# Rate the rules' verdict

Source: https://immiscible.fly.dev/docs/api/post-api-w-wid-approvals-apid-feedback

`POST /api/w/:wid/approvals/:apid/feedback`

Say whether the rules' verdict on a request was right: `agree` is `true` (thumbs up) or `false`. It is kept in the audit log with the verdict it was about, so whoever writes the rules can see where they ask too much or too little. It changes nothing on its own.

| Field | Description |
|---|---|
| `agree` | `true` or `false` |
| `note` | optional, up to 280 characters |

## Authentication

Session cookie. A signed-in person: the console's session cookie. Every state-changing request also carries the header `x-immiscible-csrf: 1`, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.

## Path parameters

- `wid` (string, required): Workspace id
- `apid` (string, required): Approval id

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/approvals/apr_3k9d02aa/feedback" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION" \
  -H "x-immiscible-csrf: 1" \
  -H "content-type: application/json" \
  -d '{
    "agree": false,
    "note": "We pay this courier every month."
  }'
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/approvals/apr_3k9d02aa/feedback', {
  method: 'POST',
  headers: {
    cookie: `__Host-sid=${process.env.IMMISCIBLE_SESSION}`,
    'x-immiscible-csrf': '1',
    'content-type': 'application/json',
  },
  body: JSON.stringify({
    agree: false,
    note: 'We pay this courier every month.',
  }),
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import os
import requests

res = requests.post(
    "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/approvals/apr_3k9d02aa/feedback",
    headers={
        "cookie": f"__Host-sid={os.environ['IMMISCIBLE_SESSION']}",
        "x-immiscible-csrf": "1",
        "content-type": "application/json",
    },
    json={
        "agree": False,
        "note": "We pay this courier every month.",
    },
)
print(res.status_code, res.json())
```
