# Set Approvers and Access

> Replaces the full list of grants on an approval flow.

- **URL**: https://orshot.com/docs/api-reference/approvals-permissions-set

---

The Approvals API is available on Enterprise plans, or through first-party apps (the Orshot app and the Orshot MCP server). This endpoint needs [`manage` access](/docs/api-reference/approvals-overview#access-levels).
See [Enterprise pricing](https://orshot.com/pricing) to get access.

Replaces the full list of grants on an approval flow. Grantees are people (user uuid), groups, a whole role (reviewer) or a pending invite. Being an admin does not make someone an approver: only a decide grant does. Refused with no_approver if a review stage would have nobody who can approve. Read the current list first with [get approvers and access](https://orshot.com/docs/api-reference/approvals-permissions-get) and send it back edited. Reviewers can't change access.

## Endpoint

```markdown tab="Endpoint"
https://api.orshot.com/v1/approval-flows/:flow/permissions
```

## Path Parameters

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `flow` | String | Yes | The approval flow's id or slug. A number is an id, anything else a slug. |

## Request Body

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `grants` | Array | Yes | The complete list of grants; replaces the current one. Up to 500 items. |

### `grants[]`

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `stage` | String | No | Limit the grant to one stage; omit for the whole flow. A number is an id, anything else a slug. Can be `null`. |
| `grantee` | Object | Yes | Fields in the table below. |
| `permission` | String | Yes | manage, decide, review, contribute or watch. |

### `grants[].grantee`

| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `type` | String | Yes | One of `user`, `group`, `role`, `invite`, `embed_user`. |
| `id` | Integer or String | Yes | user: uuid; group: id or slug; role: role key (e.g. reviewer); invite: invite id; embed_user: eui_ id. Up to 128 characters. |

## Headers

| Header | Required | Description |
| ------ | -------- | ----------- |
| `Authorization` | Yes | `Bearer <API key or OAuth token>` |
| `x-workspace-id` | No | OAuth tokens with several workspaces: the workspace to act in. API keys ignore it. |
| `X-Orshot-User-Id` | No | API keys only: the user id of the owner, admin or member this call is for. See Acting for a Team Member below. |
| `X-Session-Id` | No | Groups the calls of one agent or MCP session in the activity history. |

## Acting for a Team Member

With an API key, you can send `X-Orshot-User-Id` with the user id of an owner, admin or member of the workspace to make this call for them. It needs both the key's access level and that person's own access, and it's credited to them: people see "Priya Shah, via API key", and they aren't notified about their own change. See [acting for a team member](https://orshot.com/docs/api-reference/approvals-overview#acting-for-a-team-member).

## Request

**Request**
```js
await fetch("https://api.orshot.com/v1/approval-flows/brand-and-legal/permissions", {
  method: "PUT",
  headers: {
    "Content-Type": "application/json",
    Authorization: "Bearer <ORSHOT_API_KEY>",
  },
  body: JSON.stringify({
    "grants": [
      {
        "stage": "brand-review",
        "grantee": {
          "type": "user",
          "id": "9a4c7e2b-1d6f-4e3a-8b5c-2f7d0e9a4c61"
        },
        "permission": "decide"
      },
      {
        "stage": "legal-review",
        "grantee": {
          "type": "group",
          "id": "legal"
        },
        "permission": "decide"
      },
      {
        "grantee": {
          "type": "role",
          "id": "reviewer"
        },
        "permission": "review"
      }
    ]
  }),
});
```

**Response**
```json
{
  "grants": [
    {
      "id": 1,
      "stage": {
        "id": 2,
        "slug": "brand-review",
        "name": "Brand review"
      },
      "grantee": {
        "type": "user",
        "id": "9a4c7e2b-1d6f-4e3a-8b5c-2f7d0e9a4c61",
        "label": "Priya Shah"
      },
      "permission": "decide",
      "createdAt": "2026-09-28T09:30:00.000Z"
    },
    {
      "id": 2,
      "stage": {
        "id": 4,
        "slug": "legal-review",
        "name": "Legal review"
      },
      "grantee": {
        "type": "group",
        "id": 1,
        "label": "Legal team"
      },
      "permission": "decide",
      "createdAt": "2026-09-28T09:30:00.000Z"
    }
  ],
  "stagesWithoutApprover": [],
  "warnings": []
}
```

## Response Fields

Responds `200` with:

| Field | Type | Description |
| ----- | ---- | ----------- |
| `grants` | Array | List of ApprovalGrant, fields below. |
| `grants[].id` | Integer | Numeric id. |
| `grants[].stage` | Object | `{ id, slug, name, archived? }`. or null (whole flow); grants on an archived stage are kept as they are by permissions.set. |
| `grants[].grantee` | Object | `{ type: user or group or role or invite or embed_user, id, label }`. |
| `grants[].permission` | String | One of `manage`, `decide`, `review`, `contribute`, `watch`. |
| `grants[].createdAt` | String | ISO 8601 timestamp. |
| `warnings` | Array | Non-blocking notices, each `{ code, message? }`, for example `no_approver`. Always present on writes, empty when there is nothing to say. |

## Error Responses

Every error has the same body: `error`, `code`, `message` and `helpUrl`, plus the fields that apply (`required`, `role`, `context`, `blockers`, `violations`, `issues`, `current`). Branch on `error`; `code` is more specific. See the [error reference](https://orshot.com/docs/error-reference).

| Status Code | Error | Description |
| ----------- | ----- | ----------- |
| 401 | `oauth_token_invalid` | The OAuth token is invalid, expired or revoked. |
| 403 | `api_key_missing` | No `Authorization: Bearer` header. |
| 403 | `permission_denied` | You don't have access to do this. Ask an owner or admin. `code` names the capability, for example `approval.item.decide_denied`; `required` and `role` say what was missing. With `code: insufficient_scope`: the OAuth token lacks `workspace:approvals:admin`. With `code: approval.member_header_not_member`: `X-Orshot-User-Id` names someone who isn't an owner, admin or member of the workspace now. With `code: approval.member_header_not_allowed`: an OAuth token sent `X-Orshot-User-Id`. |
| 403 | `plan_required` | The workspace's plan doesn't include Approvals, or doesn't include this part of it. |
| 403 | `enterprise_api_required` | Using approvals with an API key needs an Enterprise plan. Contact hi@orshot.com to turn it on. |
| 404 | `not_found` | This doesn't exist or isn't available to you. Reviewers get this, never 403, for flows and templates outside their access. |
| 422 | `validation_failed` | Some fields aren't valid: the fields listed in issues. `issues` lists each field with a path and a reason. |
| 422 | `no_approver` | Nobody would be able to approve in the 'the stage' stage. Keep at least one approver there. |
| 422 | `validation_failed` | With `code: approval.member_header_invalid`: `X-Orshot-User-Id` isn't a user id. |
| 429 | `rate_limit_exceeded` | More than 120 approvals requests in a minute from one person or key. Wait for Retry-After. |
| 503 | `approvals_unavailable` | Approvals aren't available right now. Try again in a moment. Also returned while approvals are not switched on for the API. |