OAuth · Approve authorization
Approves the pending OAuth authorization from the dashboard consent screen (Passport session endpoint).
auth_token is the single-use nonce the authorize redirect handed to the dashboard (GET /oauth/authorize → 302 to {front}/oauth/authorize?auth_token=…). It is bound to the web session: this endpoint needs the dashboard session cookie plus X-XSRF-TOKEN — a personal access token never authenticates it.
Body (JSON):
auth_token— the nonce above. Passport compares it with the session and answers a missing or stale one with its own 403.read_only(boolean, required) — the level the consent screen’s selector chose:trueonly reads,falsereads and makes changes. It is stored for the user and this client once the code is issued, and preselects it on the next consent screen for the same app. Any other field in the body is rejected (422).
Responses:
- With
Accept: application/json(what the SPA sends): 200{"redirect": url}— the client callback carryingcodeandstate. The SPA navigates there itself, top level, because a cross-origin XHR cannot follow a 302 to the client’s origin (ConvertsAuthorizationRedirectToJson). - Without it (plain navigation): 302 with the same URL in
Location. - Expired, unknown or reused
auth_token: 403 — the nonce is single use, and the SPA renders its own invalid state for this status. read_onlymissing or not a boolean: 422 — the request stays pending and can be retried with the sameauth_token.- While an administrator impersonates the user: 404 with
Credentials cannot be created while impersonating a user.— approving is refused outright, whateverread_onlywas sent.
Host root, no /api prefix.
Request
This endpoint expects an object.
auth_token
read_only
Response
200 OK · redirect as data
redirect
Errors
403
Forbidden Error
422
Unprocessable Entity Error
