> Source: https://wexa.ai/docs/tools/promote-flow

# promote-flow

Snapshot a process flow exactly as it stands now and record that snapshot as its next version, becoming the live one. Use this when a flow's structure is where you want it — editing a flow records nothing on its own, so without a promote there is no history to return to. The previous live version becomes `superseded`; version numbers only ever increase. Admin role required.

## What it is called on each surface

The wire name is `promote-flow` everywhere: it is what the Wexa MCP server advertises, the REST path is
`POST /v1/promote-flow`, and each SDK exposes it under its own language's naming convention.

| Surface | Name |
| --- | --- |
| Wexa MCP server | `promote-flow` |
| REST API | `POST /v1/promote-flow` |
| TypeScript SDK | `fabric.promoteFlow()` |
| Python SDK | `fabric.promote_flow()` |

## Arguments

1 of the 1 argument is required. Omitting a required one is refused before the tool runs, at the validation stage, so it costs nothing and changes nothing.

| Argument | Type | Required | Notes |
| --- | --- | --- | --- |
| `process_flow_id` | string | Required | Process flow id. Required. |

`project_id`, `projectID`, `organization_id` and `executed_by` are not arguments you pass: the
platform binds all four from the credential you authenticated with, and both SDKs refuse them
before the request leaves your process — see
[server-bound arguments](/docs/get-started/scope-and-server-bound-arguments).

## What it returns

The three surfaces wrap this differently, and code written against one will not read another
correctly — see [return shape](/docs/tools/overview#return-shape).

A real response, captured from a live call to `promote-flow`:

`snapshot` came back populated and is shown as `…` here, because the real value runs to
thousands of characters. Read it from your own call rather than from this page.

**Result of promote-flow**

**REST API**

```json
{
  "lifecycle_id": "qlc_000181",
  "result": {
    "id": "fver_9f3fc6a6-4f55-44d6-b7ba-c2329a8e0461",
    "agentflowId": "6ab1945e7566f41b5c28e308",
    "version": 2,
    "status": "promoted",
    "snapshot": "\u2026",
    "agentCount": 1,
    "promotedBy": "6a79a770b6c128ccc24bfca7",
    "promotedAt": "2026-09-21T20:41:37.225918542Z",
    "parentVersion": 1
  }
}
```

**Wexa MCP server**

```json
{
  "content": [
    {
      "type": "text",
      "text": "{\"lifecycle_id\":\"qlc_000181\",\"result\":{\"id\":\"fver_9f3fc6a6-4f55-44d6-b7ba-c2329a8e0461\",\"agentflowId\":\"6ab1945e7566f41b5c28e308\",\"version\":2,\"status\":\"promoted\",\"snapshot\":\"\\u2026\",\"agentCount\":1,\"promotedBy\":\"6a79a770b6c128ccc24bfca7\",\"promotedAt\":\"2026-09-21T20:41:37.225918542Z\",\"parentVersion\":1}}"
    }
  ],
  "isError": false
}
```

**TypeScript SDK**

```ts
// the object you get back IS the result — there is no `.result` to read
{
  id: 'fver_9f3fc6a6-4f55-44d6-b7ba-c2329a8e0461',
  agentflowId: '6ab1945e7566f41b5c28e308',
  version: 2,
  status: 'promoted',
  snapshot: '…',
  agentCount: 1,
  promotedBy: '6a79a770b6c128ccc24bfca7',
  promotedAt: '2026-09-21T20:41:37.225918542Z',
  parentVersion: 1
}

// The TS SDK names these camelCase — lifecycleId, traceId — where Python uses
// lifecycle_id and trace_id. Both are non-enumerable: readable, but omitted by
// Object.keys() and JSON.stringify(). `result.lifecycleId` here is undefined.
result.lifecycleId // 'qlc_000181'
```

**Python SDK**

```python
# a dict subclass; `result` is already unwrapped
{
 "id": "fver_9f3fc6a6-4f55-44d6-b7ba-c2329a8e0461",
 "agentflowId": "6ab1945e7566f41b5c28e308",
 "version": 2,
 "status": "promoted",
 "snapshot": "\u2026",
 "agentCount": 1,
 "promotedBy": "6a79a770b6c128ccc24bfca7",
 "promotedAt": "2026-09-21T20:41:37.225918542Z",
 "parentVersion": 1
}

out.lifecycle_id  # 'qlc_000181' — an attribute, not a key
```

Keeping the `lifecycle_id` is what lets you ask later why a call was allowed, refused or held.

## Calling it

The same call on all four surfaces. Pick a tab once and every code block in the documentation follows it.

The ids in this example are real: they resolve against the project the documentation is written
against, so the call runs as written once you point it at your own deployment. Swap them for the
ids of your own objects.

**Call promote-flow**

**Wexa MCP server**

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "promote-flow",
    "arguments": {
      "process_flow_id": "6ab1945e7566f41b5c28e308"
    }
  }
}
```

**REST API**

```bash
curl -sS https://fabric.wexa.ai/v1/promote-flow \
  -H "authorization: Bearer $FABRIC_API_KEY" \
  -H "content-type: application/json" \
  -d '{"process_flow_id":"6ab1945e7566f41b5c28e308"}'
```

**TypeScript SDK**

```ts
import { Fabric } from '@wexa-fabric/sdk'

const fabric = new Fabric()
const { result } = await fabric.promoteFlow({
  process_flow_id: "6ab1945e7566f41b5c28e308"
})
```

**Python SDK**

```python
from wexa import Fabric

fabric = Fabric()
out = fabric.promote_flow(process_flow_id="6ab1945e7566f41b5c28e308")
```

## Errors

Both SDKs raise the same typed errors, chosen from the gateway's own error string first and its
HTTP status second. `promote-flow` checks the `fabric:orchestrate.write` grant, and reaches the seven classes every
tool reaches — listed under [the common set](/docs/tools/errors#the-common-set). These are the ones specific to it:

| Error | Status | Raised when |
| --- | --- | --- |
| `NotFound` | 404 | `process_flow_id` matches no process flow in this project. |
| `ApprovalRequired` | 202 | A policy held this call for a person to approve. The error carries the approval id; see below. |
| `ConfigurationError` | 5xx | `promote-flow` is not available to you. Retrying will not help. |

## Governance

Every call to `promote-flow` runs through the same ten-stage lifecycle as every other Wexa tool: the
credential is resolved to a scope, the `fabric:orchestrate.write` grant is checked, quota is drawn down, the arguments are
validated, policy rules are evaluated, the call is executed, the result is shaped and redacted, and an audit
record is written. The `lifecycle_id` in the response is the handle to that record.

`promote-flow` is marked consequential, which means it changes something rather than only reading. Two things
follow. It is audited in full rather than lightly, and a policy rule may hold it for human approval — in which
case the call returns `202` and an `ApprovalRequired` error carrying the approval id, and the SDKs can wait for
the decision and resume rather than making you call again.

## See also

[The tool index](/docs/tools/overview), [errors](/docs/tools/errors),
and [which identifier goes where](/docs/tools/identifiers).
