---
title: "Approve or deny access request"
method: POST
path: "/api/apps/{app_id}/access-requests/{request_id}/{action}"
---

# Approve or deny access request

`POST /api/apps/{app_id}/access-requests/{request_id}/{action}`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Approves or denies someone's request to join the app.

Approving a request from someone who confirmed their email adds them to the app's users with the request's role, and emails them that they're in. A request made before email confirmation existed is marked `approved` instead, and the person joins when they next sign in. Someone who signed up with a password can't be approved until they confirm their email. Approving an entry that's already `approved` or `completed` sends the approval email again.

Denying deletes the request without notifying the person, and denying an invitation withdraws it. Denying a `completed` entry deletes only the entry; remove the person with [Remove app user](/api-reference/remove-app-user).

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>

## Path parameters

- `request_id` string, required — ID of the access request, as `id` in the response of [List access requests](/api-reference/list-access-requests).
- `action` 'approve' | 'deny', required — `approve` to let the person in, or `deny` to delete the request.
- `app_id` string, required — ID of the app.

## Response `200`

The reviewed access request.

- ReviewAccessRequestResponse — Doc-only: the handler returns a plain dict with exactly these keys.
  - `success` boolean, required — Always `true`. A review that doesn't happen returns an error instead.
  - `message` string, required — `Access request approved` or `Access request denied`.
  - `access_request` ReviewedAccessRequest, required
    - `id` string, required — ID of the access request.
    - `app_id` string, required — ID of the app.
    - `email` string, required — Email of the person.
    - `status` string, required — `completed` when the person was added to the app, `approved` when they join once they sign up, or `denied`.

## Other responses

- `400` — You're approving someone who signed up with a password and hasn't confirmed their email yet.
- `401` — Missing or invalid credentials.
- `403` — You don't have editor access to this app, or your API key is read-only.
- `404` — App not found, or the app has no access request with this ID.
- `422` — `action` isn't `approve` or `deny`.

## Changes

> 18 revisions in range; 1 not diffed.

- **2026-09-28** `28fc82924122` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/adexad/apis/base44-app-management-api/changes/api/apps/:app_id/access-requests/:request_id/:action/post.md)

---

[API](https://skmtc.dev/adexad/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/adexad/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/adexad/apis/base44-app-management-api/revisions/28fc82924122?raw)
