The stage-level input directive pauses before a stage until someone answers: a message, an id, the ok button text, a submitter list of users or groups, a submitterParameter that records who approved, and parameters to ask for. In decl-input, an agent none pipeline, a Build stage comes first:
stage('Deploy to production') {
options { timeout(time: 30, unit: 'MINUTES') }
input {
message 'Deploy BookNest to production?'
id 'Approve'
ok 'Deploy'
submitter 'admin'
submitterParameter 'APPROVER'
parameters { choice(name: 'STRATEGY', choices: ['rolling', 'blue-green']) }
}
agent { label 'linux' }
steps { echo "Deploying with ${STRATEGY}, approved by ${APPROVER}" }
}The build stops at "Input requested", and its Paused for Input page shows the form:

While it waited, agent-1 was idle: the stage's agent is allocated only after the answer. A script approves by posting to the input's URL:
J=http://localhost:32080; AUTH="admin:$JENKINS_TOKEN"
curl -s -u "$AUTH" -X POST $J/job/decl-input/1/input/Approve/submit \
--data-urlencode 'json={"parameter":[{"name":"STRATEGY","value":"blue-green"}]}' \
--data-urlencode 'proceed=Deploy'
sleep 8
curl -s -u "$AUTH" $J/job/decl-input/1/consoleText | sed -n '/Input requested/,$p'Input requested Approved by BookNest Admin ... Deploying with blue-green, approved by admin
Always pair input with a timeout in the stage's options, or an unanswered prompt keeps the build open forever. Keep the wait outside any agent (a top-level agent { label 'linux' } would hold agent-1's only executor throughout), and restrict submitter so that people who can push code cannot also release it.