Submit Consent
POST/v1/open-api/oauth/authorize/consent
Records the employee's decision and returns the URL the page must send the browser to.
This endpoint never redirects by itself — it answers with redirectTo and the page
navigates.
On approval an authorization code is issued and redirectTo carries code (and
state, when one was supplied); the code is single-use and expires in 10 minutes. On
refusal (approved: false) redirectTo carries error=access_denied instead, and no
code is created.
codeChallenge and codeChallengeMethod must be passed through unchanged from the
authorize query. Dropping them silently breaks the client: it holds a verifier the code
was never bound to and cannot complete the exchange.
Authenticated with the employee's CRM session token, exactly like
GET /v1/open-api/oauth/authorize. The company is taken from the verified token.
Request
Responses
- 200
- 400
- 401
- 429
The decision was recorded; navigate the browser to redirectTo.
Invalid request (400). messageCode 6907 — clientId or redirectUri is
missing, the client is unknown, or a public client omitted codeChallenge; 6902 —
the redirectUri is not registered; 6904 — approvedGrants is empty or contains
a grant outside the application's allowed set; 6916 — the application is
suspended.
Missing or invalid employee CRM token (401, messageCode 6204).
Too many OAuth requests from this IP (429).