curl --request POST \
--url https://api.opal.dev/v1/campaigns/{campaign_id}/reviews \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"decisions": [
{
"campaign_item_review_id": "4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b",
"decision": "APPROVED",
"note": "Access is still required for on-call.",
"access_level_remote_id": "arn:aws:iam::123456789012:role/ReadOnly",
"new_reviewer_user_ids": [
"3c90c3cc-0d44-4b50-8888-8dd25736052a"
],
"assignment_source": "MANUAL"
}
]
}
'import requests
url = "https://api.opal.dev/v1/campaigns/{campaign_id}/reviews"
payload = { "decisions": [
{
"campaign_item_review_id": "4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b",
"decision": "APPROVED",
"note": "Access is still required for on-call.",
"access_level_remote_id": "arn:aws:iam::123456789012:role/ReadOnly",
"new_reviewer_user_ids": ["3c90c3cc-0d44-4b50-8888-8dd25736052a"],
"assignment_source": "MANUAL"
}
] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
decisions: [
{
campaign_item_review_id: '4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b',
decision: 'APPROVED',
note: 'Access is still required for on-call.',
access_level_remote_id: 'arn:aws:iam::123456789012:role/ReadOnly',
new_reviewer_user_ids: ['3c90c3cc-0d44-4b50-8888-8dd25736052a'],
assignment_source: 'MANUAL'
}
]
})
};
fetch('https://api.opal.dev/v1/campaigns/{campaign_id}/reviews', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.opal.dev/v1/campaigns/{campaign_id}/reviews",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'decisions' => [
[
'campaign_item_review_id' => '4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b',
'decision' => 'APPROVED',
'note' => 'Access is still required for on-call.',
'access_level_remote_id' => 'arn:aws:iam::123456789012:role/ReadOnly',
'new_reviewer_user_ids' => [
'3c90c3cc-0d44-4b50-8888-8dd25736052a'
],
'assignment_source' => 'MANUAL'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.opal.dev/v1/campaigns/{campaign_id}/reviews"
payload := strings.NewReader("{\n \"decisions\": [\n {\n \"campaign_item_review_id\": \"4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b\",\n \"decision\": \"APPROVED\",\n \"note\": \"Access is still required for on-call.\",\n \"access_level_remote_id\": \"arn:aws:iam::123456789012:role/ReadOnly\",\n \"new_reviewer_user_ids\": [\n \"3c90c3cc-0d44-4b50-8888-8dd25736052a\"\n ],\n \"assignment_source\": \"MANUAL\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.opal.dev/v1/campaigns/{campaign_id}/reviews")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"decisions\": [\n {\n \"campaign_item_review_id\": \"4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b\",\n \"decision\": \"APPROVED\",\n \"note\": \"Access is still required for on-call.\",\n \"access_level_remote_id\": \"arn:aws:iam::123456789012:role/ReadOnly\",\n \"new_reviewer_user_ids\": [\n \"3c90c3cc-0d44-4b50-8888-8dd25736052a\"\n ],\n \"assignment_source\": \"MANUAL\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.opal.dev/v1/campaigns/{campaign_id}/reviews")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"decisions\": [\n {\n \"campaign_item_review_id\": \"4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b\",\n \"decision\": \"APPROVED\",\n \"note\": \"Access is still required for on-call.\",\n \"access_level_remote_id\": \"arn:aws:iam::123456789012:role/ReadOnly\",\n \"new_reviewer_user_ids\": [\n \"3c90c3cc-0d44-4b50-8888-8dd25736052a\"\n ],\n \"assignment_source\": \"MANUAL\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"reviews": [
{
"campaign_item_review_id": "4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b",
"decision": "APPROVED",
"note": "<string>",
"decided_at": "2023-11-07T05:31:56Z",
"updated_access_level_remote_id": "<string>",
"reassigned_to_reviewer_ids": [
"3c90c3cc-0d44-4b50-8888-8dd25736052a"
]
}
]
}Submit campaign item review decisions
Submits one or more review decisions for campaign item reviews assigned
to the authenticated user. Mirrors the GraphQL reviewCampaignItems
mutation.
Each decision targets a campaign_item_review_id that must belong to
this campaign and be assigned to the caller. Supported decisions are
APPROVED, REVOKED, CHANGE_ROLE, and REASSIGNED.
For CHANGE_ROLE, access_level_remote_id is required. For
REASSIGNED, either supply new_reviewer_user_ids (manual) or an
assignment_source preset (PRINCIPAL_MANAGER / ASSET_ADMIN_OWNER).
Reassignment also requires the campaign configuration flag
allow_reviewer_reassignment to be enabled.
When the campaign uses revoke_on: ACTION, REVOKED decisions revoke
access immediately.
curl --request POST \
--url https://api.opal.dev/v1/campaigns/{campaign_id}/reviews \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"decisions": [
{
"campaign_item_review_id": "4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b",
"decision": "APPROVED",
"note": "Access is still required for on-call.",
"access_level_remote_id": "arn:aws:iam::123456789012:role/ReadOnly",
"new_reviewer_user_ids": [
"3c90c3cc-0d44-4b50-8888-8dd25736052a"
],
"assignment_source": "MANUAL"
}
]
}
'import requests
url = "https://api.opal.dev/v1/campaigns/{campaign_id}/reviews"
payload = { "decisions": [
{
"campaign_item_review_id": "4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b",
"decision": "APPROVED",
"note": "Access is still required for on-call.",
"access_level_remote_id": "arn:aws:iam::123456789012:role/ReadOnly",
"new_reviewer_user_ids": ["3c90c3cc-0d44-4b50-8888-8dd25736052a"],
"assignment_source": "MANUAL"
}
] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
decisions: [
{
campaign_item_review_id: '4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b',
decision: 'APPROVED',
note: 'Access is still required for on-call.',
access_level_remote_id: 'arn:aws:iam::123456789012:role/ReadOnly',
new_reviewer_user_ids: ['3c90c3cc-0d44-4b50-8888-8dd25736052a'],
assignment_source: 'MANUAL'
}
]
})
};
fetch('https://api.opal.dev/v1/campaigns/{campaign_id}/reviews', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.opal.dev/v1/campaigns/{campaign_id}/reviews",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'decisions' => [
[
'campaign_item_review_id' => '4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b',
'decision' => 'APPROVED',
'note' => 'Access is still required for on-call.',
'access_level_remote_id' => 'arn:aws:iam::123456789012:role/ReadOnly',
'new_reviewer_user_ids' => [
'3c90c3cc-0d44-4b50-8888-8dd25736052a'
],
'assignment_source' => 'MANUAL'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.opal.dev/v1/campaigns/{campaign_id}/reviews"
payload := strings.NewReader("{\n \"decisions\": [\n {\n \"campaign_item_review_id\": \"4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b\",\n \"decision\": \"APPROVED\",\n \"note\": \"Access is still required for on-call.\",\n \"access_level_remote_id\": \"arn:aws:iam::123456789012:role/ReadOnly\",\n \"new_reviewer_user_ids\": [\n \"3c90c3cc-0d44-4b50-8888-8dd25736052a\"\n ],\n \"assignment_source\": \"MANUAL\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.opal.dev/v1/campaigns/{campaign_id}/reviews")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"decisions\": [\n {\n \"campaign_item_review_id\": \"4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b\",\n \"decision\": \"APPROVED\",\n \"note\": \"Access is still required for on-call.\",\n \"access_level_remote_id\": \"arn:aws:iam::123456789012:role/ReadOnly\",\n \"new_reviewer_user_ids\": [\n \"3c90c3cc-0d44-4b50-8888-8dd25736052a\"\n ],\n \"assignment_source\": \"MANUAL\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.opal.dev/v1/campaigns/{campaign_id}/reviews")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"decisions\": [\n {\n \"campaign_item_review_id\": \"4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b\",\n \"decision\": \"APPROVED\",\n \"note\": \"Access is still required for on-call.\",\n \"access_level_remote_id\": \"arn:aws:iam::123456789012:role/ReadOnly\",\n \"new_reviewer_user_ids\": [\n \"3c90c3cc-0d44-4b50-8888-8dd25736052a\"\n ],\n \"assignment_source\": \"MANUAL\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"reviews": [
{
"campaign_item_review_id": "4b8f2c1a-9d3e-4f6a-8b1c-2e5d7a9f0c3b",
"decision": "APPROVED",
"note": "<string>",
"decided_at": "2023-11-07T05:31:56Z",
"updated_access_level_remote_id": "<string>",
"reassigned_to_reviewer_ids": [
"3c90c3cc-0d44-4b50-8888-8dd25736052a"
]
}
]
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
The ID of the campaign.
Body
Input for submitting review decisions on one or more campaign item reviews.
The decisions to record. Each targets a single campaign item review.
Show child attributes
Show child attributes
Response
The updated campaign item reviews.
Result of submitting campaign item review decisions.
Updated reviews in the same order as the request decisions.
Show child attributes
Show child attributes
Was this page helpful?