---
title: "Approvals · intentic sandbox API"
description: "Things the agent has prepared, waiting for you to say yes. Every route in the approvals group of the intentic sandbox API."
url: "https://intentic.dev/api/approvals/"
---

Ship and share

# Approvals

Things the agent has prepared, waiting for you to say yes

**On this page (6 sections)**

- [Things waiting for your yes](#approvals-list)
- [Approve, edit or retry one](#approvals-upsert)
- [Reject one](#approvals-remove)
- [Hooks waiting for your yes](#approvals-hookRequests)
- [Let a hook set run](#approvals-approveHooks)
- [Keep a hook set off without being asked again](#approvals-dismissHooks)

The owner's side of the queue: posts to publish, actions to carry out. The agent writes the files directly; this is the inbox, the one call that covers approving, editing and retrying, and the deletion that is a rejection.

**GET`/approvals` Things waiting for your yes**

Everything an agent has prepared and would like to do: posts to publish, actions to carry out. Nothing here has happened yet.

### What you send

Nothing. Call it as it is.

### What comes back

| Field | Type |
| --- | --- |
| `approvals` The queue | object[] |
| `when kind is "post"` | shape |
| `platform` Where it should go | string |
| `content` The post itself | string |
| `title` A title, where the site wants… | string |
| `target` Where on the site: a community,… | string |
| `media` Anything to attach, as workspace paths | string[] |
| `actsAs` Whose name it acts under | string |
| `scheduledAt` When it should happen, in milliseconds | number |
| `status` Where it is: proposed by the… | "proposed" | "approved" | "running" | "done" … (5) |
| `createdAt` When it was written, in milliseconds | number |
| `startedAt` When it started being carried out,… | number |
| `finishedAt` When it was done, in milliseconds | number |
| `result` What came back, when something did:… | string |
| `error` Why it failed, written as a… | string |
| `id` The approval's id | string |
| `when kind is "action"` | shape |
| `summary` What will happen, in one line:… | string |
| `details` The specifics, as Markdown: everything you… | string |
| `instructions` What to do once approved, written… | string |
| `actsAs` Whose name it acts under | string |
| `scheduledAt` When it should happen, in milliseconds | number |
| `status` Where it is: proposed by the… | "proposed" | "approved" | "running" | "done" … (5) |
| `createdAt` When it was written, in milliseconds | number |
| `startedAt` When it started being carried out,… | number |
| `finishedAt` When it was done, in milliseconds | number |
| `result` What came back, when something did:… | string |
| `error` Why it failed, written as a… | string |
| `id` The approval's id | string |
| `invalid` Files that could not be read… | string[] |

Try it answered in this tab

curl

```bash
curl "$SANDBOX/approvals" \
 -H "x-intentic-control: $INTENTIC_TOKEN"
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.approvals.list();
```

**POST`/approvals` Approve, edit or retry one**

All three are the same act with a different field changed, so they share one call. Send the item back as you want it.

### What you send

| Field | Type | Where |
| --- | --- | --- |
| `when kind is "post"` | shape | body |
| `platform` required Where it should go | string | body |
| `content` required The post itself | string | body |
| `title` A title, where the site wants… | string | body |
| `target` Where on the site: a community,… | string | body |
| `media` Anything to attach, as workspace paths | string[] | body |
| `actsAs` Whose name it acts under | string | body |
| `scheduledAt` When it should happen, in milliseconds | number | body |
| `status` Where it is: proposed by the… | "proposed" | "approved" | "running" | "done" … (5) | body |
| `createdAt` When it was written, in milliseconds | number | body |
| `startedAt` When it started being carried out,… | number | body |
| `finishedAt` When it was done, in milliseconds | number | body |
| `result` What came back, when something did:… | string | body |
| `error` Why it failed, written as a… | string | body |
| `id` required The approval's id | string | body |
| `when kind is "action"` | shape | body |
| `summary` required What will happen, in one line:… | string | body |
| `details` The specifics, as Markdown: everything you… | string | body |
| `instructions` required What to do once approved, written… | string | body |
| `actsAs` Whose name it acts under | string | body |
| `scheduledAt` When it should happen, in milliseconds | number | body |
| `status` Where it is: proposed by the… | "proposed" | "approved" | "running" | "done" … (5) | body |
| `createdAt` When it was written, in milliseconds | number | body |
| `startedAt` When it started being carried out,… | number | body |
| `finishedAt` When it was done, in milliseconds | number | body |
| `result` What came back, when something did:… | string | body |
| `error` Why it failed, written as a… | string | body |
| `id` required The approval's id | string | body |

### What comes back

| Field | Type |
| --- | --- |
| `ok` Always true | true |

Try it answered in this tab

curl

```bash
curl -X POST "$SANDBOX/approvals" \
 -H "x-intentic-control: $INTENTIC_TOKEN" \
 -H "content-type: application/json" \
 -d '{"kind":"post","platform":"…","content":"export const start = () => listen(PORT);\n","title":"Update the changelog","target":"…","media":["…","…"],"actsAs":"…","scheduledAt":1,"status":"proposed","createdAt":1,"startedAt":1,"finishedAt":1,"result":"…","error":"The repository has no remote configured.","id":"a1b2c3d4"}'
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.approvals.upsert({
 "kind": "post",
 "platform": "…",
 "content": "export const start = () => listen(PORT);\n",
 "title": "Update the changelog",
 "target": "…",
 "media": [
 "…",
 "…"
 ],
 "actsAs": "…",
 "scheduledAt": 1,
 "status": "proposed",
 "createdAt": 1,
 "startedAt": 1,
 "finishedAt": 1,
 "result": "…",
 "error": "The repository has no remote configured.",
 "id": "a1b2c3d4"
});
```

**DELETE`/approvals/{id}` Reject one**

Throws it away undone.

### What you send

| Field | Type | Where |
| --- | --- | --- |
| `id` required Which approval | string | address |

### What comes back

| Field | Type |
| --- | --- |
| `ok` Always true | true |

Try it answered in this tab

curl

```bash
curl -X DELETE "$SANDBOX/approvals/a1b2c3d4" \
 -H "x-intentic-control: $INTENTIC_TOKEN"
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.approvals.remove({
 "id": "a1b2c3d4"
});
```

**GET`/approvals/hooks` Hooks waiting for your yes**

Hook sets a turn found in Claude Code's settings files, in a skill's or subagent's definition, or in a plugin the turn loads that the sandbox does not ship (its hooks and its hooks module, code that runs inside Claude Code), that nobody has approved in that exact form. Until one is approved, turns in this workspace run with every hook switched off; the sandbox's own safeguards are not hooks of this kind and keep working.

### What you send

Nothing. Call it as it is.

### What comes back

| Field | Type |
| --- | --- |
| `requests` Hook sets waiting for a yes,… | object[] |
| `digest` The set's fingerprint: every hook as… | string |
| `seenAt` When a turn first found this… | number |
| `conversationId` The conversation whose turn found it,… | string |
| `hooks` Every hook in the set | object[] |
| `source` Whose configuration declares it: the sandbox's… | "user" | "project" | "plugin" |
| `plugin` The plugin that declares it, by… | string |
| `declaredIn` The skill, subagent or command whose… | string |
| `event` When it runs, in Claude Code's… | string |
| `matcher` Which tools it is limited to,… | string |
| `type` What kind of hook it is:… | string |
| `run` Exactly what it runs: the command… | string |
| `scripts` The files those hooks run by… | object[] |
| `path` A file one of the hooks… | string |
| `sha256` Its contents when the hooks were… | string |
| `plugins` The plugins whose hooks or modules… | object[] |
| `name` The plugin, as the sandbox lists… | string |
| `from` What brought it into the turn:… | "plugin" | "extension" | "persona" | "skills" … (5) |
| `source` Which settings enable it or hold… | "user" | "project" |
| `dir` Where its files were read | string |
| `module` Its hooks module, code that runs… | object |
| `path` The plugin's hooks module, as its… | string |
| `hooks` The moments it acts on, in… | string[] |
| `calls` What it reaches for while it… | string[] |
| `unreadable` Why the sandbox could not tell… | string |
| `marketplaces` Plugin marketplaces Claude Code's settings add,… | object[] |
| `source` Whose settings add it: the sandbox's… | "user" | "project" |
| `name` The marketplace's name in those settings | string |
| `location` Where Claude Code fetches it from,… | string |
| `dismissed` Kept off on purpose: no longer… | boolean |
| `ledgerUnreadable` The record of what was approved… | boolean |

Try it answered in this tab

curl

```bash
curl "$SANDBOX/approvals/hooks" \
 -H "x-intentic-control: $INTENTIC_TOKEN"
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.approvals.hookRequests();
```

**POST`/approvals/hooks/{digest}/approve` Let a hook set run**

Approves exactly this set, commands and the bytes of the files they run, plugin modules included, from the next turn on. Any later change to either is a new set and asks again. Owner and maintainers only, and never through a token a program holds.

### What you send

| Field | Type | Where |
| --- | --- | --- |
| `digest` required Which hook set, by its fingerprint | string | address |

### What comes back

| Field | Type |
| --- | --- |
| `ok` Always true | true |

Try it answered in this tab

curl

```bash
curl -X POST "$SANDBOX/approvals/hooks/%E2%80%A6/approve" \
 -H "x-intentic-control: $INTENTIC_TOKEN"
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.approvals.approveHooks({
 "digest": "…"
});
```

**POST`/approvals/hooks/{digest}/dismiss` Keep a hook set off without being asked again**

Takes the set off the list. Its hooks stay switched off; a change to them is a new set, which asks again.

### What you send

| Field | Type | Where |
| --- | --- | --- |
| `digest` required Which hook set, by its fingerprint | string | address |

### What comes back

| Field | Type |
| --- | --- |
| `ok` Always true | true |

Try it answered in this tab

curl

```bash
curl -X POST "$SANDBOX/approvals/hooks/%E2%80%A6/dismiss" \
 -H "x-intentic-control: $INTENTIC_TOKEN"
```

TypeScript

```typescript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.approvals.dismissHooks({
 "digest": "…"
});
```

More in Ship and share

[Previous ← Sharing](https://intentic.dev/api/share/)[Next Issues →](https://intentic.dev/api/issues/)
