> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nora.my/llms.txt
> Use this file to discover all available pages before exploring further.

# nora approvals

> Decide approval gates from the CLI or wire an external approval workflow.

Approvals are the human gate before certain agent actions ship. `approvals` lets you list pending approvals, decide them, and configure the webhook that pushes approval requests to external systems (Slack bots, custom review UIs).

## Commands

| Command | Description |
| - | - |
| `approvals list [flags]` | List approval rows with filters. |
| `approvals get <id>` | Fetch one approval row (full context). |
| `approvals decide <id> --approve\|--reject` | Approve or reject a pending row. |
| `approvals describe <flow-slug>` | Print webhook URL & payload shape for external approvals. |
| `approvals set-webhook <flow-slug> [url]` | Set or clear the approval webhook URL. |

## `approvals list`

```bash theme={null}
nora approvals list \
  --status pending \
  --kind tool \
  --limit 20
```

Filters:

* `--status pending|approved|rejected|expired`
* `--kind agent|route|tool|action|cost`: which gate kind.
* `--source builder_run|api|webhook|schedule`: where the invocation came from.
* `--limit <n>`: max rows. Default 50.

Add `--json` for structured output.

## `approvals get`

```bash theme={null}
nora approvals get ap_abc
```

Prints the full approval row:

* What's being approved (kind, target block, arguments).
* When it was raised.
* Related trace ID.
* Timeout.
* Prior related approvals on the same trace (if any).

Approvers use this to make an informed decision.

## `approvals decide`

```bash theme={null}
# Approve
nora approvals decide ap_abc --approve --reason "Amount within limits"

# Reject
nora approvals decide ap_abc --reject --reason "Duplicate refund" --external QA_TICKET_42
```

Flags:

* `--approve` **or** `--reject` (exactly one, required).
* `--reason <text>`: mandatory in compliance mode; strongly recommended always.
* `--external <id>`: external tracking ID (e.g. ticket number, PR reference).

Deciding is a one-way action: you can't undo, but you can raise a new approval on the same trace to correct.

## `approvals describe`

```bash theme={null}
nora approvals describe support-agent
```

Prints the webhook contract:

* URL Nora POSTs to when a new approval opens.
* Signing header format.
* Payload shape.
* Callback endpoint for your external system to hit back.

Use to wire up a Slack bot or custom review UI.

Add `--json` for machine output.

## `approvals set-webhook`

```bash theme={null}
# Set
nora approvals set-webhook support-agent https://approvals.internal/hooks/nora

# Clear
nora approvals set-webhook support-agent --clear
```

When a webhook is set, every new approval both surfaces in-app **and** POSTs to the webhook. When cleared, only in-app.

This is a convenience wrapper for `nora flows settings update --set-approval-webhook`.

## Recipes

### Bulk-approve everything from a trusted source

```bash theme={null}
for id in $(nora approvals list --status pending --source schedule --json | jq -r '.[].id'); do
  nora approvals decide "$id" --approve --reason "auto-approved scheduled run"
done
```

Careful: approve is not undoable. Only auto-approve sources you truly trust.

### Slack-integrated approvals

```bash theme={null}
# One-time setup: wire the webhook
nora approvals set-webhook support-agent https://slack-approvals.internal/hooks/nora

# From your Slack bot on button press
curl -X POST https://api.platform.nora.my/approvals/ap_abc/decide \
  -H "Authorization: Bearer $NORA_TOKEN" \
  -d '{"verdict":"approve","reason":"Alice approved via Slack","external":"slack-msg-xyz"}'
```

The endpoint accepts the same payload shape as `approvals decide`.

### Timeout policy: auto-reject stale approvals

Add a cron job:

```bash theme={null}
# Reject anything pending > 24h
cutoff=$(date -v-1d +%s)
for row in $(nora approvals list --status pending --json | jq -c '.[]'); do
  age=$(echo "$row" | jq -r '.created_at' | date -j -f "%Y-%m-%dT%H:%M:%SZ" +%s -)
  if [ "$age" -lt "$cutoff" ]; then
    id=$(echo "$row" | jq -r '.id')
    nora approvals decide "$id" --reject --reason "auto-rejected: pending >24h"
  fi
done
```

Or configure the timeout directly on the approval gate (via `agents update --set-cost-approval` and related flags).

## Approval gate kinds

* **agent** Agent's answer requires approval before sending.
* **route** Agent's routing decision (which branch to take) requires approval.
* **tool** a specific Tool call requires approval before executing.
* **action** an Action requires approval before firing.
* **cost** approval required when run cost exceeds threshold.

Each is turned on per-block (see [`nora agents`](/cli/agents), [`nora tools`](/cli/tools), [`nora actions`](/cli/actions)).

## Related

* [Approve & deploy](/reliable/simulation/verify-deploy): the concept doc for approvals.
* [`nora flows settings`](/cli/flow-settings): approval webhook setting.
* [Audit trail](/reliable/versions/audit): every decision is logged with actor and reason.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.