---
search:
  tags:
    - OAuth
    - POST
seo:
  description: >-
    Exact configured browser Origin required. Pending request binds registered…
    Reference for the POST /oauth/owner/consent endpoint in the agentsub Gateway
    API.
sidebar:
  label: Explicit human owner OAuth consent
  badge: POST
title: Explicit human owner OAuth consent
type: openapi-operation
---
Exact configured browser Origin required. Pending request binds registered client, redirect, resource and S256 challenge; no bearer credentials in query strings. Human consent rejects AgentID social Clerk identities. Successful consent is one use and returns only the registered callback URL.

`POST /oauth/owner/consent`

**Request body** (`application/json`, required)

- `requestId` (string, required)
- `decision` (string, required)

Request body example:

```json
{
  "requestId": "string",
  "decision": "approve"
}
```

**Responses**

- `200` — Successful response
- `400` — OAuth error JSON (\`invalid\_request\`, \`invalid\_client\`, \`invalid\_grant\`, \`invalid\_scope\`, \`invalid\_target\`, \`invalid\_redirect\_uri\`, \`invalid\_client\_metadata\`, \`unsupported\_grant\_type\`)
- `403` — Untrusted origin, agent actor, invalid session or scope mismatch

Response example, 200:

```json
{
  "redirectUrl": "http://example.com"
}
```
