apr_. For why agents ask and how the run waits, see Approvals and questions.
States
resolvedBy is { "type": "system" } when the platform closed the approval. An agent can never resolve an approval.
Triggers
Fields
string
required
Public approval id,
apr_….string
required
Always
approval.string
required
The workspace’s public id. Left out of list rows.
string
The linked task,
tsk_…. Null when the approval has no task.string
The raising session. Null when no run raised it. Left out of list rows.
string
The raising run,
run_…. Null when no run raised it, as with a learning review.string
required
What raised it. One of the six triggers above.
string
required
open or resolved.string
required
What is gated, in plain words, with secrets masked.
object
required
The gated action.
object
required
Who raised it.
type is agent with an agt_ id, or system. Never a user.object
The one user who may resolve it, or
{ "type": "system" }. Null when no default approver was found. Any user may then resolve it.object
outcome (approve, reject or expired) and reason, the note. Null while open.string
once or always, for an approved tool_permission. Null otherwise.object
{ "type": "user", "id": "usr_…" } or { "type": "system" }. Null while open.string
When it was resolved. Null while open.
string
required
When it was raised.
string
required
When it last changed.
CLI
API
EveryPOST below needs an Idempotency-Key header.
Approving a
tool_permission with appliedScope: "always" adds an allow rule to the requesting agent.
Errors
For shared codes, such as idempotency errors, see API errors.
Limits
- A list page holds 25 approvals by default and 100 at most.
- A
tool_permissionapproval expires 24 hours after its run ends. The sweep runs once an hour. - A
platform_changeapproval expires 7 days after it is raised.
Approvals and questions
Why an agent asks, and how its run waits.
Answer approvals
Decide on an approval from the inbox or the terminal.
Question
The other way an agent hands control back.
Run
The run that raises an approval.