---
search:
  tags:
    - OAuth
    - GET
seo:
  description: >-
    Authorization code with mandatory S256, exact registered redirect, resource
    and… Reference for the GET /oauth/authorize endpoint in the agentsub Gateway
    API.
sidebar:
  label: Authorization endpoint (302 to AgentID)
  badge: GET
title: Authorization endpoint (302 to AgentID)
type: openapi-operation
---
Authorization code with mandatory S256, exact registered redirect, resource and state. Default redirects fixed agentsub identity-choice/consent UI with an opaque five-minute request identifier. Optional identity_provider=agentid starts AgentID directly. Human Google/Clerk identity requires explicit trusted-origin human consent before a one-minute code is issued.

`GET /oauth/authorize`

**Responses**

- `302` — Redirect to AgentID upstream authorization
- `400` — OAuth error JSON (\`invalid\_request\`, \`invalid\_client\`, \`invalid\_grant\`, \`invalid\_scope\`, \`invalid\_target\`, \`invalid\_redirect\_uri\`, \`invalid\_client\_metadata\`, \`unsupported\_grant\_type\`)
- `429` — OAuth error JSON (\`temporarily\_unavailable\` — registration/authorization caps reached)
- `503` — OAuth error JSON (\`temporarily\_unavailable\` — credentials or storage not configured)
