# Create an Approval Flow

> Creates an approval flow with the stages you list, in order.

- **URL**: https://orshot.com/docs/api-reference/approvals-flows-create

---

The Approvals API is available on Enterprise plans, or through first-party apps (the Orshot app and the Orshot MCP server). This endpoint needs [`manage` access](/docs/api-reference/approvals-overview#access-levels).
See [Enterprise pricing](https://orshot.com/pricing) to get access.

Creates an approval flow with the stages you list, in order. Prefer [create an approval flow from a preset](https://orshot.com/docs/api-reference/approvals-flows-from-preset) unless the person described custom stages. Stage categories drive behaviour: open (work in progress), review (approvers decide here), approved (signed off, locked). Fails with flow_limit_reached when the plan's limit is used up. Reviewers can't create flows.

Send an `Idempotency-Key` header to retry safely: a repeat within 24 hours returns the first response and changes nothing.

## Endpoint

```markdown tab="Endpoint"
https://api.orshot.com/v1/approval-flows
```

## Request Body

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `name` | String | Yes | Display name. Up to 80 characters. |
| `slug` | String | No | Stable id for the API and MCP; generated from the name when omitted. |
| `description` | String | No | Optional description. Up to 500 characters. |
| `color` | String | No | Chip colour. One of `subtle`, `blue`, `green`, `amber`, `rose`, `orange`, `purple`. Can be `null`. |
| `blocksRenders` | Boolean | No | Templates in this flow render through the API only from stages that allow it. Default `true`. |
| `settings` | Object | No | Flow settings to change (partial). |
| `stages` | Array | Yes | Stages in board order. Up to 30 items. |

### `settings`

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `entry` | Object | No | Fields in the table below. |
| `onEdit` | String | No | One of `require_reapproval`, `keep_approved_rendering`. |

### `settings.entry`

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `mode` | String | No | One of `manual`, `filter`, `all`. |
| `stage` | String | No | Can be `null`. |
| `filters` | Object | No | Fields in the table below. |
| `includeEmbedTemplates` | Boolean | No |  |

### `settings.entry.filters`

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `folderIds` | Array | No | Up to 100 items. |
| `tags` | Array | No | Up to 100 items. |

### `stages[]`

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `name` | String | Yes | Display name. Up to 80 characters. |
| `slug` | String | No | Stable id; generated from the name when omitted. |
| `category` | String | Yes | open, review, approved, done, rejected or archived. |
| `color` | String | No | The stage's color, on its chips and the dot on its board column. Leave it out or send null for no color (the default): a plain chip. One of `subtle`, `blue`, `green`, `amber`, `rose`, `orange`, `purple`. Can be `null`. |
| `rules` | Object | No | Stage rules to change (partial). |

### `stages[].rules`

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `editable` | Boolean | No | The design can be edited while the template is in this stage. |
| `render` | Object | No | Output kinds the render API may produce from this stage. |
| `enter` | Object | No | Fields in the table below. |
| `approval` | Object | No | Fields in the table below. |
| `next` | Object | No | Fields in the table below. |
| `onEdit` | String | No | One of `require_reapproval`, `keep_approved_rendering`. |
| `dueHours` | Integer | No | From 1 to 8760. Can be `null`. |

### `stages[].rules.render`

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `image` | Boolean | No |  |
| `pdf` | Boolean | No |  |
| `video` | Boolean | No |  |

### `stages[].rules.enter`

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `from` | String or Array | No | Stages a template may come from: "any" or a list of stage slugs. Must be `"any"`. Up to 50 items. |
| `requireComment` | Boolean | No | Moving a template here needs a comment. |
| `requires` | String | No | The grant a manual move into this stage needs. One of `contribute`, `decide`. |

### `stages[].rules.approval`

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `mode` | String | No | One of `any`, `all`, `count`. |
| `count` | Integer | No | From 1 to 50. |
| `allowSelf` | Boolean | No | The person who submitted may approve (owners and admins always may). |
| `perOutput` | Boolean | No | Approvals name the output kinds they cover. |
| `allowConditions` | Boolean | No | Approvers may attach field limits to an approval. |

### `stages[].rules.next`

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `onApproved` | String | No | Can be `null`. |
| `onChangesRequested` | String | No | Can be `null`. |

## Headers

| Header | Required | Description |
| ------ | -------- | ----------- |
| `Authorization` | Yes | `Bearer <API key or OAuth token>` |
| `x-workspace-id` | No | OAuth tokens with several workspaces: the workspace to act in. API keys ignore it. |
| `X-Orshot-User-Id` | No | API keys only: the user id of the owner, admin or member this call is for. See Acting for a Team Member below. |
| `Idempotency-Key` | No | Up to 255 visible characters, unique per request. A replay within 24 hours returns the stored response with Idempotent-Replayed: true. |
| `X-Session-Id` | No | Groups the calls of one agent or MCP session in the activity history. |

## Acting for a Team Member

With an API key, you can send `X-Orshot-User-Id` with the user id of an owner, admin or member of the workspace to make this call for them. It needs both the key's access level and that person's own access, and it's credited to them: people see "Priya Shah, via API key", and they aren't notified about their own change. See [acting for a team member](https://orshot.com/docs/api-reference/approvals-overview#acting-for-a-team-member).

## Request

**Request**
```js
await fetch("https://api.orshot.com/v1/approval-flows", {
  method: "POST",
  headers: {
    "Content-Type": "application/json",
    Authorization: "Bearer <ORSHOT_API_KEY>",
    "Idempotency-Key": "<unique request id>",
  },
  body: JSON.stringify({
    "name": "Developers",
    "blocksRenders": false,
    "stages": [
      {
        "name": "To do",
        "category": "open"
      },
      {
        "name": "Done",
        "category": "done"
      }
    ]
  }),
});
```

**Response**
```json
{
  "flow": {
    "id": 2,
    "slug": "developers",
    "name": "Developers",
    "description": null,
    "color": null,
    "blocksRenders": false,
    "settings": {
      "entry": {
        "mode": "manual",
        "stage": null,
        "filters": {
          "folderIds": [],
          "tags": []
        },
        "includeEmbedTemplates": false
      },
      "onEdit": "require_reapproval"
    },
    "presetSlug": null,
    "presetVersion": null,
    "sortKey": "r",
    "createdAt": "2026-09-28T09:30:00.000Z",
    "updatedAt": "2026-09-28T09:30:00.000Z",
    "archivedAt": null,
    "stages": [
      {
        "id": 6,
        "slug": "to-do",
        "name": "To do",
        "color": null,
        "category": "open",
        "rules": {
          "editable": true,
          "render": {
            "image": false,
            "pdf": false,
            "video": false
          },
          "enter": {
            "from": "any",
            "requireComment": false,
            "requires": "contribute"
          },
          "approval": {
            "mode": "any",
            "count": 1,
            "allowSelf": false,
            "perOutput": false,
            "allowConditions": false
          },
          "next": {
            "onApproved": null,
            "onChangesRequested": null
          },
          "onEdit": "require_reapproval",
          "dueHours": null
        },
        "sortKey": "i",
        "archivedAt": null,
        "itemCount": 0
      },
      {
        "id": 7,
        "slug": "done",
        "name": "Done",
        "color": null,
        "category": "done",
        "rules": {
          "editable": false,
          "render": {
            "image": false,
            "pdf": false,
            "video": false
          },
          "enter": {
            "from": "any",
            "requireComment": false,
            "requires": "contribute"
          },
          "approval": {
            "mode": "any",
            "count": 1,
            "allowSelf": false,
            "perOutput": false,
            "allowConditions": false
          },
          "next": {
            "onApproved": null,
            "onChangesRequested": null
          },
          "onEdit": "require_reapproval",
          "dueHours": null
        },
        "sortKey": "r",
        "archivedAt": null,
        "itemCount": 0
      }
    ]
  },
  "warnings": []
}
```

## Response Fields

Responds `201` with:

| Field | Type | Description |
| ----- | ---- | ----------- |
| `flow` | Object | One ApprovalFlow, fields below. |
| `flow.id` | Integer | Numeric id. |
| `flow.slug` | String | Stable; use it in URLs and tool calls. |
| `flow.name` | String | Display name. |
| `flow.description` | String | Can be `null`. |
| `flow.color` | String | Can be `null`. |
| `flow.blocksRenders` | Boolean | Templates render through the API only from stages that allow it. Downloads from the studio and the embed editor are never blocked. |
| `flow.settings` | Object | Flow settings v1 (rules.js). |
| `flow.presetSlug` | String | Can be `null`. |
| `flow.presetVersion` | Integer | Can be `null`. |
| `flow.sortKey` | String | Position in its list, as sortable text. |
| `flow.stages` | Array | List of ApprovalStage (on get). |
| `flow.viewer` | Object | `{ capabilities, stages, canArchive }`. On get, what you may do here: capabilities for the flow as a whole (approvals.view, flow.manage, item.add, item.move, item.remove, item.decide, item.override, comment.create...), stages maps each stage id to the capabilities you have in it. item.move in a stage means you may put a template there (approved stages take approvers only); its enter.from rule still applies. canArchive says whether you may archive the flow, which stays open when it is over the plan's limit. |
| `flow.overPlanLimit` | Boolean | True when the flow is past the plan's limit of live approval flows (on list and get; the first flows in list order stay active). Such a flow can be read, commented on and archived. Every other change to it or its templates (add, move, take out, approve, request changes, withdraw an approval, change the flow, its stages or its access) is refused with 403 flow_limit_reached, code approval.flow.over_plan_limit. It doesn't block API renders, lock edits or wait on anyone. Archiving an active flow makes the next one active; upgrading makes them all active. |
| `flow.createdAt` | String | ISO 8601 timestamp. |
| `flow.updatedAt` | String | ISO 8601 timestamp. |
| `flow.archivedAt` | String | ISO 8601 timestamp. Can be `null`. |
| `warnings` | Array | Non-blocking notices, each `{ code, message? }`, for example `no_approver`. Always present on writes, empty when there is nothing to say. |

## Error Responses

Every error has the same body: `error`, `code`, `message` and `helpUrl`, plus the fields that apply (`required`, `role`, `context`, `blockers`, `violations`, `issues`, `current`). Branch on `error`; `code` is more specific. See the [error reference](https://orshot.com/docs/error-reference).

| Status Code | Error | Description |
| ----------- | ----- | ----------- |
| 401 | `oauth_token_invalid` | The OAuth token is invalid, expired or revoked. |
| 403 | `api_key_missing` | No `Authorization: Bearer` header. |
| 403 | `permission_denied` | You don't have access to do this. Ask an owner or admin. `code` names the capability, for example `approval.item.decide_denied`; `required` and `role` say what was missing. With `code: insufficient_scope`: the OAuth token lacks `workspace:approvals:admin`. With `code: approval.member_header_not_member`: `X-Orshot-User-Id` names someone who isn't an owner, admin or member of the workspace now. With `code: approval.member_header_not_allowed`: an OAuth token sent `X-Orshot-User-Id`. |
| 403 | `plan_required` | The workspace's plan doesn't include Approvals, or doesn't include this part of it. |
| 403 | `enterprise_api_required` | Using approvals with an API key needs an Enterprise plan. Contact hi@orshot.com to turn it on. |
| 403 | `flow_limit_reached` | Your plan allows N approval flows. Archive one or upgrade to add more. |
| 404 | `not_found` | This doesn't exist or isn't available to you. Reviewers get this, never 403, for flows and templates outside their access. |
| 409 | `state_conflict` | With `code: approval.request_in_progress`: the same Idempotency-Key is still running. |
| 422 | `validation_failed` | Some fields aren't valid: the fields listed in issues. `issues` lists each field with a path and a reason. |
| 422 | `no_approver` | Nobody would be able to approve in the 'the stage' stage. Keep at least one approver there. |
| 422 | `validation_failed` | With `code: approval.member_header_invalid`: `X-Orshot-User-Id` isn't a user id. |
| 422 | `validation_failed` | With `code: approval.idempotency_key_reused`: the Idempotency-Key was used with a different request. |
| 429 | `rate_limit_exceeded` | More than 120 approvals requests in a minute from one person or key. Wait for Retry-After. |
| 503 | `approvals_unavailable` | Approvals aren't available right now. Try again in a moment. Also returned while approvals are not switched on for the API. |