---
title: "Describe an authorization request"
url: https://docs.truemarkets.co/api/auth/oauth-authorize-details
description: "What the consent screen renders: who is asking, for what, and whether"
---

Docs index: https://docs.truemarkets.co/llms.txt

# Describe an authorization request

```
GET https://api.truemarkets.co/v1/auth/oauth/authorize/details
```

What the consent screen renders: who is asking, for what, and whether
we vouch for the name.

It validates the same request `/oauth/authorize` did, so the screen
cannot be made to describe a grant that would not actually be issued.

`unverified` is true for a client that registered itself and chose its
own name. `redirect_host` is shown beside the name because the host is
the part a client cannot assert freely.

## Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `client_id` | query | string | yes |  |
| `redirect_uri` | query | string (uri) | yes |  |
| `response_type` | query | string, one of `code` | yes |  |
| `code_challenge` | query | string | yes |  |
| `code_challenge_method` | query | string, one of `S256` | yes |  |
| `resource` | query | string (uri) | yes |  |
| `scope` | query | string | no |  |
| `state` | query | string | no |  |

## Responses

Every error status returns the same body, described in [Errors](https://docs.truemarkets.co/developer-resources/errors.md).

### 200

The request as the consent screen should present it

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `client_id` | string | yes |  |
| `client_name` | string | yes | Always the client's own claim; the callback host is not. |
| `redirect_host` | string | yes | Host of the callback this grant would be returned to. |
| `scopes` | array of string | yes |  |
| `vendor` | string | yes | The allowlist family whose rule admitted this client. |
| `verification` | string, one of `vendor`, `local` | yes | What the authorization server can vouch for, based on where the grant is delivered rather than on the name. `vendor` — the callback belongs to a recognised host, so only that vendor can receive the code. `local` — a loopback callback, so a program on the user's own machine, which cannot be identified further. |
| `dynamically_registered` | boolean | yes | True for a self-registered client, whose name is its own unvetted claim; the consent screen labels the name accordingly. |

### 400

The authorize request does not validate.

### 401

The client is unknown or disabled.
