---
title: "Approve an invoice at a specific policy tier"
method: POST
path: "/invoices/{id}/approve-policy"
tags: ["invoices"]
---

# Approve an invoice at a specific policy tier

`POST /invoices/{id}/approve-policy`

Records the authenticated user's approval at a specific Advanced Policy tier without force-approving the entire invoice. Approval is implicit for the authenticated user at the named policy tier.

`policy_id` is carried in the request body rather than the URL path (unlike the path shown in the original spec) — the 4-segment path documented there exceeds the max depth this API Gateway resource tree supports (3 segments; see `ottiapi/modules/api_endpoint_tree/main.tf`'s `depth_1/2/3_paths` locals).

## Path parameters

- `id` string, required

## Headers

- `Authorization` string, required
- `X-Api-Key` string, required
- `X-API-Version` string
- `Idempotency-Key` string

## Request body

- object
  - `policy_id` string, required — Policy ID

## Response `200`

Successful response with updated invoice approval state

- InvoicesPostInvoicesIdApprovePolicyResponse200 — Empty response body

## Other responses

- `401` — Unauthorized - Authentication required or invalid credentials
- `403` — Forbidden - Access denied or insufficient permissions

---

[API](https://skmtc.dev/ottimate/apis/api-reference.md) · [All operations](https://skmtc.dev/ottimate/apis/api-reference/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/ottimate/api-reference/revisions/ba91ff4c6969/schema)
