Administration

accountants.requests.decide

Approve or deny an accountant's access or more-time request with id, decision, optional expiresInDays (30, 90 or null), accessExpiresOn for more-time approvals, note, expectedRevision and idempotencyKey. Administrator access is required. MCP calls also require accounting:admin; the web agent asks for approval before changing outside access. Direct API requests cannot perform these access-granting actions.

POST/api/v1/accounting/accountants.requests.decide

Permissions

accounting:readaccounting:writeaccounting:admin

Who can call it

admin

Retries

Idempotency key required, with expectedRevision

MCP

accounting_accountants_requests_decide

Reaches outside Oatmilk

It emails people or calls another service.

Fields

  • idstring (ID)Required

    The record's ID.

  • decisionenumRequired

    What you decided.

    approvedeny
  • expiresInDays30 or 90 or null
  • accessExpiresOnstring or null
  • notestring

    A short note, kept with the record.

    at most 1000 characters

  • expectedRevisionintegerRequired

    The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again.

    at most 9007199254740991 · greater than 0

  • idempotencyKeystringRequired

    Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.

    8–200 characters

Example

curl https://app.getoatmilk.com/api/v1/accounting/accountants.requests.decide \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
  "decision": "approve",
  "expectedRevision": 3
}'
Response
{
  "data": { … }
}

Try it

Try it

Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.

POST/api/v1/accounting/accountants.requests.decide
curl https://app.getoatmilk.com/api/v1/accounting/accountants.requests.decide \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
  "decision": "approve",
  "expectedRevision": 3
}'

More in Administration.