Skip to content

Emits user.tool_confirmation, bound to the approval state machine and AUDITED with a redacted fingerprint.

POST
/v1/m/claude-agents/sessions/{id}/tool-confirmation
curl --request POST \
--url https://example.com/v1/m/claude-agents/sessions/example/tool-confirmation \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "deny_message": "example", "result": "example", "tool_use_id": "example" }'

Emits user.tool_confirmation, bound to the approval state machine and AUDITED with a redacted fingerprint.

id
required
string

Path parameter id.

X-Olivares-Tenant
string format: uuid

Target tenant id; required when the principal can act in more than one tenant.

Media type application/json
object
deny_message
Any of:
string
result
required

After Unicode whitespace trimming and lowercasing, the handler requires allow or deny.

string
tool_use_id
required

After Unicode whitespace trimming, the handler requires a non-empty tool-use identifier.

string
Example generated
{
"deny_message": "example",
"result": "example",
"tool_use_id": "example"
}

OK

Media type application/json
object
Example generated
{}

Bad request

Media type application/json
object
Example generated
{}

Unauthenticated

Media type application/json
object
Example generated
{}

Forbidden

Media type application/json
object
Example generated
{}

Not found

Media type application/json
object
Example generated
{}

Conflict / setup required

Media type application/json
object
Example generated
{}

Rate limited

Media type application/json
object
Example generated
{}