8 operations. Call each with POST https://app.chirply.io/api/v1/actions/<name> and a bearer token; the response is { "data": { "action", "summary", "result" } }. A read badge means the operation changes nothing; write requires the credential’s write scope.
Approve or decline an access request
agency_access.decide_requestwriteconfirm
Approve an agency's request to enter this account for a set number of hours (typically 4, 24, 72, 168), or decline it. An approval expires on its own — nothing has to be run to end it. Only an owner or admin OF THIS ACCOUNT can decide; an agency cannot approve its own request.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Parameters
Field
Type
Required
Description
id
string (uuid)
required
The request to decide.
decision
"approve" | "deny"
required
approve grants access for the window below; deny refuses it.
hours
integer
optional
How many hours the access lasts. Required when approving; ignored when declining.
Over MCP the same operation is the tool agency_access_decide_request at https://app.chirply.io/api/mcp, same bearer token, same input.
Read account access settings
agency_access.get_settingsread
Read how this workspace handles outside access: whether its managing agency can enter whenever they need to or must request a window first, and — for an agency — how its own people appear on its clients' team pages.
Over MCP the same operation is the tool agency_access_list_requests at https://app.chirply.io/api/mcp, same bearer token, same input.
Read the account access log
agency_access.logread
Read this account's access log — every request, approval, entry, expiry and view-as session by anyone outside the account, newest first, with the stated reason attached. The log is append-only: entries can be added but never edited or deleted, including by Chirply.
Over MCP the same operation is the tool agency_access_log at https://app.chirply.io/api/mcp, same bearer token, same input.
Request access to a client account
agency_access.requestwrite
Ask one of this agency's client accounts for permission to enter it, stating why. The client sees the reason, approves it for a window they choose, and the reason is attached to every entry in their access log. Only needed for clients who have turned approval on; for everyone else the agency can enter directly.
Parameters
Field
Type
Required
Description
org_id
string (uuid)
required
The client account to ask. Must be a sub-account of this agency.
reason
string
required
Why access is needed. The client reads this when deciding, and it stays on their access log.
ticket_ref
string
optional
Your own support ticket reference, shown alongside the reason.
Over MCP the same operation is the tool agency_access_request at https://app.chirply.io/api/mcp, same bearer token, same input.
End an access window early
agency_access.revoke_requestwriteconfirm
End an approved access window before it expires. Either side can do this — the account taking the access back, or the agency giving it up. The log records who ended it.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Over MCP the same operation is the tool agency_access_revoke_request at https://app.chirply.io/api/mcp, same bearer token, same input.
Choose how the agency gets in
agency_access.set_policywriteconfirmadmin only
Set whether this account's managing agency has standing access, or must request access and be approved for a window first. Changing to 'approval_required' takes effect immediately: the agency cannot enter again until this account approves a request, which can delay support. Either way, every visit is recorded in the access log.
Marked confirm: this operation is irreversible, reaches real people, or spends money. Holding a credential is itself the confirmation for API and MCP callers — call it only when you mean it. The in-app assistant refuses to run it without a human approving first.
Parameters
Field
Type
Required
Description
mode
"standing" | "approval_required"
required
standing = the agency can enter whenever they need to. approval_required = they must ask, state a reason, and be granted a window that expires on its own.
Over MCP the same operation is the tool agency_access_set_policy at https://app.chirply.io/api/mcp, same bearer token, same input.
Choose how you appear to your clients
agency_access.set_presencewriteadmin only
Set how this agency's own people appear in its clients' team lists: under the agency's business name, as individual names and email addresses, or not shown at all. This changes DISPLAY ONLY — nobody's access changes, and every visit is still written to each client's access log whichever option is chosen.
Parameters
Field
Type
Required
Description
mode
"branded" | "visible" | "hidden"
required
branded = Clients see one row under your business name instead of a personal email address. Honest about the access, without putting a stranger's inbox on their team page. visible = Clients see your people exactly as they are, with their names and email addresses. hidden = Your people do not appear in the client's team list at all. Their access is unchanged and every entry is still recorded in the account's access log.
label
string
optional
The name clients see under 'branded'. Defaults to the agency's workspace name.