Skip to main content
Some agent steps should not run unattended: calling a destructive tool, asking the user a question, or starting an OAuth flow. Nasiko pauses the run, records a HITL request, and resumes when a human resolves it. Approvals surface in:
  • nasiko chat (orchestrator and nasiko chat -a)
  • nasiko maf workflow run … --wait
  • MCP tool calls whose permission is ask
  • The HTTP API below
There is no separate Approvals screen in the open-source dashboard. Pending requests are prompted inline in the CLI. Superusers can requeue a stuck resume via the API.

Kinds of pause

MCP connectors with per-agent tool stance ask raise tool_approval. See Tool permissions.

Resolve from the CLI

When nasiko chat or maf run --wait hits a pause, the CLI prints the request and waits for a decision. Ctrl+C cancels the prompt without killing the session; the HITL row stays pending until you resolve or cancel it. NO_COLOR is honored.

API

All routes except requeue require the user who owns the pause (or an admin). Requeue is superuser only.

Resolve body

Fields used depend on the kind. Unused fields are ignored.
A 403 from the LLM router or MCP gateway is not a HITL pause — it is attribution or a permission denial.