Show HN: ApproveAPI – Real-Time user approvals via email, SMS, and push
approveapi.com
approveapi.com
Reading the comments here it seems a lot of people are triggered. instead of acknowledging the idea is good and they wish they had build at themselves, they are in denial dismissing it's utility by saying it won't work as a business, or they could build it internally. I say this in the Spirit of a good hn comment is something we can learn from and I believe people can learn from examining their own reactions. it seems the denial and dismissal simply serves to make one feel better about the realisation that they missed the chance to build this even though they could have and it is a good idea. so instead of facing that feeling and learning something useful they "alter reality" by downplaying the idea is good to limit the pain.
my point is that that's not a very useful response because it neutralizes the opportunity that could be something to learn from. and I guess if you do this pattern of behaviour enough then, you stop yourself learning many times miss the chance to create things you want and maybe get addicted to this reaction of altering reality to feel better rather than learning something to get a result.
I think the core of why people are responding how they are is that there’s not a big moat here, yet. You mention people being triggered due to missing out on their opportunity to build it- but in reality someone can just knock these folks off after a couple of weekends. That’s not to say the tech here shouldn’t exist, or that this isn’t a business. It is, I’d pay for it, I just wouldn’t pay for long. That’s ok though, it’s just a specific type of business.
I hope they stumble across something sticky in their solution that makes them painful to replicate. These sorts of utilities are always welcome and they make bootstrapping faster and faster every year.
I built this out internally for my app, and it took me a little over a day to do it. Had this existed when I built it out, I absolutely would have just paid a buck per 100 emails to save myself time; however, I don't think it's a challenging enough problem on its surface to keep someone from re-writing it and replacing you long term. All that being said, it's a good foundational product, and hopefully you'll add some more features that make it sticky / become aggressive on pricing at scale.
Best of luck!
Agreed, it's nice to get something up and running for a personal project, but I'm building a commercial app that has to pass a basic security audit and every 3rd party service adds another attack vector and potential leak of sensitive data (like name, Email & phone).
I love the idea of being able to run a service like this though that's basically a set and forget hackathon project.
It's a pretty solid idea otherwise.
This seems to be the default position of almost everyone in IT, everywhere I go. People make this claim without doing any calculations.
I can imagine building this in house would be at least a few weeks of developer work and some more devops. That's tens of thousands of dollars. You'd have to send a million emails to break even. How many of this kind of transactional email do you send per year?
That's $2 per month of cost.
A developer costs $150k a year, and if it takes a month to develop, you could have the service for some 5000 months.
In-house developers should focus on the business domain, not on custom building business processes.
Legal needs to review because it is sending employee PII (emails, phone numbers, etc) to a third party, who now knows the individuals in critical "approval roles".
Next hit up security and have them do an audit since this is going to be part of a security control. For bonus points, the internal pentest team finds a bypass that ApproveAPI needs to fix.
Your $150k a year developer is now spending 3-5 hours a week for 3 weeks shepherding a vendor onboarding for something they could have built and tested in a few hours.
And in most cases, vendor management isn't going to get involved for something that will be expensed on a credit card for $2/mo
Once had an internal infrastructure team estimate £70K for the infrastructure to host a single static HTML page.... :-)
But it is part of a business critical flow, and therefore handing it over to a third party is absolutely unthinkable.
I constantly see people not even considering what it means to be giving (potentially critical) business processes away to another company, not having any real knowledge in house, and not realizing that sometimes partners suck and won't help you fix problems in their software.
Neither is a sure bet all of the time, but just dismissing pulling things in house neglects a lot of other downsides to outsourcing.
I also want to mention that we do support volume pricing, so if you want to send lots of approvals per month we can work together on a price that makes sense for your use case -- just reach out to us at support@approveapi.com.
At $100 per hour for a professional, you could save around $159 by using this service.
Seems like the pricing works out to me. You just have to figure out how much time is wasted in traditional approval and how much time this approval method saves the customers.
Approvals here cost ~1¢. Picking a figure of $100k as a developer salary (as it was the first result in a quick search) that puts a lowish bound as about $400/day. So you could take your estimate of build & maintenance times per year, multiply by about 40-50,000 and that's how many approvals you're looking at.
So if you're google doing this every login, sure, that would be prohibitively expensive. If it's my accountants site doing it before they charge me a different amount for filing (there's one of these every year) or being the approve/reject part of an HR holiday system, or anything less common you'd have to be pretty big before it'd be worth spending a day or so building it yourself.
Personally I could see myself using it in some automated workflows I'm building now. Script runs, but before it does something irreversible (e.g. ordering an item) it checks with me that things look OK. It'll cost me a tiny fraction of the total spending, and it's ready right now (and works!).
In the `POST /prompt` endpoint provide a way to pass metadata that does not need to be shown to the user, and return that back in the prompt answer object sent in the webhook/callback.
This is helpful in cases, where I want to send some internal transaction or event reference codes that will help me to properly co-relate the answer into my flow.
Best of luck!
One way to track users is also to specify approve/reject redirect urls with random tokens (though we agree that private metadata is more ergonomic in this case).
If not, you should include detailed examples for
"Send magic sign-in links, two-step verification, re-authenticate long-lived sessions, new device confirmations, verify identity for lost accounts or customer support."
Small point, I'm not in the US so it'd be good to see the international SMS prices. There's no link I could see on the main page and the one after signing in doesn't resolve: https://dashboard.approveapi.com/full-sms-pricing
edit -
With customisation, can I put in links? Pictures?
Re: customization, we're quickly adding more customizations like colors/images, etc. Currently you can add a logo for your company, and customize all the text on the approval (approve text/reject text/title/body/etc). You can also specify redirect on {approve, reject} links to take the user somewhere after they answer the prompt.
FWIW, my current use-case I'd like to put in here is that I've got some auto-generated art based on user inputs that I'll be shipping off. There's some stuff that could go wrong, so having a final check before the order goes in would be great.
Currently the workflow would be
Auto generate
I check occasionally, manually set the order to go.
I'd like to change it to
Auto generate -> send me either the picture itself or a link to it, I hit approve/reject -> order completed automatically
For ~1 cent per order, it's not worth me even getting email alerting setup.
I hope it's okay if I give you a thought of mine. I built/am building a larger system but built-in is sending SMS's. I live in Israel, so Twilio works, but is an expensive option.
What I did is I have a sort of data access layer between the 'send SMS request' and many different API providers of the customers choosing. This lets them make a choice or, in my case, use a provider they already bought an SMS package with.
Some small feedback:
* The code in the "Test it in the Console" section is missing \'s, so you can't actually copy paste it as is now.
* The demo on the homepage suggests that there's some magic dynamic stuff happening in the email, which makes the actual email a bit of a letdown (though this is understandable)
For example, imagine that you are responsible for rolling the build this week, and you need to get a sign off from an assigned person on each sister team, confirming that they tested their feature area before you push the trigger and roll the build. You can either email and try to contact each person individually, but the cleanest way to solve this issue would be to create a multi-person approval, where you can track the status of a sign off for each sister team in real time. Approval serves as an affirmation in this scenario.
I'm not too fond of the lack of API password tbh. Cool idea otherwise.
Can this be used for phone number verification? If so how this would work? The user would get a text with a link? Or shortcode?
Or they just don't build it and approve things not via an API. There may be a lot of processes out there that could benefit from something like this.