A valid request URL is required to generate request examples{
"stamped": true
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "receipt_not_found",
"message": "<string>"
}
}{
"error": {
"code": "payload_too_large",
"message": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Mark a receipt reviewed
Records that a person opened this receipt, and who. This is what makes a needs review queue possible: requiresManualReview says an action’s physical effect is unknown, and until now nothing said whether anybody came to look.
IT IS NOT AN APPROVAL. It says somebody read the receipt. Nothing in this service treats it as consent to the action, and the receipts it is used on are precisely the ones whose effect could not be confirmed.
The first call wins and later ones answer 200 with stamped: false, because who looked first is a fact about them and two colleagues opening the same row is ordinary rather than an error. Reading the receipt afterwards returns reviewedAt and reviewedBy.
Needs a signed in person. An API key has nobody behind it, so it cannot have looked at anything.
Hosted deployments only. A local checkout does not mount this route, so calling it there is a 404.
A valid request URL is required to generate request examples{
"stamped": true
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "receipt_not_found",
"message": "<string>"
}
}{
"error": {
"code": "payload_too_large",
"message": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Authorizations
The control surface credential. Send Authorization: Bearer <token>.
Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.
Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.
Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.
Path Parameters
The key the action was sent with, percent encoded. 1 to 128 printable ASCII characters.
Query Parameters
Which device's receipt, when the same key was used on more than one.
Response
The receipt is marked. stamped is false when somebody else got there first.
True when THIS call set the mark; false when it was already set by an earlier reader.