Deny a request
Deny a pending request. A credential cannot decide an approval it requested, whether it is the requesting API key or the requesting OAuth app acting for the same user.
/api/v2/approvals/{id}/denyAuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
idstringrequiredPublic approval identifier.
X-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
Idempotency-KeystringStable retry key for a mutation. The key is claimed atomically before the handler runs, so concurrent retries execute the side effect at most once. Replaying the key for the same request (same method, path, workspace and JSON body) returns the original response with an X-Idempotent-Replay: true header. Reusing the key for a different request returns 409 with error code idempotency_key_reuse. A duplicate arriving while the first is still in flight waits and then replays; if the first does not finish in time the duplicate gets 409 idempotency_request_in_progress. Keys are retained for 24 hours. Only successful (2xx) responses are stored; a failed request frees the key so it can be retried.
application/jsonnotestringApproval decision returned, with the executed invocation when applicable.
successbooleanrequiredtruedataApprovalDecisionrequiredShow propertiesHide properties
approvalApprovalrequiredShow propertiesHide properties
idstringrequiredkindstringrequiredactioncustomstatusstringrequiredpendingapproveddeniedexpiredtitlestringrequireddescriptionstring | nullrequiredpayloadobjectrequiredSecret-safe review payload.
decisionNotestring | nullrequireddecidedByApprovalActor | nullThe recorded reviewer who finalized the decision, not all voters. Null for pending, expired, automated or unattributed decisions. Available to approval readers; not copied into invocation responses.
Show propertiesHide properties
typestringrequiredapi_keyuseridstringrequiredStable recorded reviewer identity. Never an API key value.
displayNamestring | nullrequiredNull when no historical display name was recorded.
nullvotesApprovalVote[]Recorded votes in chronological order on detail reads, including long-poll results. Omitted on list, create and decide responses; fetch the detail to audit all reviewers.
Show propertiesHide properties
ApprovalVotedecisionstringrequiredapprovedenydecidedByApprovalActor | nullrequiredShow propertiesHide properties
ApprovalActornullnotestring | nullrequireddecidedAtstring<date-time>requiredrequiredApprovalsintegerrequiredDistinct approvers needed (N-of-M), as resolved from the governing policy when the approval was created.
approvedCountintegerrequiredApprovals recorded so far.
matchedPolicyIdstring | nullrequiredThe policy that governed this approval, as recorded when it was created. Null when no policy matched (the default gate applied) and on approvals recorded before policies existed.
matchedPolicyVersioninteger | nullrequiredThe version of that policy at the time. Null exactly when matchedPolicyId is null.
policyExplanationstring | nullrequiredA human-readable account of how the policy was applied. Null on approvals recorded before it was kept. It is the approval's own record; an invocation carries its own decision and does not need this.
decisionOriginstring | nullrequiredWho decided. Persisted, not inferred from status. Null while pending. unknown marks a decision made before origin was recorded whose evidence does not settle it; it is never guessed. assistant is an approval by opt-in Anlyon Vigil inside the limits an admin set; it never denies.
humanpolicysystemunknownassistantnullexpiresAtstring<date-time>requireddecidedAtstring<date-time> | nullrequiredcreatedAtstring<date-time>requiredadviceobjectAnlyon Vigil's suggestion, on dashboard (session) responses only and only for workspaces that opted in. API-key callers never receive it.
Show propertiesHide properties
statusstringrequiredpendingreadyfailedskippedstatusReasonstring | nullrequiredWhy advice failed or was skipped, e.g. quota_exceeded, timeout, already_decided.
modelstring | nullrequiredVigil's public model version. Auto-approve thresholds are calibrated per version.
recommendationstring | nullrequiredapprovedenyreviewnullrisknumber | nullrequiredExpected harm if approving were wrong, 0 routine to 4 critical.
riskLevelstring | nullrequiredroutinelowmoderatehighcriticalnullconfidencenumber | nullrequiredreasonsstring[]requiredflagsobject | nullrequiredShow propertiesHide properties
injectionSuspectednumber | nullrequiredconsistentWithHistorynumber | nullrequiredamountUnusualnumber | nullrequiredhistoryobject | nullrequiredThis agent and action over the last 30 days.
Show propertiesHide properties
approvedintegerrequireddeniedintegerrequiredmaxAmountnumber | nullrequiredmedianAmountnumber | nullrequiredauditRequestedbooleanrequiredThis Vigil decision was sampled for a person to check.
auditVerdictstring | nullrequiredagreedisagreenullcreatedAtstring<date-time>requiredcompletedAtstring<date-time> | nullrequiredinvocationInvocationShow propertiesHide properties
idstringrequiredeffectIdstring | nullrequiredThe governed effect this invocation created, for a governed action (an adapter or a declaration). Its outcome, evidence and recovery are at GET /api/v2/actions/effects/{id}. Null for template actions.
gradestring | nullOn invoke responses and single reads: the receipt grade of the effect this invocation created. See Effect.grade. Absent when the invocation has no effect, and on list reads.
confirmedacknowledgedunknownfailedrefuseddeniedpendingnullretryOfstring | nullrequiredThe failed invocation this one deliberately retried.
retriedBystring | nullOn single reads: the invocation that retried this one.
resolutionobject | nullOn single reads: the operator's confirmed outcome for an invocation that was unknown.
Show propertiesHide properties
outcomestringrequiredsucceededfailedevidencestringrequiredexternalReferencestring | nullrequiredresolvedByobjectrequiredShow propertiesHide properties
typestringrequiredapi_keyuseridstringrequiredresolvedAtstring<date-time>requiredactionNamestringrequiredactionVersionIdstring | nullrequiredThe immutable action version this invocation ran. Lets an audit answer which definition executed a given call rather than inferring it. Null only for invocations recorded before versioning existed.
statusstringrequiredunknown means the request may have reached the destination and Anlyon cannot confirm what happened a timeout, or a socket that died after the request was written. It is deliberately distinct from failed, which means the call did not happen: an error before anything left, such as a blocked URL or an invalid template. Do not retry an unknown invocation automatically. Reconcile it with the destination first; retrying is how one refund becomes two. This value is additive clients that do not know it should treat an unrecognised status as not-successful rather than as failed.
pending_approvalrunningsucceededfailedunknowndeniedexpiredresponseStatusinteger | nullrequiredbodystring | nullrequiredRedacted and truncated upstream response body.
errorstring | nullrequireddurationMsinteger | nullrequiredapprovalIdstring | nullrequireddecisionInvocationDecision | nullrequiredWhy the request was allowed or refused, when a policy, a person or expiry decided it. Persisted on the invocation, so it reads the same after the policy is edited or deleted. Null while undecided, for an invocation that ran with no gate, and on rows recorded before this field existed. For a request that was never sent, responseStatus and body stay null: no response is fabricated.
Show propertiesHide properties
sourcestringrequiredpolicyhumansystemassistantcodestringrequiredPOLICY_DENIEDPOLICY_APPROVEDHUMAN_APPROVEDHUMAN_DENIEDAPPROVAL_EXPIREDASSISTANT_APPROVEDeffectstringrequiredWhat actually happened to the request.
approveddeniedexpiredexplanationstringrequiredpolicyobject | nullrequiredThe policy that decided, as it stood at decision time. Null when no policy decided.
Show propertiesHide properties
idstringrequirednamestringrequiredversionintegerrequireddecidedAtstring<date-time>requiredDatabase time the decision was committed.
nullcreatedAtstring<date-time>requiredcompletedAtstring<date-time> | nullrequiredBad Request - Invalid input data
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectUnauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectAuthenticated credential lacks the required scope or workspace access.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectNot Found - Resource does not exist
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectThe request conflicts with current resource state or a concurrent decision.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectToo Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
