List open questions and approvals
package main
import ( "fmt" "net/http" "io")
func main() {
url := "https://api.vampikez.fun/v1/sessions/9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731/interactions"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close() body, _ := io.ReadAll(res.Body)
fmt.Println(res) fmt.Println(string(body))
}const url = 'https://api.vampikez.fun/v1/sessions/9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731/interactions';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.vampikez.fun/v1/sessions/9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731/interactions \ --header 'Authorization: Bearer <token>'Requires wamp.cloud.sessions:read. Returns only the currently open requests, oldest first, and is not paged. ask_user and exit_plan_mode are answered by a new Turn with replyTo.interactionId; approval carries the exact proposed action in request.approval and is answered by PUT …/interactions/{interactionId}/decision, resuming the same Run. Open approvals may coexist with an awaiting question. Resolved and expired Interactions remain recoverable from the event log.
Authorizations
Section titled “Authorizations”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters”A UUID identifying one Cloud resource; Session, Turn, Publication and Merge ids are minted by the caller so an ambiguous retry addresses the same durable command instead of creating a second one.
Example
9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731A UUID you mint and own; it is the idempotency key for creation and the address of every Turn, artifact and publication underneath
Responses
Section titled “ Responses ”Open Interactions
object
An open question or live approval. Questions park their Run in awaiting and take a reply Turn; approvals keep the Run running and take a decision command.
object
Opaque runtime-assigned interaction id, unique within its Session; send it back verbatim as replyTo.interactionId
Session this request belongs to
Run that opened the request and that resumes once it is answered
Ask_user and exit_plan_mode suspend the Run; approval awaits a decision inside the running Run
open while it still needs an answer, resolved once a Turn answered it, expired when the workspace was lost, the Run was cancelled, or the Session was archived
Request payload by kind. Approval includes the exact action in request.approval.input; opened events omit it.
object
One sanitized ask_user field. Native questions use display labels only; ACP form fields additionally carry stable field ids, typed wire values, defaults and JSON-Schema-derived constraints. An empty options array is a free-text or numeric field.
object
Exact approval request retained on an open Interaction. Vendor always options are displayed for context but are never valid Cloud decisions.
object
A UUID identifying one Cloud resource; Session, Turn, Publication and Merge ids are minted by the caller so an ambiguous retry addresses the same durable command instead of creating a second one.
Absolute Unix time in milliseconds
Complete proposed action; never a truncated preview
object
object
The Turn that answered this request; present once status is resolved
object
A UUID identifying one Cloud resource; Session, Turn, Publication and Merge ids are minted by the caller so an ambiguous retry addresses the same durable command instead of creating a second one.
Absolute deadline for a live approval
Terminal reason, when present
When the agent opened the request
When the answering Turn was admitted; absent unless resolved
When the request stopped being answerable; absent unless expired
Example
{ "interactions": [ { "id": "toolu_01H8sZ4kQm2rVn9pXfB3tGdA", "sessionId": "9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731", "runId": "c47a1e08-3d6b-4a92-9f15-8b70d2e5c6a4", "kind": "ask_user", "status": "open", "request": { "questions": [ { "question": "Which limiter should the payments endpoint use?", "header": "Rate limiting strategy", "options": [ "Fixed window", "Sliding window", "Token bucket" ], "recommendedIndex": 1, "multiSelect": false, "allowCustom": true } ] }, "openedAt": "2026-08-12T09:44:38Z" }, { "id": "toolu_01K2mWpR7yLd4bQx9sTfNvHe", "sessionId": "9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731", "runId": "c47a1e08-3d6b-4a92-9f15-8b70d2e5c6a4", "kind": "exit_plan_mode", "status": "open", "openedAt": "2026-08-12T09:45:02Z" }, { "id": "toolu_01K2mWpR7yLd4bQx9sTfNvHe", "sessionId": "9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731", "runId": "c47a1e08-3d6b-4a92-9f15-8b70d2e5c6a4", "kind": "approval", "status": "open", "request": { "approval": { "requestId": "toolu_01K2mWpR7yLd4bQx9sTfNvHe", "runId": "c47a1e08-3d6b-4a92-9f15-8b70d2e5c6a4", "deadline": 1786528500000, "toolName": "Bash", "title": "Run a command", "input": { "command": "npm test" }, "options": [ { "optionId": "allow-once", "name": "Allow once", "kind": "allow_once" } ], "rememberScopes": [ "turn" ], "kind": "execute" } }, "deadline": "2026-08-12T09:55:00Z", "openedAt": "2026-08-12T09:45:00Z" } ]}No bearer was presented (bearer_credential_required), or the one presented is expired, revoked or for another audience (invalid_or_expired_credential)
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "bearer_credential_required"}Live installation, scope or organization policy denies the operation
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "insufficient_scope", "requiredScope": "wamp.cloud.sessions:create"}The resource is missing or inaccessible
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "cloud_session_not_found"}The pre-authentication edge budget or durable human-membership/App-installation budget is exhausted
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "cloud_rate_limit_exceeded", "retryAfterSeconds": 3}Headers
Section titled “Headers”IETF HTTPAPI structured quota policy
IETF HTTPAPI structured current service limit
The request was accepted and something on our side failed while answering it. Nothing about the request needs to change; the same call may succeed on retry. Retry cautiously, with backoff — a non-idempotent command may have taken effect before the fault.
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "internal_error"}A retryable condition: a workspace, runtime or provider that is not available yet, or service_unavailable while the service restarts for a release or its database cannot serve the request in time. Retry after the Retry-After this response carries.
Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.
object
Stable machine code
The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request
Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value
Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.
object
Field path, outermost segment first. An integer segment is an array index.
Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.
Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId
Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.
Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.
The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer
object
Example
{ "error": "cloud_workspace_unavailable"}