Approve
Approves a template in its current review stage, as the signed-in person.
Updated
/v1/approval-flows/{flow}/items/{item}/approvecurl -X POST "https://api.orshot.com/v1/approval-flows/<FLOW>/items/<ITEM>/approve" \
-H "Authorization: Bearer <ORSHOT_API_KEY>" \
-H "Content-Type: application/json" \
-d '{
"reviewedVersion": "<REVIEWED_VERSION>",
"outputs": [],
"conditions": {},
"comment": "<COMMENT>"
}'const res = await fetch("https://api.orshot.com/v1/approval-flows/<FLOW>/items/<ITEM>/approve", {
method: "POST",
headers: {
"Content-Type": "application/json",
Authorization: "Bearer <ORSHOT_API_KEY>",
},
body: JSON.stringify({
"reviewedVersion": "<REVIEWED_VERSION>",
"outputs": [],
"conditions": {},
"comment": "<COMMENT>"
}),
});
const data = await res.json();import requests
response = requests.post(
"https://api.orshot.com/v1/approval-flows/<FLOW>/items/<ITEM>/approve",
headers={"Authorization": "Bearer <ORSHOT_API_KEY>"},
json={
"reviewedVersion": "<REVIEWED_VERSION>",
"outputs": [],
"conditions": {},
"comment": "<COMMENT>"
},
)
data = response.json()$ch = curl_init("https://api.orshot.com/v1/approval-flows/<FLOW>/items/<ITEM>/approve");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($ch, CURLOPT_HTTPHEADER, [
"Authorization: Bearer <ORSHOT_API_KEY>",
"Content-Type: application/json",
]);
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode([
"reviewedVersion" => "<REVIEWED_VERSION>",
"outputs" => [],
"conditions" => [],
"comment" => "<COMMENT>"
]));
$data = json_decode(curl_exec($ch), true);
curl_close($ch);require "net/http"
require "json"
uri = URI("https://api.orshot.com/v1/approval-flows/<FLOW>/items/<ITEM>/approve")
req = Net::HTTP::Post.new(uri)
req["Authorization"] = "Bearer <ORSHOT_API_KEY>"
req["Content-Type"] = "application/json"
req.body = {
"reviewedVersion": "<REVIEWED_VERSION>",
"outputs": [],
"conditions": {},
"comment": "<COMMENT>"
}.to_json
res = Net::HTTP.start(uri.hostname, uri.port, use_ssl: true) { |http| http.request(req) }
data = JSON.parse(res.body)Enterprise Only
The Approvals API is available on Enterprise plans, or through first-party apps (the Orshot app and the Orshot MCP server). This endpoint needs decide access.
See Enterprise pricing to get access.
Approves a template in its current review stage, as the signed-in person. Only people with a decide grant on that stage can approve, and usually not their own submission. Send reviewedVersion (the template's current_version you looked at); if the design changed since, you get stale_review and must look again. Optional outputs limit the approval to some output kinds; conditions attach field limits (for example headline at most 40 characters) that every API render must respect. Never approve on the person's behalf without their explicit instruction.
Send an Idempotency-Key header to retry safely: a repeat within 24 hours returns the first response and changes nothing.
Endpoint#
https://api.orshot.com/v1/approval-flows/:flow/items/:item/approvePath Parameters#
| Parameter | Type | Required | Description |
|---|---|---|---|
flow | String | Yes | The approval flow's id or slug. A number is an id, anything else a slug. |
item | Integer | Yes | The approval item's id (one template in one approval flow). |
Request Body#
| Parameter | Type | Required | Description |
|---|---|---|---|
reviewedVersion | String | Yes | The template's current_version the reviewer looked at. The decision is refused with stale_review if the design changed since. |
outputs | Array | No | Output kinds this approval covers (image, pdf, video). Omit for every kind the stage allows. |
conditions | Object | No | What the approval is conditional on, e.g. { fields: { headline: { maxLength: 40 } } }. A field name is at most 200 characters, and the whole object at most 32000 characters as JSON. |
comment | String | No | Optional note. Up to 5000 characters. |
conditions#
| Parameter | Type | Required | Description |
|---|---|---|---|
v | Number | No | Must be 1. |
fields | Object | No | Fields in the table below. |
imageDomains | Array | No | Up to 50 items. |
conditions.fields.<name>#
| Parameter | Type | Required | Description |
|---|---|---|---|
maxLength | Integer | No | From 0 to 100000. |
minLength | Integer | No | From 0 to 100000. |
locked | Boolean | No | |
allowedValues | Array | No | Up to 200 items. |
allowedDomains | Array | No | Up to 50 items. |
Headers#
| Header | Required | Description |
|---|---|---|
Authorization | Yes | Bearer <API key or OAuth token> |
x-workspace-id | No | OAuth tokens with several workspaces: the workspace to act in. API keys ignore it. |
Idempotency-Key | No | Up to 255 visible characters, unique per request. A replay within 24 hours returns the stored response with Idempotent-Replayed: true. |
X-Session-Id | No | Groups the calls of one agent or MCP session in the activity history. |
Acting for a Team Member#
API keys can't send X-Orshot-User-Id here: approvals come from the person, through their OAuth token or the Orshot app. With the header, the call gets 403 permission_denied, code approval.decision_person_required. See acting for a team member.
Request#
await fetch("https://api.orshot.com/v1/approval-flows/brand-and-legal/items/1/approve", {
method: "POST",
headers: {
"Content-Type": "application/json",
Authorization: "Bearer <ORSHOT_API_KEY>",
"Idempotency-Key": "<unique request id>",
},
body: JSON.stringify({
"reviewedVersion": "5b8e2f7a-3c1d-4e9b-a6f0-7d2c8e1b4a93",
"conditions": {
"fields": {
"headline": {
"maxLength": 40
}
}
},
"comment": "Cleared. Keep the headline under 40 characters."
}),
});{
"item": {
"id": 1,
"flow": {
"id": 1,
"slug": "brand-and-legal",
"name": "Brand and legal"
},
"stage": {
"id": 5,
"slug": "approved-for-automation",
"name": "Automation approved",
"category": "approved",
"color": null
},
"template": {
"id": 101,
"name": "Spring sale banner",
"thumbnailUrl": "https://storage.orshot.com/thumbnails/101.png",
"currentVersion": "5b8e2f7a-3c1d-4e9b-a6f0-7d2c8e1b4a93",
"folderId": null,
"tags": []
},
"reviewRound": 1,
"revision": 5,
"approvals": null,
"changesRequested": null,
"commentCount": 2,
"canRender": {
"image": true,
"pdf": true,
"video": true
},
"heldBack": null,
"dueAt": null,
"createdAt": "2026-09-28T09:30:00.000Z",
"updatedAt": "2026-09-28T09:30:00.000Z"
},
"decision": {
"id": 2,
"itemId": 1,
"stage": {
"id": 4,
"slug": "legal-review",
"name": "Legal review"
},
"reviewRound": 1,
"decision": "approve",
"outputs": null,
"conditions": {
"fields": {
"headline": {
"maxLength": 40
}
},
"v": 1
},
"actor": {
"id": "2d8f5a1c-6e4b-4a97-9c3d-7b0e5f1a8d24",
"name": null,
"email": null,
"role": null
},
"via": "api",
"client": null,
"createdAt": "2026-09-28T09:30:00.000Z",
"supersededAt": null
},
"warnings": []
}Response Fields#
Responds 200 with:
| Field | Type | Description |
|---|---|---|
item | Object | One ApprovalItem, fields below. |
item.id | Integer | Numeric id. |
item.flow | Object | { id, slug, name }. |
item.stage | Object | { id, slug, name, category, color }. Color is the stage's color, null when it has none. |
item.template | Object | { id, name, thumbnailUrl, currentVersion, folderId, tags }. With currentVersion to send back as reviewedVersion when approving, folderId the template's folder (null for none) and tags its tags (string[]). |
item.reviewRound | Integer | Goes up each time the template re-enters review. |
item.revision | Integer | Send it back on move (state_conflict if it changed). |
item.approvals | Object | { mode, required, approvedBy: Person[], changesRequestedBy: Person[], submitter?: { id } }. For the current round, in review stages. submitter is who submitted it when the stage keeps them from approving it themselves (the stage doesn't let people approve what they submitted, and they are not an owner or admin). |
item.changesRequested | Object | { by: Person[], stage: { id, slug, name } }. The change request it was sent back with, until it is resubmitted. Can be null. |
item.commentCount | Integer | Comments on the template (replies included, deleted ones left out). |
item.canRender | Object | { image, pdf, video }. Booleans. |
item.movedWithoutApproval | Object | { by: Person, at: ISO date, reason }. or absent, present while the template sits where an owner or admin moved it without its approvals. |
item.dueAt | String | ISO 8601 timestamp. Can be null. |
item.createdAt | String | ISO 8601 timestamp. |
item.updatedAt | String | ISO 8601 timestamp. |
decision | Object | One ApprovalDecision, fields below. |
decision.id | Integer | Numeric id. |
decision.itemId | Integer | The approval item's id. |
decision.stage | Object | { id, slug, name }. |
decision.reviewRound | Integer | |
decision.decision | String | One of approve, request_changes. |
decision.outputs | Array | List of string values. Can be null. |
decision.conditions | Object | Can be null. |
decision.actor | Object | One Person. |
decision.via | String | |
decision.client | String | Can be null. |
decision.createdAt | String | ISO 8601 timestamp. |
decision.supersededAt | String | ISO 8601 timestamp. Can be null. |
warnings | Array | Non-blocking notices, each { code, message? }, for example no_approver. Always present on writes, empty when there is nothing to say. |
Error Responses#
Every error has the same body: error, code, message and helpUrl, plus the fields that apply (required, role, context, blockers, violations, issues, current). Branch on error; code is more specific. See the error reference.
| Status Code | Error | Description |
|---|---|---|
| 401 | oauth_token_invalid | The OAuth token is invalid, expired or revoked. |
| 403 | api_key_missing | No Authorization: Bearer header. |
| 403 | permission_denied | You don't have access to do this. Ask an owner or admin. code names the capability, for example approval.item.decide_denied; required and role say what was missing. With code: insufficient_scope: the OAuth token lacks workspace:approvals:decide. With code: approval.decision_person_required: an API key sent X-Orshot-User-Id. Approvals come from the person. |
| 403 | plan_required | The workspace's plan doesn't include Approvals, or doesn't include this part of it. |
| 403 | enterprise_api_required | Using approvals with an API key needs an Enterprise plan. Contact hi@orshot.com to turn it on. |
| 404 | not_found | This doesn't exist or isn't available to you. Reviewers get this, never 403, for flows and templates outside their access. |
| 409 | stale_review | The design changed while you were reviewing it. Review the latest version and try again. current.currentVersion is the design to review instead. |
| 409 | state_conflict | Someone else moved this template first. Refresh to see where it is now. current carries the item's revision and stage now. |
| 409 | state_conflict | With code: approval.request_in_progress: the same Idempotency-Key is still running. |
| 422 | validation_failed | Some fields aren't valid: the fields listed in issues. issues lists each field with a path and a reason. |
| 422 | validation_failed | With code: approval.idempotency_key_reused: the Idempotency-Key was used with a different request. |
| 429 | rate_limit_exceeded | More than 120 approvals requests in a minute from one person or key. Wait for Retry-After. |
| 503 | approvals_unavailable | Approvals aren't available right now. Try again in a moment. Also returned while approvals are not switched on for the API. |
Ready to automate?
Start rendering images, PDFs and videos from your templates in under 2 minutes. Free plan, no credit card.
Get your API key- Image, PDF and video generation via API
- Visual editor with AI and smart layouts
- Zapier, Make, MCP and 50+ integrations
- White-label embed for your own app
- 100 free credits a month, no credit card required