Seal a decision chain
Seals a chain, proving completeness. No more steps can be added after sealing. Returns 422 (CHAIN_SEAL_NOT_TERMINAL) if the last step is a held REVIEW decision rather than a terminal disposition (ALLOW/DENY/ALERT).
Authorizations
MeshQu API key passed as a bearer token: Authorization: Bearer mqu_…. Mint one in the console (Settings → API keys).
Tenant UUID for multi-tenant isolation. Required on all authenticated routes — validated before authentication (middleware/tenant.ts), so a missing or non-UUID header returns 400 (MISSING_TENANT_ID / INVALID_TENANT_ID) before the API key is checked.
Path Parameters
Chain ID
Response
A sealed chain proof
A sealed chain proof