---
title: "Approve a web origin"
method: POST
path: "/v1/org/web-origins"
tags: ["Organizations"]
---

# Approve a web origin

`POST /v1/org/web-origins`

Approves one exact HTTPS origin (scheme, host, and optional port) for this organization. Approved origins can receive web sign-in handoffs for this organization and make credentialed browser requests to the Den API.

## Request body

- OrganizationWebOriginApproveBody
  - `origin` string, required

## Response `201`

The web origin was approved.

- OrganizationWebOrigin
  - `id` string, required
  - `origin` string, required
  - `createdAt` string, date-time, required
  - `createdByName` string, nullable, required

## Other responses

- `400` — The origin was not an exact HTTPS origin.
- `401` — The caller must be signed in.
- `403` — Only workspace owners and super-admins with a recent sign-in can approve web origins.
- `404` — The organization was not found.
- `409` — The origin is already approved or the organization reached its approved origin limit.

## Changes

- **2026-09-23** `61c4bda8422c` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/openworklabs/apis/den-api/changes/v1/org/web-origins/post.md)

---

[API](https://skmtc.dev/openworklabs/apis/den-api.md) · [All operations](https://skmtc.dev/openworklabs/apis/den-api/llms.txt) · [OpenAPI document](https://skmtc.dev/openworklabs/apis/den-api/revisions/406852f37cc0?raw)
