Skip to content

client.approvals

client.approvals — the approvals operations.

On AsyncKindgi every method is the same, awaited.

list(
*,
limit: int | None = None,
cursor: str | None = None,
status: Literal['pending', 'assigned', 'in_review', 'approved', 'rejected', 'escalated', 'expired', 'withdrawn'] | None = None,
required_role: Literal['standard', 'senior', 'admin'] | None = None,
created_after: str | None = None,
timeout: float | None = None,
) -> ApprovalCollectionPage

List approvals visible to the caller. GET /v1/approvals

Requires the token to carry a reviewerRole. Role-scoped: reviewers only see approvals whose requiredRole rank ≤ their rank (standard < senior < admin).

get(*, timeout: float | None = None) -> Approval

Fetch a single approval. GET /v1/approvals/{approvalId}

Returns 404 for ids that exist but require a higher role than the caller (avoids cross-tier existence leaks — see API-ROUTE-CONVENTIONS.md §2.4).

complete(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
**fields: Any,
) -> CompleteApprovalResult

Submit a decision on an approval. POST /v1/approvals/{approvalId}/complete

Records the decision (HitlBinding.submitReview). When the approval carries a waitTokenId and the decision is approve or reject, also completes the waitpoint so the suspended run resumes.

audit_bundle(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
**fields: Any,
) -> ExportAuditBundleResult

Export a signed audit bundle for a decided approval. POST /v1/approvals/{approvalId}/audit-bundle

Canonicalizes the approval + decision + evidence as sorted-key JSON and signs with the deployment's Ed25519 key looked up by signingKeyId. Envelope shape mirrors provenance.export byte-for-byte so SDK clients can reuse a single verifyEd25519 wrapper for both. Only meaningful post-decision — pending approvals return 409 approval-not-decided.