Moves an ACTIVE Cryptographic Exchange to SUSPENDED and invalidates the linked
Capability Grant projection, so runtime authorization stops honouring it.
The body is an OPTIMISTIC-LOCKING ENVELOPE that also carries the operator's
justification. version is the discriminator last read from the
exchange detail response; a stale value is refused with 409 and nothing is
written.
reason is MANDATORY (PRD 231). It is recorded verbatim at canonical
position 21 of the signed AdminAuditEvent, which is what makes the suspension
answerable later: an audit row can no longer say that an exchange was suspended
without saying why. It is bounded at AuditFieldBounds.MAX_REASON_LENGTH (1,000
UTF-8 BYTES, not characters - the unit the signed preimage and every
carrier downstream of it are measured in) - the same bound applied
before signing, so no accepted value is
silently truncated on its way into the preimage. The reason is NEVER written to
a log line (231.19).
Authorization: requires scope admin.tenant.exchange.suspend.
The tenant boundary is resolved from the JWT claim, never from the path.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||