/api/public/v1/time-off-requests/{requestId}/reviewApprove or deny time off
Records a decision, including changing one already made — plans shift, and a reviewer who approved last week has to be able to walk it back without the employee re-submitting. Anyone above the requester in the reporting chain, or `hr:admin`, may decide — never the requester themselves whatever scopes they hold. A decision taken by anyone other than the direct manager is reported to that manager, since the request was theirs to answer. A cancelled request is terminal. Re-deciding to the status it already has is a no-op, so a retry never notifies twice.
Required scope
The access token must carry this scope. A token missing it gets 403 Forbidden. Grant them to an API client under Settings → Company → API, and to a teammate under Employee → Permissions.
Path Parameters
| Name | Type | Required | Description |
|---|---|---|---|
requestId | string | Required | Request ID. |
Request Body
| Property | Type | Description |
|---|---|---|
decision | string | The call. |
note | string | Included in the notification when the decision is DENIED. |
curl -X POST "https://www.pxb.app/api/public/v1/time-off-requests/{requestId}/review" \
-H "Authorization: Bearer your_access_token" \
-H "Content-Type: application/json" \
-d '{
"decision": "APPROVED"
}'{
"message": "Request approved.",
"content": {
"changed": true
}
}{
"message": "You cannot review your own request."
}{
"message": "This request was cancelled by the employee."
}In the console
The same thing done by hand, for anyone comparing the API against the screen they already use.