# Comment

> Adds a comment or a reply (parentId) to a template, optionally pinned to a page or element.

- **URL**: https://orshot.com/docs/api-reference/approvals-comments-create

---

The Approvals API is available on Enterprise plans, or through first-party apps (the Orshot app and the Orshot MCP server). This endpoint needs [`move` access](/docs/api-reference/approvals-overview#access-levels).
See [Enterprise pricing](https://orshot.com/pricing) to get access.

Adds a comment or a reply (parentId) to a template, optionally pinned to a page or element. Mention up to 20 workspace members as `@[Name](user:<id>)` with ids from [list people to mention](https://orshot.com/docs/api-reference/approvals-people-list); more than 20, or someone outside the workspace, is refused with validation_failed. The name in each mention is replaced with the person's profile name when the comment is saved. Someone who can't see the template keeps the mention but isn't notified. Comments are posted as the signed-in person.

Send an `Idempotency-Key` header to retry safely: a repeat within 24 hours returns the first response and changes nothing.

## Endpoint

```markdown tab="Endpoint"
https://api.orshot.com/v1/studio/templates/:templateId/comments
```

## Path Parameters

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `templateId` | Integer | Yes | The template's id. |

## Request Body

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `body` | String | Yes | Comment text. @mention up to 20 people as `@[Name](user:<uuid>)`. Each name is replaced with the person's profile name when saved. Up to 5000 characters. |
| `parentId` | Integer | No | Reply to this comment. |
| `anchor` | Object | No | Fields in the table below. |
| `flow` | String | No | Approval flow this comment is about, if any. A number is an id, anything else a slug. |

### `anchor`

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `page` | Integer or String | No | Page number or id. Up to 64 characters. |
| `elementId` | String | No | Element the comment points at. Up to 128 characters. |
| `x` | Number | No | Horizontal position, 0 to 1. |
| `y` | Number | No | Vertical position, 0 to 1. |

## Headers

| Header | Required | Description |
| ------ | -------- | ----------- |
| `Authorization` | Yes | `Bearer <API key or OAuth token>` |
| `x-workspace-id` | No | OAuth tokens with several workspaces: the workspace to act in. API keys ignore it. |
| `X-Orshot-User-Id` | No | API keys only: the user id of the owner, admin or member this call is for. See Acting for a Team Member below. |
| `Idempotency-Key` | No | Up to 255 visible characters, unique per request. A replay within 24 hours returns the stored response with Idempotent-Replayed: true. |
| `X-Session-Id` | No | Groups the calls of one agent or MCP session in the activity history. |

## Acting for a Team Member

With an API key, you can send `X-Orshot-User-Id` with the user id of an owner, admin or member of the workspace to make this call for them. It needs both the key's access level and that person's own access, and it's credited to them: people see "Priya Shah, via API key", and they aren't notified about their own change. See [acting for a team member](https://orshot.com/docs/api-reference/approvals-overview#acting-for-a-team-member).

## Request

**Request**
```js
await fetch("https://api.orshot.com/v1/studio/templates/101/comments", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    Authorization: "Bearer <ORSHOT_API_KEY>",
    "Idempotency-Key": "<unique request id>",
  },
  body: JSON.stringify({
    "body": "@[Priya Shah](user:9a4c7e2b-1d6f-4e3a-8b5c-2f7d0e9a4c61) can you check the claim in the headline?"
  }),
});
```

**Response**
```json
{
  "comment": {
    "id": 4,
    "templateId": 101,
    "parentId": null,
    "author": {
      "id": "b5d2e8f1-7a3c-4b69-9e0d-3c8a1f6b2e45",
      "name": "Jordan Lee",
      "email": "jordan@acme.com",
      "role": "member"
    },
    "body": "@[Priya Shah](user:9a4c7e2b-1d6f-4e3a-8b5c-2f7d0e9a4c61) can you check the claim in the headline?",
    "anchor": null,
    "item": null,
    "resolvedAt": null,
    "editedAt": null,
    "deletedAt": null,
    "createdAt": "2026-09-28T09:30:00.000Z"
  },
  "warnings": []
}
```

## Response Fields

Responds `201` with:

| Field | Type | Description |
| ----- | ---- | ----------- |
| `comment` | Object | One Comment, fields below. |
| `comment.id` | Integer | Numeric id. |
| `comment.templateId` | Integer | The template's id. |
| `comment.parentId` | Integer | Can be `null`. |
| `comment.author` | Object | One Person. The team member it was posted for when an API key sent X-Orshot-User-Id, else the person or `{ type: api_key, id, label }`. |
| `comment.postedVia` | Object | `{ type: api_key, id, label }`. Only on a comment an API key posted for a team member (X-Orshot-User-Id): the key it came through, so it reads "Priya Shah, via API key". |
| `comment.body` | String |  |
| `comment.anchor` | Object | `{ page, elementId, x, y }`. Can be `null`. |
| `comment.item` | Object | `{ id, flowId, stageId }`. Context when written. Can be `null`. |
| `comment.resolvedAt` | String | ISO 8601 timestamp. Can be `null`. |
| `comment.editedAt` | String | ISO 8601 timestamp. Can be `null`. |
| `comment.createdAt` | String | ISO 8601 timestamp. |
| `warnings` | Array | Non-blocking notices, each `{ code, message? }`, for example `no_approver`. Always present on writes, empty when there is nothing to say. |

## Error Responses

Every error has the same body: `error`, `code`, `message` and `helpUrl`, plus the fields that apply (`required`, `role`, `context`, `blockers`, `violations`, `issues`, `current`). Branch on `error`; `code` is more specific. See the [error reference](https://orshot.com/docs/error-reference).

| Status Code | Error | Description |
| ----------- | ----- | ----------- |
| 401 | `oauth_token_invalid` | The OAuth token is invalid, expired or revoked. |
| 403 | `api_key_missing` | No `Authorization: Bearer` header. |
| 403 | `permission_denied` | You don't have access to do this. Ask an owner or admin. `code` names the capability, for example `approval.item.decide_denied`; `required` and `role` say what was missing. With `code: insufficient_scope`: the OAuth token lacks `workspace:approvals:write`. With `code: approval.member_header_not_member`: `X-Orshot-User-Id` names someone who isn't an owner, admin or member of the workspace now. With `code: approval.member_header_not_allowed`: an OAuth token sent `X-Orshot-User-Id`. |
| 403 | `plan_required` | The workspace's plan doesn't include Approvals, or doesn't include this part of it. |
| 403 | `enterprise_api_required` | Using approvals with an API key needs an Enterprise plan. Contact hi@orshot.com to turn it on. |
| 404 | `not_found` | This doesn't exist or isn't available to you. Reviewers get this, never 403, for flows and templates outside their access. |
| 409 | `state_conflict` | With `code: approval.request_in_progress`: the same Idempotency-Key is still running. |
| 422 | `validation_failed` | Some fields aren't valid: the fields listed in issues. `issues` lists each field with a path and a reason. |
| 422 | `validation_failed` | With `code: approval.member_header_invalid`: `X-Orshot-User-Id` isn't a user id. |
| 422 | `validation_failed` | With `code: approval.idempotency_key_reused`: the Idempotency-Key was used with a different request. |
| 429 | `rate_limit_exceeded` | More than 120 approvals requests in a minute from one person or key. Wait for Retry-After. |
| 503 | `approvals_unavailable` | Approvals aren't available right now. Try again in a moment. Also returned while approvals are not switched on for the API. |