Skip to main content
Side-effecting integration actions and destructive actions pause the run until someone approves them. Read-only actions do not pause. The rules are in the workspace under Integrations, on Approval settings.

Who is notified

The workspace owner and the person who requested the action get an email. Telegram is used when that channel is connected. The same request appears on the dashboard Approvals page.

What the API call sees

Streaming and non-streaming both stop at the first approval round. A non-streaming response includes status, run_id, and thread_id. status is completed or awaiting_approval. pending_tool_approvals is present only while the run is waiting. denied_tool_calls is present only when a policy denied a call, with reason policy_deny. The response text includes [Waiting for approval: …]. A streaming call sends a tool_approval event, then the same fields on the final usage event. review_url opens https://app.fetchhive.com/{workspace_id}/approvals?approval={approval_id} after sign-in. The email token is not in the API response. Secret-like argument values are replaced with [redacted]. If a response also includes pending_delegations, answer the tool approval first. With tool approvals turned off, status is completed and the approval arrays are omitted.

How to answer

Open the dashboard link, use the email link, or decide with an API key: POST /v1/public/workspaces/{workspace_id}/tool_action_approvals/{id}/decide decision is allow_once or deny. always_allow returns 422 always_allow_requires_dashboard. A second decision returns 409. An expired approval returns 410.

How to continue

Re-invoke the same agent and thread_id with decided_tool_approvals: [{ "approval_id": "…" }]. Send an empty message or a new one. Only approval_id is read. If you omit decided_tool_approvals and reuse the thread, Fetch Hive loads terminal approvals from that thread that have not resumed yet. Send the ids when you can. A webhook trigger or a call with async.callback_url resumes on its own after the decision. The callback receives agent.awaiting_approval, then agent.completed with resumed_from_run_id.

Expiry and the round limit

An approval expires 24 hours after it is created, unless TOOL_APPROVAL_TTL_HOURS is set. A run chain stops after five approval rounds and appends [Approval limit reached].

Always allow

Always allow is set in the dashboard. An API key cannot create that policy.