# contractorOps.timesheets.review

Approve or return submitted time entries in a single atomic review, for one pay period (periodId) or for one contractor's hours outside a pay period (contractorId). Supply decisions with hoursId, expectedRevision and decision, a review reason, and idempotencyKey. A decision on a mistake the contractor reported in approved hours also carries the correctionId and decides approved or declined; approving it applies the corrected values, and declining leaves the entry as approved. Approval never sends money.

`POST /api/v1/accounting/contractorOps.timesheets.review`

Permissions: `accounting:read`, `accounting:write` · Roles: admin, finance · Idempotency key required

MCP tool: `accounting_contractor_ops_timesheets_review`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `periodId` | string (ID) |  | The ID of a contractor pay period. |
| `contractorId` | string (ID) |  | The ID of a contractor, from contractors.list. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |
| `reason` | string | Yes | A short note saying why, kept in the record's history. 3–1000 characters. |
| `decisions` | array of objects | Yes | 1–200 items. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/contractorOps.timesheets.review \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "reason": "Synthetic example from the docs",
  "decisions": [
    {
      "hoursId": "1a2b3c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d",
      "expectedRevision": 3,
      "decision": "approved"
    }
  ],
  "periodId": "4d5e6f7a-8b9c-4d0e-8f1a-2b3c4d5e6f7a"
}'
```

Reference page: https://app.getoatmilk.com/docs/api/contractorOps.timesheets.review
