List approvals
/api/v2/approvalsAuthorizationBearer token (Anlyon API key) · headerrequiredWorkspace API key sent as Authorization: Bearer <key>.
better-auth.session_tokenAPI key · cookierequiredBrowser session used by dashboard-only operations.
statusstringpendingapproveddeniedexpireddecisionOriginstringFilter by who decided. automated is policy, system or assistant, so an inbox can show people the decisions that need them and keep machine-made ones as an audit trail.
humanpolicysystemunknownassistantautomatedlimitintegeroffsetintegerX-Request-IdstringOptional caller correlation ID. Unsafe or oversized values are replaced.
Approvals returned.
successbooleanrequiredtruedataApproval[]requiredShow propertiesHide properties
Approvalidstringrequiredkindstringrequiredactioncustomstatusstringrequiredpendingapproveddeniedexpiredtitlestringrequireddescriptionstring | nullrequiredpayloadobjectrequiredSecret-safe review payload.
decisionNotestring | nullrequireddecidedByApprovalActor | nullThe recorded reviewer who finalized the decision, not all voters. Null for pending, expired, automated or unattributed decisions. Available to approval readers; not copied into invocation responses.
Show propertiesHide properties
typestringrequiredapi_keyuseridstringrequiredStable recorded reviewer identity. Never an API key value.
displayNamestring | nullrequiredNull when no historical display name was recorded.
nullvotesApprovalVote[]Recorded votes in chronological order on detail reads, including long-poll results. Omitted on list, create and decide responses; fetch the detail to audit all reviewers.
Show propertiesHide properties
ApprovalVotedecisionstringrequiredapprovedenydecidedByApprovalActor | nullrequiredShow propertiesHide properties
ApprovalActornullnotestring | nullrequireddecidedAtstring<date-time>requiredrequiredApprovalsintegerrequiredDistinct approvers needed (N-of-M), as resolved from the governing policy when the approval was created.
approvedCountintegerrequiredApprovals recorded so far.
matchedPolicyIdstring | nullrequiredThe policy that governed this approval, as recorded when it was created. Null when no policy matched (the default gate applied) and on approvals recorded before policies existed.
matchedPolicyVersioninteger | nullrequiredThe version of that policy at the time. Null exactly when matchedPolicyId is null.
policyExplanationstring | nullrequiredA human-readable account of how the policy was applied. Null on approvals recorded before it was kept. It is the approval's own record; an invocation carries its own decision and does not need this.
decisionOriginstring | nullrequiredWho decided. Persisted, not inferred from status. Null while pending. unknown marks a decision made before origin was recorded whose evidence does not settle it; it is never guessed. assistant is an approval by opt-in Anlyon Vigil inside the limits an admin set; it never denies.
humanpolicysystemunknownassistantnullexpiresAtstring<date-time>requireddecidedAtstring<date-time> | nullrequiredcreatedAtstring<date-time>requiredadviceobjectAnlyon Vigil's suggestion, on dashboard (session) responses only and only for workspaces that opted in. API-key callers never receive it.
Show propertiesHide properties
statusstringrequiredpendingreadyfailedskippedstatusReasonstring | nullrequiredWhy advice failed or was skipped, e.g. quota_exceeded, timeout, already_decided.
modelstring | nullrequiredVigil's public model version. Auto-approve thresholds are calibrated per version.
recommendationstring | nullrequiredapprovedenyreviewnullrisknumber | nullrequiredExpected harm if approving were wrong, 0 routine to 4 critical.
riskLevelstring | nullrequiredroutinelowmoderatehighcriticalnullconfidencenumber | nullrequiredreasonsstring[]requiredflagsobject | nullrequiredShow propertiesHide properties
injectionSuspectednumber | nullrequiredconsistentWithHistorynumber | nullrequiredamountUnusualnumber | nullrequiredhistoryobject | nullrequiredThis agent and action over the last 30 days.
Show propertiesHide properties
approvedintegerrequireddeniedintegerrequiredmaxAmountnumber | nullrequiredmedianAmountnumber | nullrequiredauditRequestedbooleanrequiredThis Vigil decision was sampled for a person to check.
auditVerdictstring | nullrequiredagreedisagreenullcreatedAtstring<date-time>requiredcompletedAtstring<date-time> | nullrequiredpaginationOffsetPaginationrequiredShow propertiesHide properties
totalintegerrequiredpageintegerrequiredlimitintegerrequiredtotalPagesintegerrequiredhasMorebooleanrequiredBad Request - Invalid input data
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectUnauthorized - Invalid or missing API key
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectAuthenticated credential lacks the required scope or workspace access.
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobjectToo Many Requests - Rate limit exceeded
successbooleanrequiredrequestIdstringrequiredCorrelation ID matching the X-Request-Id response header.
errorobjectrequiredShow propertiesHide properties
codestringmessagestringdetailsobject
