---
title: "Start an authorization request"
url: https://docs.truemarkets.co/api/auth/oauth-authorize
description: "The authorization endpoint (RFC 6749 4.1.1). A valid request is"
---

Docs index: https://docs.truemarkets.co/llms.txt

# Start an authorization request

```
GET https://api.truemarkets.co/v1/auth/oauth/authorize
```

The authorization endpoint (RFC 6749 4.1.1). A valid request is
redirected to the consent screen with its parameters intact; the
signed-in user's decision comes back through `/oauth/consent`.

Where a failure is reported depends on what failed. An unknown client
or an unregistered `redirect_uri` is answered here, because the only
target we could redirect to is the one we just refused to trust.
Everything else redirects back to the client with `error` and `state`
(RFC 6749 4.1.2.1).

PKCE is required and `code_challenge_method` must be `S256`.

## Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `client_id` | query | string | yes |  |
| `redirect_uri` | query | string (uri) | yes | Must match one the client registered, byte-for-byte outside loopback. |
| `response_type` | query | string, one of `code` | yes |  |
| `code_challenge` | query | string | yes | base64url SHA-256 of the client's code verifier. |
| `code_challenge_method` | query | string, one of `S256` | yes |  |
| `resource` | query | string (uri) | yes | RFC 8707 resource indicator; becomes the access token's audience. |
| `scope` | query | string | no | Space-delimited. Defaults to every scope the client registered for. |
| `state` | query | string | no | Echoed back unchanged so the client can detect an unsolicited response. |

## Responses

Every error status returns the same body, described in [Errors](https://docs.truemarkets.co/developer-resources/errors.md).

### 302

Redirect to the consent screen, or back to the client's `redirect_uri` carrying `error` and `state`.

### 400

Unknown client, or a redirect_uri the client did not register.

### 401

The client is unknown or disabled.
