Deny an access request
Denies an access request that is still in approval, with a required reason. The token user is usually not an assigned approver, so the caller names the approver to deny on behalf of via on_behalf_of_user_id; the acting token user is then persisted as the deputy (replacement). Omit it only when the acting user is themselves a current approver. A single denial terminates the request; an already-closed request returns a validation error.
Authorizations
Bearer token authentication. Pass your AccessOwl API token in the Authorization header as Bearer <token>.
Headers
Optional key (1–255 chars) for safely retrying a request. Reusing the same key for the same request returns 409 Conflict and is not processed again — this confirms the request was already received. Keys are retained for 14 days.
1 - 255Path Parameters
Access request ID
Body
Deny parameters
Request body for denying an access request
Response
Access request denied
An access request
Application ID
Access request ID
Requested permission IDs
Request reason
Resource ID
Current status of the access request
pending_approval, pending_permissions_assignment, access_granted, denied, rejected, processing_access, scheduled, pending_dependency The ordered approval steps with their approvers and decisions. Empty for auto-approved requests.
Duration of time-based access as an ISO 8601 duration (e.g. "PT1H", "P7D"); null for permanent access
When the time-based access expires; null for permanent access or a time-based request that has not been granted yet
User ID of the grantee
Creation timestamp
Provisioning type
application_admin, automatic User ID of the requestor
Reason the request was ended: the denial reason when denied, the provisioner's rejection reason when rejected; null otherwise. The status field says which kind it was.

