> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trusset.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Request Instrument Approval

> The exact message the token controller signs before your platform submits its record

Returns the message the token's on-chain controller signs so your instance can publish the instrument record on the controller's behalf. Send the same body you will send to [Save Instrument](/endpoints/tokenization/save-instrument). The request runs every check the save runs on that body and writes nothing, so a record that would be refused is refused before anybody signs.

This is the first call of the [issuer-signed flow](/endpoints/tokenization/issuer-signed-record). Your instance needs no role on the token: the controller's signature is the authority, and it is checked on chain when the record is saved.

## Path Parameters

<ParamField path="tokenAddress" type="string" required>The token contract address. It has to be an active import of your instance.</ParamField>

## Body Parameters

<ParamField body="instrument" type="object">The record fields, exactly as you will send them to [Save Instrument](/endpoints/tokenization/save-instrument).</ParamField>
<ParamField body="documents" type="array">The documents, exactly as you will send them.</ParamField>
<ParamField body="presentation" type="object">The overview, when you send it with the record.</ParamField>
<ParamField body="takeOver" type="boolean">Send `true` when `takeOverRequired` says another instance asserts the current record. It is not part of the signed content when the body carries any record content.</ParamField>

## Response Fields

<ResponseField name="data" type="object">
  <Expandable>
    <ResponseField name="message" type="string">The text the controller signs, unchanged. It names the token, the chain, your instance, the content digest, the record version and the signing time.</ResponseField>
    <ResponseField name="contentDigest" type="string">keccak256 over the canonical JSON of the record content. See [the content digest](/endpoints/tokenization/issuer-signed-record#the-content-digest).</ResponseField>
    <ResponseField name="recordVersion" type="integer">The version the approval applies to, `0` when no record exists yet.</ResponseField>
    <ResponseField name="chainId" type="integer">The chain the record belongs to.</ResponseField>
    <ResponseField name="signedAt" type="string">The signing time written into the message. Send it back unchanged.</ResponseField>
    <ResponseField name="expiresAt" type="string">Ten minutes after `signedAt`. A save after that is refused with `ISSUER_APPROVAL_EXPIRED`.</ResponseField>
    <ResponseField name="takeOverRequired" type="boolean">`true` when another instance asserts the current record, so the save needs `takeOver: true`.</ResponseField>
    <ResponseField name="signWith" type="string">Which wallets can sign and how.</ResponseField>
    <ResponseField name="issuerApproval" type="object">The `issuerApproval` object for the save, with `signer` and `signature` left for you to fill.</ResponseField>
  </Expandable>
</ResponseField>

<RequestExample>
  ```bash cURL theme={null}
  curl -X POST "https://api.trusset.org/instruments/api/0x9f8c1d4b2e7a3056c1b8f4d29e0a7c3518b6d24f/approval-request" \
    -H "X-API-Key: trusset_your_key_here" \
    -H "Content-Type: application/json" \
    -d '{
      "instrument": { "securityClass": "BOND", "isin": "DE000A0F5UF5", "currency": "EUR" },
      "documents": []
    }'
  ```
</RequestExample>

<ResponseExample>
  ```json Response theme={null}
  {
    "success": true,
    "data": {
      "tokenAddress": "0x9f8c1d4b2e7a3056c1b8f4d29e0a7c3518b6d24f",
      "chainId": 11155111,
      "instanceId": "inst_abc123",
      "contentDigest": "0x7d3a1c0e2f9b4a6d8c5e3f1a0b9c7d5e3f1a2b4c6d8e0f1a3b5c7d9e1f3a5b7c",
      "recordVersion": 0,
      "signedAt": "2026-10-07T14:33:39.000Z",
      "expiresAt": "2026-10-07T14:43:39.000Z",
      "message": "Trusset instrument record\nToken: 0x9f8c1d4b2e7a3056c1b8f4d29e0a7c3518b6d24f on chain 11155111\nInstance: inst_abc123\nContent digest: 0x7d3a1c0e2f9b4a6d8c5e3f1a0b9c7d5e3f1a2b4c6d8e0f1a3b5c7d9e1f3a5b7c\nRecord version: 0\nSigned at: 2026-10-07T14:33:39.000Z",
      "takeOverRequired": false,
      "signWith": "personal_sign (EIP-191) by the token's owner, one of its agents or a holder of its admin role; a contract wallet signs through ERC-1271",
      "issuerApproval": { "signer": null, "signature": null, "recordVersion": 0, "signedAt": "2026-10-07T14:33:39.000Z" }
    }
  }
  ```
</ResponseExample>

## Error Codes

| Code | HTTP | Cause |
| - | - | - |
| `INVALID_ADDRESS` | `400` | `tokenAddress` is not a valid address |
| `INVALID_INSTRUMENT` | `400` | The body carries an unknown member, or a record field failed validation. `details` names every failing field |
| `INVALID_DOCUMENTS` | `400` | A document failed validation |
| `INVALID_PRESENTATION` | `400` | An overview field failed validation |
| `IMPORT_NOT_FOUND` | `404` | The token is not an active import of your instance |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.