Browse docs · Concepts
Get started
Concepts
Guides
Security
Reference
Docs / Concepts
Approvals
Require a human to approve sensitive agent operations. The broker holds the request, a person decides in the dashboard, and the broker executes exactly what was approved.
Mark a rule with "require_approval": true and every matching call waits for a person. The broker executes the operation with exactly the parameters that were approved.
The flow
- The agent calls
POST /v1/actions. The broker answers202:{"status": "approval_required", "request_id": "8a41d0c2", "poll": "/v1/actions/8a41d0c2"} - The request appears in Approvals with the agent, operation and parameters.
- Someone approves or denies it.
- The agent polls
GET /v1/actions/{id}. While waiting it seespending; after approval the first poll executes the operation and returns the result. A denial returnsdenied.
Guarantees
- The approved parameters are fingerprinted; a different call cannot ride on an approval.
- An approved request executes once.
- Requests expire if nobody decides.
- A lockdown blocks execution even of approved requests.
The MCP tools expose the same flow: pastkeys_execute returns approval_required, and pastkeys_check_operation polls.