---
title: "List access requests"
method: GET
path: "/api/apps/{app_id}/access-requests/all"
---

# List access requests

`GET /api/apps/{app_id}/access-requests/all`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Returns the people who asked to join the app and the people invited to it who haven't joined yet, newest first.

Check `status` on each entry. `pending` means the person asked for access and is waiting for you to [approve or deny](/api-reference/approve-or-deny-access-request) it. `approved` means they're invited or approved but haven't joined yet. `completed` means they've joined: the entry stays while they're one of the app's users, and they also appear in [List app users](/api-reference/list-app-users). Requests still waiting for the person to confirm their email don't appear.

Set `role` to list one role only. Every matching entry comes back at once, with no paging.

<Note>This endpoint accepts a personal API key belonging to a user with access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>

## Path parameters

- `app_id` string, required — ID of the app.

## Query parameters

- `role` string, nullable — List only entries with this app role. `all`, or leaving it out, lists every role.

## Response `200`

The app's access requests and pending invitations.

- AccessRequestSummary[]
  - `id` string, required — ID of the access request.
  - `app_id` string, required — ID of the app.
  - `email` string, required — Email of the person.
  - `full_name` string, nullable, required — Name of the person, or `null` when they didn't give one.
  - `role` string, required — App role the person gets when they join.
  - `status` string, required — `pending` when the person asked for access and is waiting for your review, `approved` when they're invited or approved but haven't joined yet, or `completed` once they've joined.
  - `requested_at` string, required — When the request or invitation was made, as a UTC timestamp in ISO 8601 format.
  - `data` object, required — Custom `User` fields stored on the invitation, limited by the `User` entity's field-level read rules.

## Other responses

- `401` — Missing or invalid credentials.
- `403` — You don't have access to this app, or your API key is read-only.
- `404` — App not found.

## Changes

- **2026-09-27** `5e69adeb8667` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/base44/apis/base44-app-management-api/changes/api/apps/:app_id/access-requests/all/get.md)

---

[API](https://skmtc.dev/base44/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/base44/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/base44/apis/base44-app-management-api/revisions/5e69adeb8667?raw)
