## The claim response is not an `ActionAuthorization`
`GET /v1/approvals/{id}/claim` serves the **approval-claim** envelope defined in
[`approval-claim.md`](approval-claim.md). It is not the `ActionAuthorization`
object that secrets-engine's `validate_action_authorization` currently expects,
and a PEP that points that validator at this URL fails closed for the wrong
reason.
Both envelopes carry `schema_version: "0.1"`, so the version check passes and
the mismatch surfaces later as a missing-field or wrong-authority error. Do not
read that failure as an approval-engine outage.
| Validator expectation | What the claim actually serves |
| --- | --- |
| `id` (canonical UUID) | `approval_id` — the object id, same value, different key |
| `status == "approved"` | `state` (`approved`, `consumed`, `revoked`, `superseded`, `expired`, `requested`) plus the `valid_now` predicate |
| `superseded_by` | absent; supersession appears as `state: "superseded"` |
| `provenance.authority == "state-hub"` | `issuer: "approval-engine"` — this engine is the authority for the approval object; the State Hub is a read model and never issues one |
| `request` (full CheckRequest) | `binding` (`action`, `actor`, `principal`, `purpose`, `target`) plus `binding.digest`, and `binding.pdp_digest` when recorded at issue |
| `approvals.required_count` / `entries` | not exposed; the distinct-approver threshold is already folded into `valid_now`, with `reason_code: "insufficient_approvers"` when unmet |
| policy package/version pin | not carried; the policy pin belongs to the access-engine decision, not to the approval fact |
The omissions are deliberate. A claim is a *fact about an approval object*, not
a decision and not a permission; approver identities and policy pins are not
republished to consumers. The consumer checks in
[`approval-claim.md`](approval-claim.md) ("Required verification") are the
supported validation path.
Reconciling the two envelopes is a cross-repo contract change under
`GH-DEC-2026-003`, not a unilateral edit here. Until it is decided, this engine
keeps serving the approval-claim shape and does not emit a `state-hub`