# Limiting External Access Requests - API Not working

**URL:** <https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954>\
**Category:** SHF Discussion and Questions\
**Tags:** apis, identity-security-cloud\
**Created:** [February 12, 2026, 4:23am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954 "2026-02-12T04:23:51Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Otunba\_skillz](https://avatars.discourse-cdn.com/v4/letter/o/ecc23a/32.png) [@Otunba\_skillz](https://developer.sailpoint.com/discuss/u/Otunba_skillz)\
**Post date:** [February 12, 2026, 4:23am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/1 "2026-02-12T04:23:51Z")

</div>

My team and i are trying to implement access request restriction as per this document [Limiting External Access Requests](https://documentation.sailpoint.com/connectors/servicenow/service_catalog/help/integrating_service_catalog/limit_ext_requests.html).  
We are looking at the option number one which is the API option. Basically we want to set the `“approvalsMustBeExternal": true`. However, this doesnt seems to be working. We have tried using just the body in the doc as docmented but still no luck. We have also tried doing a GET request on the access request config and pass the response of the GET request after updating the field but still no luck.

First error we got was :

> {
> 
> ```
> "detailCode": "400.1 Bad request content",
> 
> "trackingId": "",
> 
> "messages": \[
> 
> {
> 
> "locale": "en-US",
> 
> "localeOrigin": "DEFAULT",
> 
> "text": "The request was syntactically correct but its content is semantically invalid."
> 
> },
> 
> {
> 
> "locale": "und",
> 
> "localeOrigin": "REQUEST",
> 
> "text": "The request was syntactically correct but its content is semantically invalid."
> 
> }
> 
> \],
> 
> "causes": \[\]
> 
> ```
> 
> }

And the second error we got was:

> {
> 
> ```
> "detailCode": "500.1 Downstream error",
> 
> "trackingId": "",
> 
> "messages": \[
> 
> {
> 
> "locale": "en-US",
> 
> "localeOrigin": "DEFAULT",
> 
> "text": "A call from this server to another component has failed."
> 
> },
> 
> {
> 
> "locale": "und",
> 
> "localeOrigin": "REQUEST",
> 
> "text": "A call from this server to another component has failed."
> 
> }
> 
> \],
> 
> "causes": \[
> 
> {
> 
> "locale": "en-US",
> 
> "localeOrigin": "DEFAULT",
> 
> "text": "Failed to update Configuration."
> 
> }
> 
> \]
> 
> ```
> 
> }

I will be glad if someone can help out…Thanks

---

<div class="post-metadata">

**Author:** ![sidharth\_tarlapally](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/sidharth_tarlapally/32/26178_2.png) [@sidharth\_tarlapally](https://developer.sailpoint.com/discuss/u/sidharth_tarlapally)\
**Post date:** [February 12, 2026, 8:52am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/2 "2026-02-12T08:52:00Z")

</div>

Hi @Otunba_skillz

can you show the body and url (mask sensitive data)

---

<div class="post-metadata">

**Author:** ![Otunba\_skillz](https://avatars.discourse-cdn.com/v4/letter/o/ecc23a/32.png) [@Otunba\_skillz](https://developer.sailpoint.com/discuss/u/Otunba_skillz)\
**Post date:** [February 13, 2026, 1:08am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/3 "2026-02-13T01:08:48Z")

</div>

For the URL, i tried both the BETA and V3 .  
The URL is https:xxxxx/access-request-config and as for the body, i have tried different ones e.g

```auto
{

    "approvalsMustBeExternal": true,

    "autoApprovalEnabled": false,

    "reauthorizationEnabled": false,

    "requestOnBehalfOfConfig": {

        "allowRequestOnBehalfOfAnyoneByAnyone": true,

        "allowRequestOnBehalfOfEmployeeByManager": false,

        "allowRequestOnBehalfOfForMachineIdentity": true

    },

    "approvalReminderAndEscalationConfig": {

        "daysUntilEscalation": 0,

        "daysBetweenReminders": 0,

        "maxReminders": 0,

        "fallbackApproverRef": null

    },

    "entitlementRequestConfig": {

        "allowEntitlementRequest": true,

        "requestCommentsRequired": false,

        "deniedCommentsRequired": false,

        "grantRequestApprovalSchemes": null,

        "revokeRequestApprovalSchemes": null

    },

    "govGroupVisibilityEnabled": false,

    "fallbackAccessDurationInDays": null

}

```

I have also tried another body where i removed all the null values completely in the payload.

Also i have tried another body where i populated the null values with actual values from a user in my tenant but still all resulted in an error. You can try this in your tenant and let me know if that endpoint works with any body you try it with pls

---

<div class="post-metadata">

**Author:** ![JackSparrow](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jacksparrow/32/19685_2.png) [@JackSparrow](https://developer.sailpoint.com/discuss/u/JackSparrow)\
**Post date:** [February 13, 2026, 1:07pm UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/4 "2026-02-13T13:07:15Z")

</div>

Hello @Otunba_skillz , Can you try removing below objects from the body? I don’t see these fields in thr API documentation

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/d/4/d4688e78cf7ae03fa84bf4bf11de666852f4e214.png)

---

<div class="post-metadata">

**Author:** ![Otunba\_skillz](https://avatars.discourse-cdn.com/v4/letter/o/ecc23a/32.png) [@Otunba\_skillz](https://developer.sailpoint.com/discuss/u/Otunba_skillz)\
**Post date:** [February 15, 2026, 11:46pm UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/6 "2026-02-15T23:46:04Z")

</div>

Thanks Theja, i did that but still got an error. Did u try this on your end to see if it works? pls find the body and response below:

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/4/4/44ba24d625ac186f365f698d4ce79a64f5958367.png)

---

<div class="post-metadata">

**Author:** ![kompala](https://avatars.discourse-cdn.com/v4/letter/k/ea5d25/32.png) [@kompala](https://developer.sailpoint.com/discuss/u/kompala)\
**Post date:** [February 16, 2026, 11:33am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/7 "2026-02-16T11:33:45Z")

</div>

@Otunba_skillz We set that couple of years back in our tenant and it worked fine. I think below is the json that we used,

{  
“approvalsMustBeExternal”: true,  
“autoApprovalEnabled”: true,  
“requestOnBehalfOfConfig”: {  
“allowRequestOnBehalfOfAnyoneByAnyone”: true,  
“allowRequestOnBehalfOfEmployeeByManager”: true  
},  
“approvalReminderAndEscalationConfig”: {},  
“entitlementRequestConfig”: {}  
}

Please try if this still works.

---

<div class="post-metadata">

**Author:** ![kompala](https://avatars.discourse-cdn.com/v4/letter/k/ea5d25/32.png) [@kompala](https://developer.sailpoint.com/discuss/u/kompala)\
**Post date:** [February 16, 2026, 2:51pm UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/8 "2026-02-16T14:51:59Z")

</div>

If you still want to pass the values based on the Get request, remove the entries that has the value as null and try it as well.

---

<div class="post-metadata">

**Author:** ![Otunba\_skillz](https://avatars.discourse-cdn.com/v4/letter/o/ecc23a/32.png) [@Otunba\_skillz](https://developer.sailpoint.com/discuss/u/Otunba_skillz)\
**Post date:** [February 17, 2026, 4:12am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/9 "2026-02-17T04:12:49Z")

</div>

Hello Vidya,  
I tried exactly what you posted and still got the below error. i can confirm my tenant is up and running and other apis are working fine. Can u pls help verify by testing this in your sandbox tenant just so we verify the api endpoint is not broken.

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/7/9/79b9f117bf4fb3f5dee44b3cd2f390a516bb6506.png)

---

<div class="post-metadata">

**Author:** ![Otunba\_skillz](https://avatars.discourse-cdn.com/v4/letter/o/ecc23a/32.png) [@Otunba\_skillz](https://developer.sailpoint.com/discuss/u/Otunba_skillz)\
**Post date:** [February 17, 2026, 4:14am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/10 "2026-02-17T04:14:17Z")

</div>

Hello Theja,  
I have tried this but still no luck. See my responses below in other user’s response

---

<div class="post-metadata">

**Author:** ![Otunba\_skillz](https://avatars.discourse-cdn.com/v4/letter/o/ecc23a/32.png) [@Otunba\_skillz](https://developer.sailpoint.com/discuss/u/Otunba_skillz)\
**Post date:** [February 17, 2026, 4:16am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/11 "2026-02-17T04:16:54Z")

</div>

Hello Vidya,  
I have tried this as well but no luck

---

<div class="post-metadata">

**Author:** ![kompala](https://avatars.discourse-cdn.com/v4/letter/k/ea5d25/32.png) [@kompala](https://developer.sailpoint.com/discuss/u/kompala)\
**Post date:** [February 17, 2026, 6:05am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/12 "2026-02-17T06:05:44Z")

</div>

@Otunba_skillz This seems SailPoint has added additional dependency and hence the old one is not working, I will try to check in my non prod env. and see if it works.

---

<div class="post-metadata">

**Author:** ![Otunba\_skillz](https://avatars.discourse-cdn.com/v4/letter/o/ecc23a/32.png) [@Otunba\_skillz](https://developer.sailpoint.com/discuss/u/Otunba_skillz)\
**Post date:** [February 18, 2026, 1:48am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/14 "2026-02-18T01:48:42Z")

</div>

All good…i’ll wait and see what you come back with

---

<div class="post-metadata">

**Author:** ![kompala](https://avatars.discourse-cdn.com/v4/letter/k/ea5d25/32.png) [@kompala](https://developer.sailpoint.com/discuss/u/kompala)\
**Post date:** [February 18, 2026, 3:08am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/15 "2026-02-18T03:08:43Z")

</div>

@Otunba_skillz Some how in one of my new tenant, external approvals is already set to true. I am not sure who did it since many people use that common tenant.

But i tried to modify it with various versions of JSON, i am also getting the same semantically incorrect error. I am trying to reach out to others to see if they have any details about it

---

<div class="post-metadata">

**Author:** ![Otunba\_skillz](https://avatars.discourse-cdn.com/v4/letter/o/ecc23a/32.png) [@Otunba\_skillz](https://developer.sailpoint.com/discuss/u/Otunba_skillz)\
**Post date:** [February 18, 2026, 3:36am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/16 "2026-02-18T03:36:06Z")

</div>

Okk thanks. Hopefully something comes outta it

---

<div class="post-metadata">

**Author:** ![kompala](https://avatars.discourse-cdn.com/v4/letter/k/ea5d25/32.png) [@kompala](https://developer.sailpoint.com/discuss/u/kompala)\
**Post date:** [February 19, 2026, 1:17am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/17 "2026-02-19T01:17:07Z")

</div>

@Otunba_skillz I got this working with the help of my great colleague. Below is the way to enable it,

Change to V2026 API and set the headers as below,

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/e/5/e54cbe1f9bcc1bb749a2584145234d48c6584b6c.png)

and call the API and it is working

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/1/e/1e8769d8385bb49846e1bbe3a1afe3f8c808aab1.png)

JSON used is below

```auto
{
  "approvalsMustBeExternal": true,
  "reauthorizationEnabled": false,
  "requestOnBehalfOfConfig": {
    "allowRequestOnBehalfOfAnyoneByAnyone": true,
    "allowRequestOnBehalfOfEmployeeByManager": false,
    "allowRequestOnBehalfOfForMachineIdentity": true
  },
  "entitlementRequestConfig": {
    "allowEntitlementRequest": true,
    "requestCommentsRequired": false,
    "deniedCommentsRequired": false,
    "grantRequestApprovalSchemes": null,
    "revokeRequestApprovalSchemes": null
  },
  "govGroupVisibilityEnabled": false,
  "fallbackAccessDurationInDays": null
}

```

Please let me know if it worked for you. If so, i request you to mark this as the solution.

---

<div class="post-metadata">

**Author:** ![kompala](https://avatars.discourse-cdn.com/v4/letter/k/ea5d25/32.png) [@kompala](https://developer.sailpoint.com/discuss/u/kompala)\
**Post date:** [February 19, 2026, 2:38am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/18 "2026-02-19T02:38:42Z")

</div>

Below is the python code for you to execute it. Modify the tenant, client id and client secret in the start of the program

```auto
import requests

# Set the necessary variables
tenant_id = ""
client_id = ""
client_secret = ""
base_url = f"https://{tenant_id}.api.identitynow.com"

# Get an access token
auth_url = f"{base_url}/oauth/token"
auth_data = {
    "grant_type": "client_credentials",
    "client_id": client_id,
    "client_secret": client_secret,
}
auth_response = requests.post(auth_url, data=auth_data)
print(auth_response)

#Extract the access token from the response
access_token = auth_response.json()["access_token"]
print(access_token)

# API Call to get Sources
url = f"{base_url}/v2026/access-request-config"
headers = {
    'Authorization': f'Bearer {access_token}',
	'Content-Type': 'application/json',
    'X-SailPoint-Experimental': 'true'
}

json = {
  "approvalsMustBeExternal": True,
  "reauthorizationEnabled": False,
  "requestOnBehalfOfConfig": {
    "allowRequestOnBehalfOfAnyoneByAnyone": True,
    "allowRequestOnBehalfOfEmployeeByManager": False,
    "allowRequestOnBehalfOfForMachineIdentity": True
  },
  "entitlementRequestConfig": {
    "allowEntitlementRequest": True,
    "requestCommentsRequired": False,
    "deniedCommentsRequired": False,
    "grantRequestApprovalSchemes": None,
    "revokeRequestApprovalSchemes": None
  },
  "govGroupVisibilityEnabled": False,
  "fallbackAccessDurationInDays": None
}

response = requests.request("PUT",url, headers=headers,json=json)

if response.status_code == 200:
    data = response.json()
    print(f"Successfully completed the modification and response is {data}")
  
else:
    print(f"Request for sources failed with status code: {response.status_code}")

```

---

<div class="post-metadata">

**Author:** ![Otunba\_skillz](https://avatars.discourse-cdn.com/v4/letter/o/ecc23a/32.png) [@Otunba\_skillz](https://developer.sailpoint.com/discuss/u/Otunba_skillz)\
**Post date:** [February 20, 2026, 6:40am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/19 "2026-02-20T06:40:38Z")

</div>

Hello Vidya,  
thanks alot for your response.  
I tried it via postman and got the following error. Attached is the headers, body and endpoint.

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/5/8/585198a02c4f1e1ffa75101476d7b9eff3ba69b9.png)

 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/5/8/581ff64bdb9357dc0b1af978e84436cb35a448f2.png)

---

<div class="post-metadata">

**Author:** ![Otunba\_skillz](https://avatars.discourse-cdn.com/v4/letter/o/ecc23a/32.png) [@Otunba\_skillz](https://developer.sailpoint.com/discuss/u/Otunba_skillz)\
**Post date:** [February 20, 2026, 6:41am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/20 "2026-02-20T06:41:39Z")

</div>

I was able to get it to work with this Python script you shared. Thanks alot for this. Not sure why it didn’t work with postman but only with the script

---

<div class="post-metadata">

**Author:** ![Otunba\_skillz](https://avatars.discourse-cdn.com/v4/letter/o/ecc23a/32.png) [@Otunba\_skillz](https://developer.sailpoint.com/discuss/u/Otunba_skillz)\
**Post date:** [February 27, 2026, 4:40am UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/21 "2026-02-27T04:40:39Z")

</div>

Hello Vidya,  
I finally got it to work in Postman by changing the collection to V2025. So both the script and Postman works fine in our Dev Tenant. However, the same change is not working in our Production Tenant. Be it the python script or the API collection, none of them is working for our Production Tenant. Below is the error message i am getting. Any help thoughts will be appreciated

> {
> 
> ```
> "detailCode": "404 Not found",
> 
> "trackingId": "22xxxx37ef204ca98xxxxxx",
> 
> "messages": \[
> 
> {
> 
> "locale": "und",
> 
> "localeOrigin": "REQUEST",
> 
> "text": "The server did not find a current representation for the target resource."
> 
> },
> 
> {
> 
> "locale": "en-US",
> 
> "localeOrigin": "DEFAULT",
> 
> "text": "The server did not find a current representation for the target resource."
> 
> }
> 
> \],
> 
> "causes": \[\]
> 
> ```
> 
> }

---

<div class="post-metadata">

**Author:** ![kompala](https://avatars.discourse-cdn.com/v4/letter/k/ea5d25/32.png) [@kompala](https://developer.sailpoint.com/discuss/u/kompala)\
**Post date:** [February 27, 2026, 12:56pm UTC](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954/22 "2026-02-27T12:56:06Z")

</div>

HTTP 404, probably URL is wrong ?

[Next page](https://developer.sailpoint.com/discuss/t/limiting-external-access-requests-api-not-working/195954.md?page=2)
