For AI agents: a documentation index is available at the root level at /llms.txt. Append /llms.txt to any URL for a page-level index, or .md for the markdown version of any page.
Submit a request for access to resource groups and/or endpoints in one namespace. Admin must approve in the app (approve/reject are not on this public surface). Both admin and member API keys may create requests.
The requester defaults to the user the API key belongs to. An admin key may override it with `requesterId` to file on someone else's behalf; a member key may not (403). A key with no associated user — an organization-owned key, whose creator WorkOS does not record — must supply `requesterId`, or the request is rejected with 400: a request cannot be attributed to the key itself, because approval mints the grant against the requester and policy bundles resolve by user.
Authentication
AuthorizationBearer
WorkOS API key (Authorization: Bearer sk_...). Scope comes from the key's permissions: a key carrying `passport:admin` has admin scope (full catalog CRUD), any other key has member scope (reads + access requests). Organization-owned keys are admin by ownership and carry no associated user; keys minted for a user carry theirs, which is what access requests and `createdBy` are attributed to.
Headers
Idempotency-KeystringOptional
Optional idempotency key, retained 24h and bound to the request that first used it. Resending the same request replays the stored response (with `Idempotent-Replayed: true`); reusing the key with a different body or path returns 422; retrying while the original is still in flight returns 409 with `Retry-After`. A failed request releases its key.
Request
This endpoint expects an object.
namespaceIdstringRequiredformat: "uuid"
entitieslist of objectsRequired
requesterIdstring or nullOptionalformat: "^user_[A-Za-z0-9]{1,58}$"
The WorkOS user the access is for. Defaults to the user the key belongs to, and is REQUIRED for an organization-owned key, which has no associated user. A member key may omit it or set it to its own user id; any other value is rejected with 403. Only the user_... format is checked — the id is NOT verified to exist, so a wrong but well-formed value is accepted here and approval then mints a grant no one can use (bundles resolve by user id).
Submit a request for access to resource groups and/or endpoints in one namespace. Admin must approve in the app (approve/reject are not on this public surface). Both admin and member API keys may create requests.
The requester defaults to the user the API key belongs to. An admin key may override it with requesterId to file on someone else’s behalf; a member key may not (403). A key with no associated user — an organization-owned key, whose creator WorkOS does not record — must supply requesterId, or the request is rejected with 400: a request cannot be attributed to the key itself, because approval mints the grant against the requester and policy bundles resolve by user.
WorkOS API key (Authorization: Bearer sk_…). Scope comes from the key’s permissions: a key carrying passport:admin has admin scope (full catalog CRUD), any other key has member scope (reads + access requests). Organization-owned keys are admin by ownership and carry no associated user; keys minted for a user carry theirs, which is what access requests and createdBy are attributed to.
Optional idempotency key, retained 24h and bound to the request that first used it. Resending the same request replays the stored response (with Idempotent-Replayed: true); reusing the key with a different body or path returns 422; retrying while the original is still in flight returns 409 with Retry-After. A failed request releases its key.