> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lmrp.uk/llms.txt
> Use this file to discover all available pages before exploring further.

# Suspend, revoke or reinstate a licence

> **Permission:** `pnc.licences.manage`. Needs a signed-in user; service credentials are refused with `USER_REQUIRED`.

**Access:** Browser session only.

`VALID` or `EXPIRED` may be suspended or revoked. `SUSPENDED` may be revoked or reinstated (`VALID`). `REVOKED` may be reinstated. `until` applies only to a suspension, which lapses by itself at that time. Renewing an expired licence is an amendment of `expiresAt`, not a status change.



## OpenAPI

````yaml /api-reference/openapi.json post /pnc/licences/{id}/status
openapi: 3.1.0
info:
  title: Argus API
  version: 0.1.0
  summary: The HTTP API behind the Argus web application.
  description: >-
    Argus is the operations platform for the UK London Mayfair ER:LC community.
    This document describes the API its own web application uses.


    **This is an internal application API.** It is not a stable public API:
    paths, fields and behaviour can change with any release, there is no
    versioning, and browser requests are tied to the application's own origin.
    Scoped service credentials exist for the community's own integrations.


    All paths are relative to `/api` on the deployment's origin. Responses are
    JSON, never cacheable, and carry an `X-Request-Id` header.
servers:
  - url: http://localhost:3000/api
    description: Local development
  - url: '{origin}/api'
    description: A deployment. `origin` is that deployment's `APP_URL`.
    variables:
      origin:
        default: https://argus.example.org
        description: The application's public origin, with no trailing slash.
security: []
tags:
  - name: Authentication
    description: >-
      Discord sign-in, Roblox account linking, the current user, and temporary
      Developer Access.
  - name: CAD Incidents
    description: >-
      Control's incidents: creation, editing, closure, and dispatching units to
      them.
  - name: CAD Units
    description: Control's view of operational units and their crew.
  - name: CAD Calls
    description: Incoming calls and how they become, or join, incidents.
  - name: CAD Events
    description: The append-only operational history.
  - name: MDT
    description: >-
      Self-service for the people crewing a unit: booking on and off, joining a
      unit, and changing its status.
  - name: Civilians
    description: 'The civilian portal: a member''s own characters, licences and vehicles.'
  - name: PNC Lookup
    description: >-
      Searching people and vehicles, full records, record history and official
      vehicle status.
  - name: PNC Licences
    description: Official changes to driving licences.
  - name: PNC Records
    description: Official records attached to people.
  - name: PNC Warrants
    description: Warrants and their lifecycle.
  - name: PNC Markers
    description: Markers and BOLOs on people and vehicles.
  - name: Staff
    description: Staff profiles and role membership.
  - name: Shifts
    description: Staff shifts.
  - name: Sessions
    description: Operational roleplay sessions.
  - name: Moderation
    description: Warnings, kicks and bans, with their delivery state.
  - name: Audit
    description: The append-only audit log.
  - name: Administration
    description: Accounts, roles and service credentials.
  - name: ERLC
    x-displayName: ER:LC
    description: Live data from the ER:LC private server.
paths:
  /pnc/licences/{id}/status:
    post:
      tags:
        - PNC Licences
      summary: Suspend, revoke or reinstate a licence
      description: >-
        **Permission:** `pnc.licences.manage`. Needs a signed-in user; service
        credentials are refused with `USER_REQUIRED`.


        **Access:** Browser session only.


        `VALID` or `EXPIRED` may be suspended or revoked. `SUSPENDED` may be
        revoked or reinstated (`VALID`). `REVOKED` may be reinstated. `until`
        applies only to a suspension, which lapses by itself at that time.
        Renewing an expired licence is an amendment of `expiresAt`, not a status
        change.
      operationId: setLicenceStatus
      parameters:
        - name: id
          in: path
          required: true
          schema:
            $ref: '#/components/schemas/Id'
          description: Licence ID.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                status:
                  type: string
                  enum:
                    - VALID
                    - SUSPENDED
                    - REVOKED
                reason:
                  type: string
                  minLength: 3
                  maxLength: 500
                until:
                  type: string
                  format: date-time
                  description: >-
                    End of a suspension. ISO-8601 with a zone; must be in the
                    future.
              required:
                - status
                - reason
              additionalProperties: false
            example:
              status: SUSPENDED
              reason: Drink driving, pending court
              until: '2026-11-06T00:00:00.000Z'
      responses:
        '200':
          description: Success.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/OfficialLicence'
                required:
                  - data
              example:
                data:
                  id: cmg6a2lic000hl508lic00001
                  number: HART9144223PA85
                  categories:
                    - B
                  status: SUSPENDED
                  suspendedUntil: '2026-11-06T00:00:00.000Z'
                  issuedAt: '2026-10-06T19:30:00.000Z'
                  expiresAt: '2036-10-06T19:30:00.000Z'
                  points: 3
                  endorsements:
                    - id: cmg6a3end000il508end00001
                      code: SP30
                      reason: Exceeding 30 mph limit
                      points: 3
                      createdAt: '2026-10-06T19:42:10.000Z'
                      expiresAt: null
                      active: true
                      issuedBy:
                        id: cmg5x1k2a0000l508a1b2c3d4
                        displayName: Olivia Officer
                      removedAt: null
                      removedBy: null
                      removalReason: null
                      record:
                        id: cmg6a5rec000kl508rec00001
                        reference: REC-000045
        '400':
          description: >-
            `INVALID_INPUT`: a parameter or body field fails validation;
            `details` lists each problem.


            `INVALID_JSON`: the body is missing or is not valid JSON.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error:
                  code: INVALID_INPUT
                  message: Request validation failed.
                  details:
                    - path:
                        - status
                      message: Invalid input
                requestId: 3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70
        '401':
          $ref: '#/components/responses/Unauthenticated'
        '403':
          description: >-
            `FORBIDDEN`: the caller lacks `pnc.licences.manage`.


            `USER_REQUIRED`: the caller is a service credential.


            `INVALID_ORIGIN`: a browser request whose `Origin` is not the
            application's own.


            `ACCOUNT_DISABLED`: the account is suspended or disabled.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error:
                  code: FORBIDDEN
                  message: 'Permission required: pnc.licences.manage.'
                requestId: 3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70
        '404':
          description: '`NOT_FOUND`: no such licence.'
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error:
                  code: NOT_FOUND
                  message: Licence not found.
                requestId: 3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70
        '409':
          description: >-
            `INVALID_TRANSITION`: the licence cannot move from its current
            status to the requested one.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
              example:
                error:
                  code: INVALID_TRANSITION
                  message: A licence that is revoked cannot be set to suspended.
                requestId: 3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70
        '429':
          $ref: '#/components/responses/RateLimited'
        default:
          $ref: '#/components/responses/UnexpectedError'
      security:
        - sessionCookie: []
components:
  schemas:
    Id:
      type: string
      minLength: 1
      maxLength: 64
      pattern: ^[a-zA-Z0-9_-]+$
      description: Argus record identifier.
    OfficialLicence:
      type: object
      properties:
        id:
          $ref: '#/components/schemas/Id'
        number:
          type: string
        categories:
          type: array
          items:
            type: string
            enum:
              - A
              - B
              - C
              - D
        status:
          type: string
          enum:
            - VALID
            - EXPIRED
            - SUSPENDED
            - REVOKED
          description: >-
            Worked out when read: a licence past `expiresAt` reads `EXPIRED`,
            and a suspension past `suspendedUntil` has lapsed.
        suspendedUntil:
          type:
            - string
            - 'null'
          format: date-time
        issuedAt:
          type: string
          format: date-time
        expiresAt:
          type: string
          format: date-time
        points:
          type: integer
          description: Sum of endorsements that are neither removed nor expired.
        endorsements:
          type: array
          items:
            $ref: '#/components/schemas/OfficialEndorsement'
      required:
        - id
        - number
        - categories
        - status
        - suspendedUntil
        - issuedAt
        - expiresAt
        - points
        - endorsements
      description: >-
        A driving licence as the PNC shows it, including removed endorsements
        and who recorded each.
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: Stable machine-readable code.
            message:
              type: string
            details:
              description: >-
                Present on some errors. Validation failures carry an array of
                `{path, message}`; ER:LC failures carry `{availability:
                "unavailable"}`.
          required:
            - code
            - message
        requestId:
          type: string
          format: uuid
          description: >-
            Also sent as the `X-Request-Id` header. Quote it when reporting a
            problem.
      required:
        - error
        - requestId
    OfficialEndorsement:
      type: object
      properties:
        id:
          $ref: '#/components/schemas/Id'
        code:
          type:
            - string
            - 'null'
        reason:
          type: string
        points:
          type: integer
          minimum: 1
          maximum: 12
        createdAt:
          type: string
          format: date-time
        expiresAt:
          type:
            - string
            - 'null'
          format: date-time
        active:
          type: boolean
        issuedBy:
          $ref: '#/components/schemas/Person'
        removedAt:
          type:
            - string
            - 'null'
          format: date-time
        removedBy:
          anyOf:
            - $ref: '#/components/schemas/Person'
            - type: 'null'
        removalReason:
          type:
            - string
            - 'null'
        record:
          type:
            - object
            - 'null'
          properties:
            id:
              $ref: '#/components/schemas/Id'
            reference:
              type: string
          required:
            - id
            - reference
      required:
        - id
        - code
        - reason
        - points
        - createdAt
        - expiresAt
        - active
        - issuedBy
        - removedAt
        - removedBy
        - removalReason
        - record
    Person:
      type: object
      properties:
        id:
          $ref: '#/components/schemas/Id'
        displayName:
          type: string
      required:
        - id
        - displayName
      description: A minimal reference to an Argus user.
  headers:
    RequestId:
      schema:
        type: string
        format: uuid
      description: Identifies this request in server logs.
    RetryAfter:
      schema:
        type: integer
        minimum: 1
      description: Seconds to wait before trying again.
  responses:
    Unauthenticated:
      description: >-
        `UNAUTHENTICATED`: no session cookie, or an invalid, expired or revoked
        service credential.


        `SESSION_EXPIRED`: the session has ended.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: UNAUTHENTICATED
              message: Sign in to continue.
            requestId: 3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70
    RateLimited:
      description: >-
        `RATE_LIMITED`: more than 180 reads or 60 writes in a minute for this
        caller.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
        Retry-After:
          $ref: '#/components/headers/RetryAfter'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: RATE_LIMITED
              message: Too many requests.
            requestId: 3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70
    UnexpectedError:
      description: >-
        Any other failure, in the same error envelope: `INTERNAL_ERROR` (500),
        `METHOD_NOT_ALLOWED` (405), `BODY_TOO_LARGE` (413, over 16 KiB) or
        `UNSUPPORTED_MEDIA_TYPE` (415, body not sent as `application/json`).
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INTERNAL_ERROR
              message: The request could not be completed.
            requestId: 3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70
  securitySchemes:
    sessionCookie:
      type: apiKey
      in: cookie
      name: __Host-argus-session
      description: >-
        The opaque session cookie set by Discord sign-in. Named `argus-session`
        outside production. HttpOnly, so scripts cannot read it; same-origin
        requests send it automatically. Requests other than GET must also carry
        an `Origin` header equal to the application's own origin.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.