Adopt a published widget package version
Adopting a second version of a package the company already holds is a version change on the same row rather than a second install, because two live installs of one package would make the effective grant ambiguous.
Authorizations
Bearer token authentication
Body
Separate from the update body because the version is required here and meaningless there. One shared schema advertised the version as optional, so a generated client could omit a field the endpoint actually needs.
The published version to adopt.
A full replacement rather than an addition. Create is also the upgrade path, so a default would let a re-install silently drop every grant the merchant had already given. An empty array is a valid request meaning the package is granted nothing.
Response
The company already held this package, so the same row moved to the requested version rather than a second installation being created.
A company's adoption of a published widget package version. granted is the merchant's decision and is stored apart from the manifest's own declaration, so narrowing a grant never edits an artifact: the effective set is the intersection, computed per request, which is why a revocation takes effect on the next call rather than at the next publish.
The company's grant epoch after this write. Descriptors are cached by (version, company, epoch), so a bumped epoch is what retires every cached descriptor at once.