# ConnectorAuthorizationReview

object type

A VALIDATED connector authorize request, resolved for the consent face: the client's words + the redirect host PROMINENT (the consent MUST) + the RFC 8252 loopback flag + the scope story + YOUR eligible orgs. An invalid request REFUSES typed and the face shows the error — the wire never builds a redirect from an unvalidated request (the open-redirect law).

## Fields

| Field | Type | Notes |
| --- | --- | --- |
| `clientId` | [String](/types/#scalars) `String!` | The presented client_id — a dcr_… registration or a CIMD https URL (the identity the grant will bind to). |
| `clientName` | [String](/types/#scalars) | The client's self-declared display name (absent when the registration carried none — show the clientId). |
| `clientSource` | [String](/types/#scalars) `String!` | Where the client's identity came from: dcr (a registered row) or cimd (a fetched client-metadata document). |
| `redirectUri` | [String](/types/#scalars) `String!` | The EXACT redirect the browser will be sent to on approve/deny (already matched against the client's registered URIs — loopback matches port-agnostic per RFC 8252). |
| `redirectHost` | [String](/types/#scalars) `String!` | The redirect's host, for PROMINENT display (the spec's consent MUST: the user sees where the code goes). |
| `loopback` | [Boolean](/types/#scalars) `Boolean!` | True when the redirect is an RFC 8252 loopback (a local program on the approver's machine will receive the code — the face carries the extra warning). |
| `scope` | [String](/types/#scalars) `String!` | The scope the grant will carry (v1: almondtill:read — the read-only integration template; the minted key's descriptors are the law server-side). |
| `offlineAccess` | [Boolean](/types/#scalars) `Boolean!` | True when the client asked for offline_access (a refresh token — the connector stays signed in without re-consent until revoked). |
| `resource` | [String](/types/#scalars) `String!` | The RFC 8707 resource the tokens will be bound to (the canonical MCP endpoint). |
| `eligibleOrgs` | [ConnectorAuthorizationOrg](/types/ConnectorAuthorizationOrg/) `[ConnectorAuthorizationOrg!]!` | YOUR eligible acting orgs (ACTIVE + owned by your account), sysId-ordered — the consent names exactly ONE. |

## Used by

- [connectorAuthorization](/reference/system-and-integration-setup/connectorAuthorization/)
