Auditor's Action API Overview

Overview

Whenever the auditor takes any action on your expense report, the Audit Action API pushes out this information to your system. This event and the associated data will be sent as shown below:

  • AppZen posts the auditor's action to your system.
  • AppZen tries to send the webhook up to three times.
  • The following audit workflow events are supported:
    • Automatic Approved
    • Automatic Reject
    • Manual Approved
    • Manual Reject

Webhook__1_.png

 

Webhook Details

The webhook details are as follows : 

  1. Before any report-related actions, the webhook sends out test events to verify the connection. This ensures reduced communication errors during live workflows.
  2. Only on receiving a response with HTTP Status Code 200 is the communication considered successful.

AppZen supports multiple Authentication mechanisms: 

1. API Key-based Authentication - In this case, the  webhook configuration is as follows:

{
	"customerId" : xx32,
	"appzenProduct" : "EXPENSE",
	"externalPlatform" : "WEBHOOK",
	"baseUrl" : "<ExternalSystemURL>",
	"authnType" : "ApiKey",
	"authnConfigName" : "identifierName",
	"credentialsJson" : {
		"x-api-key" : "providedAPIKey"
	}
}

2. OAuth 2.0 Support - In this case, the  webhook configuration is as follows:

{
	"customerId" : xx32,
	"appzenProduct" : "EXPENSE",
	"externalPlatform" : "WEBHOOK",
	"baseUrl" : "<ExternalSystemURL>",
	"authnType" : "OAuth2.0",
	"authnConfigName" : "identifierName",
	"credentialsJson" : 
      {
	"client_id" : "id",
	"client_secret" : "secret",
        "scopes" : <optional>,
        "token_url" : <URL which needs to be called for getting the token>
        "token" : {<store actual Client Auth Token to be used for API calls>}
      }
}

 

External status confirmation (EMS callback)

The webhook above only sends the auditor's action to your system, it does not, by itself, advance the report's status in AppZen. After your system processes the webhook, it is expected to confirm the change by calling back: 

PUT /reports/{report_id}/external_status

AppZen's report status is not updated until this callback is received.

If this callback is never sent,  for example, because of an error or a gap in how your system processes the webhook,  the report's status in AppZen stays unchanged indefinitely, with no error surfaced on the AppZen side. This can look like a stuck report, even though AppZen is working as expected: it is correctly waiting for your system's explicit confirmation.

If a report appears stuck in a pending-approval status for an API/webhook-based integration, first confirm that the report received the auditor's-action webhook and that your system successfully called back with the external status update for that specific report before assuming a platform issue.

 

Sample Webhook Payload 

{
  "report_Id" : "XYZ",
  "audit_status" : "MANUAL_AUDIT_APPROVED",
  "auditor_comments" : "{comments}",
  "actioned_by" : "{auditor_email}",
  "event" : "report_status_change",
}

 

 

See Also

Was this article helpful?
0 out of 0 found this helpful