Skip to main content

ConsentRequest

The employee's decision, posted by the consent page. clientId and redirectUri are required in practice — a request missing either is rejected as invalid_request.

clientIdstring

The application being approved or refused.

Example: uysot_app_9f86d081884c7d659a2f
redirectUristring

Must be one the application registered, and match what the flow started with.

Example: https://claude.ai/api/mcp/auth_callback
statestringnullable

Echoed onto the redirect when present.

approvedGrants object[]

The grants the employee approved. Must be non-empty and within the application's allowed set when approved is true; ignored on refusal.

  • Array [
  • permissionOpenApiPermission

    The resource the grant applies to.

    Possible values: [PERMISSION_OPEN_API_LEAD, PERMISSION_OPEN_API_LEAD_NOTE, PERMISSION_OPEN_API_LEAD_TASK, PERMISSION_OPEN_API_CONTRACT, PERMISSION_OPEN_API_CONTRACT_PAYMENT, PERMISSION_OPEN_API_BOOKING, PERMISSION_OPEN_API_CALL, PERMISSION_OPEN_API_MCP]

    scopeOpenApiScope

    The action allowed on that resource.

    Possible values: [READ, SAVE, DELETE]

  • ]
  • approvedboolean

    false means the employee refused — the redirect carries error=access_denied.

    Default value: true
    Example: true
    codeChallengestringnullable

    PKCE challenge, passed through unchanged from the authorize query. Required for a public client; dropping it leaves the client holding a verifier that matches nothing.

    codeChallengeMethodstringnullable

    PKCE method, passed through unchanged. Only S256 is accepted.

    Example: S256
    ConsentRequest
    {
    "clientId": "uysot_app_9f86d081884c7d659a2f",
    "redirectUri": "https://claude.ai/api/mcp/auth_callback",
    "state": "string",
    "approvedGrants": [
    {
    "permission": "PERMISSION_OPEN_API_LEAD",
    "scope": "READ"
    }
    ],
    "approved": true,
    "codeChallenge": "string",
    "codeChallengeMethod": "S256"
    }