Skip to main content
POST
Grant an access request

Closing tasks provisioned outside AccessOwl

This endpoint is the API equivalent of Mark as granted. For an application with no provisioning integration it only closes the record in AccessOwl and never touches the application itself, which is exactly the case where access was granted elsewhere. For an application with a provisioning integration, AccessOwl starts provisioning as soon as the request is fully approved, so there is no manual task to close and this endpoint is not what triggers the integration. If you provision an integrated app yourself, ask AccessOwl support to turn provisioning off on that integration so its tasks become manual admin tasks again.
To be notified when a manual provisioning task is created for an admin, subscribe to the request.approved webhook event. For apps without a provisioning integration, that event fires at the moment the task is created and the admin is notified. request.created fires earlier, when the request is submitted and not yet approved.

Authorizations

Authorization
string
header
required

Bearer token authentication. Pass your AccessOwl API token in the Authorization header as Bearer <token>.

Headers

Idempotency-Key
string

Optional key (1–255 chars) for safely retrying a request. Reusing the same key for the same request returns 409 Conflict and is not processed again — this confirms the request was already received. Keys are retained for 14 days.

Required string length: 1 - 255

Path Parameters

access_request_id
string<uuid>
required

Access request ID

Response

Access request granted

An access request

application_id
string<uuid>
required

Application ID

id
string<uuid>
required

Access request ID

permission_ids
string<uuid>[]
required

Requested permission IDs

request_reason
string
required

Request reason

resource_id
string<uuid>
required

Resource ID

status
enum<string>
required

Current status of the access request

Available options:
pending_approval,
pending_permissions_assignment,
access_granted,
denied,
rejected,
processing_access,
scheduled,
pending_dependency
duration
string | null

Duration of time-based access as an ISO 8601 duration (e.g. "PT1H", "P7D"); null for permanent access

expires_at
string<date-time> | null

When the time-based access expires; null for permanent access or a time-based request that has not been granted yet

grantee_user_id
string<uuid>

User ID of the grantee

inserted_at
string<date-time>

Creation timestamp

provisioning_type
enum<string> | null

Provisioning type

Available options:
application_admin,
automatic
requestor_user_id
string<uuid>

User ID of the requestor

Last modified on August 28, 2026