Approve a pending access request
Approve the request and grant the requester access to every requested entity, expiring per its durationDays. Admin key only (403 for a member key). Only pending requests change; a decided or cancelled request is a 409.
Authentication
WorkOS API key (Authorization: Bearer sk_...). Scope comes from the key's permissions: a key carrying passport:admin has admin scope (full catalog CRUD), any other key has member scope (reads + access requests). Organization-owned keys are admin by ownership and carry no associated user; keys minted for a user carry theirs, which is what access requests and createdBy are attributed to.
Path parameters
Headers
Optional idempotency key, retained 24h and bound to the request that first used it. Resending the same request replays the stored response (with Idempotent-Replayed: true); reusing the key with a different body or path returns 422; retrying while the original is still in flight returns 409 with Retry-After. A failed request releases its key.

