Request an approval
/api/v2/approvalsAuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
X-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
Idempotency-KeystringStable retry key for a mutation. The key is claimed atomically before the handler runs, so concurrent retries execute the side effect at most once. Replaying the key for the same request (same method, path, workspace and JSON body) returns the original response with an X-Idempotent-Replay: true header. Reusing the key for a different request returns 409 with error code idempotency_key_reuse. A duplicate arriving while the first is still in flight waits and then replays; if the first does not finish in time the duplicate gets 409 idempotency_request_in_progress. Keys are retained for 24 hours. Only successful (2xx) responses are stored; a failed request frees the key so it can be retried.
application/jsontitlestringrequireddescriptionstringpayloadobjectexpiresInSecondsintegerrunIdstringExisting run in this API key environment for approval lifecycle spans.
parentSpanIdstringOptional parent span within runId.
Approval requested.
successbooleanrequiredtruedataApprovalrequiredShow propertiesHide properties
idstringrequiredkindstringrequiredactioncustomstatusstringrequiredpendingapproveddeniedexpiredtitlestringrequireddescriptionstring | nullrequiredpayloadobjectrequiredSecret-safe review payload.
decisionNotestring | nullrequireddecidedByApprovalActor | nullThe recorded reviewer who finalized the decision, not all voters. Null for pending, expired, automated or unattributed decisions. Available to approval readers; not copied into invocation responses.
Show propertiesHide properties
typestringrequiredapi_keyuseridstringrequiredStable recorded reviewer identity. Never an API key value.
displayNamestring | nullrequiredNull when no historical display name was recorded.
nullvotesApprovalVote[]Recorded votes in chronological order on detail reads, including long-poll results. Omitted on list, create and decide responses; fetch the detail to audit all reviewers.
Show propertiesHide properties
ApprovalVotedecisionstringrequiredapprovedenydecidedByApprovalActor | nullrequiredShow propertiesHide properties
ApprovalActornullnotestring | nullrequireddecidedAtstring<date-time>requiredrequiredApprovalsintegerrequiredDistinct approvers needed (N-of-M), as resolved from the governing policy when the approval was created.
approvedCountintegerrequiredApprovals recorded so far.
matchedPolicyIdstring | nullrequiredThe policy that governed this approval, as recorded when it was created. Null when no policy matched (the default gate applied) and on approvals recorded before policies existed.
matchedPolicyVersioninteger | nullrequiredThe version of that policy at the time. Null exactly when matchedPolicyId is null.
policyExplanationstring | nullrequiredA human-readable account of how the policy was applied. Null on approvals recorded before it was kept. It is the approval's own record; an invocation carries its own decision and does not need this.
decisionOriginstring | nullrequiredWho decided. Persisted, not inferred from status. Null while pending. unknown marks a decision made before origin was recorded whose evidence does not settle it; it is never guessed. assistant is an approval by opt-in Anlyon Vigil inside the limits an admin set; it never denies.
humanpolicysystemunknownassistantnullexpiresAtstring<date-time>requireddecidedAtstring<date-time> | nullrequiredcreatedAtstring<date-time>requiredadviceobjectAnlyon Vigil's suggestion, on dashboard (session) responses only and only for workspaces that opted in. API-key callers never receive it.
Show propertiesHide properties
statusstringrequiredpendingreadyfailedskippedstatusReasonstring | nullrequiredWhy advice failed or was skipped, e.g. quota_exceeded, timeout, already_decided.
modelstring | nullrequiredVigil's public model version. Auto-approve thresholds are calibrated per version.
recommendationstring | nullrequiredapprovedenyreviewnullrisknumber | nullrequiredExpected harm if approving were wrong, 0 routine to 4 critical.
riskLevelstring | nullrequiredroutinelowmoderatehighcriticalnullconfidencenumber | nullrequiredreasonsstring[]requiredflagsobject | nullrequiredShow propertiesHide properties
injectionSuspectednumber | nullrequiredconsistentWithHistorynumber | nullrequiredamountUnusualnumber | nullrequiredhistoryobject | nullrequiredThis agent and action over the last 30 days.
Show propertiesHide properties
approvedintegerrequireddeniedintegerrequiredmaxAmountnumber | nullrequiredmedianAmountnumber | nullrequiredauditRequestedbooleanrequiredThis Vigil decision was sampled for a person to check.
auditVerdictstring | nullrequiredagreedisagreenullcreatedAtstring<date-time>requiredcompletedAtstring<date-time> | nullrequiredBad Request - Invalid input data
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectUnauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectPayment Required - Usage quota exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectAuthenticated credential lacks the required scope or workspace access.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectToo Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
