On this page
connectorAuthorization
query · in the family System and integration setup
What it does
Review an AI-connector sign-in request (Claude, ChatGPT, …) — who is asking, where the sign-in code would be sent, and which of your organizations it could act in.
Validate + resolve ONE connector authorize request for the consent face: the client's words + the redirect host + YOUR eligible orgs. EVERY invalid request refuses typed (the face SHOWS the error and never redirects — the open-redirect law). OWNER-gated engine-side (the mintApiKey posture; consent is an owner act). Template class (integration config — off the floor).
What happens
Read-only; mints nothing. An invalid or unknown request shows the error here and never redirects anywhere.
Careful
OWNER-gated — connector consent is owner work.
Who may call it
Capability area: System and integration setup — Registers, connections and the settings your systems run on.
- Owner
- System Administrator
- An API key whose scope allows
api:connectorAuthorization
Arguments
| Name | Type | Required | Notes |
|---|---|---|---|
responseType | String String! | yes | No further notes. |
clientId | String String! | yes | No further notes. |
redirectUri | String String! | yes | No further notes. |
codeChallenge | String String! | yes | No further notes. |
codeChallengeMethod | String String! | yes | No further notes. |
state | String | no | No further notes. |
scope | String | no | No further notes. |
resource | String | no | No further notes. |
Returns
ConnectorAuthorizationReview ConnectorAuthorizationReview! — A VALIDATED connector authorize request, resolved for the consent face: the client's words + the redirect host PROMINENT (the consent MUST) + the RFC 8252 loopback flag + the scope story + YOUR eligible orgs. An invalid request REFUSES typed and the face shows the error — the wire never builds a redirect from an unvalidated request (the open-redirect law).
Example request
query ExampleConnectorAuthorization($responseType: String!, $clientId: String!, $redirectUri: String!, $codeChallenge: String!, $codeChallengeMethod: String!, $state: String) {
connectorAuthorization(responseType: $responseType, clientId: $clientId, redirectUri: $redirectUri, codeChallenge: $codeChallenge, codeChallengeMethod: $codeChallengeMethod, state: $state) {
clientId
clientName
clientSource
redirectUri
redirectHost
loopback
scope
offlineAccess
resource
}
}
Variables:
{
"responseType": "<response type>",
"clientId": "<client id>",
"redirectUri": "<redirect uri>",
"codeChallenge": "<code challenge>",
"codeChallengeMethod": "<code challenge method>",
"state": "<state>"
}
Example response
{
"data": {
"connectorAuthorization": {
"clientId": "<client id>",
"clientName": "Blue jeans",
"clientSource": "<client source>",
"redirectUri": "<redirect uri>",
"redirectHost": "<redirect host>",
"loopback": true,
"scope": "<scope>",
"offlineAccess": true,
"resource": "<resource>"
}
},
"extensions": {
"at": {
"callId": "01EXAMPLE-CALL-ID",
"version": {
"requested": null,
"serviced": {
"name": "genesis",
"number": 0
}
}
}
}
}
Errors this call can answer
VALIDATION/INVALID— Something in the request is not valid. (VALIDATION)AUTHN/REQUIRED— Sign in to do this. (AUTHN)AUTHZ/FORBIDDEN— Your role does not allow this action. (AUTHZ)RATE_LIMIT/THROTTLED— Too many requests in a short time. (RATE_LIMIT)