OAuth · Deny authorization
Denies the pending OAuth authorization from the dashboard consent screen (Passport session endpoint).
Same contract as the approve: single-use auth_token, dashboard session cookie plus X-XSRF-TOKEN.
Responses:
- With
Accept: application/json: 200{"redirect": url}— the client callback carryingerror=access_deniedandstate, delivered to the client the same way it receives a code (the SPA navigates top level). - Without it: 302 with the same URL in
Location. - Expired, unknown or reused
auth_token: 403.
Host root, no /api prefix.
Request
This endpoint expects an object.
auth_token
Response
200 OK · denial redirect
redirect
