Skip to main content

Get Consent Context

GET 

/v1/open-api/oauth/authorize

Everything the consent page needs to render itself: which application is asking, its logo, which grants it wants, and whether this employee already approved it.

This is not the browser-facing authorization endpoint. The URL an OAuth client is sent to is the consent page, which is a frontend route; the page then calls this API to fill itself in. Opening this path in a browser only yields 401.

Authenticated with the employee's CRM session token as Authorization: Bearer <token>, not with an Open API token — the token is verified against the core service on every call. No particular employee permission is needed: being signed in is enough, because the company is taken from the verified token and never from the request, so an employee can only ever consent for their own company.

The request is validated before anything is shown: response_type must be code, the client_id must exist and not be suspended, the redirect_uri must be one the application registered, and every requested grant must be within the application's allowed set. A public client must also present a code_challenge.

code_challenge and code_challenge_method are echoed back unchanged so the page can put them straight into the consent body without parsing the query string itself.

Request​

Responses​

Context for the consent page.