Approve or reject a step
Answers a sign-off an agent run is waiting on, and lets the run carry on.
Read the outstanding ones from approvals[] on the run — each carries the step’s name, the files it touches and, for a before gate, the params it proposes.
Rejecting needs a reason. { "decision": "reject", "note": "Wrong signer." } — a rejection without a note is a 400.
Editing before you approve. Send params to replace the proposed inputs, files to replace the files the step works on (ids from POST /v1/files or the run’s own inputs). The two together must stay under 1 MiB.
The response carries the decision plus run.status, so you know whether the run moved on, finished, or is blocked on the next thing. ?wait= holds the request while the run picks the work back up, releasing early the moment it finishes or blocks again.
Deciding the same sign-off twice is a 409 — the first answer stands.
An API key has no person behind it, so the run records your organization’s key as the actor rather than a named individual.
Learn more: Agents guide
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Path parameters
Headers
Query parameters
How many seconds to hold the request open. Releases early the moment the run finishes or blocks on a person. Maximum 120; 0 returns immediately.
Request
Approve to let the step run (or its result stand), reject to refuse it. A rejection needs a note.
Response headers
true when this response replays an earlier request.