## Execute a notification button

`POST /v1/notifications/:id/confirm`

Presses a button on a request notification on behalf of the token owner: runs the button action, such as accepting an invitation or confirming a request, and deletes the notification.

## Parameters

| Parameter | Type | Required | Description |
|----------|-----|:-----:|---------|
| `id` (path) | number | yes | Notification identifier — the `data.notifications[].id` field in the [notification feed](./list.md) `GET /v1/notifications`. A positive integer |

## Request fields (body)

| Field | Type | Required | Description |
|------|-----|:-----:|---------|
| `value` | string, number | yes | Value of the pressed button from the `data.notifications[].notifyButtons` field of the [notification feed](./list.md) — the part of the button's `COMMAND_PARAMS` after the `\|` character. For `"38959\|Y"` it is `Y`. An empty string, `0` and `"0"` are not accepted |

## Examples

### curl — personal key

```bash
curl -X POST "https://vibecode.bitrix24.com/v1/notifications/38959/confirm" \
  -H "X-Api-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "value": "Y" }'
```

### curl — OAuth application

```bash
curl -X POST "https://vibecode.bitrix24.com/v1/notifications/38959/confirm" \
  -H "X-Api-Key: YOUR_APP_KEY" \
  -H "Authorization: Bearer USER_SESSION_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{ "value": "Y" }'
```

### JavaScript — personal key

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/notifications/38959/confirm', {
  method: 'POST',
  headers: {
    'X-Api-Key': 'YOUR_API_KEY',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({ value: 'Y' }),
})

const { data } = await res.json()
console.log(data.resultMessage[0])
```

### JavaScript — OAuth application

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/notifications/38959/confirm', {
  method: 'POST',
  headers: {
    'X-Api-Key': 'YOUR_APP_KEY',
    'Authorization': 'Bearer USER_SESSION_TOKEN',
    'Content-Type': 'application/json',
  },
  body: JSON.stringify({ value: 'Y' }),
})

const { data } = await res.json()
```

## Response fields

| Field | Type | Description |
|------|-----|----------|
| `success` | boolean | `true` on success |
| `data.resultMessage` | string[] | Result messages. Bitrix24 writes the text — escape it before displaying it in a UI |

## Response example

HTTP 200:

```json
{
  "success": true,
  "data": {
    "resultMessage": ["Invitation accepted"]
  }
}
```

## Error response example

422 — the notification has no buttons, or the token owner has no such notification:

```json
{
  "success": false,
  "error": {
    "code": "BITRIX_ERROR",
    "message": "Notification is absent, unavailable to the token owner, or cannot perform this action.",
    "b24Code": "NOTIFICATION_ACTION_FAILED"
  }
}
```

## Errors

| HTTP | Code | Description |
|------|-----|----------|
| 400 | `INVALID_PARAMS` | The path `id` is not a positive integer |
| 400 | `INVALID_PARAMS` | `value` is missing, is neither a string nor a number, is empty or equals `0` / `"0"` |
| 400 | `INVALID_PARAMS` | Another body field or a query string parameter was passed, or the body is not a JSON object. The field is named in the message. Checked before the Bitrix24 call |
| 400 | `FST_ERR_CTP_EMPTY_JSON_BODY` | The `Content-Type: application/json` header was sent with an empty body |
| 422 | `BITRIX_ERROR` | The notification does not exist, is unavailable to the token owner or does not perform this action — including a notification without buttons. The Bitrix24 error code `NOTIFICATION_ACTION_FAILED` is in the `error.b24Code` field |
| 502 | `BITRIX_UNAVAILABLE` | Bitrix24 returned a response without the list of result messages |
| 403 | `SCOPE_DENIED` | The key lacks the `im` scope |
| 403 | `WRITE_BLOCKED_READONLY_KEY` | The key is in read-only mode. Checked before the Bitrix24 call |
| 403 | `BITRIX_ACCESS_DENIED` | Bitrix24 denied access |
| 401 | `TOKEN_MISSING` | The key has no configured tokens |
| 401 | `MISSING_API_KEY` | The `X-Api-Key` header was not sent |

Full list of common API errors — [Errors](/docs/errors).

## Known specifics

- `notifyButtons` in the [feed](./list.md) is a JSON string. Parse the string before reading the buttons' `COMMAND_PARAMS`.
- After the button is pressed, the notification is gone from the feed, and pressing it again returns `422 BITRIX_ERROR`.
- A notification without buttons has no `notifyButtons` field in the feed, and pressing returns `422 BITRIX_ERROR`. The notification stays in the feed.
- The button is pressed on behalf of the token owner: with a personal key, the key owner; with an OAuth application key and the `Authorization: Bearer` header, the session user.

## See also

- [Notification feed](./list.md)
- [Answer a notification](./answer.md)
- [Mark as read](./read.md)
- [Errors](/docs/errors)
