> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List pipeline authority requests

> The approvals inbox: every request a pipeline run raised for protected settings (services, network, caches, resources, timeouts, permissions, secrets) no administrator has approved, newest first by keyset. Filter by status, repository or application. Requires pipelines.read. Approve one through POST /api/v1/org/pipelines/definitions/{definition_id}/approve; dismiss one through its dismiss route.



## OpenAPI

````yaml https://platform.ankra.app/openapi.json get /api/v1/org/pipelines/authority-requests
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
tags:
  - name: Clusters
    description: Create, inspect and manage clusters, and the stacks deployed on them.
  - name: Managed Clusters
    description: Provider-managed control planes, driven through one common surface.
  - name: Imported Clusters
    description: Clusters that already existed and were connected to Ankra.
  - name: Cluster Access
    description: Kubeconfigs, service-account tokens and per-cluster access grants.
  - name: Kubernetes
    description: Read and act on the Kubernetes objects inside a cluster.
  - name: AWS Clusters
    description: >-
      Provision and manage self-managed k3s / kubeadm clusters on AWS EC2 in
      your own VPC.
  - name: DigitalOcean Clusters
    description: Provision and manage DigitalOcean Kubernetes clusters.
  - name: Hetzner Clusters
    description: Provision and manage Hetzner Kubernetes clusters.
  - name: OVH Clusters
    description: Provision and manage OVH Kubernetes clusters.
  - name: Scaleway Clusters
    description: Provision and manage Scaleway Kapsule clusters.
  - name: UpCloud Clusters
    description: Provision and manage UpCloud Kubernetes clusters.
  - name: Applications
    description: Deploy, configure and observe applications across the fleet.
  - name: Pipelines
    description: Pipeline definitions and the approval of the authority they declare.
  - name: Backups
    description: >-
      Backup vaults, restore points, protection posture and captures for stacks
      and application deployments; a completed capture is not a verified
      restore.
  - name: Stack Profiles
    description: Reusable stack definitions, their versions and sharing.
  - name: Services
    description: >-
      Versioned service packages and explicit sharing. Runtime admission is
      separate from publication.
  - name: Charts
    description: Browse the chart catalogue behind stacks and addons.
  - name: Helm
    description: Helm registries, credentials and the charts they expose.
  - name: Executions
    description: Long-running platform executions and their jobs.
  - name: Operations
    description: Cancel in-flight cluster operations and their jobs.
  - name: Chat
    description: Conversational sessions, plans and confirmable actions.
  - name: AI Management
    description: >-
      Customer agent lifecycle, authenticated identity and organisation
      automation controls.
  - name: AI Agent Runs
    description: Autonomous agent runs and their outcomes.
  - name: AI Tickets
    description: The AI ticket board, its sync connections and settings.
  - name: AI Playbooks
    description: Reusable playbooks the AI lanes execute.
  - name: AI Conditions
    description: Conditions that gate AI autonomy.
  - name: AI Remediation
    description: >-
      The organisation's auto-remediation policy: what the AI lanes may fix by
      themselves, and who approves the rest.
  - name: AI Engineering Handoffs
    description: Work the AI lanes escalate to a human engineer.
  - name: AI Environment
    description: The environment and base stacks AI demos deploy into.
  - name: Security
    description: Findings, advisories, SBOMs, compliance and posture.
  - name: Cost
    description: Cluster and fleet cost, rate cards and cost settings.
  - name: Decisions
    description: >-
      The decision ledger behind the Security and Cost queues: proposals a
      surface computed, the approve and set-aside decisions people took on them,
      and the receipts of running them.
  - name: Billing
    description: Subscription and spend caps.
  - name: Organisation
    description: Members, invitations, audit logs and organisation settings.
  - name: Account Tokens
    description: Personal access tokens for the API and CLI.
  - name: Credentials
    description: The shared credential store.
  - name: AWS Credentials
    description: >-
      AWS credentials: access keys or CloudFormation-onboarded STS roles for
      cost, EKS and self-managed provisioning.
  - name: Azure Credentials
    description: Azure credentials and SSH keys.
  - name: DigitalOcean Credentials
    description: DigitalOcean credentials and SSH keys.
  - name: Hetzner Credentials
    description: Hetzner credentials and SSH keys.
  - name: OVH Credentials
    description: OVH credentials and SSH keys.
  - name: Scaleway Credentials
    description: Scaleway credentials.
  - name: UpCloud Credentials
    description: UpCloud credentials and SSH keys.
  - name: Data Source Credentials
    description: Credentials for metrics and log sources.
  - name: DNS Credentials
    description: Credentials for DNS providers.
  - name: Object Storage Buckets
    description: >-
      Buckets Ankra creates and manages on an organisation's own provider
      credentials.
  - name: DNS
    description: DNS zones and records, including custom organisation zones.
  - name: Cloudflare
    description: Cloudflare domains and the credentials behind them.
  - name: Variables
    description: Organisation- and cluster-scoped variables.
  - name: SOPS
    description: Encrypt and decrypt values with the organisation SOPS config.
  - name: Alerts
    description: Alert integrations and ingest credentials.
  - name: Notifications
    description: Notification routes and their delivery targets.
  - name: Support
    description: Support tickets.
  - name: AI Settings
    description: Organisation AI provider, model catalog and per-function model settings
paths:
  /api/v1/org/pipelines/authority-requests:
    get:
      tags:
        - Pipelines
      summary: List pipeline authority requests
      description: >-
        The approvals inbox: every request a pipeline run raised for protected
        settings (services, network, caches, resources, timeouts, permissions,
        secrets) no administrator has approved, newest first by keyset. Filter
        by status, repository or application. Requires pipelines.read. Approve
        one through POST
        /api/v1/org/pipelines/definitions/{definition_id}/approve; dismiss one
        through its dismiss route.
      operationId: listPipelineAuthorityRequestsToken
      parameters:
        - name: status
          in: query
          required: false
          schema:
            type: string
            enum:
              - pending
              - approved
              - dismissed
              - superseded
        - name: repository_id
          in: query
          required: false
          schema:
            type: string
            format: uuid
        - name: application_id
          in: query
          required: false
          schema:
            type: string
            format: uuid
        - name: cursor
          in: query
          required: false
          schema:
            type: string
          description: The next_cursor of the previous page.
        - name: limit
          in: query
          required: false
          schema:
            type: integer
            minimum: 1
            maximum: 100
      responses:
        '200':
          description: One page of requests.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PipelineAuthorityRequestPage'
        '401':
          description: Authentication required
        '403':
          description: Missing pipelines.read
        '422':
          description: Malformed status, id, cursor or limit
        '500':
          description: Internal error
      security:
        - BearerAuth: []
components:
  schemas:
    PipelineAuthorityRequestPage:
      type: object
      additionalProperties: false
      required:
        - items
        - next_cursor
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/PipelineAuthorityRequest'
        next_cursor:
          type:
            - string
            - 'null'
    PipelineAuthorityRequest:
      type: object
      additionalProperties: false
      required:
        - id
        - organisation_id
        - repository_id
        - application_id
        - definition_id
        - protected_hash
        - approved_hash
        - run_id
        - head_sha
        - ref
        - pull_request_number
        - requested_by
        - status
        - resolved_by
        - resolved_at
        - resolved_via
        - reason
        - diff
        - last_refusal
        - created_at
        - updated_at
      properties:
        id:
          type: string
          format: uuid
        organisation_id:
          type: string
          format: uuid
        repository_id:
          type: string
          format: uuid
        application_id:
          type:
            - string
            - 'null'
          format: uuid
        definition_id:
          type: string
          format: uuid
          description: >-
            The definition to approve: POST
            /api/v1/org/pipelines/definitions/{definition_id}/approve resolves
            this request.
        protected_hash:
          type: string
          description: Identity of the protected settings an approval grants.
        approved_hash:
          type:
            - string
            - 'null'
          description: >-
            Identity of the settings the raising run executed under instead;
            null when nothing was ever approved.
        run_id:
          type: string
          format: uuid
          description: The newest pipeline run that raised or joined this request.
        head_sha:
          type: string
        ref:
          type: string
        pull_request_number:
          type:
            - integer
            - 'null'
        requested_by:
          type: string
          description: >-
            The principal behind the run, as `<lane>:<identity>`
            (github:<login>, user:<id>).
        status:
          type: string
          enum:
            - pending
            - approved
            - dismissed
            - superseded
        resolved_by:
          type:
            - string
            - 'null'
          description: Ankra user id of the person who approved or dismissed it.
        resolved_at:
          type:
            - string
            - 'null'
          format: date-time
        resolved_via:
          type:
            - string
            - 'null'
          enum:
            - portal
            - github_check
            - cli
            - api
            - null
        reason:
          type:
            - string
            - 'null'
          description: The dismissal's reason; null unless dismissed.
        diff:
          type: object
          additionalProperties: false
          required:
            - sections
            - yaml
          properties:
            sections:
              type: array
              items:
                type: object
                additionalProperties: false
                required:
                  - section
                  - path
                  - from
                  - to
                properties:
                  section:
                    type: string
                  path:
                    type: string
                  from:
                    type:
                      - string
                      - 'null'
                    description: >-
                      What the approved authority declares at the path; null
                      when nothing.
                  to:
                    type:
                      - string
                      - 'null'
                    description: >-
                      What the requesting definition declares; null when it
                      dropped the value. Credential-bearing literals read
                      `<withheld>`.
            yaml:
              type: string
              description: >-
                The requesting definition's protected settings in the canonical
                form an approval digests, with credential-bearing literals
                withheld.
        last_refusal:
          description: >-
            The last approval press from a source-control host that was refused;
            null when none was.
          anyOf:
            - type: 'null'
            - type: object
              additionalProperties: false
              required:
                - sender
                - reason
                - message
                - at
              properties:
                sender:
                  type: string
                reason:
                  type: string
                  enum:
                    - bot
                    - unmapped
                    - unverified
                    - service_principal
                    - not_admin
                message:
                  type: string
                at:
                  type: string
                  format: date-time
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
  securitySchemes:
    BearerAuth:
      bearerFormat: PAT
      scheme: bearer
      type: http

````