Skip to content
Anlyon
Esc
↑↓navigate↵open⌘Jpreview

Request an approval

POST/api/v2/approvals
Authorization
AuthorizationBearer token (Anlyon API key) · headerrequired

Workspace API key sent as Authorization: Bearer <key>.

or
better-auth.session_tokenAPI key · cookierequired

Browser session used by dashboard-only operations.

Header parameters
X-Request-Idstring

Optional caller correlation ID. Unsafe or oversized values are replaced.

max length 128
Idempotency-Keystring

Stable retry key for a mutation. The key is claimed atomically before the handler runs, so concurrent retries execute the side effect at most once. Replaying the key for the same request (same method, path, workspace and JSON body) returns the original response with an X-Idempotent-Replay: true header. Reusing the key for a different request returns 409 with error code idempotency_key_reuse. A duplicate arriving while the first is still in flight waits and then replays; if the first does not finish in time the duplicate gets 409 idempotency_request_in_progress. Keys are retained for 24 hours. Only successful (2xx) responses are stored; a failed request frees the key so it can be retried.

min length 1 · max length 255
Request body
requiredapplication/json
titlestringrequired
min length 1 · max length 200
descriptionstring
max length 2000
payloadobject
expiresInSecondsinteger
min 60 · max 2592000
runIdstring

Existing run in this API key environment for approval lifecycle spans.

max length 80
parentSpanIdstring

Optional parent span within runId.

max length 80
Responses
201

Approval requested.

successbooleanrequired
Allowed:true
dataApprovalrequired
Show properties
idstringrequired
kindstringrequired
Allowed:actioncustom
statusstringrequired
Allowed:pendingapproveddeniedexpired
titlestringrequired
descriptionstring | nullrequired
payloadobjectrequired

Secret-safe review payload.

decisionNotestring | nullrequired
decidedByApprovalActor | null

The recorded reviewer who finalized the decision, not all voters. Null for pending, expired, automated or unattributed decisions. Available to approval readers; not copied into invocation responses.

Show properties
Any of:
ApprovalActor
typestringrequired
Allowed:api_keyuser
idstringrequired

Stable recorded reviewer identity. Never an API key value.

displayNamestring | nullrequired

Null when no historical display name was recorded.

null
null
votesApprovalVote[]

Recorded votes in chronological order on detail reads, including long-poll results. Omitted on list, create and decide responses; fetch the detail to audit all reviewers.

Show properties
Array of ApprovalVote
decisionstringrequired
Allowed:approvedeny
decidedByApprovalActor | nullrequired
Show properties
Any of:
ApprovalActor
ApprovalActor
null
null
notestring | nullrequired
decidedAtstring<date-time>required
requiredApprovalsintegerrequired

Distinct approvers needed (N-of-M), as resolved from the governing policy when the approval was created.

min 1
approvedCountintegerrequired

Approvals recorded so far.

min 0
matchedPolicyIdstring | nullrequired

The policy that governed this approval, as recorded when it was created. Null when no policy matched (the default gate applied) and on approvals recorded before policies existed.

matchedPolicyVersioninteger | nullrequired

The version of that policy at the time. Null exactly when matchedPolicyId is null.

policyExplanationstring | nullrequired

A human-readable account of how the policy was applied. Null on approvals recorded before it was kept. It is the approval's own record; an invocation carries its own decision and does not need this.

decisionOriginstring | nullrequired

Who decided. Persisted, not inferred from status. Null while pending. unknown marks a decision made before origin was recorded whose evidence does not settle it; it is never guessed. assistant is an approval by opt-in Anlyon Vigil inside the limits an admin set; it never denies.

Allowed:humanpolicysystemunknownassistantnull
expiresAtstring<date-time>required
decidedAtstring<date-time> | nullrequired
createdAtstring<date-time>required
adviceobject

Anlyon Vigil's suggestion, on dashboard (session) responses only and only for workspaces that opted in. API-key callers never receive it.

Show properties
statusstringrequired
Allowed:pendingreadyfailedskipped
statusReasonstring | nullrequired

Why advice failed or was skipped, e.g. quota_exceeded, timeout, already_decided.

modelstring | nullrequired

Vigil's public model version. Auto-approve thresholds are calibrated per version.

recommendationstring | nullrequired
Allowed:approvedenyreviewnull
risknumber | nullrequired

Expected harm if approving were wrong, 0 routine to 4 critical.

min 0 · max 4
riskLevelstring | nullrequired
Allowed:routinelowmoderatehighcriticalnull
confidencenumber | nullrequired
min 0 · max 1
reasonsstring[]required
flagsobject | nullrequired
Show properties
injectionSuspectednumber | nullrequired
min 0 · max 1
consistentWithHistorynumber | nullrequired
min 0 · max 1
amountUnusualnumber | nullrequired
min 0 · max 1
historyobject | nullrequired

This agent and action over the last 30 days.

Show properties
approvedintegerrequired
min 0
deniedintegerrequired
min 0
maxAmountnumber | nullrequired
medianAmountnumber | nullrequired
auditRequestedbooleanrequired

This Vigil decision was sampled for a person to check.

auditVerdictstring | nullrequired
Allowed:agreedisagreenull
createdAtstring<date-time>required
completedAtstring<date-time> | nullrequired
400

Bad Request - Invalid input data

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
401

Unauthorized - Invalid or missing API key

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
402

Payment Required - Usage quota exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
403

Authenticated credential lacks the required scope or workspace access.

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
429

Too Many Requests - Rate limit exceeded

successbooleanrequired
requestIdstringrequired

Correlation ID matching the X-Request-Id response header.

errorobjectrequired
Show properties
codestring
messagestring
detailsobject
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST 'https://api.anlyon.com/api/v2/approvals' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "title": "string",
  "description": "string",
  "payload": {},
  "expiresInSeconds": 60,
  "runId": "string",
  "parentSpanId": "string"
}'
Response
{
  "success": true,
  "data": {
    "id": "apr_01JABCDEF",
    "kind": "action",
    "status": "pending",
    "title": "string",
    "description": "string",
    "payload": {},
    "decisionNote": "string",
    "decidedBy": {
      "type": "api_key",
      "id": "string",
      "displayName": "string"
    },
    "votes": [
      {
        "decision": "approve",
        "decidedBy": {
          "type": "api_key",
          "id": "string",
          "displayName": "string"
        },
        "note": "string",
        "decidedAt": "2019-08-24T14:15:22Z"
      }
    ],
    "requiredApprovals": 1,
    "approvedCount": 0,
    "matchedPolicyId": "string",
    "matchedPolicyVersion": 0,
    "policyExplanation": "string",
    "decisionOrigin": "human",
    "expiresAt": "2019-08-24T14:15:22Z",
    "decidedAt": "2019-08-24T14:15:22Z",
    "createdAt": "2019-08-24T14:15:22Z",
    "advice": {
      "status": "pending",
      "statusReason": "string",
      "model": "vigil-1",
      "recommendation": "approve",
      "risk": 0,
      "riskLevel": "routine",
      "confidence": 0,
      "reasons": [
        "string"
      ],
      "flags": {
        "injectionSuspected": 0,
        "consistentWithHistory": 0,
        "amountUnusual": 0
      },
      "history": {
        "approved": 0,
        "denied": 0,
        "maxAmount": 0,
        "medianAmount": 0
      },
      "auditRequested": true,
      "auditVerdict": "agree",
      "createdAt": "2019-08-24T14:15:22Z",
      "completedAt": "2019-08-24T14:15:22Z"
    }
  }
}