---
title: "Poll pending-agent approval status (consent awaiting page)"
method: GET
path: "/oauth/consent/agent/status"
tags: ["OAuth"]
---

# Poll pending-agent approval status (consent awaiting page)

`GET /oauth/consent/agent/status`

Minimal tri-state poll for the pending-agent awaiting page (P4 hybrid).

Anonymous but keyed by the signed ``agent-status`` blob — never a bare
agent id, so the endpoint cannot be used to enumerate or probe agents:
the id it reports on is the one SIGNED into the blob, which only the
consent flow mints, and only for an agent it verified belongs to the
handle's subject. The response carries ONLY the tri-state — no name,
owner, or scopes — and non-terminal lifecycle states (disabled, archived,
a vanished row) all read as ``pending``, so possession of a blob is not a
lifecycle oracle either. Any verification failure (bad signature, wrong
purpose, expired ``iat``, malformed blob) is a 400 ``invalid_grant``; the
page treats a 400 as terminal ("retry the connection") because the blob
shares the consent handle's lifetime — a retry re-enters the flow, which
re-parks on a fresh awaiting page while the agent stays pending. Shares
the approval-status poll's own per-IP rate bucket (same cadence, same
caller shape).

## Query parameters

- `st` string, required — Signed agent-status blob minted by the consent flow's pending arm

## Response `200`

Successful Response

- ConsentAgentStatusResponse — Minimal tri-state for the consent page's pending-agent awaiting page (P4). Deliberately carries nothing else — no agent name, owner, or scopes — so the anonymous poll endpoint cannot be used to read agent details. The poll is keyed by a signed ``agent-status`` blob bound to one agent id, never a bare id, and non-terminal lifecycle states (disabled, archived, a vanished row) all read as ``pending`` so the endpoint is not a lifecycle oracle either.
  - `status` 'pending' | 'approved' | 'denied', required

## Other responses

- `400` — Malformed, tampered, or expired agent-status blob.
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-09-10** `cfb8387e3e80` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/oauth/consent/agent/status/get.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc.dev/jentic/apis/jentic-control-plane-api/revisions/e4688b93dfc7?raw)
