For AI agents: the documentation index is at /llms.txt, and this page is available as Markdown at /api/auth/oauth-authorize.md.
Start an authorization request
GET/oauth/authorize
The authorization endpoint (RFC 6749 4.1.1). A valid request is
redirected to the consent screen with its parameters intact; the
signed-in user's decision comes back through /oauth/consent.
Where a failure is reported depends on what failed. An unknown client
or an unregistered redirect_uri is answered here, because the only
target we could redirect to is the one we just refused to trust.
Everything else redirects back to the client with error and state
(RFC 6749 4.1.2.1).
PKCE is required and code_challenge_method must be S256.
Request
Responses
- 302
- 400
- 401
Redirect to the consent screen, or back to the client's
redirect_uri carrying error and state.
Response Headers
Unknown client, or a redirect_uri the client did not register.
The client is unknown or disabled.