Approvals API

Approvals endpoints in the Brix REST API: 5 operations (GET, POST), with auth, permissions and curl examples.

View as Markdown

Base URL https://api.brixsignage.com. Send Authorization: Bearer $BRIX_API_KEY unless an operation says No auth. The permission chip names what the key must hold. See Authentication and scopes, Errors and rate limits and Pagination.

GET/v1/approvals

Bearer token screen.view

List approval requests the caller is allowed to see, newest first. Use ?state= to narrow the list to requests still awaiting a decision. The response is capped because approval history only grows over time. Newest first. The route needs screen.view, but each request is listed only if the caller can also view (or approve) that content kind at its location — e.g. playlist.view for a playlist. A screen.view-only key gets an empty list.

ParameterInTypeRequiredDescription
statequery"pending" | "approved" | "rejected" | "withdrawn"noOnly requests in this state (`pending` = the inbox).
limitqueryintegernoAt most this many (default and max 500).
curl "https://api.brixsignage.com/v1/approvals" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 200 Success.

FieldTypeDescription
dataarray of ApprovalRequest
data[].idstringApproval request id.
data[].contentKindstring`playlist`, `schedule`, `creative`, `layout`, `creative-override`, `media`, `app`, …
data[].contentIdstring
data[].contentNamestring
data[].thumbnailUrlstring | null
data[].nodeIdstringThe content's home location; empty string for the workspace root.
data[].nodeNamestring
data[].requestedByNamestring
data[].requestedAtstringISO-8601 timestamp (UTC).
data[].notestring | null
data[].changesarray of anyWhat changed since the last approved version: `{kind, label, detail, thumbnailUrl?}` items for kinds the server diffs; for other kinds, whatever the requester sent.
data[].state"pending" | "approved" | "rejected" | "withdrawn"
data[].requestedByIdstringUser id, or `apikey:<id>` for a key.
data[].levelsarray of objectThe approval chain, one entry per tier.
data[].levels[].nodeIdstring
data[].levels[].nodeNamestring
data[].levels[].approverIdsarray of string
data[].levels[].approverNamesarray of string
data[].currentLevelintegerIndex into `levels` awaiting a decision while pending.
data[].decisionsarray of object
data[].decisions[].levelinteger
data[].decisions[].decidedByIdstring
data[].decisions[].decidedByNamestring | null
data[].decisions[].decidedAtstringISO-8601 timestamp (UTC).
data[].decisions[].notestring | null
data[].decidedByNamestring | null
data[].decidedAtstring | null
data[].decisionNotestring | null

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 The token lacks the permission this operation needs (see `x-brix-permission`).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/approvals

Bearer token

Open an approval request for a piece of content. The authenticated caller becomes the requester. Decide the request with POST /v1/approvals/:id/decide, or cancel it with POST /v1/approvals/:id/withdraw.

curl -X POST "https://api.brixsignage.com/v1/approvals" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

GET/v1/approvals/{id}

Bearer token screen.view

Retrieve one approval request. If the request falls outside what you are allowed to see, this returns 404 rather than 403, so its existence is not revealed.

ParameterInTypeRequiredDescription
idpathstringyesIdentifier for id.
curl "https://api.brixsignage.com/v1/approvals/{id}" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/approvals/{id}/decide

Bearer token screen.view

Approve or reject a pending approval request. A reason is required when rejecting. The decision is applied to the underlying content's approval status. Decides the CURRENT level of the chain. Approving the last level lets the content air; approving an earlier level passes it to the next. Besides screen.view, the caller must be a named approver for the level or hold the content kind's approve permission (playlist.approve, schedule.approve, …) at the level's location.

ParameterInTypeRequiredDescription
idpathstringyesApproval request id.

Request body application/json

FieldTypeRequiredDescription
decision"approved" | "rejected"yes
decisionNotestringnoRequired to reject.
curl -X POST "https://api.brixsignage.com/v1/approvals/{id}/decide" \
  -H "Authorization: Bearer $BRIX_API_KEY" \
  -H "Content-Type: application/json"

Response 200 Success.

FieldTypeDescription
dataApprovalRequestA request to approve content before it can air.
data.idstringApproval request id.
data.contentKindstring`playlist`, `schedule`, `creative`, `layout`, `creative-override`, `media`, `app`, …
data.contentIdstring
data.contentNamestring
data.thumbnailUrlstring | null
data.nodeIdstringThe content's home location; empty string for the workspace root.
data.nodeNamestring
data.requestedByNamestring
data.requestedAtstringISO-8601 timestamp (UTC).
data.notestring | null
data.changesarray of anyWhat changed since the last approved version: `{kind, label, detail, thumbnailUrl?}` items for kinds the server diffs; for other kinds, whatever the requester sent.
data.state"pending" | "approved" | "rejected" | "withdrawn"
data.requestedByIdstringUser id, or `apikey:<id>` for a key.
data.levelsarray of objectThe approval chain, one entry per tier.
data.levels[].nodeIdstring
data.levels[].nodeNamestring
data.levels[].approverIdsarray of string
data.levels[].approverNamesarray of string
data.currentLevelintegerIndex into `levels` awaiting a decision while pending.
data.decisionsarray of object
data.decisions[].levelinteger
data.decisions[].decidedByIdstring
data.decisions[].decidedByNamestring | null
data.decisions[].decidedAtstringISO-8601 timestamp (UTC).
data.decisions[].notestring | null
data.decidedByNamestring | null
data.decidedAtstring | null
data.decisionNotestring | null

Response 401 Missing, expired or revoked bearer token.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 403 Not eligible to decide this level, or `self_approval` (another approver exists).

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 404 No such request.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 409 `already_decided`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 422 Bad `decision`, or a rejection without `decisionNote`.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

POST/v1/approvals/{id}/withdraw

Bearer token

Cancel your own pending approval request. The content it was attached to returns to draft status.

ParameterInTypeRequiredDescription
idpathstringyesIdentifier for id.
curl -X POST "https://api.brixsignage.com/v1/approvals/{id}/withdraw" \
  -H "Authorization: Bearer $BRIX_API_KEY"

Response 4XX Client error. 404 rather than 403 for another tenant's resource, so account existence is not leaked.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.

Response 5XX Server error. The body carries a `requestId` to quote to support.

FieldTypeDescription
errorstringMachine-readable code: `unauthorized`, `forbidden`, `not_found`, `validation_error`, `conflict`, `rate_limited`, `internal_error`, …
messagestringHuman-readable explanation. Safe to show an operator.
requestIdstringPresent on 5xx: quote it to support.