extractions:write and document organization/project access. Use existing authentication headers and X-Project-ID when using an active project. Check capabilities first. Only documents with persisted review_decision_managed=true use this endpoint. Unmanaged documents use the existing PUT approval/edit endpoint, even if their project now opts in. Only managed pending can transition to approved, rejected, or expired. Terminal decisions cannot be changed or reopened.
Reject
wrong_document, duplicate_document, out_of_scope, other. Omit reviewed_results, including explicit null. Rejection retains the document, results, technical status, and credit history. Your integration reads the decision and cancels its own downstream work.
Approve
Approval requires technicalstatus=completed. It remains available for already-managed pending documents when enrollment/rejection/expiry are disabled.
Caller-triggered expiry
An authorized API-key caller can expire a document that has been pending for strictly more than ten days, measured by server UTC time fromreview_requested_at. Interactive users cannot expire documents. No scheduler or webhook is provided. A local polling timeout does not expire a document.
reviewed_results. Historical unmanaged pending records are not enrolled or eligible for this expiry API. Managed pending age uses its recorded UTC review request time.
Response and retries
Success returns the current state and decision evidence. An identical retry with the same caller and idempotency key returns the original decision without another event. Generate a new UUID for a new decision. Do not change the payload or caller when retrying an uncertain request. Access checks still apply to retries.
Multiple extraction rows for one legacy document identity can return
409; resolve the identity before deciding. Concurrent decisions have one winner.