Skip to content

List open questions and approvals

GET
/v1/sessions/{sessionId}/interactions
curl --request GET \
--url https://api.vampikez.fun/v1/sessions/9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731/interactions \
--header 'Authorization: Bearer <token>'

Requires wamp.cloud.sessions:read. Returns only the currently open requests, oldest first, and is not paged. ask_user and exit_plan_mode are answered by a new Turn with replyTo.interactionId; approval carries the exact proposed action in request.approval and is answered by PUT …/interactions/{interactionId}/decision, resuming the same Run. Open approvals may coexist with an awaiting question. Resolved and expired Interactions remain recoverable from the event log.

sessionId
required

A UUID identifying one Cloud resource; Session, Turn, Publication and Merge ids are minted by the caller so an ambiguous retry addresses the same durable command instead of creating a second one.

string format: uuid
Example
9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731

A UUID you mint and own; it is the idempotency key for creation and the address of every Turn, artifact and publication underneath

Open Interactions

Media typeapplication/json
object
interactions
required
Array<object>

An open question or live approval. Questions park their Run in awaiting and take a reply Turn; approvals keep the Run running and take a decision command.

object
id
required

Opaque runtime-assigned interaction id, unique within its Session; send it back verbatim as replyTo.interactionId

string
sessionId
required

Session this request belongs to

string format: uuid
runId
required

Run that opened the request and that resumes once it is answered

string format: uuid
kind
required

Ask_user and exit_plan_mode suspend the Run; approval awaits a decision inside the running Run

string
Allowed values: ask_user exit_plan_mode approval
status
required

open while it still needs an answer, resolved once a Turn answered it, expired when the workspace was lost, the Run was cancelled, or the Session was archived

string
Allowed values: open resolved expired
request

Request payload by kind. Approval includes the exact action in request.approval.input; opened events omit it.

object
questions
Array<object>
<= 4 items

One sanitized ask_user field. Native questions use display labels only; ACP form fields additionally carry stable field ids, typed wire values, defaults and JSON-Schema-derived constraints. An empty options array is a free-text or numeric field.

object
question
required
string
<= 2000 characters
options
required
Array<string>
<= 20 items
header
string
<= 80 characters
recommendedIndex
integer
multiSelect
required
boolean
allowCustom
required
boolean
fieldId
string
<= 128 characters
customFieldId
string
<= 128 characters
optionValues
Array
<= 20 items
valueType
string
Allowed values: string number integer boolean string[]
required
boolean
defaultValue
One of:
string
<= 4000 characters
format
string
Allowed values: email uri date date-time
minLength
integer
<= 4000
maxLength
integer
<= 4000
pattern
string
<= 128 characters
minimum
number
maximum
number
minItems
integer
<= 20
maxItems
integer
<= 20
prompt
string
<= 2000 characters
plan
string
<= 65536 characters
approval

Exact approval request retained on an open Interaction. Vendor always options are displayed for context but are never valid Cloud decisions.

object
requestId
required
string
>= 1 characters <= 255 characters
runId

A UUID identifying one Cloud resource; Session, Turn, Publication and Merge ids are minted by the caller so an ambiguous retry addresses the same durable command instead of creating a second one.

string format: uuid
deadline
required

Absolute Unix time in milliseconds

integer
toolName
required
string
>= 1 characters
title
string
input
required

Complete proposed action; never a truncated preview

object
key
additional properties
any
options
Array<object>
object
optionId
required
string
name
required
string
kind
required
string
Allowed values: allow_once allow_always reject_once reject_always
description
string
rememberScopes
Array<string>
Allowed values: chat project turn
kind
string
Allowed values: read edit delete move search execute think fetch switch_mode other
reason
string
destination
string
confinement
string
Allowed values: sandbox network outside
itemId
string
response

The Turn that answered this request; present once status is resolved

object
turnId

A UUID identifying one Cloud resource; Session, Turn, Publication and Merge ids are minted by the caller so an ambiguous retry addresses the same durable command instead of creating a second one.

string format: uuid
deadline

Absolute deadline for a live approval

string format: date-time
resolution

Terminal reason, when present

string
Allowed values: approved denied always_allowed project_allowed turn_allowed timed_out cancelled workspace_lost session_archived run_cancelled run_ended request_gone authority_revoked
openedAt
required

When the agent opened the request

string format: date-time
resolvedAt

When the answering Turn was admitted; absent unless resolved

string format: date-time
expiredAt

When the request stopped being answerable; absent unless expired

string format: date-time
Example
{
"interactions": [
{
"id": "toolu_01H8sZ4kQm2rVn9pXfB3tGdA",
"sessionId": "9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731",
"runId": "c47a1e08-3d6b-4a92-9f15-8b70d2e5c6a4",
"kind": "ask_user",
"status": "open",
"request": {
"questions": [
{
"question": "Which limiter should the payments endpoint use?",
"header": "Rate limiting strategy",
"options": [
"Fixed window",
"Sliding window",
"Token bucket"
],
"recommendedIndex": 1,
"multiSelect": false,
"allowCustom": true
}
]
},
"openedAt": "2026-08-12T09:44:38Z"
},
{
"id": "toolu_01K2mWpR7yLd4bQx9sTfNvHe",
"sessionId": "9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731",
"runId": "c47a1e08-3d6b-4a92-9f15-8b70d2e5c6a4",
"kind": "exit_plan_mode",
"status": "open",
"openedAt": "2026-08-12T09:45:02Z"
},
{
"id": "toolu_01K2mWpR7yLd4bQx9sTfNvHe",
"sessionId": "9f2b7c14-59d3-4f7a-b8e1-2a6c05d4e731",
"runId": "c47a1e08-3d6b-4a92-9f15-8b70d2e5c6a4",
"kind": "approval",
"status": "open",
"request": {
"approval": {
"requestId": "toolu_01K2mWpR7yLd4bQx9sTfNvHe",
"runId": "c47a1e08-3d6b-4a92-9f15-8b70d2e5c6a4",
"deadline": 1786528500000,
"toolName": "Bash",
"title": "Run a command",
"input": {
"command": "npm test"
},
"options": [
{
"optionId": "allow-once",
"name": "Allow once",
"kind": "allow_once"
}
],
"rememberScopes": [
"turn"
],
"kind": "execute"
}
},
"deadline": "2026-08-12T09:55:00Z",
"openedAt": "2026-08-12T09:45:00Z"
}
]
}

No bearer was presented (bearer_credential_required), or the one presented is expired, revoked or for another audience (invalid_or_expired_credential)

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "bearer_credential_required"
}

Live installation, scope or organization policy denies the operation

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "insufficient_scope",
"requiredScope": "wamp.cloud.sessions:create"
}

The resource is missing or inaccessible

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "cloud_session_not_found"
}

The pre-authentication edge budget or durable human-membership/App-installation budget is exhausted

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "cloud_rate_limit_exceeded",
"retryAfterSeconds": 3
}
Retry-After
integer
>= 1
RateLimit-Policy
string

IETF HTTPAPI structured quota policy

RateLimit
string

IETF HTTPAPI structured current service limit

The request was accepted and something on our side failed while answering it. Nothing about the request needs to change; the same call may succeed on retry. Retry cautiously, with backoff — a non-idempotent command may have taken effect before the fault.

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "internal_error"
}

A retryable condition: a workspace, runtime or provider that is not available yet, or service_unavailable while the service restarts for a release or its database cannot serve the request in time. Retry after the Retry-After this response carries.

Media typeapplication/json

Failure body returned with every non-2xx JSON response; branch on the machine code, never on prose or on the HTTP status alone.

object
error
required

Stable machine code

string
requiredScope

The installation capability the presented credential lacks, returned with insufficient_scope so an integrator knows exactly which capability to request

string
retryAfterSeconds

Advisory seconds to wait before retrying; returned on rate-limit denials, where the Retry-After header carries the same value

integer
>= 1
issues

Returned with invalid_request: one entry per field of the request body or query that was refused. The WAMP Account API sends the same two keys under the same field name, and no others are sent by either.

Array<object>
object
path
required

Field path, outermost segment first. An integer segment is an array index.

Array<string | integer>
message
required

Short reason the field was refused. Prose for a human to read; branch on the code and the path, never on this.

string
parameter

Returned with invalid_path_parameter: the name of the path segment that is not a valid id, such as sessionId or artifactId

string
mediaType

Returned with unsupported_media_type: the Content-Type you sent, echoed back. Omitted when the request carried a body and no Content-Type at all, which is the same refusal. Request bodies are read only under application/json and RFC 6839 application/*+json; anything else is never parsed, so no field of it was ever seen.

string
allow

Returned with method_not_allowed: the methods this path does answer, the same list as the Allow header on the response. Read the header if you want one code path for every 405 on the API.

Array<string>
outcome

The winning approval decision on 409 cloud_interaction_conflict, when an answer exists; absent for a closed or expired request without an answer

object
interactionId
required
string
>= 1 characters <= 255 characters
choice
required
string
Allowed values: allow_once allow_turn allow_chat deny
status
required
string
Allowed values: open resolved expired
resolution
required
string | null
key
additional properties
any
Example
{
"error": "cloud_workspace_unavailable"
}
Retry-After
integer