Skip to main content
POST
Allow and execute an exact approval

Authorizations

Authorization
string
header
required

A human (abh_…), agent (aba_…), browser (abb_…) or machine delegation (abd_…) token. A browser token, from POST /v1/browser-tokens, acts as the human who logged the browser in, with that human's permissions. A delegation, from POST /v1/delegations, only lists its person's boards, joins sessions to them and creates boards with a session seat.

Headers

Idempotency-Key
string
Required string length: 1 - 128

Path Parameters

approval
string
required
Pattern: ^apr_[0-9A-HJKMNP-TV-Z]{26}$

Body

application/json

always is invalid_request for every category except invite_people/add_people, even if the person could do the action.

always
boolean
default:false

Response

Success

202 is pending with no side effect; 200/201 is executed. Invite secrets appear only on the authenticated execution response, never in stored approval, listings, next or idempotent responses. A repeated executed approval cannot issue another invite or retrieve the old secret.

state
enum<string>
required
Available options:
pending,
executed
approval
object
required

Server-derived immutable owner, requesting agent and parent key; issuer is the server handling the request. payload_hash is SHA-256 of canonical action JSON including all ids. No secret is stored in an approval. Expired requests never execute. A terminal request cannot be modified or executed again.

next
object

D222 handover alongside the existing hint. Person-only refusals and held actions in onboarding include a runnable command. A command is guidance, never permission.

invite
object