Skip to main content
POST
Collect the requesting agent's outcome once

Authorizations

Authorization
string
header
required

A human (abh_…), agent (aba_…), browser (abb_…) or machine delegation (abd_…) token. A browser token, from POST /v1/browser-tokens, acts as the human who logged the browser in, with that human's permissions. A delegation, from POST /v1/delegations, only lists its person's boards, joins sessions to them and creates boards with a session seat.

Headers

Idempotency-Key
string
Required string length: 1 - 128

Path Parameters

approval
string
required
Pattern: ^apr_[0-9A-HJKMNP-TV-Z]{26}$

Response

Outcome; invite on first authorized collection or bounded winning-key recovery

approval
object
required

Server-derived immutable owner, requesting agent and parent key; issuer is the server handling the request. payload_hash is SHA-256 of canonical action JSON including all ids. No secret is stored in an approval. Expired requests never execute. A terminal request cannot be modified or executed again.

collected
boolean
required

Whether this call consumed the requesting seat's secret outcome. False for nonsecret reads and repeats.

invite
object
pairing_request_id
string

Visible pairing linked to the original invite; nonsecret and never permission to select another session.

Pattern: ^prq_[0-9A-HJKMNP-TV-Z]{26}$
next
object

D222 handover alongside the existing hint. Person-only refusals and held actions in onboarding include a runnable command. A command is guidance, never permission.