Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview

Approve a request

Decide a pending request. For an action approval, this executes and returns the parked invocation. A credential cannot decide an approval it requested, whether it is the requesting API key or the requesting OAuth app acting for the same user.

POST/api/v2/approvals/{id}/approve
Authorization
AuthorizationBearer token (Anlyon API key) · headerrequired

Workspace API key sent as Authorization: Bearer <key>.

or
better-auth.session_tokenAPI key · cookierequired

Browser session used by dashboard-only operations.

Path parameters
idstringrequired

Public approval identifier.

min length 1 · max length 100
Header parameters
X-Request-Idstring

Optional caller correlation ID. Unsafe or oversized values are replaced.

max length 128
Idempotency-Keystring

Stable retry key for a mutation. The key is claimed atomically before the handler runs, so concurrent retries execute the side effect at most once. Replaying the key for the same request (same method, path, workspace and JSON body) returns the original response with an X-Idempotent-Replay: true header. Reusing the key for a different request returns 409 with error code idempotency_key_reuse. A duplicate arriving while the first is still in flight waits and then replays; if the first does not finish in time the duplicate gets 409 idempotency_request_in_progress. Keys are retained for 24 hours. Only successful (2xx) responses are stored; a failed request frees the key so it can be retried.

min length 1 · max length 255
Request body
application/json
notestring
max length 1000
Responses
200

Approval decision returned, with the executed invocation when applicable.

successbooleanrequired
Allowed:true
dataApprovalDecisionrequired
Show properties
approvalApprovalrequired
Show properties
idstringrequired
kindstringrequired
Allowed:actioncustom
statusstringrequired
Allowed:pendingapproveddeniedexpired
titlestringrequired
descriptionstring | nullrequired
payloadobjectrequired

Secret-safe review payload.

decisionNotestring | nullrequired
decidedByApprovalActor | null

The recorded reviewer who finalized the decision, not all voters. Null for pending, expired, automated or unattributed decisions. Available to approval readers; not copied into invocation responses.

Show properties
Any of:
ApprovalActor
typestringrequired
Allowed:api_keyuser
idstringrequired

Stable recorded reviewer identity. Never an API key value.

displayNamestring | nullrequired

Null when no historical display name was recorded.

null
null
votesApprovalVote[]

Recorded votes in chronological order on detail reads, including long-poll results. Omitted on list, create and decide responses; fetch the detail to audit all reviewers.

Show properties
Array of ApprovalVote
decisionstringrequired
Allowed:approvedeny
decidedByApprovalActor | nullrequired
Show properties
Any of:
ApprovalActor
ApprovalActor
null
null
notestring | nullrequired
decidedAtstring<date-time>required
requiredApprovalsintegerrequired

Distinct approvers needed (N-of-M), as resolved from the governing policy when the approval was created.

min 1
approvedCountintegerrequired

Approvals recorded so far.

min 0
matchedPolicyIdstring | nullrequired

The policy that governed this approval, as recorded when it was created. Null when no policy matched (the default gate applied) and on approvals recorded before policies existed.

matchedPolicyVersioninteger | nullrequired

The version of that policy at the time. Null exactly when matchedPolicyId is null.

policyExplanationstring | nullrequired

A human-readable account of how the policy was applied. Null on approvals recorded before it was kept. It is the approval's own record; an invocation carries its own decision and does not need this.

decisionOriginstring | nullrequired

Who decided. Persisted, not inferred from status. Null while pending. unknown marks a decision made before origin was recorded whose evidence does not settle it; it is never guessed. assistant is an approval by opt-in Anlyon Vigil inside the limits an admin set; it never denies.

Allowed:humanpolicysystemunknownassistantnull
expiresAtstring<date-time>required
decidedAtstring<date-time> | nullrequired
createdAtstring<date-time>required
adviceobject

Anlyon Vigil's suggestion, on dashboard (session) responses only and only for workspaces that opted in. API-key callers never receive it.

Show properties
statusstringrequired
Allowed:pendingreadyfailedskipped
statusReasonstring | nullrequired

Why advice failed or was skipped, e.g. quota_exceeded, timeout, already_decided.

modelstring | nullrequired

Vigil's public model version. Auto-approve thresholds are calibrated per version.

recommendationstring | nullrequired
Allowed:approvedenyreviewnull
risknumber | nullrequired

Expected harm if approving were wrong, 0 routine to 4 critical.

min 0 · max 4
riskLevelstring | nullrequired
Allowed:routinelowmoderatehighcriticalnull
confidencenumber | nullrequired
min 0 · max 1
reasonsstring[]required
flagsobject | nullrequired
Show properties
injectionSuspectednumber | nullrequired
min 0 · max 1
consistentWithHistorynumber | nullrequired
min 0 · max 1
amountUnusualnumber | nullrequired
min 0 · max 1
historyobject | nullrequired

This agent and action over the last 30 days.

Show properties
approvedintegerrequired
min 0
deniedintegerrequired
min 0
maxAmountnumber | nullrequired
medianAmountnumber | nullrequired
auditRequestedbooleanrequired

This Vigil decision was sampled for a person to check.

auditVerdictstring | nullrequired
Allowed:agreedisagreenull
createdAtstring<date-time>required
completedAtstring<date-time> | nullrequired
invocationInvocation
Show properties
idstringrequired
effectIdstring | nullrequired

The governed effect this invocation created, for a governed action (an adapter or a declaration). Its outcome, evidence and recovery are at GET /api/v2/actions/effects/{id}. Null for template actions.

gradestring | null

On invoke responses and single reads: the receipt grade of the effect this invocation created. See Effect.grade. Absent when the invocation has no effect, and on list reads.

Allowed:confirmedacknowledgedunknownfailedrefuseddeniedpendingnull
retryOfstring | nullrequired

The failed invocation this one deliberately retried.

retriedBystring | null

On single reads: the invocation that retried this one.

resolutionobject | null

On single reads: the operator's confirmed outcome for an invocation that was unknown.

Show properties
outcomestringrequired
Allowed:succeededfailed
evidencestringrequired
externalReferencestring | nullrequired
resolvedByobjectrequired
Show properties
typestringrequired
Allowed:api_keyuser
idstringrequired
resolvedAtstring<date-time>required
actionNamestringrequired
actionVersionIdstring | nullrequired

The immutable action version this invocation ran. Lets an audit answer which definition executed a given call rather than inferring it. Null only for invocations recorded before versioning existed.

statusstringrequired

unknown means the request may have reached the destination and Anlyon cannot confirm what happened a timeout, or a socket that died after the request was written. It is deliberately distinct from failed, which means the call did not happen: an error before anything left, such as a blocked URL or an invalid template. Do not retry an unknown invocation automatically. Reconcile it with the destination first; retrying is how one refund becomes two. This value is additive clients that do not know it should treat an unrecognised status as not-successful rather than as failed.

Allowed:pending_approvalrunningsucceededfailedunknowndeniedexpired
responseStatusinteger | nullrequired
min 100 · max 599
bodystring | nullrequired

Redacted and truncated upstream response body.

errorstring | nullrequired
durationMsinteger | nullrequired
min 0
approvalIdstring | nullrequired
decisionInvocationDecision | nullrequired

Why the request was allowed or refused, when a policy, a person or expiry decided it. Persisted on the invocation, so it reads the same after the policy is edited or deleted. Null while undecided, for an invocation that ran with no gate, and on rows recorded before this field existed. For a request that was never sent, responseStatus and body stay null: no response is fabricated.

Show properties
Any of:
InvocationDecision
sourcestringrequired
Allowed:policyhumansystemassistant
codestringrequired
Allowed:POLICY_DENIEDPOLICY_APPROVEDHUMAN_APPROVEDHUMAN_DENIEDAPPROVAL_EXPIREDASSISTANT_APPROVED
effectstringrequired

What actually happened to the request.

Allowed:approveddeniedexpired
explanationstringrequired
policyobject | nullrequired

The policy that decided, as it stood at decision time. Null when no policy decided.

Show properties
idstringrequired
namestringrequired
versionintegerrequired
decidedAtstring<date-time>required

Database time the decision was committed.

null
null
createdAtstring<date-time>required
completedAtstring<date-time> | nullrequired
400

Bad Request - Invalid input data

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
401

Unauthorized - Invalid or missing API key

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
403

Authenticated credential lacks the required scope or workspace access.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
404

Not Found - Resource does not exist

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
409

The request conflicts with current resource state or a concurrent decision.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
429

Too Many Requests - Rate limit exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST 'https://api.anlyon.com/api/v2/approvals/string/approve' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "note": "string"
}'
Response
{
  "success": true,
  "data": {
    "approval": {
      "id": "apr_01JABCDEF",
      "kind": "action",
      "status": "pending",
      "title": "string",
      "description": "string",
      "payload": {},
      "decisionNote": "string",
      "decidedBy": {
        "type": "api_key",
        "id": "string",
        "displayName": "string"
      },
      "votes": [
        {
          "decision": "approve",
          "decidedBy": {
            "type": "api_key",
            "id": "string",
            "displayName": "string"
          },
          "note": "string",
          "decidedAt": "2019-08-24T14:15:22Z"
        }
      ],
      "requiredApprovals": 1,
      "approvedCount": 0,
      "matchedPolicyId": "string",
      "matchedPolicyVersion": 0,
      "policyExplanation": "string",
      "decisionOrigin": "human",
      "expiresAt": "2019-08-24T14:15:22Z",
      "decidedAt": "2019-08-24T14:15:22Z",
      "createdAt": "2019-08-24T14:15:22Z",
      "advice": {
        "status": "pending",
        "statusReason": "string",
        "model": "vigil-1",
        "recommendation": "approve",
        "risk": 0,
        "riskLevel": "routine",
        "confidence": 0,
        "reasons": [
          "string"
        ],
        "flags": {
          "injectionSuspected": 0,
          "consistentWithHistory": 0,
          "amountUnusual": 0
        },
        "history": {
          "approved": 0,
          "denied": 0,
          "maxAmount": 0,
          "medianAmount": 0
        },
        "auditRequested": true,
        "auditVerdict": "agree",
        "createdAt": "2019-08-24T14:15:22Z",
        "completedAt": "2019-08-24T14:15:22Z"
      }
    },
    "invocation": {
      "id": "inv_01JABCDEF",
      "effectId": "eff_01JABCDEF",
      "grade": "confirmed",
      "retryOf": "string",
      "retriedBy": "string",
      "resolution": {
        "outcome": "succeeded",
        "evidence": "string",
        "externalReference": "string",
        "resolvedBy": {
          "type": "api_key",
          "id": "string"
        },
        "resolvedAt": "2019-08-24T14:15:22Z"
      },
      "actionName": "string",
      "actionVersionId": "acv_01JABCDEF",
      "status": "pending_approval",
      "responseStatus": 100,
      "body": "string",
      "error": "string",
      "durationMs": 0,
      "approvalId": "string",
      "decision": {
        "source": "policy",
        "code": "POLICY_DENIED",
        "effect": "approved",
        "explanation": "Denied by policy \"refund_order_denied\", version 2. The request was not sent.",
        "policy": {
          "id": "apol_01JABCDEF",
          "name": "string",
          "version": 0
        },
        "decidedAt": "2019-08-24T14:15:22Z"
      },
      "createdAt": "2019-08-24T14:15:22Z",
      "completedAt": "2019-08-24T14:15:22Z"
    }
  }
}