Create an Approval Flow

Creates an approval flow with the stages you list, in order.

Updated

POST
/v1/approval-flows
curl -X POST "https://api.orshot.com/v1/approval-flows" \
  -H "Authorization: Bearer <ORSHOT_API_KEY>" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "<NAME>",
    "stages": [],
    "slug": "<SLUG>",
    "description": "<DESCRIPTION>"
  }'

Creates an approval flow with the stages you list, in order. Prefer create an approval flow from a preset unless the person described custom stages. Stage categories drive behaviour: open (work in progress), review (approvers decide here), approved (signed off, locked). Fails with flow_limit_reached when the plan's limit is used up. Reviewers can't create flows.

Send an Idempotency-Key header to retry safely: a repeat within 24 hours returns the first response and changes nothing.

Endpoint#

Endpoint
https://api.orshot.com/v1/approval-flows

Request Body#

ParameterTypeRequiredDescription
nameStringYesDisplay name. Up to 80 characters.
slugStringNoStable id for the API and MCP; generated from the name when omitted.
descriptionStringNoOptional description. Up to 500 characters.
colorStringNoChip colour. One of subtle, blue, green, amber, rose, orange, purple. Can be null.
blocksRendersBooleanNoTemplates in this flow render through the API only from stages that allow it. Default true.
settingsObjectNoFlow settings to change (partial).
stagesArrayYesStages in board order. Up to 30 items.

settings#

ParameterTypeRequiredDescription
entryObjectNoFields in the table below.
onEditStringNoOne of require_reapproval, keep_approved_rendering.

settings.entry#

ParameterTypeRequiredDescription
modeStringNoOne of manual, filter, all.
stageStringNoCan be null.
filtersObjectNoFields in the table below.
includeEmbedTemplatesBooleanNo

settings.entry.filters#

ParameterTypeRequiredDescription
folderIdsArrayNoUp to 100 items.
tagsArrayNoUp to 100 items.

stages[]#

ParameterTypeRequiredDescription
nameStringYesDisplay name. Up to 80 characters.
slugStringNoStable id; generated from the name when omitted.
categoryStringYesopen, review, approved, done, rejected or archived.
colorStringNoThe stage's color, on its chips and the dot on its board column. Leave it out or send null for no color (the default): a plain chip. One of subtle, blue, green, amber, rose, orange, purple. Can be null.
rulesObjectNoStage rules to change (partial).

stages[].rules#

ParameterTypeRequiredDescription
editableBooleanNoThe design can be edited while the template is in this stage.
renderObjectNoOutput kinds the render API may produce from this stage.
enterObjectNoFields in the table below.
approvalObjectNoFields in the table below.
nextObjectNoFields in the table below.
onEditStringNoOne of require_reapproval, keep_approved_rendering.
dueHoursIntegerNoFrom 1 to 8760. Can be null.

stages[].rules.render#

ParameterTypeRequiredDescription
imageBooleanNo
pdfBooleanNo
videoBooleanNo

stages[].rules.enter#

ParameterTypeRequiredDescription
fromString or ArrayNoStages a template may come from: "any" or a list of stage slugs. Must be "any". Up to 50 items.
requireCommentBooleanNoMoving a template here needs a comment.
requiresStringNoThe grant a manual move into this stage needs. One of contribute, decide.

stages[].rules.approval#

ParameterTypeRequiredDescription
modeStringNoOne of any, all, count.
countIntegerNoFrom 1 to 50.
allowSelfBooleanNoThe person who submitted may approve (owners and admins always may).
perOutputBooleanNoApprovals name the output kinds they cover.
allowConditionsBooleanNoApprovers may attach field limits to an approval.

stages[].rules.next#

ParameterTypeRequiredDescription
onApprovedStringNoCan be null.
onChangesRequestedStringNoCan be null.

Headers#

HeaderRequiredDescription
AuthorizationYesBearer <API key or OAuth token>
x-workspace-idNoOAuth tokens with several workspaces: the workspace to act in. API keys ignore it.
X-Orshot-User-IdNoAPI keys only: the user id of the owner, admin or member this call is for. See Acting for a Team Member below.
Idempotency-KeyNoUp to 255 visible characters, unique per request. A replay within 24 hours returns the stored response with Idempotent-Replayed: true.
X-Session-IdNoGroups the calls of one agent or MCP session in the activity history.

Acting for a Team Member#

With an API key, you can send X-Orshot-User-Id with the user id of an owner, admin or member of the workspace to make this call for them. It needs both the key's access level and that person's own access, and it's credited to them: people see "Priya Shah, via API key", and they aren't notified about their own change. See acting for a team member.

Request#

JavaScript
await fetch("https://api.orshot.com/v1/approval-flows", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    Authorization: "Bearer <ORSHOT_API_KEY>",
    "Idempotency-Key": "<unique request id>",
  },
  body: JSON.stringify({
    "name": "Developers",
    "blocksRenders": false,
    "stages": [
      {
        "name": "To do",
        "category": "open"
      },
      {
        "name": "Done",
        "category": "done"
      }
    ]
  }),
});
JSON
{
  "flow": {
    "id": 2,
    "slug": "developers",
    "name": "Developers",
    "description": null,
    "color": null,
    "blocksRenders": false,
    "settings": {
      "entry": {
        "mode": "manual",
        "stage": null,
        "filters": {
          "folderIds": [],
          "tags": []
        },
        "includeEmbedTemplates": false
      },
      "onEdit": "require_reapproval"
    },
    "presetSlug": null,
    "presetVersion": null,
    "sortKey": "r",
    "createdAt": "2026-09-28T09:30:00.000Z",
    "updatedAt": "2026-09-28T09:30:00.000Z",
    "archivedAt": null,
    "stages": [
      {
        "id": 6,
        "slug": "to-do",
        "name": "To do",
        "color": null,
        "category": "open",
        "rules": {
          "editable": true,
          "render": {
            "image": false,
            "pdf": false,
            "video": false
          },
          "enter": {
            "from": "any",
            "requireComment": false,
            "requires": "contribute"
          },
          "approval": {
            "mode": "any",
            "count": 1,
            "allowSelf": false,
            "perOutput": false,
            "allowConditions": false
          },
          "next": {
            "onApproved": null,
            "onChangesRequested": null
          },
          "onEdit": "require_reapproval",
          "dueHours": null
        },
        "sortKey": "i",
        "archivedAt": null,
        "itemCount": 0
      },
      {
        "id": 7,
        "slug": "done",
        "name": "Done",
        "color": null,
        "category": "done",
        "rules": {
          "editable": false,
          "render": {
            "image": false,
            "pdf": false,
            "video": false
          },
          "enter": {
            "from": "any",
            "requireComment": false,
            "requires": "contribute"
          },
          "approval": {
            "mode": "any",
            "count": 1,
            "allowSelf": false,
            "perOutput": false,
            "allowConditions": false
          },
          "next": {
            "onApproved": null,
            "onChangesRequested": null
          },
          "onEdit": "require_reapproval",
          "dueHours": null
        },
        "sortKey": "r",
        "archivedAt": null,
        "itemCount": 0
      }
    ]
  },
  "warnings": []
}

Response Fields#

Responds 201 with:

FieldTypeDescription
flowObjectOne ApprovalFlow, fields below.
flow.idIntegerNumeric id.
flow.slugStringStable; use it in URLs and tool calls.
flow.nameStringDisplay name.
flow.descriptionStringCan be null.
flow.colorStringCan be null.
flow.blocksRendersBooleanTemplates render through the API only from stages that allow it. Downloads from the studio and the embed editor are never blocked.
flow.settingsObjectFlow settings v1 (rules.js).
flow.presetSlugStringCan be null.
flow.presetVersionIntegerCan be null.
flow.sortKeyStringPosition in its list, as sortable text.
flow.stagesArrayList of ApprovalStage (on get).
flow.viewerObject{ capabilities, stages, canArchive }. On get, what you may do here: capabilities for the flow as a whole (approvals.view, flow.manage, item.add, item.move, item.remove, item.decide, item.override, comment.create...), stages maps each stage id to the capabilities you have in it. item.move in a stage means you may put a template there (approved stages take approvers only); its enter.from rule still applies. canArchive says whether you may archive the flow, which stays open when it is over the plan's limit.
flow.overPlanLimitBooleanTrue when the flow is past the plan's limit of live approval flows (on list and get; the first flows in list order stay active). Such a flow can be read, commented on and archived. Every other change to it or its templates (add, move, take out, approve, request changes, withdraw an approval, change the flow, its stages or its access) is refused with 403 flow_limit_reached, code approval.flow.over_plan_limit. It doesn't block API renders, lock edits or wait on anyone. Archiving an active flow makes the next one active; upgrading makes them all active.
flow.createdAtStringISO 8601 timestamp.
flow.updatedAtStringISO 8601 timestamp.
flow.archivedAtStringISO 8601 timestamp. Can be null.
warningsArrayNon-blocking notices, each { code, message? }, for example no_approver. Always present on writes, empty when there is nothing to say.

Error Responses#

Every error has the same body: error, code, message and helpUrl, plus the fields that apply (required, role, context, blockers, violations, issues, current). Branch on error; code is more specific. See the error reference.

Status CodeErrorDescription
401oauth_token_invalidThe OAuth token is invalid, expired or revoked.
403api_key_missingNo Authorization: Bearer header.
403permission_deniedYou don't have access to do this. Ask an owner or admin. code names the capability, for example approval.item.decide_denied; required and role say what was missing. With code: insufficient_scope: the OAuth token lacks workspace:approvals:admin. With code: approval.member_header_not_member: X-Orshot-User-Id names someone who isn't an owner, admin or member of the workspace now. With code: approval.member_header_not_allowed: an OAuth token sent X-Orshot-User-Id.
403plan_requiredThe workspace's plan doesn't include Approvals, or doesn't include this part of it.
403enterprise_api_requiredUsing approvals with an API key needs an Enterprise plan. Contact hi@orshot.com to turn it on.
403flow_limit_reachedYour plan allows N approval flows. Archive one or upgrade to add more.
404not_foundThis doesn't exist or isn't available to you. Reviewers get this, never 403, for flows and templates outside their access.
409state_conflictWith code: approval.request_in_progress: the same Idempotency-Key is still running.
422validation_failedSome fields aren't valid: the fields listed in issues. issues lists each field with a path and a reason.
422no_approverNobody would be able to approve in the 'the stage' stage. Keep at least one approver there.
422validation_failedWith code: approval.member_header_invalid: X-Orshot-User-Id isn't a user id.
422validation_failedWith code: approval.idempotency_key_reused: the Idempotency-Key was used with a different request.
429rate_limit_exceededMore than 120 approvals requests in a minute from one person or key. Wait for Retry-After.
503approvals_unavailableApprovals aren't available right now. Try again in a moment. Also returned while approvals are not switched on for the API.
Was this page helpful?

Ready to automate?

Start rendering images, PDFs and videos from your templates in under 2 minutes. Free plan, no credit card.

Get your API key
  • Image, PDF and video generation via API
  • Visual editor with AI and smart layouts
  • Zapier, Make, MCP and 50+ integrations
  • White-label embed for your own app
  • 100 free credits a month, no credit card required