GETpartial

Review an application’s authorization request in the browser

Browser-rendered HTML consent page, not a JSON API. Open this URL in the user’s browser to sign in and review the requested scopes, Rules and disclosure. The page uses the session-authenticated authorization operation to prepare and approve the request, then JavaScript navigates to the registered redirect URI with the authorization result and state. The document GET does not return an HTTP callback redirect. API clients exchange the returned code at /api/oauth/token. Open the approvalUrl returned by a hosted-link request unchanged; it contains only link and loads the saved authorization inputs. Otherwise, supply all eight direct-request fields: response_type, client_id, redirect_uri, scope, resource, code_challenge, code_challenge_method and state. The parameters are individually optional here because the linked and direct forms are alternatives. Direct partner requests also require case_id or standing_offer=true. A party selection requires case_id. Non-connector requests for the hosted MCP resource require case_id; connector clients use their registered MCP resource and cannot request standing authority.

/oauth/authorizeauthorizeAccountOAuthInBrowser

Authentication and authority

No bearer credential is required.

Parameters

NameLocationRequirementSchema
link

Hosted-link identifier from the returned approvalUrl. Replaces the direct-request fields; use the complete returned URL unchanged.

queryOptional{"type":"string","example":"pco_link.dXNlcl90ZXN0.example"}
response_type

Required for direct authorization without link.

queryOptional{"type":"string","const":"code"}
client_id

Registered client identifier. Required for direct authorization without link.

queryOptional{"type":"string"}
redirect_uri

Redirect URI accepted by the client’s registration. Required for direct authorization without link.

queryOptional{"type":"string","format":"uri"}
scope

Space-separated scopes within the client’s registered authority. Required for direct authorization without link.

queryOptional{"type":"string","example":"cases:read offline_access"}
resource

Exact API or hosted MCP resource for the requested token. Required for direct authorization without link.

queryOptional{"type":"string","format":"uri","example":"https://peoplescourt.ai/api"}
code_challenge

Base64url SHA-256 PKCE challenge without padding. Required for direct authorization without link.

queryOptional{"type":"string","pattern":"^[A-Za-z0-9_-]{43}$","example":"E9Melhoa2OwvFrEMTJguCHaoeK1t8URWbuGJSstw-cM"}
code_challenge_method

Required for direct authorization without link.

queryOptional{"type":"string","const":"S256"}
state

Caller-generated state returned unchanged for callback verification. Required for direct authorization without link.

queryOptional{"type":"string","minLength":1,"maxLength":1024}
case_id

Existing case to delegate. Required for non-connector hosted MCP access and for partner access without a standing offer.

queryOptional{"type":"string"}
party

Side to delegate within case_id. The signed-in account’s membership must authorize that side.

queryOptional{"type":"string","enum":["claimant","respondent"]}
standing_offer

Use true to offer bounded standing authority for a direct partner request without case_id. The person must separately approve the displayed bounds; this parameter grants no authority. Connector clients cannot request it.

queryOptional{"type":"boolean","default":false}

Responses

200

HTML page for sign-in and authorization review.

text/html

{
  "type": "string"
}
403

HTML authorization page for a signed-in account that must verify its email before proceeding.

text/html

{
  "type": "string"
}

Example response

Successful response

"response_test"

Errors

Read the response status and stable error code. See errors and rate limits for recovery. Refresh the resource before resolving a state or digest conflict.

Idempotency and retries

  • For throttling, honor Retry-After when present. Back off on retryable server failures.