Invoke an action
Execute an enabled action inline, or park it behind a human approval when the action is gated.
Which definition runs depends on how the call is attributed. Passing a runId whose run names an agent runs the action version that agent’s published version pins, if it pins one – this is the path a rollback restores. Without a runId, or when the agent pins nothing for this action, the action’s current definition runs. The response reports the version that actually executed as actionVersionId.
With an Idempotency-Key, the key is also recorded on the invocation and kept for its whole life, including after it fails. A retry with the same key after the 24-hour replay window (or after the replay store loses the key) is answered from the invocation’s current state with X-Idempotent-Replay: current-state and 200, or 202 while it still waits for approval. It is never executed, admitted or charged again. The same key from a different credential or with a different body returns 409 idempotency_key_reuse. A request refused before the invocation is recorded (for example invalid input) leaves the key unused. To run the action again deliberately, use a new key.
/api/v2/actions/{ref}/invokeAuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
refstringrequiredAction name or public action identifier.
X-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
Idempotency-KeystringStable retry key for a mutation. The key is claimed atomically before the handler runs, so concurrent retries execute the side effect at most once. Replaying the key for the same request (same method, path, workspace and JSON body) returns the original response with an X-Idempotent-Replay: true header. Reusing the key for a different request returns 409 with error code idempotency_key_reuse. A duplicate arriving while the first is still in flight waits and then replays; if the first does not finish in time the duplicate gets 409 idempotency_request_in_progress. Keys are retained for 24 hours. Only successful (2xx) responses are stored; a failed request frees the key so it can be retried.
application/jsoninputobjectrunIdstringExisting run in this API key environment to receive the automatic action_call span.
parentSpanIdstringOptional parent span within runId.
retryOfstringA failed invocation of the same action that this call deliberately retries. Needs its own Idempotency-Key. Refused while the original is unknown (resolve it first) or succeeded, and once it has already been retried.
operationKeystringGoverned actions only (an adapter or a declaration). Stable operation identity: the same key with the same request returns the existing effect. The same key with a different request is a 409. Defaults to the Idempotency-Key. Different keys do not make two requests different business operations.
previewIdstringGoverned actions only. A reviewed preview this invocation must match exactly (409 PREVIEW_MISMATCH, PREVIEW_EXPIRED or PREVIEW_ALREADY_USED otherwise).
dependsOnobject[]Governed actions only. Effects that must already have the stated outcome. Pending and unknown never satisfy a dependency (409 DEPENDENCY_UNRESOLVED).
Show propertiesHide properties
objecteffectstringrequiredoutcomestringrequiredsucceededfailedcompensatesstringGoverned actions only. The effect this one compensates. A compensation is its own governed effect.
Invocation completed or parked for approval.
successbooleanrequiredtruedataActionInvocationrequiredShow propertiesHide properties
idstringrequiredeffectIdstring | nullrequiredThe governed effect this invocation created, for a governed action (an adapter or a declaration). Its outcome, evidence and recovery are at GET /api/v2/actions/effects/{id}. Null for template actions.
gradestring | nullOn invoke responses and single reads: the receipt grade of the effect this invocation created. See Effect.grade. Absent when the invocation has no effect, and on list reads.
confirmedacknowledgedunknownfailedrefuseddeniedpendingnullretryOfstring | nullrequiredThe failed invocation this one deliberately retried.
retriedBystring | nullOn single reads: the invocation that retried this one.
resolutionobject | nullOn single reads: the operator's confirmed outcome for an invocation that was unknown.
Show propertiesHide properties
outcomestringrequiredsucceededfailedevidencestringrequiredexternalReferencestring | nullrequiredresolvedByobjectrequiredShow propertiesHide properties
typestringrequiredapi_keyuseridstringrequiredresolvedAtstring<date-time>requiredactionNamestringrequiredactionVersionIdstring | nullrequiredThe immutable action version this invocation ran. Lets an audit answer which definition executed a given call rather than inferring it. Null only for invocations recorded before versioning existed.
statusstringrequiredunknown means the request may have reached the destination and Anlyon cannot confirm what happened a timeout, or a socket that died after the request was written. It is deliberately distinct from failed, which means the call did not happen: an error before anything left, such as a blocked URL or an invalid template. Do not retry an unknown invocation automatically. Reconcile it with the destination first; retrying is how one refund becomes two. This value is additive clients that do not know it should treat an unrecognised status as not-successful rather than as failed.
pending_approvalrunningsucceededfailedunknowndeniedexpiredresponseStatusinteger | nullrequiredbodystring | nullrequiredRedacted and truncated upstream response body.
errorstring | nullrequireddurationMsinteger | nullrequiredapprovalIdstring | nullrequireddecisionInvocationDecision | nullrequiredWhy the request was allowed or refused, when a policy, a person or expiry decided it. Persisted on the invocation, so it reads the same after the policy is edited or deleted. Null while undecided, for an invocation that ran with no gate, and on rows recorded before this field existed. For a request that was never sent, responseStatus and body stay null: no response is fabricated.
Show propertiesHide properties
sourcestringrequiredpolicyhumansystemassistantcodestringrequiredPOLICY_DENIEDPOLICY_APPROVEDHUMAN_APPROVEDHUMAN_DENIEDAPPROVAL_EXPIREDASSISTANT_APPROVEDeffectstringrequiredWhat actually happened to the request.
approveddeniedexpiredexplanationstringrequiredpolicyobject | nullrequiredThe policy that decided, as it stood at decision time. Null when no policy decided.
Show propertiesHide properties
idstringrequirednamestringrequiredversionintegerrequireddecidedAtstring<date-time>requiredDatabase time the decision was committed.
nullcreatedAtstring<date-time>requiredcompletedAtstring<date-time> | nullrequiredpendingApprovalbooleanrequiredInvocation completed or parked for approval.
successbooleanrequiredtruedataActionInvocationrequiredShow propertiesHide properties
idstringrequiredeffectIdstring | nullrequiredThe governed effect this invocation created, for a governed action (an adapter or a declaration). Its outcome, evidence and recovery are at GET /api/v2/actions/effects/{id}. Null for template actions.
gradestring | nullOn invoke responses and single reads: the receipt grade of the effect this invocation created. See Effect.grade. Absent when the invocation has no effect, and on list reads.
confirmedacknowledgedunknownfailedrefuseddeniedpendingnullretryOfstring | nullrequiredThe failed invocation this one deliberately retried.
retriedBystring | nullOn single reads: the invocation that retried this one.
resolutionobject | nullOn single reads: the operator's confirmed outcome for an invocation that was unknown.
Show propertiesHide properties
outcomestringrequiredsucceededfailedevidencestringrequiredexternalReferencestring | nullrequiredresolvedByobjectrequiredShow propertiesHide properties
typestringrequiredapi_keyuseridstringrequiredresolvedAtstring<date-time>requiredactionNamestringrequiredactionVersionIdstring | nullrequiredThe immutable action version this invocation ran. Lets an audit answer which definition executed a given call rather than inferring it. Null only for invocations recorded before versioning existed.
statusstringrequiredunknown means the request may have reached the destination and Anlyon cannot confirm what happened a timeout, or a socket that died after the request was written. It is deliberately distinct from failed, which means the call did not happen: an error before anything left, such as a blocked URL or an invalid template. Do not retry an unknown invocation automatically. Reconcile it with the destination first; retrying is how one refund becomes two. This value is additive clients that do not know it should treat an unrecognised status as not-successful rather than as failed.
pending_approvalrunningsucceededfailedunknowndeniedexpiredresponseStatusinteger | nullrequiredbodystring | nullrequiredRedacted and truncated upstream response body.
errorstring | nullrequireddurationMsinteger | nullrequiredapprovalIdstring | nullrequireddecisionInvocationDecision | nullrequiredWhy the request was allowed or refused, when a policy, a person or expiry decided it. Persisted on the invocation, so it reads the same after the policy is edited or deleted. Null while undecided, for an invocation that ran with no gate, and on rows recorded before this field existed. For a request that was never sent, responseStatus and body stay null: no response is fabricated.
Show propertiesHide properties
sourcestringrequiredpolicyhumansystemassistantcodestringrequiredPOLICY_DENIEDPOLICY_APPROVEDHUMAN_APPROVEDHUMAN_DENIEDAPPROVAL_EXPIREDASSISTANT_APPROVEDeffectstringrequiredWhat actually happened to the request.
approveddeniedexpiredexplanationstringrequiredpolicyobject | nullrequiredThe policy that decided, as it stood at decision time. Null when no policy decided.
Show propertiesHide properties
idstringrequirednamestringrequiredversionintegerrequireddecidedAtstring<date-time>requiredDatabase time the decision was committed.
nullcreatedAtstring<date-time>requiredcompletedAtstring<date-time> | nullrequiredpendingApprovalbooleanrequiredBad Request - Invalid input data
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectUnauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectPayment Required - Usage quota exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectAuthenticated credential lacks the required scope or workspace access.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectNot Found - Resource does not exist
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectThe request conflicts with current resource state or a concurrent decision.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectToo Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectA required provider or platform dependency is not configured or available.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
