OAuth

Approve or deny a pending client inline (approval-pending page)

Thin wrapper over the admin approval path for the approval-pending page.

Authorization is byte-identical to POST /admin/oauth-clients/{id}:approve / :deny (oauth-clients:write, org:admin implies it) and the decision itself is the SAME OAuthClientService.approve/deny calls — same audit records, same D7 active/approval_status coupling; this endpoint only translates the signed state blob into the client row. CSRF posture matches the consent POST: no ambient credential is honored — the browser must explicitly present the SPA bearer token, which a cross-site form cannot do.

post/oauth/approval/decision

Request body

action'approve' | 'deny' required
statestring required

Response

Successful Response

status'pending' | 'approved' | 'denied' required

Changes

Changed in 1 of the 114 revisions of this API.1