Sign in with Denpa — step 3: the user's decision
POST /api/protocol/v1/auth/authorize
POST
/api/protocol/v1/auth/authorize
Approve or deny. First-party session cookie and same-origin only — an app can never approve itself. Returns the redirect URL (?code=…&state=… or ?error=access_denied).
Authorizations
Section titled “Authorizations ”Request Body required
Section titled “Request Body required ”object
challengeId
required
string
decision
required
string
Responses
Section titled “ Responses ”Redirect
object
redirectUrl
string
unauthenticated
object
error
required
Stable machine-readable code (snake_case) or a short reason.
string
message
string
key
additional properties
any
Cross-origin refused
object
error
required
Stable machine-readable code (snake_case) or a short reason.
string
message
string
key
additional properties
any