> ## Documentation Index
> Fetch the complete documentation index at: https://hfsaa.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Deny an application and email the reason



## OpenAPI

````yaml /openapi.yaml post /v1/admin/api-applications/{applicationId}/deny
openapi: 3.1.0
info:
  title: HFSAA Public API
  version: 1.2.2
  description: >
    API-key protected access to HFSAA-certified restaurants, meat markets, and
    dining halls.

    Every directory-data route in the `/v1` namespace requires an API key; there
    are no

    anonymous data endpoints. Public health and developer-onboarding routes are
    explicitly

    marked with `security: []` and do not expose directory data.

    Developers can request test access without creating an account. Test keys do
    not

    expire automatically, but they are restricted to the test environment and
    quota.

    Successful data responses may be cached privately for no more than one hour.
  contact:
    name: HFSAA
servers:
  - url: https://api.hfsaa.org
    description: Production
  - url: https://hfsaa-public-api-staging.idris-ocasio.workers.dev
    description: Test
security:
  - ApiKeyAuth: []
paths:
  /v1/admin/api-applications/{applicationId}/deny:
    post:
      tags:
        - Administration
      summary: Deny an application and email the reason
      operationId: denyDeveloperApplication
      parameters:
        - $ref: '#/components/parameters/ApplicationId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - reason
              properties:
                reason:
                  type: string
                  maxLength: 1000
      responses:
        '200':
          description: Denied and decision email sent.
        '401':
          $ref: '#/components/responses/Unauthorized'
        '409':
          description: The application cannot be denied in its current state.
      security:
        - AdminBearer: []
components:
  parameters:
    ApplicationId:
      name: applicationId
      in: path
      required: true
      schema:
        type: string
        format: uuid
  responses:
    Unauthorized:
      description: The Bearer credential is missing or invalid.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  schemas:
    Error:
      type: object
      additionalProperties: false
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              example: invalid_parameter
            message:
              type: string
              example: limit must be between 1 and 100.
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: hfsaa_test_... or hfsaa_live_...
      description: 'Use the API key as `Authorization: Bearer <api-key>`.'
    AdminBearer:
      type: http
      scheme: bearer
      bearerFormat: HFSAA administrator token

````