# Waiting on Me

> Lists what needs the signed-in person: templates waiting on their approval (default), comments that mention them, or everything.

- **URL**: https://orshot.com/docs/api-reference/approvals-inbox-get

---

The Approvals API is available on Enterprise plans, or through first-party apps (the Orshot app and the Orshot MCP server). This endpoint needs [`read` access](/docs/api-reference/approvals-overview#access-levels) and acts for one person: send their OAuth token, or an API key with their user id in `X-Orshot-User-Id`.
See [Enterprise pricing](https://orshot.com/pricing) to get access.

Lists what needs the signed-in person: templates waiting on their approval (default), comments that mention them, or everything. The best first call when someone asks what they need to review. With filter mentions or all, the mentions come in a mentions list, from this workspace only. For a reviewer limited to some flows, a mention disappears when they lose access to its flow or template, and comes back if access returns.

Results come in pages: pass `nextCursor` back as `cursor` until it is `null`.

## Endpoint

```markdown tab="Endpoint"
https://api.orshot.com/v1/approvals/inbox
```

## Query Parameters

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `filter` | String | No | One of `waiting_on_me`, `mentions`, `all`. Default `"waiting_on_me"`. |
| `cursor` | String | No | Cursor from the previous page's nextCursor. A cursor the API didn't write starts again from the first page. Up to 200 characters. |
| `limit` | Integer | No | Results per page (1 to 100). Default `50`. |

## Headers

| Header | Required | Description |
| ------ | -------- | ----------- |
| `Authorization` | Yes | `Bearer <API key or OAuth token>` |
| `x-workspace-id` | No | OAuth tokens with several workspaces: the workspace to act in. API keys ignore it. |
| `X-Orshot-User-Id` | With an API key | The user id of the owner, admin or member this call is for. OAuth tokens don't send it. See Acting for a Team Member below. |
| `X-Session-Id` | No | Groups the calls of one agent or MCP session in the activity history. |

## Acting for a Team Member

This acts for one person. With an API key, send `X-Orshot-User-Id` with the user id of an owner, admin or member of the workspace: the answer is theirs, as their own OAuth token would get it, within the key's workspace. Without the header, API keys get `403 permission_denied`, code `approval.person_required`. See [acting for a team member](https://orshot.com/docs/api-reference/approvals-overview#acting-for-a-team-member).

## Request

**Request**
```js
await fetch("https://api.orshot.com/v1/approvals/inbox", {
  headers: { Authorization: "Bearer <ORSHOT_OAUTH_TOKEN>" },
});
```

**Response**
```json
{
  "items": [
    {
      "id": 1,
      "flow": {
        "id": 1,
        "slug": "brand-and-legal",
        "name": "Brand and legal"
      },
      "stage": {
        "id": 2,
        "slug": "brand-review",
        "name": "Brand review",
        "category": "review",
        "color": null
      },
      "template": {
        "id": 101,
        "name": "Spring sale banner",
        "thumbnailUrl": "https://storage.orshot.com/thumbnails/101.png",
        "currentVersion": "5b8e2f7a-3c1d-4e9b-a6f0-7d2c8e1b4a93",
        "folderId": null,
        "tags": []
      },
      "reviewRound": 1,
      "revision": 2,
      "approvals": {
        "mode": "any",
        "required": 1,
        "approvedBy": [],
        "changesRequestedBy": [],
        "submitter": {
          "id": "b5d2e8f1-7a3c-4b69-9e0d-3c8a1f6b2e45"
        }
      },
      "changesRequested": null,
      "commentCount": 1,
      "canRender": {
        "image": false,
        "pdf": false,
        "video": false
      },
      "heldBack": null,
      "dueAt": null,
      "createdAt": "2026-09-28T09:30:00.000Z",
      "updatedAt": "2026-09-28T09:30:00.000Z"
    }
  ],
  "nextCursor": null
}
```

## Response Fields

Responds `200` with:

| Field | Type | Description |
| ----- | ---- | ----------- |
| `items` | Array | List of ApprovalItem, fields below. |
| `items[].id` | Integer | Numeric id. |
| `items[].flow` | Object | `{ id, slug, name }`. |
| `items[].stage` | Object | `{ id, slug, name, category, color }`. Color is the stage's color, null when it has none. |
| `items[].template` | Object | `{ id, name, thumbnailUrl, currentVersion, folderId, tags }`. With currentVersion to send back as reviewedVersion when approving, folderId the template's folder (null for none) and tags its tags (string[]). |
| `items[].reviewRound` | Integer | Goes up each time the template re-enters review. |
| `items[].revision` | Integer | Send it back on move (state_conflict if it changed). |
| `items[].approvals` | Object | `{ mode, required, approvedBy: Person[], changesRequestedBy: Person[], submitter?: { id } }`. For the current round, in review stages. submitter is who submitted it when the stage keeps them from approving it themselves (the stage doesn't let people approve what they submitted, and they are not an owner or admin). |
| `items[].changesRequested` | Object | `{ by: Person[], stage: { id, slug, name } }`. The change request it was sent back with, until it is resubmitted. Can be `null`. |
| `items[].commentCount` | Integer | Comments on the template (replies included, deleted ones left out). |
| `items[].canRender` | Object | `{ image, pdf, video }`. Booleans. |
| `items[].movedWithoutApproval` | Object | `{ by: Person, at: ISO date, reason }`. or absent, present while the template sits where an owner or admin moved it without its approvals. |
| `items[].dueAt` | String | ISO 8601 timestamp. Can be `null`. |
| `items[].createdAt` | String | ISO 8601 timestamp. |
| `items[].updatedAt` | String | ISO 8601 timestamp. |
| `nextCursor` | String | Can be `null`. Pass it back as `cursor` for the next page; `null` on the last page. |

## Error Responses

Every error has the same body: `error`, `code`, `message` and `helpUrl`, plus the fields that apply (`required`, `role`, `context`, `blockers`, `violations`, `issues`, `current`). Branch on `error`; `code` is more specific. See the [error reference](https://orshot.com/docs/error-reference).

| Status Code | Error | Description |
| ----------- | ----- | ----------- |
| 401 | `oauth_token_invalid` | The OAuth token is invalid, expired or revoked. |
| 403 | `api_key_missing` | No `Authorization: Bearer` header. |
| 403 | `permission_denied` | You don't have access to do this. Ask an owner or admin. `code` names the capability, for example `approval.item.decide_denied`; `required` and `role` say what was missing. With `code: insufficient_scope`: the OAuth token lacks `workspace:approvals:read`. API keys without `X-Orshot-User-Id` get `approval.person_required`: this acts for one person. With `code: approval.member_header_not_member`: `X-Orshot-User-Id` names someone who isn't an owner, admin or member of the workspace now. With `code: approval.member_header_not_allowed`: an OAuth token sent `X-Orshot-User-Id`. |
| 403 | `plan_required` | The workspace's plan doesn't include Approvals, or doesn't include this part of it. |
| 403 | `enterprise_api_required` | Approvals through third-party apps need an Enterprise plan. Contact hi@orshot.com to turn it on. |
| 404 | `not_found` | This doesn't exist or isn't available to you. Reviewers get this, never 403, for flows and templates outside their access. |
| 422 | `validation_failed` | Some fields aren't valid: the fields listed in issues. `issues` lists each field with a path and a reason. |
| 422 | `validation_failed` | With `code: approval.member_header_invalid`: `X-Orshot-User-Id` isn't a user id. |
| 429 | `rate_limit_exceeded` | More than 120 approvals requests in a minute from one person or key. Wait for Retry-After. |
| 503 | `approvals_unavailable` | Approvals aren't available right now. Try again in a moment. Also returned while approvals are not switched on for the API. |