Application boundary#
These paths belong to your YAADMIN installation. They are not callable product-website APIs. Authenticated mutations require a session-matched X-CSRF-Token unless the route is public. Handler-local error codes are not exhaustive downstream schemas.
Verified routes#
GET/api/approvals/pending⌄
Pending approvals.
- Authentication
- session
- Permission
- no separate permission identifier in handler (admin/owner/runtime checks as above)
- Request body
- none
- Query parameters
- none explicitly read
- Headers
- none beyond shared session/CSRF
- Response structure
{approvals}- Important errors
- 503
- Approval behavior
- session-owned approval preview/decision/execution; see §7.
Verified route registration · handler api_pending_approvals. Some definitions may be partially redacted; no missing fields are inferred.
GET/api/approvals/{approval_id}/preview⌄
Approval preview.
- Authentication
- session
- Permission
- no separate permission identifier in handler (admin/owner/runtime checks as above)
- Request body
- none
- Query parameters
- none explicitly read
- Headers
- none beyond shared session/CSRF
- Response structure
JSONResponse(preview, headers={'Cache-Control': 'private, no-store', 'X-Content-Type-Options': 'nosniff'})- Important errors
- 403, 404, 409
- Approval behavior
- session-owned approval preview/decision/execution; see §7.
Verified route registration · handler api_approval_preview. Some definitions may be partially redacted; no missing fields are inferred.
POST/api/approvals/batch/approve⌄
Approve batch.
- Authentication
- session
- Permission
- no separate permission identifier in handler (admin/owner/runtime checks as above)
- Request body
- ApprovalBatchPayload [batch_id, approval_ids]
- Query parameters
- none explicitly read
- Headers
- none beyond shared session/CSRF
- Response structure
{ok, cancelled, decision, batch_id, max_concurrency, items, answer, warning, approvals}; {ok, decision, batch_id, max_concurrency, items, approvals}- Important errors
- 400, 409
- Approval behavior
- session-owned approval preview/decision/execution; see §7.
Request fields
Verified route registration · handler api_approve_batch. Some definitions may be partially redacted; no missing fields are inferred.
POST/api/approvals/{approval_id}/approve⌄
Approve.
- Authentication
- session
- Permission
- no separate permission identifier in handler (admin/owner/runtime checks as above)
- Request body
- none
- Query parameters
- none explicitly read
- Headers
- none beyond shared session/CSRF
- Response structure
{ok, cancelled, decision, approval_id, answer, warning, approvals}; {ok, decision, approval_id, execution, answer, mcp_content, approvals}- Important errors
- 403, 409
- Approval behavior
- session-owned approval preview/decision/execution; see §7.
Verified route registration · handler api_approve. Some definitions may be partially redacted; no missing fields are inferred.
POST/api/approvals/{approval_id}/reject⌄
Reject.
- Authentication
- session
- Permission
- no separate permission identifier in handler (admin/owner/runtime checks as above)
- Request body
- none
- Query parameters
- none explicitly read
- Headers
- none beyond shared session/CSRF
- Response structure
{ok, decision, approval, approvals}- Important errors
- 403, 409
- Approval behavior
- session-owned approval preview/decision/execution; see §7.
Verified route registration · handler api_reject. Some definitions may be partially redacted; no missing fields are inferred.
Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.