Only the milestone creator can edit it, and only while it is proposed or changes_requested.
Editing resets the other party’s approval and returns the milestone to proposed status.
Once accepted, milestones are permanently locked.
JWT access token obtained from /auth-verify (login context) or /auth-signup. Set the bearer_token environment variable in your API client to apply it globally.