List reviews
GET/v1/reviews
List approval reviews of a bank. Requires the connector:reviews:list scope. Bank
callers see the reviews of their own bank; platform operators call the same endpoint
with the operator scope and must pass filter[bank_id].
The four-eyes model
A review is a human approval gate on one operation. The platform opens it
automatically when policy requires sign-off for an operation (for example a high-value
transfer). While the review is open the operation waits in state PENDING_REVIEW, and
webhook subscribers receive operation.manual_review and review.created.
- Who can decide. A reviewer submits
APPROVEorREJECTwithPOST /v1/reviews/{review_id}/decisions. A review withrequired_role: CHECKERneeds theconnector:reviews:decidescope; a review withrequired_role: APPROVERaccepts that scope or the operator scopeconnector:operator:reviews:decide. - Maker and checker are different people. The principal that submitted the
operation under review cannot decide on its review (
403). - Distinct approvals. Each principal counts once. The review is
APPROVEDwhenrecorded_distinct_approvalsreachesrequired_distinct_approvals. A singleREJECTends the review asREJECTED. - Effect on the operation. When approved, the operation continues processing. When
rejected, a
PRE_EXECUTION_GATEreview rejects the operation (stateREJECTED). A review withrequired_role: CHECKERgates the commit of an already initiated ledger transfer (mode: POST_LEDGER_INITIATION_COMMIT_GATE); on either decision the operation moves toPENDING_COMMITSand the platform completes or unwinds the ledger step. - A review still open when its operation is cancelled becomes
CANCELLED.
Review states: PENDING (open), then APPROVED, REJECTED or CANCELLED. EXPIRED
is reserved and not currently set.
Filters, ordering and pagination
filter[operation_id] returns the reviews of one operation. Results are ordered oldest
first (by creation time). Use page[size] (1 to 200, default 20) and follow
links.next until it is absent.
Request
Responses
- 200
- 400
- 401
- 403
- 429
- 503
One page of reviews, oldest first.
The request is malformed: invalid JSON syntax, an invalid path or query parameter, a
missing required header such as Idempotency-Key, or a single field that fails its own
format rule. Fix the request before retrying; retrying it unchanged fails again.
The bearer token is missing, malformed, expired, signed by an unknown key, or was not issued by the platform IAM for the Lyriq Connector. Obtain a new token and retry. See the Authentication section.
The token is valid but may not perform this request: it lacks the required scope, has
no bank membership, needs an x-dan-bank-id header to choose between several
memberships, names a bank in x-dan-bank-id it has no membership for, or the caller's
bank is suspended or terminated. A new token with the same configuration fails the same
way. See the Authentication section.
The request was refused because a rate limit was reached (code RATE_LIMITED). No
Retry-After header is sent; retry with exponential backoff.
The request could not be served right now. Either the network is not fully operational
(OUTBOUND_HALTED or READ_ONLY: mutations are refused while read endpoints keep
working; OPERATIONAL_STATE_UNKNOWN: the state could not be determined), or a platform
dependency is temporarily unavailable. No Retry-After header is sent; retry later with
backoff. When retrying a mutation, reuse the same Idempotency-Key and body.