Skip to content

Approve a request to join

POST
/orgs/{org}/access-requests/{id}/approve
curl --request POST \
--url https://api.sloose.com/orgs/org_9f3c/access-requests/ar_3k9d/approve \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "role": "operator" }'

Makes the ordinary invitation — to the address the person asked from, at the role given (an operator unless another is, and never above your own), for seven days — and mails it, exactly as inviting them on People would. Once: two administrators approving together approve it once, and the second is told it is done. Recorded in the org’s audit (People).

When the person has joined since, or an invitation is already waiting for them, the request is approved and no second invitation is made (invited: false, with because).

Administrators, and a session only.

org
required

The org id the session was issued for. A token for one org can never read another.

string
Example
org_9f3c

The org id the session was issued for. A token for one org can never read another.

id
required

The request, from the link in the administrators’ mail.

string
Example
ar_3k9d

The request, from the link in the administrators’ mail.

Media typeapplication/json
object
role

The role the invitation is for: operator unless given. A value that is not one of these is ignored, as when none is given.

string | null
Allowed values: operator builder admin

Approved.

Media typeapplication/json
object
request
required
object
id
required
string
orgName
required
string
requesterName
required

The name they signed in with. Null when they gave none, or gave one that could be read as Sloose — it is not shown, here or in the mail, since it is theirs to choose.

string | null
requesterEmail
required
string
crmName
required

The CRM the person’s Zoho sign-in proved, as it names itself — null, by the same rule, when that name could be read as Sloose.

string | null
status
required
string
Allowed values: open approved expired
requestedAt
required
string
expiresAt
required
string
decidedAt
required
string | null
invited
required

Whether an invitation was made and mailed now.

boolean
because
string
Allowed values: ALREADY_MEMBER ALREADY_INVITED
Example
{
"request": {
"status": "open"
},
"because": "ALREADY_MEMBER"
}

No bearer, or one that is expired, revoked or no longer resolves to a member.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Not an owner or administrator of this org, a bearer issued for another org, an API token (code: SESSION_REQUIRED), or a staff member’s view of the org — a read-only one as on any write (code: IMPERSONATION_READ_ONLY), and a write-capable one too (code: IMPERSONATION_REFUSED), since the invitation it makes would outlast the view.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

No such request in this org (code: ACCESS_REQUEST_NOT_FOUND).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Approved already (code: ALREADY_APPROVED), or lapsed (code: REQUEST_EXPIRED) — the person can ask again from the CRM tab.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

The invitation could not be emailed (code: INVITATION_NOT_SENT): none was made, the request is open again, and approving again tries again.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Report a problem with this page