Skip to navigation

OAuth · Approve authorization

View as MarkdownOpen in Claude

Approves the pending OAuth authorization from the dashboard consent screen (Passport session endpoint).

auth_token is the single-use nonce the authorize redirect handed to the dashboard (GET /oauth/authorize → 302 to {front}/oauth/authorize?auth_token=…). It is bound to the web session: this endpoint needs the dashboard session cookie plus X-XSRF-TOKEN — a personal access token never authenticates it.

Body (JSON):

  • auth_token — the nonce above. Passport compares it with the session and answers a missing or stale one with its own 403.
  • read_only (boolean, required) — the level the consent screen’s selector chose: true only reads, false reads and makes changes. It is stored for the user and this client once the code is issued, and preselects it on the next consent screen for the same app. Any other field in the body is rejected (422).

Responses:

  • With Accept: application/json (what the SPA sends): 200 {"redirect": url} — the client callback carrying code and state. The SPA navigates there itself, top level, because a cross-origin XHR cannot follow a 302 to the client’s origin (ConvertsAuthorizationRedirectToJson).
  • Without it (plain navigation): 302 with the same URL in Location.
  • Expired, unknown or reused auth_token: 403 — the nonce is single use, and the SPA renders its own invalid state for this status.
  • read_only missing or not a boolean: 422 — the request stays pending and can be retried with the same auth_token.
  • While an administrator impersonates the user: 404 with Credentials cannot be created while impersonating a user. — approving is refused outright, whatever read_only was sent.

Host root, no /api prefix.

Request

This endpoint expects an object.
auth_tokenstringOptional
read_onlybooleanOptional

Response

200 OK · redirect as data

redirectstringOptional

Errors

403
Forbidden Error
422
Unprocessable Entity Error