# Decide an approval (phone)

Source: https://immiscible.fly.dev/docs/api/post-api-mobile-v1-w-wid-approvals-apid-decide

`POST /api/mobile/v1/w/:wid/approvals/:apid/decide`

The console's decision, with the console's rules: who may decide, named approvers, separation of duties, a fresh check. `decision` is `approve` or `deny`. An approval above the line without a `stepUp` proof is answered `403 step_up_required` with the challenge to sign.

## Authentication

Device token. A bearer token issued to one phone after its owner signs in through the browser, sent as `Authorization: Bearer`. The rules are the console's rules; approving above a line needs a fresh step-up proof from the device. Writes carry `x-immiscible-csrf: 1`.

## Path parameters

- `wid` (string, required): Workspace id
- `apid` (string, required): Approval id

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/api/mobile/v1/w/$IMMISCIBLE_WORKSPACE/approvals/apr_3k9d02aa/decide" \
  -H "content-type: application/json" \
  -d '{
    "decision": "approve",
    "note": "Expected renewal."
  }'
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/api/mobile/v1/w/$IMMISCIBLE_WORKSPACE/approvals/apr_3k9d02aa/decide', {
  method: 'POST',
  headers: {
    'content-type': 'application/json',
  },
  body: JSON.stringify({
    decision: 'approve',
    note: 'Expected renewal.',
  }),
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import requests

res = requests.post(
    "https://immiscible.fly.dev/api/mobile/v1/w/$IMMISCIBLE_WORKSPACE/approvals/apr_3k9d02aa/decide",
    headers={
        "content-type": "application/json",
    },
    json={
        "decision": "approve",
        "note": "Expected renewal.",
    },
)
print(res.status_code, res.json())
```
