# platform.admin.accessRequests.review

Platform administrators only: approve or decline a waitlist request at its current revision. Approving emails the person a link to set up their workspace; platformAi lets their company use Oatmilk's AI credits instead of only its own keys. Declining sends nothing, and a declined request can be approved later.

`POST /api/v1/accounting/platform.admin.accessRequests.review`

Permissions: `accounting:read`, `accounting:write`, `accounting:admin` · Roles: admin · Idempotency key required · Send `expectedRevision`

MCP tool: `accounting_platform_admin_access_requests_review`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `requestId` | string (ID) | Yes | The ID of the related record. |
| `decision` | enum | Yes | What you decided. One of: `approve`, `decline`. |
| `expectedRevision` | integer | Yes | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. at most 9007199254740991; greater than 0. |
| `platformAi` | boolean |  | Default `false`. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/platform.admin.accessRequests.review \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "requestId": "1a2b3c4d-5e6f-4a7b-8c9d-0e1f2a3b4c5d",
  "decision": "approve",
  "expectedRevision": 3
}'
```

Reference page: https://app.getoatmilk.com/docs/api/platform.admin.accessRequests.review
