# The App Install object

### The App Install object

```json
{
  "id": "appinst_test_61VGZmT4pXc8Rk2w41LUZiLcTVChK7Ab",
  "object": "apps.install",
  "account": "acct_1LQeGxLUZiLcTVCh",
  "app": "app_61VGZkQ7mRbN3xPa41LUZiLcTVChQ9Ye",
  "approval_required": false,
  "auth_code": null,
  "channel": "public",
  "content_security_policy_granted": {
    "connect_src": [
      "https://api.example.com/"
    ],
    "image_src": [
      "https://cdn.example.com/"
    ]
  },
  "content_security_policy_pending": {
    "connect_src": [],
    "image_src": []
  },
  "created": 1725000000,
  "created_by": null,
  "endpoints_granted": [
    "https://example.com/stripe/webhook"
  ],
  "endpoints_pending": [],
  "livemode": false,
  "permissions_granted": [
    "customer_read",
    "event_read"
  ],
  "permissions_pending": [],
  "status": "installed"
}
```

## Attributes

- `id` (string)
  Unique identifier for the object.

- `object` (string, value is "apps.install")
  String representing the object’s type. Objects of the same type share the same value.

- `account` (string)
  The ID of the account that the app install belongs to.

- `app` (string)
  The ID of the app installed.

- `approval_required` (boolean)
  Whether the installer must authorize pending permissions, content security policy entries, or endpoints. For private apps, `approval_required` stays `false`; creating or reauthorizing the install through the API installs the newest completed upload and grants its permissions.

- `auth_code` (string, nullable)
  The authorization code for an oauth app install.

- `channel` (enum)
  The distribution channel associated with the app install.
Possible enum values:
  - `private_live`
    A private app installed in live mode.

  - `private_test`
    A private app installed in test mode.

  - `public`
    The published version of the app.

  - `review`
    The app as installed by Stripe for app review.

  - `testing`
    A pre-release version of the app installed for external testing.

- [`content_security_policy_granted`](https://docs.stripe.com/api/apps/installs/object.md?query=content_security_policy_granted) (object)
  The content security policy entries authorized by the installer.

- [`content_security_policy_pending`](https://docs.stripe.com/api/apps/installs/object.md?query=content_security_policy_pending) (object)
  The content security policy entries requested by the latest app version that the installer has not authorized.

- `created` (timestamp)
  Time at which the object was created. Measured in seconds since the Unix epoch.

- `created_by` (string, nullable)
  The ID of the embedding platform that created the install, if applicable.

- `endpoints_granted` (array of strings)
  The endpoint URLs authorized by the installer.

- `endpoints_pending` (array of strings)
  The endpoint URLs requested by the latest app version that the installer has not authorized.

- `livemode` (boolean)
  If the object exists in live mode, the value is `true`. If the object exists in test mode, the value is `false`.

- `permissions_granted` (array of strings)
  The permissions authorized by the installer.

- `permissions_pending` (array of strings)
  The permissions requested by the latest app version that the installer has not authorized.

- `status` (enum)
  The status of the app install.
Possible enum values:
  - `install_failed`
    The install did not complete. The app cannot be used.

  - `installed`
    The app is installed and can be used. Access that the installer has not authorized yet is listed in the pending fields.

  - `installing`
    The install is in progress.

  - `uninstall_failed`
    The uninstall did not complete.

  - `uninstalling`
    The uninstall is in progress.
