On 28 September Atlassian announced that the Confluence REST APIs will enforce approval-required publishing: in spaces where a space admin has turned on Require approval before publishing, a direct update to a published page through the API will return HTTP 409 Conflict, and the integration will have to save a draft, get it approved, and publish the approved draft instead (Confluence Cloud changelog, 28 September 2026). Three endpoints are named: PUT /wiki/rest/api/content/{id}, PUT /wiki/api/v2/pages/{id} and PUT /wiki/api/v2/pages/{id}/title. It applies to regular pages only, and only in those spaces. There is no enforcement date yet; Atlassian says the entry will be updated with one before the change is switched on.
That last sentence is why this is an admin problem before it is a developer one. When the date lands, the integrations that break will be the ones nobody knew were writing into an approval-gated space.
Why this is the right change, and why it will still hurt
In August I wrote about the four gates an admin has to open before Approvals does anything: the space setting is the last of them. Until now, that gate applied to humans in the editor and not to the API, which meant a Jira automation rule, a docs pipeline or a Marketplace app could rewrite an "approved" page with no approval at all. Closing that gap is correct. It also means every integration that relied on the gap will start failing on a date you do not control.
The two lists to build now
- Spaces with the setting on. There is no site-level report for it. Space settings → Approvals → "Require approval before publishing", one space at a time, or ask space admins to confirm. Record the space key and who owns approvals there. If you have more than a few dozen spaces, start with the ones that hold controlled documents (policies, runbooks, release notes), because those are where someone turned it on deliberately.
- Integrations that write pages. Four places to look: Jira automation rules with a Create Confluence page or page-update action (Global Automation → filter by action); Confluence automation rules that edit pages; Marketplace apps with write scopes (Atlassian Administration → Apps, then each app's permissions for
write:page:confluence or write:content:confluence); and anything with an API token, which is the one you cannot see from the console and have to ask about (CI pipelines that publish docs, scripts that stamp review dates, connectors from other tools).
Where list 1 and list 2 intersect is the change. Everything else keeps working.
What the integration owner has to do
The new sequence is: save the change as a draft, put the draft through the space's approval, then publish the approved draft. The draft and publish steps exist in the API today (?status=draft on the content endpoints, the v2 pages endpoints with draft status); the approval step is the human one, and it means an integration can no longer be "fire and forget" into a gated space. Two honest designs: route the integration's writes into a staging space without the requirement, and let a human move approved content across; or keep the writes in place and accept that each one now creates an approval request for the space's reviewers, which is the behaviour the space admin asked for when they turned the setting on.
What to tell people now, before the date
To space admins with the setting on: "API writes into this space will need approval too; tell me what integrations write here." To integration owners: "If you write to a space that requires approval, expect 409 on direct updates; here is the draft-approve-publish sequence." To the change calendar: an entry with no date, marked "watch the changelog", because the date will arrive on the changelog entry and nowhere else.
Checklist
- List spaces with Require approval before publishing on.
- List integrations that update pages (rules, apps, tokens).
- Intersect; that is the change set.
- For each, decide staging space or draft-approve-publish.
- Handle 409 explicitly in the integration, with the page id and space key in the error, so the first failure is a ticket rather than a mystery.
- Watch the changelog entry for the date.
Verified against the Confluence Cloud changelog and the Approvals space settings documentation on 30 September 2026.