# Retrieve an approval

Source: https://immiscible.fly.dev/docs/api/get-api-w-wid-approvals-apid

`GET /api/w/:wid/approvals/:apid`

The full request in plain English: the agent, the mandate, what it wants to do, every signal explained, and what influenced it. It also says where the approval sits in the evidence ledger: `requestEvidenceSeq` (the action's `agent_decision` record), `decisionEvidenceSeq` (the `agent_approval` record of the decision, or `null` while it waits), `evidenceSeq` (the later of the two) and `traceId` (the action's W3C trace, which the decision record joins).

Beside it is what a person reviews. `evidence.sources` lists what influenced the request, each marked `by: "agent"` (what the agent declared) or `by: "gateway"` (what the gateway saw it read). For a payment, `evidence.payee` gives how many times the payee was paid before, the total and the last three payments. `verdict` is one line from the rules, never a model: `kind` is `deny` (a rule refuses it), `hold` (a warning sign a person should check) or `inside` (no warning sign; a person is asked because of the amount or the payee), with up to three `reasons`. `verdictFeedback` is the caller's own thumbs up or down, if any.

## Authentication

Session cookie. A signed-in person: the console's session cookie. Every state-changing request also carries the header `x-immiscible-csrf: 1`, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.

## Path parameters

- `wid` (string, required): Workspace id
- `apid` (string, required): Approval id

## Request

curl:

```bash
curl "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/approvals/apr_3k9d02aa" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION"
```

Node:

```ts
const res = await fetch('https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/approvals/apr_3k9d02aa', {
  headers: {
    cookie: `__Host-sid=${process.env.IMMISCIBLE_SESSION}`,
  },
});
const data = await res.json();
console.log(res.status, data);
```

Python:

```python
import os
import requests

res = requests.get(
    "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/approvals/apr_3k9d02aa",
    headers={
        "cookie": f"__Host-sid={os.environ['IMMISCIBLE_SESSION']}",
    },
)
print(res.status_code, res.json())
```
