Skip to content

Approve or reject the jobs a run's environments hold. environment_names names them (every waiting one if left out; environment_ids is read as names too); state is approved or rejected; comment is kept with the review.

POST/repos/{owner}/{name}/actions/runs/{id}/pending_deployments

Only one of the environment’s reviewers may, or an admin when can_admins_bypass is on, which also skips the wait timer; with prevent_self_review, not whoever started the run. A rejected environment’s jobs fail. A workflow job’s own token cannot review. Returns the pending deployments as they stand.

The jobs still wait for the wait timer, until wait_until, unless an admin approved past the rules.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: workflow with action review_deployments, and the same inputs
  • Scope: An access token needs workflows:write.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
id string Yes The run’s id, run_….

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
environment_names array of strings No The environments to review; every waiting one if left out.
state string Yes One of approved, rejected.
comment string No Why, kept with the review.
curl -X POST https://api.g1t.sh/repos/flagon-io/g1t/actions/runs/run_01kq9b3d5f7h9k1n3q5s7u9w1y/pending_deployments \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"environment_names": [
"production"
],
"state": "approved",
"comment": "Release notes checked."
}'

A successful request answers 200 with:

[
{
"environment": {
"name": "production"
},
"state": "approved",
"needs_review": true,
"wait_until": "2026-10-08T09:31:02.551Z",
"current_user_can_approve": false,
"reviewers": [
{
"type": "User",
"reviewer": {
"login": "syntaqx"
}
},
{
"type": "Team",
"reviewer": {
"slug": "deployers"
}
}
],
"jobs": [
"Deploy the core services"
],
"reviewed_by": "syntaqx",
"comment": "Release notes checked.",
"reviewed_at": "2026-10-08T09:22:15.871Z"
}
]

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.