Create an access request

Submit a request for access to resource groups and/or endpoints in one namespace. Admin must approve in the app (approve/reject are not on this public surface). Both admin and member API keys may create requests. The requester defaults to the user the API key belongs to. An admin key may override it with `requesterId` to file on someone else's behalf; a member key may not (403). A key with no associated user — an organization-owned key, whose creator WorkOS does not record — must supply `requesterId`, or the request is rejected with 400: a request cannot be attributed to the key itself, because approval mints the grant against the requester and policy bundles resolve by user.

Authentication

AuthorizationBearer
WorkOS API key (Authorization: Bearer sk_...). Scope comes from the key's permissions: a key carrying `passport:admin` has admin scope (full catalog CRUD), any other key has member scope (reads + access requests). Organization-owned keys are admin by ownership and carry no associated user; keys minted for a user carry theirs, which is what access requests and `createdBy` are attributed to.

Headers

Idempotency-KeystringOptional
Optional idempotency key, retained 24h and bound to the request that first used it. Resending the same request replays the stored response (with `Idempotent-Replayed: true`); reusing the key with a different body or path returns 422; retrying while the original is still in flight returns 409 with `Retry-After`. A failed request releases its key.

Request

This endpoint expects an object.
namespaceIdstringRequiredformat: "uuid"
entitieslist of objectsRequired
requesterIdstring or nullOptionalformat: "^user_[A-Za-z0-9]{1,58}$"

The WorkOS user the access is for. Defaults to the user the key belongs to, and is REQUIRED for an organization-owned key, which has no associated user. A member key may omit it or set it to its own user id; any other value is rejected with 403. Only the user_... format is checked — the id is NOT verified to exist, so a wrong but well-formed value is accepted here and approval then mints a grant no one can use (bundles resolve by user id).

messagestring or nullOptional<=1000 characters
durationDaysenumOptional

Requested access lifetime. null means unlimited.

Allowed values:

Response headers

RateLimit-Limitinteger
Requests allowed in the current window.
RateLimit-Remaininginteger
Requests remaining in the current window.
RateLimit-Resetinteger
Unix epoch seconds when the window resets.

Response

Created
dataobject

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
409
Conflict Error
422
Unprocessable Entity Error
429
Too Many Requests Error
500
Internal Server Error
503
Service Unavailable Error