Skip to main content
POST
Decline a pending approval

Authorizations

Authorization
string
header
required

A human (abh_…), agent (aba_…), browser (abb_…) or machine delegation (abd_…) token. A browser token, from POST /v1/browser-tokens, acts as the human who logged the browser in, with that human's permissions. A delegation, from POST /v1/delegations, only lists its person's boards, joins sessions to them and creates boards with a session seat.

Headers

Idempotency-Key
string
Required string length: 1 - 128

Path Parameters

approval
string
required
Pattern: ^apr_[0-9A-HJKMNP-TV-Z]{26}$

Response

Success

Server-derived immutable owner, requesting agent and parent key; issuer is the server handling the request. payload_hash is SHA-256 of canonical action JSON including all ids. No secret is stored in an approval. Expired requests never execute. A terminal request cannot be modified or executed again.

id
string
required
Pattern: ^apr_[0-9A-HJKMNP-TV-Z]{26}$
person_id
string
required
Pattern: ^hum_[0-9A-HJKMNP-TV-Z]{26}$
agent_id
string
required
Pattern: ^mem_[0-9A-HJKMNP-TV-Z]{26}$
parent_key_id
string
required
Pattern: ^key_[0-9A-HJKMNP-TV-Z]{26}$
action
object
required

Exact closed payload. Names/handles never bind authority; ids are resolved before submission. Only invite_people and add_people can be allowed automatically. Server validation rejects unknown kinds and any extra field, and rechecks existing operation-specific safety constraints.

payload_hash
string
required
Pattern: ^sha256:[0-9a-f]{64}$
state
enum<string>
required
Available options:
pending,
executed,
declined,
expired
created_at
string<date-time>
required
execution
object

Nonsecret immutable execution record, saved with the side effect and approval in one transaction, for automatic allowance actions too. Cannot be overwritten or removed by deciding/replaying an approval. Server-level actions without a board event remain auditable through their terminal approval and execution; listApprovals includes them subject to current owner/access checks. Actions affecting boards also put this authorization in the existing event data, covered by data_hash (the envelope and actor stay unchanged). This adds no new event type or server hash chain.

expires_at
string<date-time>
decided_at
string<date-time>
next
object

D222 handover alongside the existing hint. Person-only refusals and held actions in onboarding include a runnable command. A command is guidance, never permission.