Either party can approve. Once both parties have approved, the milestone moves to accepted
and is permanently locked — no further edits are possible.
JWT access token obtained from /auth-verify (login context) or /auth-signup. Set the bearer_token environment variable in your API client to apply it globally.
"a1b2c3d4-e5f6-7890-abcd-ef1234567890"