← All action domains

Agency access

8 operations. Call each with POST https://app.chirply.io/api/v1/actions/<name> and a bearer token; the response is { "data": { "action", "summary", "result" } }. A read badge means the operation changes nothing; write requires the credential’s write scope.

Approve or decline an access request

agency_access.decide_requestwriteconfirm

Approve an agency's request to enter this account for a set number of hours (typically 4, 24, 72, 168), or decline it. An approval expires on its own — nothing has to be run to end it. Only an owner or admin OF THIS ACCOUNT can decide; an agency cannot approve its own request.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
idstring (uuid)requiredThe request to decide.
decision"approve" | "deny"requiredapprove grants access for the window below; deny refuses it.
hoursintegeroptionalHow many hours the access lasts. Required when approving; ignored when declining.

Example

curl -X POST https://app.chirply.io/api/v1/actions/agency_access.decide_request \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11",
    "decision": "approve"
  }'
Test with your API key

Over MCP the same operation is the tool agency_access_decide_request at https://app.chirply.io/api/mcp, same bearer token, same input.

Read account access settings

agency_access.get_settingsread

Read how this workspace handles outside access: whether its managing agency can enter whenever they need to or must request a window first, and — for an agency — how its own people appear on its clients' team pages.

Parameters

No parameters — POST an empty body.

Example

curl -X POST https://app.chirply.io/api/v1/actions/agency_access.get_settings \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{}'
Test with your API key

Over MCP the same operation is the tool agency_access_get_settings at https://app.chirply.io/api/mcp, same bearer token, same input.

List access requests

agency_access.list_requestsread

List access requests raised against this account — who asked, why, whether it was approved, and when the window ends.

Parameters

FieldTypeRequiredDescription
limitintegeroptionalMax rows to return (1–100). Default: 25
offsetintegeroptionalRows to skip. Default: 0
status"pending" | "approved" | "denied" | "revoked" | "expired"optionalOnly requests in this state.

Example

curl -X POST https://app.chirply.io/api/v1/actions/agency_access.list_requests \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "limit": 25,
    "offset": 0
  }'
Test with your API key

Over MCP the same operation is the tool agency_access_list_requests at https://app.chirply.io/api/mcp, same bearer token, same input.

Read the account access log

agency_access.logread

Read this account's access log — every request, approval, entry, expiry and view-as session by anyone outside the account, newest first, with the stated reason attached. The log is append-only: entries can be added but never edited or deleted, including by Chirply.

Parameters

FieldTypeRequiredDescription
limitintegeroptionalMax rows to return (1–100). Default: 25
offsetintegeroptionalRows to skip. Default: 0
event"request" | "approve" | "deny" | "revoke" | "expire" | "enter" | … 3 moreoptionalOnly entries of this kind.

Example

curl -X POST https://app.chirply.io/api/v1/actions/agency_access.log \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "limit": 25,
    "offset": 0
  }'
Test with your API key

Over MCP the same operation is the tool agency_access_log at https://app.chirply.io/api/mcp, same bearer token, same input.

Request access to a client account

agency_access.requestwrite

Ask one of this agency's client accounts for permission to enter it, stating why. The client sees the reason, approves it for a window they choose, and the reason is attached to every entry in their access log. Only needed for clients who have turned approval on; for everyone else the agency can enter directly.

Parameters

FieldTypeRequiredDescription
org_idstring (uuid)requiredThe client account to ask. Must be a sub-account of this agency.
reasonstringrequiredWhy access is needed. The client reads this when deciding, and it stays on their access log.
ticket_refstringoptionalYour own support ticket reference, shown alongside the reason.

Example

curl -X POST https://app.chirply.io/api/v1/actions/agency_access.request \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "org_id": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11",
    "reason": "example"
  }'
Test with your API key

Over MCP the same operation is the tool agency_access_request at https://app.chirply.io/api/mcp, same bearer token, same input.

End an access window early

agency_access.revoke_requestwriteconfirm

End an approved access window before it expires. Either side can do this — the account taking the access back, or the agency giving it up. The log records who ended it.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
idstring (uuid)requiredThe approved request to end.

Example

curl -X POST https://app.chirply.io/api/v1/actions/agency_access.revoke_request \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "2f6a1c1e-6c3b-4c62-9f6e-8a2d4b7c9e11"
  }'
Test with your API key

Over MCP the same operation is the tool agency_access_revoke_request at https://app.chirply.io/api/mcp, same bearer token, same input.

Choose how the agency gets in

agency_access.set_policywriteconfirmadmin only

Set whether this account's managing agency has standing access, or must request access and be approved for a window first. Changing to 'approval_required' takes effect immediately: the agency cannot enter again until this account approves a request, which can delay support. Either way, every visit is recorded in the access log.

Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.

Parameters

FieldTypeRequiredDescription
mode"standing" | "approval_required"requiredstanding = the agency can enter whenever they need to. approval_required = they must ask, state a reason, and be granted a window that expires on its own.

Example

curl -X POST https://app.chirply.io/api/v1/actions/agency_access.set_policy \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "mode": "standing"
  }'
Test with your API key

Over MCP the same operation is the tool agency_access_set_policy at https://app.chirply.io/api/mcp, same bearer token, same input.

Choose how you appear to your clients

agency_access.set_presencewriteadmin only

Set how this agency's own people appear in its clients' team lists: under the agency's business name, as individual names and email addresses, or not shown at all. This changes DISPLAY ONLY — nobody's access changes, and every visit is still written to each client's access log whichever option is chosen.

Parameters

FieldTypeRequiredDescription
mode"branded" | "visible" | "hidden"requiredbranded = Clients see one row under your business name instead of a personal email address. Honest about the access, without putting a stranger's inbox on their team page. visible = Clients see your people exactly as they are, with their names and email addresses. hidden = Your people do not appear in the client's team list at all. Their access is unchanged and every entry is still recorded in the account's access log.
labelstringoptionalThe name clients see under 'branded'. Defaults to the agency's workspace name.

Example

curl -X POST https://app.chirply.io/api/v1/actions/agency_access.set_presence \
  -H "Authorization: Bearer chp_live_…" \
  -H "Content-Type: application/json" \
  -d '{
    "mode": "branded"
  }'
Test with your API key

Over MCP the same operation is the tool agency_access_set_presence at https://app.chirply.io/api/mcp, same bearer token, same input.

The machine-readable version of this page is GET https://app.chirply.io/api/v1/actions?domain=agency_access — same operations, with full JSON Schemas. Authentication, errors and rate limits are covered in the API documentation home.