List Comments
Lists comment threads on a template, oldest first, with replies and resolved state.
Updated
/v1/studio/templates/{templateId}/commentscurl -X GET "https://api.orshot.com/v1/studio/templates/<TEMPLATE_ID>/comments?includeResolved=<INCLUDE_RESOLVED>&cursor=<CURSOR>&limit=10" \
-H "Authorization: Bearer <ORSHOT_API_KEY>"const res = await fetch("https://api.orshot.com/v1/studio/templates/<TEMPLATE_ID>/comments?includeResolved=<INCLUDE_RESOLVED>&cursor=<CURSOR>&limit=10", {
method: "GET",
headers: {
Authorization: "Bearer <ORSHOT_API_KEY>",
},
});
const data = await res.json();import requests
response = requests.get(
"https://api.orshot.com/v1/studio/templates/<TEMPLATE_ID>/comments?includeResolved=<INCLUDE_RESOLVED>&cursor=<CURSOR>&limit=10",
headers={"Authorization": "Bearer <ORSHOT_API_KEY>"},
)
data = response.json()$ch = curl_init("https://api.orshot.com/v1/studio/templates/<TEMPLATE_ID>/comments?includeResolved=<INCLUDE_RESOLVED>&cursor=<CURSOR>&limit=10");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "GET");
curl_setopt($ch, CURLOPT_HTTPHEADER, [
"Authorization: Bearer <ORSHOT_API_KEY>",
]);
$data = json_decode(curl_exec($ch), true);
curl_close($ch);require "net/http"
require "json"
uri = URI("https://api.orshot.com/v1/studio/templates/<TEMPLATE_ID>/comments?includeResolved=<INCLUDE_RESOLVED>&cursor=<CURSOR>&limit=10")
req = Net::HTTP::Get.new(uri)
req["Authorization"] = "Bearer <ORSHOT_API_KEY>"
res = Net::HTTP.start(uri.hostname, uri.port, use_ssl: true) { |http| http.request(req) }
data = JSON.parse(res.body)Enterprise Only
The Approvals API is available on Enterprise plans, or through first-party apps (the Orshot app and the Orshot MCP server). This endpoint needs read access.
See Enterprise pricing to get access.
Lists comment threads on a template, oldest first, with replies and resolved state.
Results come in pages: pass nextCursor back as cursor until it is null.
Endpoint#
https://api.orshot.com/v1/studio/templates/:templateId/commentsPath Parameters#
| Parameter | Type | Required | Description |
|---|---|---|---|
templateId | Integer | Yes | The template's id. |
Query Parameters#
| Parameter | Type | Required | Description |
|---|---|---|---|
includeResolved | Boolean | No | Include resolved threads. Default true. |
cursor | String | No | Cursor from the previous page's nextCursor. A cursor the API didn't write starts again from the first page. Up to 200 characters. |
limit | Integer | No | Results per page (1 to 100). Default 50. |
Headers#
| Header | Required | Description |
|---|---|---|
Authorization | Yes | Bearer <API key or OAuth token> |
x-workspace-id | No | OAuth tokens with several workspaces: the workspace to act in. API keys ignore it. |
X-Orshot-User-Id | No | API keys only: the user id of the owner, admin or member this call is for. See Acting for a Team Member below. |
X-Session-Id | No | Groups the calls of one agent or MCP session in the activity history. |
Acting for a Team Member#
With an API key, you can send X-Orshot-User-Id with the user id of an owner, admin or member of the workspace to make this call for them. The answer then follows both the key's access level and that person's own access. See acting for a team member.
Request#
await fetch("https://api.orshot.com/v1/studio/templates/101/comments", {
headers: { Authorization: "Bearer <ORSHOT_API_KEY>" },
});{
"comments": [
{
"id": 1,
"templateId": 101,
"parentId": null,
"author": {
"id": "b5d2e8f1-7a3c-4b69-9e0d-3c8a1f6b2e45",
"name": "Jordan Lee",
"email": "jordan@acme.com",
"role": "member"
},
"body": "Ready for brand review",
"anchor": null,
"item": {
"id": 1,
"stageId": 2
},
"resolvedAt": null,
"editedAt": null,
"deletedAt": null,
"createdAt": "2026-09-28T09:30:00.000Z"
},
{
"id": 2,
"templateId": 101,
"parentId": null,
"author": {
"id": "2d8f5a1c-6e4b-4a97-9c3d-7b0e5f1a8d24",
"name": "Tom Becker",
"email": "tom@acme.com",
"role": "member"
},
"body": "Cleared. Keep the headline under 40 characters.",
"anchor": null,
"item": {
"id": 1,
"stageId": 4
},
"resolvedAt": null,
"editedAt": null,
"deletedAt": null,
"createdAt": "2026-09-28T09:30:00.000Z"
}
],
"nextCursor": null
}Response Fields#
Responds 200 with:
| Field | Type | Description |
|---|---|---|
comments | Array | List of Comment, fields below. |
comments[].id | Integer | Numeric id. |
comments[].templateId | Integer | The template's id. |
comments[].parentId | Integer | Can be null. |
comments[].author | Object | One Person. The team member it was posted for when an API key sent X-Orshot-User-Id, else the person or { type: api_key, id, label }. |
comments[].postedVia | Object | { type: api_key, id, label }. Only on a comment an API key posted for a team member (X-Orshot-User-Id): the key it came through, so it reads "Priya Shah, via API key". |
comments[].body | String | |
comments[].anchor | Object | { page, elementId, x, y }. Can be null. |
comments[].item | Object | { id, flowId, stageId }. Context when written. Can be null. |
comments[].resolvedAt | String | ISO 8601 timestamp. Can be null. |
comments[].editedAt | String | ISO 8601 timestamp. Can be null. |
comments[].createdAt | String | ISO 8601 timestamp. |
nextCursor | String | Can be null. Pass it back as cursor for the next page; null on the last page. |
Error Responses#
Every error has the same body: error, code, message and helpUrl, plus the fields that apply (required, role, context, blockers, violations, issues, current). Branch on error; code is more specific. See the error reference.
| Status Code | Error | Description |
|---|---|---|
| 401 | oauth_token_invalid | The OAuth token is invalid, expired or revoked. |
| 403 | api_key_missing | No Authorization: Bearer header. |
| 403 | permission_denied | You don't have access to do this. Ask an owner or admin. code names the capability, for example approval.item.decide_denied; required and role say what was missing. With code: insufficient_scope: the OAuth token lacks workspace:approvals:read. With code: approval.member_header_not_member: X-Orshot-User-Id names someone who isn't an owner, admin or member of the workspace now. With code: approval.member_header_not_allowed: an OAuth token sent X-Orshot-User-Id. |
| 403 | plan_required | The workspace's plan doesn't include Approvals, or doesn't include this part of it. |
| 403 | enterprise_api_required | Using approvals with an API key needs an Enterprise plan. Contact hi@orshot.com to turn it on. |
| 404 | not_found | This doesn't exist or isn't available to you. Reviewers get this, never 403, for flows and templates outside their access. |
| 422 | validation_failed | Some fields aren't valid: the fields listed in issues. issues lists each field with a path and a reason. |
| 422 | validation_failed | With code: approval.member_header_invalid: X-Orshot-User-Id isn't a user id. |
| 429 | rate_limit_exceeded | More than 120 approvals requests in a minute from one person or key. Wait for Retry-After. |
| 503 | approvals_unavailable | Approvals aren't available right now. Try again in a moment. Also returned while approvals are not switched on for the API. |
Ready to automate?
Start rendering images, PDFs and videos from your templates in under 2 minutes. Free plan, no credit card.
Get your API key- Image, PDF and video generation via API
- Visual editor with AI and smart layouts
- Zapier, Make, MCP and 50+ integrations
- White-label embed for your own app
- 100 free credits a month, no credit card required