Use this API to manage merge request approvals and the group and project approval settings that govern them. All endpoints require authentication.

Endpoints to approve, unapprove, reset approvals, and retrieve approval state are available on all tiers, including Free. All other endpoints require Premium or Ultimate, and each one shows its tier.

The merge_request_iid and id path parameters must each be a single value. Passing multiple space-separated values (for example, 451 454 458) is not supported and returns 400 Bad Request. To act on multiple merge requests, make one request per merge request IID.

Retrieve approval state for a merge request

GET /api/v4/projects/{id}/merge_requests/{merge_request_iid}/approvals

Retrieves the approval state for a specified merge request. In the response, approved_by contains information about all approvers of the merge request, regardless of whether those approvals satisfy any approval rule.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
merge_request_iid
Path, required
IntegerThe IID of a merge request

Responses

CodeDescriptionSchema
200OKAPIEntitiesMergeRequestApprovals
400Bad Request—
404Not found—

Approve merge request

POST /api/v4/projects/{id}/merge_requests/{merge_request_iid}/approve

Approves a specified merge request. The currently authenticated user must be an eligible approver. The sha parameter ensures you are approving the current version of the merge request. If defined, the value must match the merge request’s HEAD commit SHA. A mismatch returns a 409 Conflict response.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
merge_request_iid
Path, required
IntegerThe IID of a merge request

Request body (application/json)

PropertyTypeDescription
publish_reviewBooleanWhen true submits pending review comments
shaStringWhen present, must have the HEAD SHA of the source branch

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesMergeRequestApprovals
400Bad Request—
401Unauthorized—
404Not found—

Reset approvals for a merge request

PUT /api/v4/projects/{id}/merge_requests/{merge_request_iid}/reset_approvals

Resets all approvals for a specified merge request. Available only to bot users with a valid project or group token. Human users receive a 401 Unauthorized response.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
merge_request_iid
Path, required
IntegerThe IID of a merge request

Responses

CodeDescriptionSchema
200OK—
400Bad Request—
401Unauthorized—
404Not found—

Unapprove a merge request

POST /api/v4/projects/{id}/merge_requests/{merge_request_iid}/unapprove

Unapproves a merge request. Removes the approval for the currently authenticated user from a specified merge request.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
merge_request_iid
Path, required
IntegerThe IID of a merge request

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesMergeRequestApprovals
400Bad Request—
401Unauthorized—
404Not found—

Schemas

Objects returned by the operations above and objects nested in their request bodies.

APIEntitiesApprovals

PropertyTypeDescription
approved_atString (date-time)Example: 2025-01-01T10:00:00Z
userAPIEntitiesUserBasic—

APIEntitiesCustomAttribute

PropertyTypeDescription
keyStringExample: foo
valueStringExample: bar

APIEntitiesMergeRequestApprovals

PropertyTypeDescription
approvedBoolean—
approved_byAPIEntitiesApprovals—
user_can_approveBoolean—
user_has_approvedBoolean—

APIEntitiesUserBasic

PropertyTypeDescription
avatar_pathStringExample: /user/avatar/28/The-Big-Lebowski-400-400.png
avatar_urlStringExample: https://gravatar.com/avatar/1
custom_attributesArray of APIEntitiesCustomAttribute—
idInteger (int64)Example: 1
lockedBoolean—
nameStringExample: Administrator
public_emailStringExample: john@example.com
stateStringExample: active
usernameStringExample: admin
web_urlStringExample: https://gitlab.example.com/root