Submit a review decision
POST/v1/reviews/:review_id/decisions
Approve or reject an open (PENDING) review. Requires the connector:reviews:decide
scope (platform operators use connector:operator:reviews:decide, which is accepted
only for reviews with required_role: APPROVER) and an Idempotency-Key header.
Checks made before the decision is accepted:
- the review exists (
404) and belongs to the caller's bank (403 BANK_SCOPE_MISMATCH); - the review is still
PENDING(409otherwise); - the caller holds the scope that the review's
required_rolerequires; - the caller is not the principal that submitted the operation under review
(
403, "review can't be self-approved"). This enforces the maker/checker rule.
What the decision does. The response is 202 Accepted with an operation that
records the decision.
APPROVEadds one distinct approval. Whenrecorded_distinct_approvalsreachesrequired_distinct_approvals, the review becomesAPPROVEDand the operation under review continues (PROCESSING, orPENDING_COMMITSfor aCHECKERreview). Otherwise the review staysPENDINGand subscribers receivereview.updated.REJECTimmediately ends the review asREJECTED. The operation under review becomesREJECTED, or for aCHECKERreview moves toPENDING_COMMITSso the platform can unwind the initiated ledger step.
Each principal decides once per review: a second, different decision by the same
principal is not counted and its tracking operation does not succeed. Retrying the same
request with the same Idempotency-Key returns the original 202 document.
comment, when sent, must not be empty or only whitespace.
Request
Responses
- 202
- 400
- 401
- 403
- 404
- 409
- 422
- 429
- 503
Accepted. The operation (data.id) tracks the decision.
The request is malformed: invalid JSON syntax, an invalid path or query parameter, a
missing required header such as Idempotency-Key, or a single field that fails its own
format rule. Fix the request before retrying; retrying it unchanged fails again.
The bearer token is missing, malformed, expired, signed by an unknown key, or was not issued by the platform IAM for the Lyriq Connector. Obtain a new token and retry. See the Authentication section.
The caller lacks the decide scope, the review belongs to another bank
(BANK_SCOPE_MISMATCH), or the caller submitted the operation under review.
The resource does not exist, or it belongs to another bank. The Lyriq Connector does not distinguish the two cases, so resources of other banks are never disclosed.
The review is no longer PENDING, or the Idempotency-Key was reused with a
different body or is still being processed.
The request is well-formed JSON but cannot be processed: the body does not match the
expected shape (a missing or unknown member, a wrong type, or a wrong data.type), or it
breaks a business or cross-field rule. Correct the request before retrying.
The request was refused because a rate limit was reached (code RATE_LIMITED). No
Retry-After header is sent; retry with exponential backoff.
The request could not be served right now. Either the network is not fully operational
(OUTBOUND_HALTED or READ_ONLY: mutations are refused while read endpoints keep
working; OPERATIONAL_STATE_UNKNOWN: the state could not be determined), or a platform
dependency is temporarily unavailable. No Retry-After header is sent; retry later with
backoff. When retrying a mutation, reuse the same Idempotency-Key and body.