---
title: "Preview current account permissions in selected workspaces."
method: POST
path: "/mcp/oauth/authorize/permissions"
tags: ["MCP OAuth"]
---

# Preview current account permissions in selected workspaces.

`POST /mcp/oauth/authorize/permissions`

Read-only authenticated preview. The request token stays in the body. Each workspace must pass current membership and MCP availability checks.

## Request body

- McpOAuthAuthorizationPermissionsRequest
  - `requestToken` string, required
  - `organizationIds` string[], required

## Response `200`

Available scope ceiling and per-workspace scopes. Response is not cacheable.

- McpOAuthAuthorizationPermissions
  - `scopes` string[], required
  - `workspaces` object[], required
    - `organizationId` string, uuid, required
    - `scopes` string[], required

## Other responses

- `400` — Request failed boundary validation.
- `401` — Invalid, expired, or revoked API key.
- `403` — Key or OAuth grant lacks the required scope.

## Changes

- **2026-09-24** `3dde15782092` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/windmill-growth/apis/traxy-customer-api-and-mcp-v1/changes/mcp/oauth/authorize/permissions/post.md)

---

[API](https://skmtc.dev/windmill-growth/apis/traxy-customer-api-and-mcp-v1.md) · [All operations](https://skmtc.dev/windmill-growth/apis/traxy-customer-api-and-mcp-v1/llms.txt) · [OpenAPI document](https://skmtc.dev/windmill-growth/apis/traxy-customer-api-and-mcp-v1/revisions/3dde15782092?raw)
