Skip to content

Approve or deny a token waiting for approval: decision is approve or deny, and reason, if given, is shown to the token's owner, who hears of it in their inbox.

POST/workspaces/{workspace}/personal-access-token-requests/{id}

An approved token reaches the workspace from its next request; a denied one reaches public repositories only. Recorded in the audit log as token.approved or token.denied. Owners only, as people.

The token’s owner hears of it in their inbox. A denied token reaches public repositories only.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: workspace with action review_token_request, and the same inputs
  • Scope: An access token needs access:admin.
Name Type Required Description
workspace string Yes The workspace’s name, e.g. “acme”.
id string Yes The token’s id, tok_….

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
decision string Yes approve or deny. A request body shaped as {"action": "approve"} is read the same way. One of approve, deny.
reason string No Why, shown to the token’s owner.
curl -X POST https://api.g1t.sh/workspaces/flagon-io/personal-access-token-requests/tok_01HZX3K2M9V7Q4N8B6D5C3A2E1 \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"decision": "approve"
}'

A successful request answers 200 with:

{
"id": "tok_01HZX3K2M9V7Q4N8B6D5C3A2E1",
"name": "release-bot",
"owner": "ada",
"description": "Publishes releases from CI",
"created_at": "2026-10-08T09:00:00.000Z",
"created_by": null,
"last_used_at": null,
"expires_at": "2026-11-07T09:00:00.000Z",
"scopes": [
"repo:read",
"code:write"
],
"workspace": "flagon-io",
"repository_selection": "selected",
"repositories": [
"flagon-io/hello"
],
"permissions": {
"code": "write",
"repo": "read"
},
"status": "active",
"review_reason": null,
"reaches": true,
"blocked_by": null
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.