Waiting on Me

Lists what needs the signed-in person: templates waiting on their approval (default), comments that mention them, or everything.

Updated

GET
/v1/approvals/inbox
curl -X GET "https://api.orshot.com/v1/approvals/inbox?filter=<FILTER>&cursor=<CURSOR>&limit=10" \
  -H "Authorization: Bearer <ORSHOT_API_KEY>"

Lists what needs the signed-in person: templates waiting on their approval (default), comments that mention them, or everything. The best first call when someone asks what they need to review. With filter mentions or all, the mentions come in a mentions list, from this workspace only. For a reviewer limited to some flows, a mention disappears when they lose access to its flow or template, and comes back if access returns.

Results come in pages: pass nextCursor back as cursor until it is null.

Endpoint#

Endpoint
https://api.orshot.com/v1/approvals/inbox

Query Parameters#

ParameterTypeRequiredDescription
filterStringNoOne of waiting_on_me, mentions, all. Default "waiting_on_me".
cursorStringNoCursor from the previous page's nextCursor. A cursor the API didn't write starts again from the first page. Up to 200 characters.
limitIntegerNoResults per page (1 to 100). Default 50.

Headers#

HeaderRequiredDescription
AuthorizationYesBearer <API key or OAuth token>
x-workspace-idNoOAuth tokens with several workspaces: the workspace to act in. API keys ignore it.
X-Orshot-User-IdWith an API keyThe user id of the owner, admin or member this call is for. OAuth tokens don't send it. See Acting for a Team Member below.
X-Session-IdNoGroups the calls of one agent or MCP session in the activity history.

Acting for a Team Member#

This acts for one person. With an API key, send X-Orshot-User-Id with the user id of an owner, admin or member of the workspace: the answer is theirs, as their own OAuth token would get it, within the key's workspace. Without the header, API keys get 403 permission_denied, code approval.person_required. See acting for a team member.

Request#

JavaScript
await fetch("https://api.orshot.com/v1/approvals/inbox", {
  headers: { Authorization: "Bearer <ORSHOT_OAUTH_TOKEN>" },
});
JSON
{
  "items": [
    {
      "id": 1,
      "flow": {
        "id": 1,
        "slug": "brand-and-legal",
        "name": "Brand and legal"
      },
      "stage": {
        "id": 2,
        "slug": "brand-review",
        "name": "Brand review",
        "category": "review",
        "color": null
      },
      "template": {
        "id": 101,
        "name": "Spring sale banner",
        "thumbnailUrl": "https://storage.orshot.com/thumbnails/101.png",
        "currentVersion": "5b8e2f7a-3c1d-4e9b-a6f0-7d2c8e1b4a93",
        "folderId": null,
        "tags": []
      },
      "reviewRound": 1,
      "revision": 2,
      "approvals": {
        "mode": "any",
        "required": 1,
        "approvedBy": [],
        "changesRequestedBy": [],
        "submitter": {
          "id": "b5d2e8f1-7a3c-4b69-9e0d-3c8a1f6b2e45"
        }
      },
      "changesRequested": null,
      "commentCount": 1,
      "canRender": {
        "image": false,
        "pdf": false,
        "video": false
      },
      "heldBack": null,
      "dueAt": null,
      "createdAt": "2026-09-28T09:30:00.000Z",
      "updatedAt": "2026-09-28T09:30:00.000Z"
    }
  ],
  "nextCursor": null
}

Response Fields#

Responds 200 with:

FieldTypeDescription
itemsArrayList of ApprovalItem, fields below.
items[].idIntegerNumeric id.
items[].flowObject{ id, slug, name }.
items[].stageObject{ id, slug, name, category, color }. Color is the stage's color, null when it has none.
items[].templateObject{ id, name, thumbnailUrl, currentVersion, folderId, tags }. With currentVersion to send back as reviewedVersion when approving, folderId the template's folder (null for none) and tags its tags (string[]).
items[].reviewRoundIntegerGoes up each time the template re-enters review.
items[].revisionIntegerSend it back on move (state_conflict if it changed).
items[].approvalsObject{ mode, required, approvedBy: Person[], changesRequestedBy: Person[], submitter?: { id } }. For the current round, in review stages. submitter is who submitted it when the stage keeps them from approving it themselves (the stage doesn't let people approve what they submitted, and they are not an owner or admin).
items[].changesRequestedObject{ by: Person[], stage: { id, slug, name } }. The change request it was sent back with, until it is resubmitted. Can be null.
items[].commentCountIntegerComments on the template (replies included, deleted ones left out).
items[].canRenderObject{ image, pdf, video }. Booleans.
items[].movedWithoutApprovalObject{ by: Person, at: ISO date, reason }. or absent, present while the template sits where an owner or admin moved it without its approvals.
items[].dueAtStringISO 8601 timestamp. Can be null.
items[].createdAtStringISO 8601 timestamp.
items[].updatedAtStringISO 8601 timestamp.
nextCursorStringCan be null. Pass it back as cursor for the next page; null on the last page.

Error Responses#

Every error has the same body: error, code, message and helpUrl, plus the fields that apply (required, role, context, blockers, violations, issues, current). Branch on error; code is more specific. See the error reference.

Status CodeErrorDescription
401oauth_token_invalidThe OAuth token is invalid, expired or revoked.
403api_key_missingNo Authorization: Bearer header.
403permission_deniedYou don't have access to do this. Ask an owner or admin. code names the capability, for example approval.item.decide_denied; required and role say what was missing. With code: insufficient_scope: the OAuth token lacks workspace:approvals:read. API keys without X-Orshot-User-Id get approval.person_required: this acts for one person. With code: approval.member_header_not_member: X-Orshot-User-Id names someone who isn't an owner, admin or member of the workspace now. With code: approval.member_header_not_allowed: an OAuth token sent X-Orshot-User-Id.
403plan_requiredThe workspace's plan doesn't include Approvals, or doesn't include this part of it.
403enterprise_api_requiredApprovals through third-party apps need an Enterprise plan. Contact hi@orshot.com to turn it on.
404not_foundThis doesn't exist or isn't available to you. Reviewers get this, never 403, for flows and templates outside their access.
422validation_failedSome fields aren't valid: the fields listed in issues. issues lists each field with a path and a reason.
422validation_failedWith code: approval.member_header_invalid: X-Orshot-User-Id isn't a user id.
429rate_limit_exceededMore than 120 approvals requests in a minute from one person or key. Wait for Retry-After.
503approvals_unavailableApprovals aren't available right now. Try again in a moment. Also returned while approvals are not switched on for the API.
Was this page helpful?

Ready to automate?

Start rendering images, PDFs and videos from your templates in under 2 minutes. Free plan, no credit card.

Get your API key
  • Image, PDF and video generation via API
  • Visual editor with AI and smart layouts
  • Zapier, Make, MCP and 50+ integrations
  • White-label embed for your own app
  • 100 free credits a month, no credit card required