> ## Documentation Index
> Fetch the complete documentation index at: https://developers.gonitro.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Bulk update package status

> Updates the status of multiple packages at once. The supported transitions are
draft → pending and pending → revoked.

Moving packages from draft to pending makes them visible to their stakeholders
so the signing flow can begin. Moving pending packages to revoked withdraws
them so stakeholders can no longer act on them.

All packages in a single call must start from the same status: the update only
succeeds for packages whose current status allows the requested transition. For
example, mixing draft and pending packages in a request that targets revoked
succeeds only for the pending packages.

When revoking, set `SuppressNotifications` to `true` to skip the revocation
notifications.

Like other bulk actions, this call is processed asynchronously and returns a
bulk action session identifier; poll the package bulk action session to follow
its progress.



## OpenAPI

````yaml /nsev/api-reference/openapi.yaml post /packages/status/bulk
openapi: 3.0.0
info:
  title: NSEV WebPortal API
  version: 4.0.0
  contact:
    name: NSEV Support Team
    url: https://connectivegroup.my.site.com/s/contactsupport?language=en_US
  description: >
    **Nitro Sign Enterprise Verified (NSEV) WebPortal API Version 4**


    A comprehensive digital signing API that enables secure document signing
    workflows.

    This API provides endpoints for managing packages, documents, elements,
    stakeholders, 

    and signing processes within the NSEV platform.


    ## Authentication


    This API supports multiple authentication methods:


    ### Basic Authentication

    Traditional HTTP Basic Authentication using username and password.


    ### OAuth 2.0


    **Client Credentials Flow (Machine-to-Machine)**

    - Full API access including administrative endpoints

    - Ideal for server-to-server integrations


    **Authorization Code Flow (User-based)**

    - Limited API access excluding administrative endpoints

    - Ideal for user-facing applications

    - Supports delegated user access scenarios


    ## API Variants


    This specification is available in two variants:

    - **Full API**: Complete API with all endpoints (BasicAuth + OAuth2 M2M)

    - **User API**: Limited API excluding admin endpoints (OAuth2 user-based
    only)


    Administrative endpoints (`/poisonqueue`, `/absenceperiods`, `/auditproofs`)
    are 

    restricted to machine-to-machine authentication only.
        
    ## Versioning


    This API follows semantic versioning principles. Major version changes may
    introduce

    breaking changes, while minor and patch versions maintain backwards
    compatibility.
servers:
  - url: '{baseUrl}/esig/webportalapi/v4'
    variables:
      baseUrl:
        default: https://your-tenant.sign.gonitro.com
        description: >-
          Your tenant-specific base URL, including scheme and host (e.g.
          https://acme.sign.gonitro.com). Each NSEV customer has a unique URL.
          Replace this with yours before sending a request. The esig path
          segment is required - the Web Application Firewall routes requests on
          it.
security:
  - basicAuth: []
  - bearerAuth: []
tags:
  - name: Configuration
    description: |
      Endpoints for retrieving system configuration settings,
      contact groups, templates and signing methods.
  - name: Packages
    description: |
      Core endpoints for creating, managing, and tracking packages
      throughout their lifecycle.
  - name: Documents
    description: |
      Endpoints for adding, removing, and managing documents within packages.
      Handles document upload, processing, and metadata management.
  - name: Elements
    description: |
      Endpoints for managing elements (fields) within documents,
      including signatures and other form elements.
  - name: Stakeholders
    description: |
      Endpoints for managing stakeholders (recipients)
      associated with packages and their roles in the package workflow.
  - name: Actors
    description: |
      Endpoints for managing individual actors within stakeholders,
      including their contact information and role preferences:
      Approver, FormFiller, Signer or Receiver
  - name: Process
    description: |
      Endpoints for managing the package process workflow, including
      process steps, parallel actions, and workflow orchestration.
  - name: AuditTrails
    description: |
      Modern endpoints for retrieving comprehensive audit trails as signed PDFs,
      verifying the integrity of audit trail data and retrieving audit events.
  - name: BulkActions
    description: |
      Endpoints for performing and managing bulk actions on multiple packages.
  - name: Users
    description: |
      Endpoints for managing user accounts, including user invitations.
  - name: AbsencePeriods
    description: |
      Administrative endpoints for managing user absence periods and
      delegation settings during out-of-office scenarios.

      **Access Level**: Machine-to-machine only (administrative access required)
paths:
  /packages/status/bulk:
    post:
      tags:
        - BulkActions
      summary: Bulk update package status
      description: >-
        Updates the status of multiple packages at once. The supported
        transitions are

        draft → pending and pending → revoked.


        Moving packages from draft to pending makes them visible to their
        stakeholders

        so the signing flow can begin. Moving pending packages to revoked
        withdraws

        them so stakeholders can no longer act on them.


        All packages in a single call must start from the same status: the
        update only

        succeeds for packages whose current status allows the requested
        transition. For

        example, mixing draft and pending packages in a request that targets
        revoked

        succeeds only for the pending packages.


        When revoking, set `SuppressNotifications` to `true` to skip the
        revocation

        notifications.


        Like other bulk actions, this call is processed asynchronously and
        returns a

        bulk action session identifier; poll the package bulk action session to
        follow

        its progress.
      operationId: bulkUpdateStatus
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/BulkModifyStatusRequest'
            examples:
              revoke:
                summary: Revoke packages without notifications
                value:
                  PackageIds:
                    - b459d74c-1f90-4d63-9f4a-6de9cead8c5e
                    - 1fdbad81-75e5-4cc8-b113-39255fa119d7
                  Status: Revoked
                  SuppressNotifications: true
      responses:
        '200':
          description: An unique identifier of the created bulk action session.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BulkActionSession.Id'
              examples:
                session-id:
                  summary: An unique identifier of the created bulk action session
                  value: b459d74c-1f90-4d63-9f4a-6de9cead8c5e
        '400':
          description: When the Content has an invalid value.
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/ValidationError'
              examples:
                invalid-value:
                  summary: When the Content has an invalid value
                  value:
                    - ErrorCode: 'Request.RequiredFieldIsMissing: status'
                      ErrorMessage: A required field is missing.
        '401':
          $ref: '#/components/responses/UnAuthorized'
components:
  schemas:
    BulkModifyStatusRequest:
      type: object
      description: Request for bulk modify package status action
      required:
        - PackageIds
        - Status
      properties:
        PackageIds:
          type: array
          items:
            $ref: '#/components/schemas/Guid'
        Status:
          type: string
          enum:
            - Pending
            - Revoked
          description: >-
            The status the packages must be updated to. Supported transitions
            are

            draft to Pending and pending to Revoked.
        SuppressNotifications:
          type: boolean
          description: >-
            When true, no notifications are sent for the status change. Only
            applies

            when Status is Revoked.
          default: false
    BulkActionSession.Id:
      allOf:
        - $ref: '#/components/schemas/Guid'
        - description: A bulk action session unique identifier
    ValidationError:
      title: Validation error
      allOf:
        - $ref: '#/components/schemas/Error'
        - description: Request failed validation
          example:
            ErrorCode: Name.MinimumLength:6
            ErrorMessage: The minimum length for a name is 6
    Guid:
      title: GUID
      type: string
      description: A globally unique identifier
      format: guid
      example: 00000000-0000-0000-0000-000000000000
    Error:
      title: Error
      type: object
      description: Something that went wrong
      example:
        ErrorCode: Something.WentWrong
        ErrorMessage: Something went wrong
      properties:
        ErrorCode:
          type: string
          description: >-
            An error code of something that went wrong, in the form of
            'Subject.Error:value'
        ErrorMessage:
          type: string
          description: A human-readable explanation of what went wrong
  responses:
    UnAuthorized:
      description: Caller is unauthorized to perform this operation
  securitySchemes:
    basicAuth:
      type: http
      scheme: basic
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Bearer token authentication using JSON Web Tokens (JWT) or opaque
        tokens.


        **Usage**: Send the access token in the Authorization header:

        ```

        Authorization: Bearer <access_token>

        ```

````