 405,
"title": "Method not allowed",
"type": "https://id.registrystack.org/problems/registry-casework/request/method-not-allowed"
}
traceparent
string

W3C trace context for the request and response.

Problem response: work-item.proposal-changed, work-item.not-offered, work-item.recovery-pending

Media typeapplication/problem+json
One of:
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: work-item.proposal-changed
detail
required
Allowed value: The proposal changed since you read it. Your private draft is retained.
status
required
Allowed value: 409
title
required
Allowed value: Work item proposal changed
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/work-item/proposal-changed
Example
{
"code": "work-item.proposal-changed",
"detail": "The proposal changed since you read it. Your private draft is retained.",
"status": 409,
"title": "Work item proposal changed",
"type": "https://id.registrystack.org/problems/registry-casework/work-item/proposal-changed"
}
Registry-Casework-Attempt
string format: uuid

Original attempt UUID, present only when the entitled recovery-pending response can disclose it.

traceparent
string

W3C trace context for the request and response.

Problem response: precondition.failed

Media typeapplication/problem+json
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: precondition.failed
detail
required
Allowed value: The item or directory changed since you loaded it. Reload and try again.
status
required
Allowed value: 412
title
required
Allowed value: Precondition failed
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/precondition/failed
Example
{
"code": "precondition.failed",
"detail": "The item or directory changed since you loaded it. Reload and try again.",
"status": 412,
"title": "Precondition failed",
"type": "https://id.registrystack.org/problems/registry-casework/precondition/failed"
}
traceparent
string

W3C trace context for the request and response.

Problem response: request.body-too-large

Media typeapplication/problem+json
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: request.body-too-large
detail
required
Allowed value: The request body exceeds the one MiB limit.
status
required
Allowed value: 413
title
required
Allowed value: Request body too large
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/request/body-too-large
Example
{
"code": "request.body-too-large",
"detail": "The request body exceeds the one MiB limit.",
"status": 413,
"title": "Request body too large",
"type": "https://id.registrystack.org/problems/registry-casework/request/body-too-large"
}
traceparent
string

W3C trace context for the request and response.

Problem response: runtime.failure

Media typeapplication/problem+json
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: runtime.failure
detail
required
Allowed value: Casework could not complete the request.
status
required
Allowed value: 500
title
required
Allowed value: Casework runtime failure
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/runtime/failure
Example
{
"code": "runtime.failure",
"detail": "Casework could not complete the request.",
"status": 500,
"title": "Casework runtime failure",
"type": "https://id.registrystack.org/problems/registry-casework/runtime/failure"
}
traceparent
string

W3C trace context for the request and response.

Problem response: source.bad-gateway

Media typeapplication/problem+json
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: source.bad-gateway
detail
required
Allowed value: The source returned a response that does not match its registered contract.
status
required
Allowed value: 502
title
required
Allowed value: Invalid source response
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/source/bad-gateway
Example
{
"code": "source.bad-gateway",
"detail": "The source returned a response that does not match its registered contract.",
"status": 502,
"title": "Invalid source response",
"type": "https://id.registrystack.org/problems/registry-casework/source/bad-gateway"
}
traceparent
string

W3C trace context for the request and response.

Problem response: service.unavailable, work-item.source-unavailable

Media typeapplication/problem+json
One of:
object
code
required
string
Allowed values: absence.cover-cycle absence.invalid-period absence.overlap absence.self-cover authentication.refused clock.recompute-preview-expired cursor.expired cursor.invalid idempotency.expired idempotency.key-reused operation.not-authorized precondition.failed precondition.required profile.not-authorized profile.not-human request.body-too-large request.invalid request.method-not-allowed request.not-found request.reason-unsupported request.source-rejected request.unprocessable request.unsupported-media-type runtime.failure service.unavailable source-profile.not-applicable source-profile.required source.bad-gateway source.not-found source.record-missing source.reviewer-not-authorized source.signature-invalid work-item.already-claimed work-item.not-holder work-item.not-offered work-item.not-visible work-item.proposal-changed work-item.recovery-pending work-item.source-unavailable work-item.superseded
detail
required
string
status
required
integer
title
required
string
traceId
required
string
type
required
string format: uri
code
required
Allowed value: service.unavailable
detail
required
Allowed value: Casework storage is unavailable. Try again after the service recovers.
status
required
Allowed value: 503
title
required
Allowed value: Casework service unavailable
type
required
Allowed value: https://id.registrystack.org/problems/registry-casework/service/unavailable
Example
{
"code": "service.unavailable",
"detail": "Casework storage is unavailable. Try again after the service recovers.",
"status": 503,
"title": "Casework service unavailable",
"type": "https://id.registrystack.org/problems/registry-casework/service/unavailable"
}
Retry-After
integer

Seconds before retrying the unavailable dependency.

traceparent
string

W3C trace context for the request and response.