Skip to main content

AuthorizeContextResponse

What the consent page renders: the application asking for access, the grants it wants, and whether this employee already approved it.

clientIdstring

The requesting application's client identifier.

Example: uysot_app_9f86d081884c7d659a2f
applicationNamestring

Application name, shown on the consent screen.

Example: Claude
applicationLogostringnullable

Absolute URL of the application logo. null when the application has none — the page then draws the first letter of the name instead.

Example: https://cdn.uysot.uz/open-api/logo/claude.png
requestedGrants object[]

The raw (permission, scope) pairs being requested. Translating them into sentences is the page's job.

  • Array [
  • permissionOpenApiPermission

    The resource the grant applies to.

    Possible values: [PERMISSION_OPEN_API_LEAD, PERMISSION_OPEN_API_LEAD_NOTE, PERMISSION_OPEN_API_LEAD_TASK, PERMISSION_OPEN_API_CONTRACT, PERMISSION_OPEN_API_CONTRACT_PAYMENT, PERMISSION_OPEN_API_BOOKING, PERMISSION_OPEN_API_CALL, PERMISSION_OPEN_API_MCP]

    scopeOpenApiScope

    The action allowed on that resource.

    Possible values: [READ, SAVE, DELETE]

  • ]
  • redirectUristring

    Where the browser will be sent once the decision is made.

    Example: https://claude.ai/api/mcp/auth_callback
    statestringnullable

    The client's opaque value, echoed back. null when none was sent.

    alreadyAuthorizedboolean

    Whether an active connection already exists. Which connection counts depends on the application's install scope — a company-scoped application asks whether the company is connected, an employee-scoped one whether this employee is.

    Example: false
    webhookEventsWebhookEvent[]

    Webhook events the application is subscribed to, so the page can disclose them. Empty when the application has no enabled webhook configuration.

    Possible values: [LEAD_CREATED, LEAD_ASSIGNED, LEAD_STAGE_CHANGED, LEAD_MERGED, LEAD_DELETED, LEAD_PROPERTIES_UPDATED, CALL_COMPLETED]

    codeChallengestringnullable

    The PKCE challenge from the authorize query, echoed unchanged. The page must send it back in the consent body verbatim.

    codeChallengeMethodstringnullable

    The PKCE method from the authorize query, echoed unchanged. S256 when present.

    Example: S256
    AuthorizeContextResponse
    {
    "clientId": "uysot_app_9f86d081884c7d659a2f",
    "applicationName": "Claude",
    "applicationLogo": "https://cdn.uysot.uz/open-api/logo/claude.png",
    "requestedGrants": [
    {
    "permission": "PERMISSION_OPEN_API_LEAD",
    "scope": "READ"
    }
    ],
    "redirectUri": "https://claude.ai/api/mcp/auth_callback",
    "state": "string",
    "alreadyAuthorized": false,
    "webhookEvents": [
    "LEAD_CREATED"
    ],
    "codeChallenge": "string",
    "codeChallengeMethod": "S256"
    }