Confirm Card-Gated Action (Stream)
curl --request POST \
--url https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"request_id": "<string>",
"approve": true
}
'import requests
url = "https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm"
payload = {
"request_id": "<string>",
"approve": True
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({request_id: '<string>', approve: true})
};
fetch('https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'request_id' => '<string>',
'approve' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm"
payload := strings.NewReader("{\n \"request_id\": \"<string>\",\n \"approve\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"request_id\": \"<string>\",\n \"approve\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"request_id\": \"<string>\",\n \"approve\": true\n}"
response = http.request(request)
puts response.read_bodyREST API - Conversations
Confirm Card-Gated Action
Approve or decline a confirmation card and continue the turn (SSE).
POST
/
v1
/
agents
/
{agent_id}
/
conversations
/
{conversation_id}
/
confirm
Confirm Card-Gated Action (Stream)
curl --request POST \
--url https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm \
--header 'Content-Type: application/json' \
--header 'x-api-key: <api-key>' \
--data '
{
"request_id": "<string>",
"approve": true
}
'import requests
url = "https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm"
payload = {
"request_id": "<string>",
"approve": True
}
headers = {
"x-api-key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'x-api-key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({request_id: '<string>', approve: true})
};
fetch('https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'request_id' => '<string>',
'approve' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm"
payload := strings.NewReader("{\n \"request_id\": \"<string>\",\n \"approve\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("x-api-key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm")
.header("x-api-key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"request_id\": \"<string>\",\n \"approve\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.xpander.ai/v1/agents/{agent_id}/conversations/{conversation_id}/confirm")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["x-api-key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"request_id\": \"<string>\",\n \"approve\": true\n}"
response = http.request(request)
puts response.read_bodyWhen a turn raises a confirmation card for a destructive action (deleting an agent, for example), approve or decline it here. The target of the action is read from the card itself, never from the body, and the action’s own permission check runs again against the confirming user.
approve: false dismisses the card and changes nothing. Streams the continued turn’s events over SSE.
See the Conversations overview for the full conversation model.Was this page helpful?

