HTML page for sign-in and authorization review.
text/html
{
"type": "string"
}Browser-rendered HTML consent page, not a JSON API. Open this URL in the user’s browser to sign in and review the requested scopes, Rules and disclosure. The page uses the session-authenticated authorization operation to prepare and approve the request, then JavaScript navigates to the registered redirect URI with the authorization result and state. The document GET does not return an HTTP callback redirect. API clients exchange the returned code at /api/oauth/token. Open the approvalUrl returned by a hosted-link request unchanged; it contains only link and loads the saved authorization inputs. Otherwise, supply all eight direct-request fields: response_type, client_id, redirect_uri, scope, resource, code_challenge, code_challenge_method and state. The parameters are individually optional here because the linked and direct forms are alternatives. Direct partner requests also require case_id or standing_offer=true. A party selection requires case_id. Non-connector requests for the hosted MCP resource require case_id; connector clients use their registered MCP resource and cannot request standing authority.
/oauth/authorizeauthorizeAccountOAuthInBrowserNo bearer credential is required.
| Name | Location | Requirement | Schema |
|---|---|---|---|
linkHosted-link identifier from the returned approvalUrl. Replaces the direct-request fields; use the complete returned URL unchanged. | query | Optional | {"type":"string","example":"pco_link.dXNlcl90ZXN0.example"} |
response_typeRequired for direct authorization without link. | query | Optional | {"type":"string","const":"code"} |
client_idRegistered client identifier. Required for direct authorization without link. | query | Optional | {"type":"string"} |
redirect_uriRedirect URI accepted by the client’s registration. Required for direct authorization without link. | query | Optional | {"type":"string","format":"uri"} |
scopeSpace-separated scopes within the client’s registered authority. Required for direct authorization without link. | query | Optional | {"type":"string","example":"cases:read offline_access"} |
resourceExact API or hosted MCP resource for the requested token. Required for direct authorization without link. | query | Optional | {"type":"string","format":"uri","example":"https://peoplescourt.ai/api"} |
code_challengeBase64url SHA-256 PKCE challenge without padding. Required for direct authorization without link. | query | Optional | {"type":"string","pattern":"^[A-Za-z0-9_-]{43}$","example":"E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM"} |
code_challenge_methodRequired for direct authorization without link. | query | Optional | {"type":"string","const":"S256"} |
stateCaller-generated state returned unchanged for callback verification. Required for direct authorization without link. | query | Optional | {"type":"string","minLength":1,"maxLength":1024} |
case_idExisting case to delegate. Required for non-connector hosted MCP access and for partner access without a standing offer. | query | Optional | {"type":"string"} |
partySide to delegate within case_id. The signed-in account’s membership must authorize that side. | query | Optional | {"type":"string","enum":["claimant","respondent"]} |
standing_offerUse true to offer bounded standing authority for a direct partner request without case_id. The person must separately approve the displayed bounds; this parameter grants no authority. Connector clients cannot request it. | query | Optional | {"type":"boolean","default":false} |
HTML page for sign-in and authorization review.
text/html
{
"type": "string"
}HTML authorization page for a signed-in account that must verify its email before proceeding.
text/html
{
"type": "string"
}"response_test"Read the response status and stable error code. See errors and rate limits for recovery. Refresh the resource before resolving a state or digest conflict.
Retry-After when present. Back off on retryable server failures.