> ## Documentation Index
> Fetch the complete documentation index at: https://docs.protodesk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Confirm a proposed Evelin action

> Only this API key or OAuth grant can access this chat. Requires current owner/admin membership. Chats retain a ceiling of the permissions granted at creation; added permissions require a new chat. Private app chats and other clients are isolated. External integrations such as Linear are unavailable. Confirm only the exact proposal reviewed and requested by the user. Conversation properties and personal reminders require conversations:write. Help Center drafts require help:articles:write; publication additionally requires help:articles:publish. Scopes must remain in the current grant and session ceiling. Stale proposals return 409. Identical retries return the original receipt without repeating the action. This can publish customer-visible Help Center content but never sends a customer message.

Apply one proposed change after user review, with its current permissions and revision checked again.

See [Chat with Evelin](/mcp/evelin#chat-with-evelin) for setup, permissions, retries, and the full workflow.


## OpenAPI

````yaml POST /ai/assistant/sessions/{sessionId}/turns/{turnId}/actions/{proposalId}/confirm
openapi: 3.1.0
info:
  title: Protodesk API
  version: 0.1.0
  description: >
    The Protodesk Platform API: sync your customers in, attach your own business
    objects (orders, bookings, listings) to conversations, post and read
    messages across channels, and receive every workspace event via signed
    webhooks or a resumable SSE stream.


    Authenticate every request with a workspace-scoped API key: `Authorization:
    Bearer pk_...`. Operations that support retry protection document an
    `Idempotency-Key` header. Reuse it only with an identical request. List
    pagination is described on each endpoint.


    Task-oriented guides: [docs.protodesk.io](https://docs.protodesk.io).
servers:
  - url: https://api.protodesk.io/v1
    description: Production
  - url: http://localhost:8080/v1
    description: Local development
security: []
tags:
  - name: Evelin
    description: >-
      Human-owned AI connections using the existing Evelin runtime. Generation
      never sends a customer message.
  - name: Customers
    description: People or companies contacting a workspace across channels.
  - name: Conversations
    description: Customer conversations attached to channels and external business objects.
  - name: Messages
    description: Customer, agent, AI, system, and internal messages inside conversations.
  - name: Attachments
    description: Scoped file transfer for messages.
  - name: Channel identities
    description: >-
      The same customer across WhatsApp, email, chat, and more — linked
      identities per channel.
  - name: Statuses & priorities
    description: The workspace's conversation statuses and priority levels.
  - name: Assignments
    description: >-
      Who a conversation has been assigned to, over time. Assign via POST
      /conversations/{conversationId}/assign.
  - name: Webhooks
    description: Webhook subscriptions for receiving workspace events.
  - name: Realtime
    description: Server-sent event stream of workspace events.
  - name: API Keys
    description: Create, list, and revoke workspace API keys.
  - name: Account
    description: The workspace and scopes behind your API key.
  - name: System
    description: Service metadata and health endpoints.
paths:
  /ai/assistant/sessions/{sessionId}/turns/{turnId}/actions/{proposalId}/confirm:
    post:
      tags:
        - Evelin
      summary: Confirm a proposed Evelin action
      description: >-
        Only this API key or OAuth grant can access this chat. Requires current
        owner/admin membership. Chats retain a ceiling of the permissions
        granted at creation; added permissions require a new chat. Private app
        chats and other clients are isolated. External integrations such as
        Linear are unavailable. Confirm only the exact proposal reviewed and
        requested by the user. Conversation properties and personal reminders
        require conversations:write. Help Center drafts require
        help:articles:write; publication additionally requires
        help:articles:publish. Scopes must remain in the current grant and
        session ceiling. Stale proposals return 409. Identical retries return
        the original receipt without repeating the action. This can publish
        customer-visible Help Center content but never sends a customer message.
      operationId: confirm_evelin_action
      parameters:
        - name: sessionId
          in: path
          required: true
          schema:
            type: string
            minLength: 1
        - name: turnId
          in: path
          required: true
          schema:
            type: string
            minLength: 1
        - name: proposalId
          in: path
          required: true
          schema:
            type: string
            minLength: 1
        - name: Idempotency-Key
          in: header
          required: true
          schema:
            type: string
            minLength: 8
            maxLength: 128
      responses:
        '200':
          description: Existing result replayed without a new effect.
        '201':
          description: Successful operation.
          content:
            application/json:
              schema:
                type: object
                required:
                  - data
                properties:
                  data:
                    $ref: '#/components/schemas/EvelinActionReceipt'
        default:
          $ref: '#/components/responses/Error'
      security:
        - ApiKeyAuth: []
components:
  schemas:
    EvelinActionReceipt:
      type: object
      description: >-
        Durable receipt of the exact proposed change; check its target, before,
        after and undo status.
      required:
        - id
        - proposalId
        - runId
        - effectId
        - type
        - target
        - before
        - after
        - confirmedAt
      properties:
        id:
          type: string
        proposalId:
          type: string
        runId:
          type: string
        effectId:
          type: string
        type:
          type: string
        target:
          type: object
          additionalProperties: true
        before:
          type: object
          additionalProperties: true
        after:
          type: object
          additionalProperties: true
        confirmedAt:
          type: string
          format: date-time
        undo:
          type: object
          properties:
            status:
              type: string
              enum:
                - available
                - changed
                - unavailable
                - undone
            undoneAt:
              type: string
              format: date-time
    ErrorEnvelope:
      type: object
      required:
        - error
      properties:
        error:
          $ref: '#/components/schemas/Error'
    Error:
      type: object
      required:
        - code
        - message
        - requestId
      properties:
        code:
          type: string
          example: route.not_found
        message:
          type: string
          example: Not found
        requestId:
          type: string
          example: req_x6q5vl75f5d53m7oet2k4r5w6a
  responses:
    Error:
      description: >-
        Error response. All /v1 responses carry RateLimit-Limit,
        RateLimit-Remaining, and RateLimit-Reset headers. A 429
        (rate_limit.exceeded) additionally carries Retry-After. Request bodies
        exceeding the route-class limit (1KB reads, 64KB writes) return 413
        (request.body_too_large).
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimitLimit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimitRemaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimitReset'
        Retry-After:
          $ref: '#/components/headers/RetryAfter'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
  headers:
    RequestId:
      description: Request id for tracing this request in logs and support.
      schema:
        type: string
        example: req_x6q5vl75f5d53m7oet2k4r5w6a
    RateLimitLimit:
      description: >-
        Request budget for the route class (read or write) applied to this
        request.
      schema:
        type: integer
        example: 40
    RateLimitRemaining:
      description: Requests remaining in the current budget after this request.
      schema:
        type: integer
        example: 39
    RateLimitReset:
      description: Seconds until the budget refills to its full limit.
      schema:
        type: integer
        example: 1
    RetryAfter:
      description: Seconds to wait before retrying, sent with 429 responses.
      schema:
        type: integer
        example: 1
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: Protodesk API key
      description: >
        Use a workspace API key in the Authorization header: Bearer pk_....
        Older pk_live_ and pk_test_ keys remain valid; their prefixes do not
        isolate data or select a separate environment.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.