---
title: "Record a consent decision"
url: https://docs.truemarkets.co/api/auth/oauth-consent
description: "The signed-in user's answer to the consent screen. Approving records"
---

Docs index: https://docs.truemarkets.co/llms.txt

# Record a consent decision

```
POST https://api.truemarkets.co/v1/auth/oauth/consent
```

The signed-in user's answer to the consent screen. Approving records
the grant and mints an authorization code; denying returns the client
to its redirect with `error=access_denied`.

The authorize parameters are repeated here and validated again, because
nothing but the user's browser carries them between the two requests.

Returns where the browser should go rather than redirecting, since the
consent screen issues this as a fetch.

## Authentication

Bearer token in `Authorization`

## Request body

`application/json`, required

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `approved` | boolean | no | False returns the client to its redirect with access_denied. |
| `client_id` | string | yes |  |
| `redirect_uri` | string (uri) | yes |  |
| `response_type` | string, one of `code` | yes |  |
| `scope` | string | no |  |
| `state` | string | no |  |
| `code_challenge` | string | yes |  |
| `code_challenge_method` | string, one of `S256` | yes |  |
| `resource` | string (uri) | yes |  |

Example:

```json
{
  "approved": true,
  "client_id": "string",
  "redirect_uri": "string",
  "response_type": "code",
  "scope": "string",
  "state": "string",
  "code_challenge": "string",
  "code_challenge_method": "S256",
  "resource": "string"
}
```

## Responses

Every error status returns the same body, described in [Errors](https://docs.truemarkets.co/developer-resources/errors.md).

### 200

Decision recorded

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `redirect_to` | string (uri) | yes | Where the browser should go next, approved or denied. |

### 400

The authorize parameters no longer validate.

### 401

Not authenticated

### 403

`error=login_required` — approving a sensitive scope such as `mcp:trade` needs a credential presented within the last few minutes, and this session's is older.
