OAuth consent: allow
The API of the console's OAuth consent page, which an MCP client's authorization request sends a person to. First-party browser only: both the request URL origin and the exact Origin header must match the console origin, and submissionToken is the proof from the consent page URL's fragment, so it never travels in a URL. Allowing, continuing without an account and denying each answer the redirect to send the browser to, and answer it again, byte for byte, when repeated with the same proof. Console session only: the person signed in to this browser connects the client to one of their accounts, with the grant they choose. A management key or an OAuth access token is refused with 403 session_required.
Authorization
ConsoleSession The console's session cookie. Admin requests from the console also send x-console-request: 1.
In: cookie
Path Parameters
The authorization's id.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/console/oauth/string/allow" \ -H "Content-Type: application/json" \ -d '{ "submissionToken": "string", "organizationId": "string", "grant": "read" }'{ "redirect": "string"}