> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.monite.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.monite.com/_mcp/server.

# Create an approval policy

POST https://api.sandbox.monite.com/v1/approval_policies
Content-Type: application/json

Create a new approval policy.

Reference: https://docs.monite.com/api/approval-policies/post-approval-policies

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Servers

- `https://api.sandbox.monite.com/v1` (sandbox, default)
- `https://api.monite.com/v1` (eu_production)
- `https://us.api.monite.com/v1` (na_production)

## Request

### Headers

- `x-monite-version` (string, required)
- `x-monite-entity-id` (string, required) — The ID of the entity that owns the requested resource.

### Body (application/json)

This endpoint expects an object.

- `name` (string, required) — The name of the approval policy.
- `script` (list of ApprovalPolicyCreateScriptItem, required) — A list of JSON objects that represents the approval policy script. The script contains the logic that determines whether an action should be sent to approval. This field is required, and it should contain at least one script object.
- `description` (string, optional) — A brief description of the approval policy.
- `ends_at` (datetime, optional) — The date and time (in the ISO 8601 format) when the approval policy stops being active and stops triggering approval workflows.If `ends_at` is provided in the request, then `starts_at` must also be provided and `ends_at` must be later than `starts_at`. The value will be converted to UTC.
- `priority` (integer, optional, default: 0) — The priority controls which approval policy takes precedence when a payable matches multiple approval policies. A higher value mean higher priority.
- `starts_at` (datetime, optional) — The date and time (in the ISO 8601 format) when the approval policy becomes active. Only payables submitted for approval during the policy's active period will trigger this policy. If omitted or `null`, the policy is effective immediately. The value will be converted to UTC.
- `trigger` (ApprovalPolicyCreateTrigger, optional) — A JSON object that represents the trigger for the approval policy. The trigger specifies the event that will trigger the policy to be evaluated.

## Response

### 201

Successful Response

- `id` (string, required)
- `created_at` (datetime, required)
- `updated_at` (datetime, required)
- `created_by` (string, required)
- `name` (string, required) — The name of the approval policy.
- `script` (list of ApprovalPolicyResourceScriptItem, required) — A list of JSON objects that represents the approval policy script. The script contains the logic that determines whether an action should be sent to approval. This field is required, and it should contain at least one script object.
- `status` (enum, required) — The current status of the approval policy.
  - Allowed values: `active`, `pending`
- `description` (string, optional) — A brief description of the approval policy.
- `ends_at` (datetime, optional) — The date and time (in the ISO 8601 format) when the approval policy stops being active and stops triggering approval workflows.If `ends_at` is provided in the request, then `starts_at` must also be provided and `ends_at` must be later than `starts_at`. The value will be converted to UTC.
- `priority` (integer, optional, default: 0) — The priority controls which approval policy takes precedence when a payable matches multiple approval policies. A higher value mean higher priority.
- `starts_at` (datetime, optional) — The date and time (in the ISO 8601 format) when the approval policy becomes active. Only payables submitted for approval during the policy's active period will trigger this policy. If omitted or `null`, the policy is effective immediately. The value will be converted to UTC.
- `trigger` (ApprovalPolicyResourceTrigger, optional) — A JSON object that represents the trigger for the approval policy. The trigger specifies the event that will trigger the policy to be evaluated.
- `updated_by` (string, optional)

## Errors

### 400 Post Approval Policies Request Bad Request Error

Possible responses: `Script validation error: {errors}.`

- `error` (ErrorSchema, required)

### 401 Post Approval Policies Request Unauthorized Error

The `Authorization` header is missing or contains an invalid or expired access token. See [Authentication](https://docs.monite.com/api/concepts/authentication) to learn how to authenticate API calls.

- `error` (ErrorSchema, required)

### 409 Post Approval Policies Request Conflict Error

Conflict

- `error` (ErrorSchema, required)

### 422 Post Approval Policies Request Unprocessable Entity Error

Validation Error

- `detail` (list of ValidationError, optional)

### 429 Post Approval Policies Request Too Many Requests Error

API rate limit has been exceeded. Check the response headers for the rate limit information.

- `any`

## Types

### ApprovalPolicyCreateScriptItem

### ApprovalPolicyCreateTrigger

A JSON object that represents the trigger for the approval policy. The trigger specifies the event that will trigger the policy to be evaluated.

### ApprovalPolicyResourceScriptItem

### ApprovalPolicyResourceTrigger

A JSON object that represents the trigger for the approval policy. The trigger specifies the event that will trigger the policy to be evaluated.

### ErrorSchema

- `message` (string, required)

### ValidationError

- `loc` (list of ValidationErrorLocItem, required)
- `msg` (string, required)
- `type` (string, required)

### ValidationErrorLocItem

## Examples

**Request**

```json
{
  "name": "name",
  "script": [
    true
  ]
}
```

**Response**

```json
{
  "id": "id",
  "created_at": "2024-01-15T09:30:00Z",
  "updated_at": "2024-01-15T09:30:00Z",
  "created_by": "created_by",
  "name": "name",
  "script": [
    true
  ],
  "status": "active",
  "description": "description",
  "ends_at": "2024-01-15T09:30:00Z",
  "priority": 1,
  "starts_at": "2024-01-15T09:30:00Z",
  "trigger": true,
  "updated_by": "updated_by"
}
```

**SDK Code**

```python
import requests

url = "https://api.sandbox.monite.com/v1/approval_policies"

payload = {
    "name": "name",
    "script": [True]
}
headers = {
    "x-monite-version": "2024-05-25",
    "x-monite-entity-id": "9d2b4c8f-2087-4738-ba91-7359683c49a4",
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.sandbox.monite.com/v1/approval_policies';
const options = {
  method: 'POST',
  headers: {
    'x-monite-version': '2024-05-25',
    'x-monite-entity-id': '9d2b4c8f-2087-4738-ba91-7359683c49a4',
    Authorization: 'Bearer <token>',
    'Content-Type': 'application/json'
  },
  body: '{"name":"name","script":[true]}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.sandbox.monite.com/v1/approval_policies"

	payload := strings.NewReader("{\n  \"name\": \"name\",\n  \"script\": [\n    true\n  ]\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("x-monite-version", "2024-05-25")
	req.Header.Add("x-monite-entity-id", "9d2b4c8f-2087-4738-ba91-7359683c49a4")
	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.sandbox.monite.com/v1/approval_policies")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["x-monite-version"] = '2024-05-25'
request["x-monite-entity-id"] = '9d2b4c8f-2087-4738-ba91-7359683c49a4'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"name\": \"name\",\n  \"script\": [\n    true\n  ]\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.sandbox.monite.com/v1/approval_policies")
  .header("x-monite-version", "2024-05-25")
  .header("x-monite-entity-id", "9d2b4c8f-2087-4738-ba91-7359683c49a4")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"name\": \"name\",\n  \"script\": [\n    true\n  ]\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.sandbox.monite.com/v1/approval_policies', [
  'body' => '{
  "name": "name",
  "script": [
    true
  ]
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'x-monite-entity-id' => '9d2b4c8f-2087-4738-ba91-7359683c49a4',
    'x-monite-version' => '2024-05-25',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.sandbox.monite.com/v1/approval_policies");
var request = new RestRequest(Method.POST);
request.AddHeader("x-monite-version", "2024-05-25");
request.AddHeader("x-monite-entity-id", "9d2b4c8f-2087-4738-ba91-7359683c49a4");
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"name\": \"name\",\n  \"script\": [\n    true\n  ]\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "x-monite-version": "2024-05-25",
  "x-monite-entity-id": "9d2b4c8f-2087-4738-ba91-7359683c49a4",
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "name": "name",
  "script": [true]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.sandbox.monite.com/v1/approval_policies")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```