## Reject a work report

`POST /v1/workday/work-reports/:id/reject`

Gives an employee's work report a neutral mark and removes the report confirmation.

Requires the `timeman` scope. Bitrix24 checks the credential owner’s permissions. READONLY keys can read reports and cannot write them.

## Parameters

| Parameter | Type | Required | Default | Description |
|----------|-----|:-----:|-----------|----------|
| `id` (path) | integer | yes | — | Report ID. List: [`GET /v1/workday/work-reports`](/docs/workday/work-reports/list) |

No request body is needed. An empty object `{}` is accepted, and any field in the body returns `400 INVALID_PARAMS`.

## Examples

### curl — personal key

```bash
curl -X POST "https://vibecode.bitrix24.com/v1/workday/work-reports/167/reject" \
  -H "X-Api-Key: YOUR_API_KEY"
```

### curl — OAuth application

```bash
curl -X POST "https://vibecode.bitrix24.com/v1/workday/work-reports/167/reject" \
  -H "X-Api-Key: YOUR_APP_KEY" \
  -H "Authorization: Bearer USER_SESSION_TOKEN"
```

### JavaScript — personal key

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/workday/work-reports/167/reject', {
  method: 'POST',
  headers: {
    'X-Api-Key': 'YOUR_API_KEY',
  },
})
const { data } = await res.json()
```

### JavaScript — OAuth application

```javascript
const res = await fetch('https://vibecode.bitrix24.com/v1/workday/work-reports/167/reject', {
  method: 'POST',
  headers: {
    'X-Api-Key': 'YOUR_APP_KEY',
    'Authorization': 'Bearer USER_SESSION_TOKEN',
  },
})
const { data } = await res.json()
```

## Response fields

| Field | Type | Description |
|------|-----|----------|
| `success` | boolean | `true` when the request succeeds |
| `data` | boolean | `true` — the mark is set |

## Response example

```json
{
  "success": true,
  "data": true
}
```

## Error response example

422 — no report with this `id` exists:

```json
{
  "success": false,
  "error": {
    "code": "BITRIX_ERROR",
    "message": "Report not found or cannot be changed"
  }
}
```

## Errors

| HTTP | Code | Description |
|------|-----|----------|
| 400 | `INVALID_PARAMS` | `id` is not a positive integer, the request body is not a JSON object, or the body contains a field |
| 422 | `BITRIX_ERROR` | No report with this `id` exists, the credential owner lacks Bitrix24 permission to mark this employee's reports, or Bitrix24 refused the operation |
| 409 | `TIMEMAN_MODULE_NOT_ENABLED` | Time Management is not available on this portal |
| 502 | `BITRIX_UNAVAILABLE` | Bitrix24 is unavailable |
| 401 | `MISSING_API_KEY` | The `X-Api-Key` header was not passed |
| 401 | `TOKEN_MISSING` | An app key was sent without a session token in `Authorization: Bearer` |
| 401 | `INVALID_SESSION` | The session token is invalid or has expired |
| 403 | `WRITE_BLOCKED_READONLY_KEY` | The key is READONLY and cannot mark reports |
| 403 | `SCOPE_DENIED` | The key lacks the `timeman` scope |
| 429 | `RATE_LIMITED` | The general request limit was exceeded |

The full list of common API errors — [Errors](/docs/errors).

## Known specifics

- **What changes in the report.** `mark` becomes `"N"` and `approve` becomes `"N"`: the report confirmation is removed. The changes are visible in [`GET /v1/workday/work-reports/:id`](/docs/workday/work-reports/get).
- **Marking your own report also requires permission.** An employee without permission to mark reports gets `422 BITRIX_ERROR` for their own report too.
- **A report that has not been submitted can be marked too.** It stays unsubmitted, and a submitted report stays submitted: `active` does not change.
- **Calling again does not return an error.** The mark stays neutral, and the response is `true` again.

## See also

- [Approve a work report](/docs/workday/work-reports/approve)
- [Disapprove a work report](/docs/workday/work-reports/disapprove)
- [Read a work report](/docs/workday/work-reports/get)
- [Send a work report](/docs/workday/work-reports/send)
- [Work reports](/docs/workday/work-reports)
- [Daily reports](/docs/workday/daily-reports)
- [Workday](/docs/workday)
