POST
/api/public/v1/time-off-requests/{requestId}/review

Approve or deny time off

Records a decision, including changing one already made — plans shift, and a reviewer who approved last week has to be able to walk it back without the employee re-submitting. Anyone above the requester in the reporting chain, or `hr:admin`, may decide — never the requester themselves whatever scopes they hold. A decision taken by anyone other than the direct manager is reported to that manager, since the request was theirs to answer. A cancelled request is terminal. Re-deciding to the status it already has is a no-op, so a retry never notifies twice.

Required scope

The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.

hr:write

Path Parameters

NameTypeRequiredDescription
requestIdstringRequiredRequest ID.

Request Body

PropertyTypeDescription
decisionstringThe call.
notestringIncluded in the notification when the decision is DENIED.
POSTExample request
curl
curl -X POST "https://www.pxb.app/api/public/v1/time-off-requests/{requestId}/review" \
  -H "Authorization: Bearer your_access_token" \
  -H "Content-Type: application/json" \
  -d '{
    "decision": "APPROVED"
  }'
200Example response
json
{
  "message": "Request approved.",
  "content": {
    "changed": true
  }
}
403Example response
json
{
  "message": "You cannot review your own request."
}
409Example response
json
{
  "message": "This request was cancelled by the employee."
}

In the console

The same thing done by hand, for anyone comparing the API against the screen they already use.

Employees → Time off
/employee/timeoff
  1. Open Time off.
  2. Approve or Deny on a request awaiting you.