Request Changes

Sends a template back with changes requested, from its current review stage.

Updated

POST
/v1/approval-flows/{flow}/items/{item}/request-changes
curl -X POST "https://api.orshot.com/v1/approval-flows/<FLOW>/items/<ITEM>/request-changes" \
  -H "Authorization: Bearer <ORSHOT_API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{
    "reviewedVersion": "<REVIEWED_VERSION>",
    "comment": "<COMMENT>"
  }'

Sends a template back with changes requested, from its current review stage. A comment saying what to change is required (comment_required otherwise). The template moves to the stage the flow names for changes and the next review starts a new round.

Send an Idempotency-Key header to retry safely: a repeat within 24 hours returns the first response and changes nothing.

Endpoint#

Endpoint
https://api.orshot.com/v1/approval-flows/:flow/items/:item/request-changes

Path Parameters#

ParameterTypeRequiredDescription
flowStringYesThe approval flow's id or slug. A number is an id, anything else a slug.
itemIntegerYesThe approval item's id (one template in one approval flow).

Request Body#

ParameterTypeRequiredDescription
reviewedVersionStringYesThe template's current_version the reviewer looked at. The decision is refused with stale_review if the design changed since.
commentStringNoWhat needs to change (required). Up to 5000 characters.

Headers#

HeaderRequiredDescription
AuthorizationYesBearer <API key or OAuth token>
x-workspace-idNoOAuth tokens with several workspaces: the workspace to act in. API keys ignore it.
Idempotency-KeyNoUp to 255 visible characters, unique per request. A replay within 24 hours returns the stored response with Idempotent-Replayed: true.
X-Session-IdNoGroups the calls of one agent or MCP session in the activity history.

Acting for a Team Member#

API keys can't send X-Orshot-User-Id here: approvals come from the person, through their OAuth token or the Orshot app. With the header, the call gets 403 permission_denied, code approval.decision_person_required. See acting for a team member.

Request#

JavaScript
await fetch("https://api.orshot.com/v1/approval-flows/brand-and-legal/items/2/request-changes", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    Authorization: "Bearer <ORSHOT_API_KEY>",
    "Idempotency-Key": "<unique request id>",
  },
  body: JSON.stringify({
    "reviewedVersion": "5b8e2f7a-3c1d-4e9b-a6f0-7d2c8e1b4a93",
    "comment": "The logo is too small on mobile."
  }),
});
JSON
{
  "item": {
    "id": 2,
    "flow": {
      "id": 1,
      "slug": "brand-and-legal",
      "name": "Brand and legal"
    },
    "stage": {
      "id": 1,
      "slug": "draft",
      "name": "Draft",
      "category": "open",
      "color": null
    },
    "template": {
      "id": 102,
      "name": "Product card",
      "thumbnailUrl": "https://storage.orshot.com/thumbnails/102.png",
      "currentVersion": "5b8e2f7a-3c1d-4e9b-a6f0-7d2c8e1b4a93",
      "folderId": null,
      "tags": []
    },
    "reviewRound": 2,
    "revision": 3,
    "approvals": null,
    "changesRequested": {
      "by": [
        {
          "id": "9a4c7e2b-1d6f-4e3a-8b5c-2f7d0e9a4c61",
          "name": "Priya Shah",
          "email": "priya@acme.com",
          "role": "member"
        }
      ],
      "stage": {
        "id": 2,
        "slug": "brand-review",
        "name": "Brand review"
      }
    },
    "commentCount": 1,
    "canRender": {
      "image": false,
      "pdf": false,
      "video": false
    },
    "heldBack": null,
    "dueAt": null,
    "createdAt": "2026-09-28T09:30:00.000Z",
    "updatedAt": "2026-09-28T09:30:00.000Z"
  },
  "decision": {
    "id": 4,
    "itemId": 2,
    "stage": {
      "id": 2,
      "slug": "brand-review",
      "name": "Brand review"
    },
    "reviewRound": 1,
    "decision": "request_changes",
    "outputs": null,
    "conditions": null,
    "actor": {
      "id": "9a4c7e2b-1d6f-4e3a-8b5c-2f7d0e9a4c61",
      "name": null,
      "email": null,
      "role": null
    },
    "via": "api",
    "client": null,
    "createdAt": "2026-09-28T09:30:00.000Z",
    "supersededAt": null
  },
  "warnings": []
}

Response Fields#

Responds 200 with:

FieldTypeDescription
itemObjectOne ApprovalItem, fields below.
item.idIntegerNumeric id.
item.flowObject{ id, slug, name }.
item.stageObject{ id, slug, name, category, color }. Color is the stage's color, null when it has none.
item.templateObject{ id, name, thumbnailUrl, currentVersion, folderId, tags }. With currentVersion to send back as reviewedVersion when approving, folderId the template's folder (null for none) and tags its tags (string[]).
item.reviewRoundIntegerGoes up each time the template re-enters review.
item.revisionIntegerSend it back on move (state_conflict if it changed).
item.approvalsObject{ mode, required, approvedBy: Person[], changesRequestedBy: Person[], submitter?: { id } }. For the current round, in review stages. submitter is who submitted it when the stage keeps them from approving it themselves (the stage doesn't let people approve what they submitted, and they are not an owner or admin).
item.changesRequestedObject{ by: Person[], stage: { id, slug, name } }. The change request it was sent back with, until it is resubmitted. Can be null.
item.commentCountIntegerComments on the template (replies included, deleted ones left out).
item.canRenderObject{ image, pdf, video }. Booleans.
item.movedWithoutApprovalObject{ by: Person, at: ISO date, reason }. or absent, present while the template sits where an owner or admin moved it without its approvals.
item.dueAtStringISO 8601 timestamp. Can be null.
item.createdAtStringISO 8601 timestamp.
item.updatedAtStringISO 8601 timestamp.
decisionObjectOne ApprovalDecision, fields below.
decision.idIntegerNumeric id.
decision.itemIdIntegerThe approval item's id.
decision.stageObject{ id, slug, name }.
decision.reviewRoundInteger
decision.decisionStringOne of approve, request_changes.
decision.outputsArrayList of string values. Can be null.
decision.conditionsObjectCan be null.
decision.actorObjectOne Person.
decision.viaString
decision.clientStringCan be null.
decision.createdAtStringISO 8601 timestamp.
decision.supersededAtStringISO 8601 timestamp. Can be null.
warningsArrayNon-blocking notices, each { code, message? }, for example no_approver. Always present on writes, empty when there is nothing to say.

Error Responses#

Every error has the same body: error, code, message and helpUrl, plus the fields that apply (required, role, context, blockers, violations, issues, current). Branch on error; code is more specific. See the error reference.

Status CodeErrorDescription
401oauth_token_invalidThe OAuth token is invalid, expired or revoked.
403api_key_missingNo Authorization: Bearer header.
403permission_deniedYou don't have access to do this. Ask an owner or admin. code names the capability, for example approval.item.decide_denied; required and role say what was missing. With code: insufficient_scope: the OAuth token lacks workspace:approvals:decide. With code: approval.decision_person_required: an API key sent X-Orshot-User-Id. Approvals come from the person.
403plan_requiredThe workspace's plan doesn't include Approvals, or doesn't include this part of it.
403enterprise_api_requiredUsing approvals with an API key needs an Enterprise plan. Contact hi@orshot.com to turn it on.
404not_foundThis doesn't exist or isn't available to you. Reviewers get this, never 403, for flows and templates outside their access.
409stale_reviewThe design changed while you were reviewing it. Review the latest version and try again. current.currentVersion is the design to review instead.
409state_conflictSomeone else moved this template first. Refresh to see where it is now. current carries the item's revision and stage now.
409state_conflictWith code: approval.request_in_progress: the same Idempotency-Key is still running.
422validation_failedSome fields aren't valid: the fields listed in issues. issues lists each field with a path and a reason.
422comment_requiredAdd a comment explaining what needs to change.
422validation_failedWith code: approval.idempotency_key_reused: the Idempotency-Key was used with a different request.
429rate_limit_exceededMore than 120 approvals requests in a minute from one person or key. Wait for Retry-After.
503approvals_unavailableApprovals aren't available right now. Try again in a moment. Also returned while approvals are not switched on for the API.
Was this page helpful?

Ready to automate?

Start rendering images, PDFs and videos from your templates in under 2 minutes. Free plan, no credit card.

Get your API key
  • Image, PDF and video generation via API
  • Visual editor with AI and smart layouts
  • Zapier, Make, MCP and 50+ integrations
  • White-label embed for your own app
  • 100 free credits a month, no credit card required