AlmondTill/G3N API

ConnectorAuthorizationReview

object type

A VALIDATED connector authorize request, resolved for the consent face: the client's words + the redirect host PROMINENT (the consent MUST) + the RFC 8252 loopback flag + the scope story + YOUR eligible orgs. An invalid request REFUSES typed and the face shows the error — the wire never builds a redirect from an unvalidated request (the open-redirect law).

Fields

FieldTypeNotes
clientIdString String!The presented client_id — a dcr_… registration or a CIMD https URL (the identity the grant will bind to).
clientNameStringThe client's self-declared display name (absent when the registration carried none — show the clientId).
clientSourceString String!Where the client's identity came from: dcr (a registered row) or cimd (a fetched client-metadata document).
redirectUriString String!The EXACT redirect the browser will be sent to on approve/deny (already matched against the client's registered URIs — loopback matches port-agnostic per RFC 8252).
redirectHostString String!The redirect's host, for PROMINENT display (the spec's consent MUST: the user sees where the code goes).
loopbackBoolean Boolean!True when the redirect is an RFC 8252 loopback (a local program on the approver's machine will receive the code — the face carries the extra warning).
scopeString String!The scope the grant will carry (v1: almondtill:read — the read-only integration template; the minted key's descriptors are the law server-side).
offlineAccessBoolean Boolean!True when the client asked for offline_access (a refresh token — the connector stays signed in without re-consent until revoked).
resourceString String!The RFC 8707 resource the tokens will be bound to (the canonical MCP endpoint).
eligibleOrgsConnectorAuthorizationOrg [ConnectorAuthorizationOrg!]!YOUR eligible acting orgs (ACTIVE + owned by your account), sysId-ordered — the consent names exactly ONE.

Used by