Skip to content

Approve impersonation request

POST/tenants/{tenant_id}/impersonations/{id}/approve

Grants approval for a pending impersonation session request. The approving admin must be different from the requesting admin. Once approved, a time-limited start_url is generated for the requesting admin to use to enter the tenant workspace.

Request

Path parameters

NameTypeRequiredDescription
tenant_idstringYes

The tenant identifier.

idstringYes

The impersonation session ID to approve.

Request body

Content type application/json.

FieldTypeRequiredDescription
notesstringNo

Optional approval notes for the audit record.

Max length: 500

Example

{
  "notes": "Verified ticket reference matches open customer complaint."
}

Responses

200 Impersonation session approved and start_url issued

Content type application/json, object · ImpersonationSessionResponseV1.

FieldTypeRequiredDescription
session_idstringNo

Unique identifier for the created or approved session.

statusstringNo

Current status of the session.

One of: "pending", "approved"

impersonation_start_urlstring, nullableNo

Time-limited URL the requesting admin uses to enter the tenant workspace. Null while the session is still pending approval. The URL contains a single-use signed token that expires after 15 minutes.

messagestringNo

Human-readable outcome message.

Example

{
  "session_id": "imp_01HXN8K2V3PABC",
  "status": "approved",
  "impersonation_start_url": "https://acme.faciotech.net/impersonation/start?token=eyJhbGciOiJIUzI1NiJ9...",
  "message": "Impersonation request approved."
}

404 Tenant or impersonation session not found

409 Session has already been approved or terminated

Example request

Paths are relative to the control-plane API base URL ($BASE_URL below).

curl -X POST "$BASE_URL/tenants/{tenant_id}/impersonations/{id}/approve" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"notes": "Verified ticket reference matches open customer complaint."}'
Loading