OAuth consent: continue without an account
The API of the console's OAuth consent page, which an MCP client's authorization request sends a person to. First-party browser only: both the request URL origin and the exact Origin header must match the console origin, and submissionToken is the proof from the consent page URL's fragment, so it never travels in a URL. Allowing, continuing without an account and denying each answer the redirect to send the browser to, and answer it again, byte for byte, when repeated with the same proof. Creates an account nobody has claimed yet, owned by the connection's own service identity, and connects the client to it with the manage grant whatever it asked for. Admitted where the deployment allows a new unclaimed account — always on the hosted service, where it is deleted unless a person claims it, and on a self-hosted deployment only while it is empty — and counted per network address with the CLI's account creation. Repeating it for the same authorization answers the same account.
Path Parameters
The authorization's id.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/console/oauth/string/guest" \ -H "Content-Type: application/json" \ -d '{ "submissionToken": "string" }'{ "redirect": "string"}