OAuth

Poll pending-agent approval status (consent awaiting page)

Minimal tri-state poll for the pending-agent awaiting page (P4 hybrid).

Anonymous but keyed by the signed agent-status blob — never a bare agent id, so the endpoint cannot be used to enumerate or probe agents: the id it reports on is the one SIGNED into the blob, which only the consent flow mints, and only for an agent it verified belongs to the handle's subject. The response carries ONLY the tri-state — no name, owner, or scopes — and non-terminal lifecycle states (disabled, archived, a vanished row) all read as pending, so possession of a blob is not a lifecycle oracle either. Any verification failure (bad signature, wrong purpose, expired iat, malformed blob) is a 400 invalid_grant; the page treats a 400 as terminal ("retry the connection") because the blob shares the consent handle's lifetime — a retry re-enters the flow, which re-parks on a fresh awaiting page while the agent stays pending. Shares the approval-status poll's own per-IP rate bucket (same cadence, same caller shape).

get/oauth/consent/agent/status

Query parameters

ststring required

Signed agent-status blob minted by the consent flow's pending arm

Signed agent-status blob minted by the consent flow's pending arm

Response

Successful Response

status'pending' | 'approved' | 'denied' required

Changes

Changed in 1 of the 114 revisions of this API.1