Skip to navigation

Approve a pending access request

Approve the request and grant the requester access to every requested entity, expiring per its durationDays. Admin key only (403 for a member key). Only pending requests change; a decided or cancelled request is a 409.

Authentication

AuthorizationBearer

WorkOS API key (Authorization: Bearer sk_...). Scope comes from the key's permissions: a key carrying passport:admin has admin scope (full catalog CRUD), any other key has member scope (reads + access requests). Organization-owned keys are admin by ownership and carry no associated user; keys minted for a user carry theirs, which is what access requests and createdBy are attributed to.

Path parameters

accessRequestIdstringRequiredformat: "uuid"

Headers

Idempotency-KeystringOptional

Optional idempotency key, retained 24h and bound to the request that first used it. Resending the same request replays the stored response (with Idempotent-Replayed: true); reusing the key with a different body or path returns 422; retrying while the original is still in flight returns 409 with Retry-After. A failed request releases its key.

Request

This endpoint expects an object.
reasonstring or nullOptional<=1024 characters
Optional note recorded as the request's decisionReason.

Response headers

RateLimit-Limitinteger
Requests allowed in the current window.
RateLimit-Remaininginteger
Requests remaining in the current window.
RateLimit-Resetinteger
Unix epoch seconds when the window resets.

Response

OK
dataobject

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
409
Conflict Error
422
Unprocessable Entity Error
429
Too Many Requests Error
500
Internal Server Error
503
Service Unavailable Error