# Identity: addresses

> Contacts waiting at a new address for the owner's decision (SPEC §5.3); Re-pin the contact at the new address, as accept_new_hosts: auto would have; Leave the pin where it is; the new address is a stranger the owner may block

## Contacts waiting at a new address for the owner's decision (SPEC §5.3)

`GET /v1/identities/{slug}/addresses/pending` · operation `listPendingAddresses`

Requires the `batondeck:contacts:read` permission (action `contact:read`).

**Parameters**

| Name | In | Type | Required | Notes |
|---|---|---|---|---|
| `slug` | path | string | yes |  |

**Responses**

| Status | Meaning |
|---|---|
| 200 | Contacts waiting at a new address for the owner's decision (SPEC §5.3) |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "pending": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "root": {
            "type": "string"
          },
          "endpoint": {
            "type": "string"
          },
          "current_endpoint": {
            "type": "string"
          },
          "why": {
            "type": "string"
          },
          "at": {
            "type": "number"
          },
          "display_name": {
            "type": "string"
          }
        },
        "required": [
          "root",
          "endpoint",
          "current_endpoint",
          "why",
          "at",
          "display_name"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "pending"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X GET 'https://api.batondeck.com/v1/identities/:slug/addresses/pending' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```


## Re-pin the contact at the new address, as accept_new_hosts: auto would have

`POST /v1/identities/{slug}/addresses/{root}/approve` · operation `approvePendingAddress`

Requires the `batondeck:contacts:manage` permission (action `address:decide`).

Refused while the workspace is suspended or on deletion hold.

**Parameters**

| Name | In | Type | Required | Notes |
|---|---|---|---|---|
| `slug` | path | string | yes |  |
| `root` | path | string | yes |  |

**Responses**

| Status | Meaning |
|---|---|
| 200 | Re-pin the contact at the new address, as accept_new_hosts: auto would have |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "root": {
      "type": "string"
    },
    "endpoint": {
      "type": "string"
    }
  },
  "required": [
    "root",
    "endpoint"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X POST 'https://api.batondeck.com/v1/identities/:slug/addresses/:root/approve' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```


## Leave the pin where it is; the new address is a stranger the owner may block

`POST /v1/identities/{slug}/addresses/{root}/reject` · operation `rejectPendingAddress`

Requires the `batondeck:contacts:manage` permission (action `address:decide`).

Refused while the workspace is suspended or on deletion hold.

**Parameters**

| Name | In | Type | Required | Notes |
|---|---|---|---|---|
| `slug` | path | string | yes |  |
| `root` | path | string | yes |  |

**Responses**

| Status | Meaning |
|---|---|
| 200 | Leave the pin where it is; the new address is a stranger the owner may block |
| 401 | No portal session, and no live API key. |
| 403 | The policy refused, or the request was cross-site. |
| 404 | No such resource, or none this session may see. |

<details>
<summary>200 response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "root": {
      "type": "string"
    }
  },
  "required": [
    "root"
  ],
  "additionalProperties": false
}
```

</details>

```sh
curl -X POST 'https://api.batondeck.com/v1/identities/:slug/addresses/:root/reject' \
  -H "Authorization: Bearer $BATONDECK_API_KEY"
```
