Skip to content
agentsub
Esc
↑↓navigate↵open⌘Jpreview

Explicit human owner OAuth consent

Exact configured browser Origin required. Pending request binds registered client, redirect, resource and S256 challenge; no bearer credentials in query strings. Human consent rejects AgentID social Clerk identities. Successful consent is one use and returns only the registered callback URL.

POST/oauth/owner/consent
Authorization
AuthorizationBearer token (JWT) · headerrequired

Clerk human owner session JWT; iss must equal the configured Clerk issuer and the identity must be a human (not agent) owner with a verified email.

Request body
requiredapplication/json
requestIdstringrequired
decisionstringrequired
Allowed:approvedeny
Responses
200

Successful response

redirectUrlstring<uri>
400

OAuth error JSON (invalid_request, invalid_client, invalid_grant, invalid_scope, invalid_target, invalid_redirect_uri, invalid_client_metadata, unsupported_grant_type)

errorstringrequired
Allowed:invalid_requestinvalid_clientinvalid_grantinvalid_scopeinvalid_targetinvalid_redirect_uriinvalid_client_metadataunsupported_grant_typeaccess_deniedtemporarily_unavailable
error_descriptionstringrequired
403

Untrusted origin, agent actor, invalid session or scope mismatch

Request
curl -X POST 'https://api.agentsub.dev/oauth/owner/consent' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "requestId": "string",
  "decision": "approve"
}'
Response
{
  "redirectUrl": "http://example.com"
}