AlmondTill/G3N API

On this page

approveConnectorAuthorization

mutation · in the family System and integration setup

What it does

Approve or deny an AI-connector sign-in — approving mints a read-only integration key for ONE organization and sends the connector its sign-in code.

Decide ONE connector authorize request: the FULL params re-validate from scratch (the review is never trusted). APPROVE (orgId REQUIRED — an eligible org: ACTIVE + owned by you) mints a REAL ApiKey through the existing mintApiKey lane (the read-only integration descriptors AT APPROVE TIME; the 12-month ceiling; the caption carries the client) + the OAuth grant + the single-use PKCE-bound code, answering {redirectTo} with code+state+iss; DENY answers {redirectTo} with error=access_denied+state+iss (RFC 9207 — iss rides every response). Revoke later = the existing key doom. OWNER-gated engine-side (the mintApiKey posture VERBATIM). Template class (hand-derived v82).

What happens

The connector gets read access equal to the read-only key template (no writes, no AI spend); the key appears in your key list and dooming it disconnects the connector.

Careful

OWNER-gated. Approve names exactly ONE active organization you own; the redirect goes only to the client’s registered address.

Who may call it

Capability area: System and integration setup — Registers, connections and the settings your systems run on.

Arguments

NameTypeRequiredNotes
decisionString String!yesNo further notes.
orgIdIDnoNo further notes.
responseTypeString String!yesNo further notes.
clientIdString String!yesNo further notes.
redirectUriString String!yesNo further notes.
codeChallengeString String!yesNo further notes.
codeChallengeMethodString String!yesNo further notes.
stateStringnoNo further notes.
scopeStringnoNo further notes.
resourceStringnoNo further notes.

Returns

ConnectorAuthorizationVerdict ConnectorAuthorizationVerdict! — The consent verdict's redirect instruction: send the browser HERE — code+state+iss on approve, error=access_denied+state+iss on deny (RFC 9207: iss rides EVERY authorization response).

Example request

mutation ExampleApproveConnectorAuthorization($decision: String!, $orgId: ID, $responseType: String!, $clientId: String!, $redirectUri: String!, $codeChallenge: String!, $codeChallengeMethod: String!) {
  approveConnectorAuthorization(decision: $decision, orgId: $orgId, responseType: $responseType, clientId: $clientId, redirectUri: $redirectUri, codeChallenge: $codeChallenge, codeChallengeMethod: $codeChallengeMethod) {
    redirectTo
  }
}

Variables:

{
  "decision": "<decision>",
  "orgId": "01900000-0000-7000-8000-b0cf4f3c0000",
  "responseType": "<response type>",
  "clientId": "<client id>",
  "redirectUri": "<redirect uri>",
  "codeChallenge": "<code challenge>",
  "codeChallengeMethod": "<code challenge method>"
}

Send it with the envelope naming the version: "extensions": {"at": {"version": {"name":"genesis","number":0}}}.

Example response

{
  "data": {
    "approveConnectorAuthorization": {
      "redirectTo": "<redirect to>"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": {
          "name": "genesis",
          "number": 0
        },
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}

Errors this call can answer

Used in