---
title: "Poll client approval status (approval-pending page)"
method: GET
path: "/oauth/approval/status"
tags: ["OAuth"]
---

# Poll client approval status (approval-pending page)

`GET /oauth/approval/status`

Minimal tri-state poll for the approval-pending page.

Anonymous but keyed by the signed approval-state blob — never a bare
client_id, so the endpoint cannot be used to enumerate registrations. Any
verification failure (bad signature, wrong purpose, expired ``iat``,
malformed blob) is a 400 ``invalid_grant``; the page reacts to a 400 by
re-running /authorize, which mints a fresh blob. The response carries ONLY
the tri-state — no names, redirect URIs, or metadata.

## Query parameters

- `st` string, required — Signed approval-state blob minted by /authorize

## Response `200`

Successful Response

- OAuthApprovalStatusResponse — Minimal tri-state approval status for a pending-client authorize request. Deliberately carries nothing else — no client name, redirect URIs, or metadata — so the anonymous poll endpoint cannot be used to read client details out of the registry.
  - `status` 'pending' | 'approved' | 'denied', required

## Other responses

- `400` — Malformed, tampered, or expired approval-state blob.
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-09-07** `97a326fd99b4` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/oauth/approval/status/get.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc.dev/jentic/apis/jentic-control-plane-api/revisions/e4688b93dfc7?raw)
