oauth

Handles `/consent` approval after the user agrees to grant requested scopes.

This endpoint:

  • Validates the redirect URI and requested scopes against the registered client.
  • Records granted scopes for the user-client pair.
  • Redirects back to /authorize to continue the OAuth flow.

Example

GET /api/v0/main-frontend/oauth/consent?client_id=test-client-id&redirect_uri=http://localhost&scopes=openid%20profile&state=random123&nonce=secure_nonce_abc HTTP/1.1
Cookie: session=abc123

Redirect back to /authorize:

HTTP/1.1 302 Found
Location: /api/v0/main-frontend/oauth/authorize?client_id=...
post/api/v0/main-frontend/oauth/consent

Request

  • The document declares no server URL.
  • Auth: none declared

Request body

client_idstring required
code_challengestring nullable
code_challenge_methodstring nullable
noncestring required
redirect_uristring required
response_typestring required
scopestring required
statestring required

Response

Consent approval response

redirect_uristring required

Changes

No recorded changes to this operation across all 49 revisions of this API.