> This page is for Taurus PROTECT, version v3.50.
> For other versions, use one of these documentation indexes:
> - v3.58 (default): https://taurushq.ferndocs.com/protect-capital/v3.58/llms.txt
> - v3.56: https://taurushq.ferndocs.com/protect-capital/v3.56/llms.txt
> - v3.54: https://taurushq.ferndocs.com/protect-capital/v3.54/llms.txt
> - v3.52: https://taurushq.ferndocs.com/protect-capital/v3.52/llms.txt
> - v3.50: https://taurushq.ferndocs.com/protect-capital/v3.50/llms.txt
> - v3.48: https://taurushq.ferndocs.com/protect-capital/v3.48/llms.txt
> - v3.46: https://taurushq.ferndocs.com/protect-capital/v3.46/llms.txt
> - v3.44: https://taurushq.ferndocs.com/protect-capital/v3.44/llms.txt
> - v3.42: https://taurushq.ferndocs.com/protect-capital/v3.42/llms.txt
> - v3.40: https://taurushq.ferndocs.com/protect-capital/v3.40/llms.txt
> - v3.38: https://taurushq.ferndocs.com/protect-capital/v3.38/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://taurushq.ferndocs.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://taurushq.ferndocs.com/_mcp/server.

# List request bundles for approval

GET https://your-protect-instance.example.com/api/rest/v1/requests/bundles/for-approval

This endpoint returns a list of request bundles for approval.
 Required role: **RequestApprover**.

Reference: https://taurushq.ferndocs.com/protect-capital/reference/requests/get-bundles-for-approval

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Request

### Query parameters

- `blockchains` (list of string, optional) — Filter on IDs or symbols of the blockchain
- `ids` (list of string, optional)
- `cursor.currentPage` (string, optional) — Base64-encoded string representing the current window of data
- `cursor.pageRequest` (string, optional) — The page to request, w.r.t the current page. Can be one of `FIRST`, `PREVIOUS`, `NEXT`, `LAST`
- `cursor.pageSize` (string, optional) — The size of the page requested. The handling service should impose a hard limit on this

## Response

### 200

A successful response.

- `results` (list of tgvalidatordRequestBundle, optional)
- `cursor` (tgvalidatordResponseCursor, optional)

## Errors

### 400 Bad Request Error

Bad Request: indicates that the server cannot or will not process the request due to something that is perceived to be a client error (for example, malformed request syntax, invalid request message framing, or deceptive request routing)

- `any`

### 401 Unauthorized Error

Unauthorized: indicates that the client request has not been completed because it lacks valid authentication credentials for the requested resource

- `any`

### 403 Forbidden Error

Forbidden: indicates that the server understands the request but refuses to authorize it

- `any`

### 404 Not Found Error

Not Found: indicates that the server cannot find the requested resource

- `any`

### 500 Internal Server Error

Internal Server Error: indicates that the server encountered an unexpected condition that prevented it from fulfilling the request

- `any`

### 503 Service Unavailable Error

Service Unavailable: indicates that the server is not ready to handle the request.

- `any`

## Types

### tgvalidatordRequestBundle

- `id` (string, optional)
- `tenantId` (string, optional)
- `blockchain` (string, optional)
- `details` (tgvalidatordRequestBundleDetails, optional)
- `status` (string, optional)
- `creationDate` (datetime, optional)
- `updateDate` (datetime, optional)
- `requests` (list of tgvalidatordRequest, optional) — This field is not always filled in, as there can be many associated requests.
- `network` (string, optional)
- `signedRequestBundles` (list of RequestBundleSignedRequestBundle, optional)

### tgvalidatordResponseCursor

- `currentPage` (string, optional)
- `hasPrevious` (boolean, optional) — Hints for UI to display whether a previous and/or next page of data are available.
- `hasNext` (boolean, optional)

### tgvalidatordRequestBundleDetails

- `error` (string, optional)
- `amount` (string, optional)
- `source` (tgvalidatordRequestBundleDetailsSource, optional)
- `destination` (tgvalidatordRequestBundleDetailsDestination, optional)

### tgvalidatordRequest

- `id` (string, optional) — Unique identifier for the request.
- `tenantId` (string, optional) — The ID of the Protect tenant where the request was created.
- `currency` (string, optional) — The currency of the request.
- `envelope` (string, optional) — This field is used internally by Protect for request signing and approvals. This field is signed and encrypted.
- `status` (string, optional) — The status of the request. One of the following: `CREATED`, `APPROVING`, `HSM_SIGNED`, `BROADCASTING`, `BROADCASTED`, `CONFIRMED`, `REJECTED`
- `trails` (list of tgvalidatordRequestTrail, optional)
- `signedRequests` (list of RequestSignedRequest, optional)
- `creationDate` (datetime, optional)
- `updateDate` (datetime, optional)
- `metadata` (tgvalidatordMetadata, optional)
- `attributes` (list of tgvalidatordRequestAttribute, optional)
- `rule` (string, optional)
- `approvers` (tgvalidatordApprovers, optional)
- `type` (string, optional) — Value used internally to distinguish between different types of blockchain transactions (e.g., staking, unstaking, transfer, delegate, etc)
- `currencyInfo` (tgvalidatordCurrency, optional)
- `needsApprovalFrom` (list of string, optional) — List of groups that the request needs approval from.
- `requestBundleId` (string, optional) — The ID of the request bundle. For more information on request bundles, see the [our docs](https://docs.taurushq.com/user-and-technical-guides/docs/accounts#bundle-request).
- `externalRequestId` (string, optional) — Identifier for the request in the user's system. This must be unique.
- `travelRuleDataInput` (tgvalidatordTravelRuleDataInput, optional)

### RequestBundleSignedRequestBundle

- `id` (string, optional)
- `status` (string, optional)
- `transaction` (string, optional)
- `hash` (string, optional)
- `details` (string, optional)
- `creationDate` (datetime, optional)
- `updateDate` (datetime, optional)
- `broadcastDate` (datetime, optional)
- `confirmationDate` (datetime, optional)

### tgvalidatordRequestBundleDetailsSource

- `totalSources` (string, optional)
- `fromWalletId` (string, optional)
- `fromAddressId` (string, optional)

### tgvalidatordRequestBundleDetailsDestination

- `totalDestinations` (string, optional)
- `toAddressId` (string, optional)
- `toWhitelistedAddressId` (string, optional)

### tgvalidatordRequestTrail

- `id` (string, optional) — ID for the event record.
- `userId` (string, optional) — The ID of the user related to the audit event. For events that are not triggered by a user, 1 is used.
- `externalUserId` (string, optional) — The external ID of the user related to the audit event. E.g., validator-core@taurusgroup.com corrosponds to user ID 1
- `action` (string, optional) — The event being logged. E.g., `broadcasting`, `hsm_signed`, `hsm_ready`, `approved`, etc...
- `comment` (string, optional) — Some more details about the event. This could be the transaction hash, or the ID or an error code associated with the event.
- `date` (datetime, optional)
- `requestStatus` (string, optional) — The status of the request at the time of the event. One of the following: `CREATED`, `APPROVING`, `APPROVED`, `HSM_SIGNED`, `HSM_READY`, `BROADCASTING`, `BROADCASTED`, `CONFIRMED`, `REJECTED`

### RequestSignedRequest

- `id` (string, optional)
- `signedRequest` (string, optional)
- `status` (string, optional)
- `hash` (string, optional)
- `block` (long, optional)
- `details` (string, optional)
- `creationDate` (datetime, optional)
- `updateDate` (datetime, optional)
- `broadcastDate` (datetime, optional)
- `confirmationDate` (datetime, optional)
- `attributes` (list of tgvalidatordSignedRequestAttribute, optional)

### tgvalidatordMetadata

- `hash` (string, optional)
- `payload` (any, optional)
- `payloadAsString` (string, optional)

### tgvalidatordRequestAttribute

- `id` (string, optional)
- `key` (string, optional)
- `value` (string, optional)
- `contentType` (string, optional)

### tgvalidatordApprovers

- `parallel` (list of tgvalidatordParallelApproversGroups, optional)

### tgvalidatordCurrency

- `name` (string, optional) — Name of the currency.
- `symbol` (string, optional) — Shorthand symbol for the currency.
- `coinTypeIndex` (string, optional) — Index used to identify the coin type in BIP44. (e.g. Bitcoin is 0, Ethereum is 60).
- `blockchain` (string, optional) — The Blockchain the currency is associated with, (e.g. ETH, BTC).
- `isToken` (boolean, optional) — Indicates if the currency is a token (e.g., ERC-20).
- `isERC20` (boolean, optional) — Indicates if the token is an ERC-20 token.
- `decimals` (string, optional) — Number of decimal places the currency uses (e.g. 18 for ETH).
- `contractAddress` (string, optional) — Smart contract address if currency is a smart contract (e.g. ERC-20.).
- `hasStaking` (boolean, optional) — Indicates if the currency supports staking.
- `isUTXOBased` (boolean, optional) — Indicates if the currency is UTXO-based (e.g. Bitcoin).
- `isAccountBased` (boolean, optional) — Indicates if the currency is account-based (e.g. Ethereum).
- `isFiat` (boolean, optional) — Indicates if the currency is a fiat currency (e.g. CHF, EUR, USD).
- `isFA12` (boolean, optional) — Indicates if the currency is based on FA12 standard (used in Tezos).
- `isFA20` (boolean, optional) — Indicates if the currency is based on FA20 standard (used in Tezos).
- `isNFT` (boolean, optional) — Indicates if the currency represents a Non-Fungible Token (NFT).
- `enabled` (boolean, optional) — Indicates if the currency is enabled in the current tenant.
- `id` (string, optional) — Unique identifier of the currency.
- `displayName` (string, optional) — Display name for the currency, (e.g. Ethereum, Bitcoin).
- `type` (string, optional) — Type of the currency. Can be `token`, `fiat`, `native` , or `signet`.
- `wlcaId` (string, optional) — White listed contract address id associated with the currency.
- `network` (string, optional) — Network or environment the currency is used on (e.g. 'mainnet', 'testnet').
- `tokenID` (string, optional) — Unique id for the token, if applicable (e.g. for NFTs).
- `logo` (string, optional) — Currency logo in Data URI scheme. Base 64 encoded. (e.g. data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAUAAAAFCAYAAACNbyblAAAAHElEQVQI12P4//8/w38GIAXDIBKE0DHxgljNBAAO9TXL0Y4OHwAAAABJRU5ErkJggg==).

### tgvalidatordTravelRuleDataInput

- `originatorPersonTravelRuleData` (tgvalidatordPersonTravelRuleData, optional)
- `originatorCompanyTravelRuleData` (tgvalidatordCompanyTravelRuleData, optional)
- `beneficiaryCompanyTravelRuleData` (tgvalidatordCompanyTravelRuleData, optional)
- `beneficiaryPersonTravelRuleData` (tgvalidatordPersonTravelRuleData, optional)
- `provider` (string, optional) — Provider is the type of the travel rule data provider. Supported provider: 'TaurusNetwork'

### tgvalidatordSignedRequestAttribute

- `id` (string, optional)
- `key` (string, optional)
- `value` (string, optional)
- `contentType` (string, optional)

### tgvalidatordParallelApproversGroups

- `sequential` (list of tgvalidatordApproversGroup, optional)

### tgvalidatordPersonTravelRuleData

- `name` (string, optional)
- `houseNumber` (string, optional)
- `street` (string, optional)
- `city` (string, optional)
- `province` (string, optional)
- `postalCode` (string, optional)
- `country` (string, optional)
- `idNumber` (string, optional)
- `externalCustomerID` (string, optional)
- `birthdate` (string, optional)
- `birthPlace` (string, optional)
- `accountNumber` (string, optional)

### tgvalidatordCompanyTravelRuleData

- `department` (string, optional)
- `buildingNumber` (string, optional)
- `street` (string, optional)
- `city` (string, optional)
- `province` (string, optional)
- `postalCode` (string, optional)
- `country` (string, optional)
- `legalEntityIdentifier` (string, optional)
- `businessName` (string, optional)
- `accountNumber` (string, optional)

### tgvalidatordApproversGroup

- `externalGroupID` (string, optional)
- `minimumSignatures` (long, optional)

## Examples

**Response**

```json
{
  "results": [
    {
      "id": "string",
      "tenantId": "string",
      "blockchain": "string",
      "details": {
        "error": "string",
        "amount": "string",
        "source": {
          "totalSources": "string",
          "fromWalletId": "string",
          "fromAddressId": "string"
        },
        "destination": {
          "totalDestinations": "string",
          "toAddressId": "string",
          "toWhitelistedAddressId": "string"
        }
      },
      "status": "string",
      "creationDate": "2024-01-15T09:30:00Z",
      "updateDate": "2024-01-15T09:30:00Z",
      "requests": [
        {
          "id": "string",
          "tenantId": "string",
          "currency": "string",
          "envelope": "string",
          "status": "string",
          "trails": [
            {
              "id": "string",
              "userId": "string",
              "externalUserId": "string",
              "action": "string",
              "comment": "string",
              "date": "2024-01-15T09:30:00Z",
              "requestStatus": "string"
            }
          ],
          "signedRequests": [
            {
              "id": "string",
              "signedRequest": "string",
              "status": "string",
              "hash": "string",
              "block": 1,
              "details": "string",
              "creationDate": "2024-01-15T09:30:00Z",
              "updateDate": "2024-01-15T09:30:00Z",
              "broadcastDate": "2024-01-15T09:30:00Z",
              "confirmationDate": "2024-01-15T09:30:00Z",
              "attributes": [
                {
                  "id": "string",
                  "key": "string",
                  "value": "string",
                  "contentType": "string"
                }
              ]
            }
          ],
          "creationDate": "2024-01-15T09:30:00Z",
          "updateDate": "2024-01-15T09:30:00Z",
          "metadata": {
            "hash": "string",
            "payloadAsString": "string"
          },
          "attributes": [
            {
              "id": "string",
              "key": "string",
              "value": "string",
              "contentType": "string"
            }
          ],
          "rule": "string",
          "approvers": {
            "parallel": [
              {
                "sequential": [
                  {
                    "externalGroupID": "string",
                    "minimumSignatures": 1
                  }
                ]
              }
            ]
          },
          "type": "string",
          "currencyInfo": {
            "name": "string",
            "symbol": "string",
            "coinTypeIndex": "string",
            "blockchain": "string",
            "isToken": true,
            "isERC20": true,
            "decimals": "string",
            "contractAddress": "string",
            "hasStaking": true,
            "isUTXOBased": true,
            "isAccountBased": true,
            "isFiat": true,
            "isFA12": true,
            "isFA20": true,
            "isNFT": true,
            "enabled": true,
            "id": "string",
            "displayName": "string",
            "type": "string",
            "wlcaId": "string",
            "network": "string",
            "tokenID": "string",
            "logo": "string"
          },
          "needsApprovalFrom": [
            "string"
          ],
          "requestBundleId": "string",
          "externalRequestId": "string",
          "travelRuleDataInput": {
            "originatorPersonTravelRuleData": {
              "name": "string",
              "houseNumber": "string",
              "street": "string",
              "city": "string",
              "province": "string",
              "postalCode": "string",
              "country": "string",
              "idNumber": "string",
              "externalCustomerID": "string",
              "birthdate": "string",
              "birthPlace": "string",
              "accountNumber": "string"
            },
            "originatorCompanyTravelRuleData": {
              "department": "string",
              "buildingNumber": "string",
              "street": "string",
              "city": "string",
              "province": "string",
              "postalCode": "string",
              "country": "string",
              "legalEntityIdentifier": "string",
              "businessName": "string",
              "accountNumber": "string"
            },
            "beneficiaryCompanyTravelRuleData": {
              "department": "string",
              "buildingNumber": "string",
              "street": "string",
              "city": "string",
              "province": "string",
              "postalCode": "string",
              "country": "string",
              "legalEntityIdentifier": "string",
              "businessName": "string",
              "accountNumber": "string"
            },
            "beneficiaryPersonTravelRuleData": {
              "name": "string",
              "houseNumber": "string",
              "street": "string",
              "city": "string",
              "province": "string",
              "postalCode": "string",
              "country": "string",
              "idNumber": "string",
              "externalCustomerID": "string",
              "birthdate": "string",
              "birthPlace": "string",
              "accountNumber": "string"
            },
            "provider": "string"
          }
        }
      ],
      "network": "string",
      "signedRequestBundles": [
        {
          "id": "string",
          "status": "string",
          "transaction": "string",
          "hash": "string",
          "details": "string",
          "creationDate": "2024-01-15T09:30:00Z",
          "updateDate": "2024-01-15T09:30:00Z",
          "broadcastDate": "2024-01-15T09:30:00Z",
          "confirmationDate": "2024-01-15T09:30:00Z"
        }
      ]
    }
  ],
  "cursor": {
    "currentPage": "string",
    "hasPrevious": true,
    "hasNext": true
  }
}
```

**SDK Code**

```python
import requests

url = "https://your-protect-instance.example.com/api/rest/v1/requests/bundles/for-approval"

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers)

print(response.json())
```

```javascript
const url = 'https://your-protect-instance.example.com/api/rest/v1/requests/bundles/for-approval';
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://your-protect-instance.example.com/api/rest/v1/requests/bundles/for-approval"

	req, _ := http.NewRequest("GET", url, nil)

	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://your-protect-instance.example.com/api/rest/v1/requests/bundles/for-approval")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://your-protect-instance.example.com/api/rest/v1/requests/bundles/for-approval")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://your-protect-instance.example.com/api/rest/v1/requests/bundles/for-approval', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://your-protect-instance.example.com/api/rest/v1/requests/bundles/for-approval");
var request = new RestRequest(Method.GET);
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = ["Authorization": "Bearer <token>"]

let request = NSMutableURLRequest(url: NSURL(string: "https://your-protect-instance.example.com/api/rest/v1/requests/bundles/for-approval")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```