> ## Documentation Index
> Fetch the complete documentation index at: https://docs.costgraph.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Approve an OAuth authorization request

> Called by the consent page with the signed-in user's decision. decision defaults to approve, which mints an authorization code and returns the client's redirect URI with code and state appended. decision=deny validates the client and redirect URI the same way, creates no code, and returns the redirect URI with error=access_denied and state. An empty scope means all of the client's allowed scopes; a scope outside the client's allowed list redirects with error=invalid_scope. A client owned by another tenant returns 403. nonce is echoed into the id_token. The browser navigates to redirect_url either way. Every redirect carries iss, the issuer URL. client_id may be a client ID metadata document URL, which must already have been loaded through the preview. resource, when given, must be an absolute https URL.



## OpenAPI

````yaml /api-reference/costgraph/openapi.json post /api/v1/oauth/authorize
openapi: 3.0.0
info:
  description: Read and manage your CostGraph organization, spend, alerts, and settings.
  title: CostGraph API
  contact: {}
  version: '1.0'
servers:
  - url: https://api.costgraph.ai
security: []
tags:
  - name: ai
    x-group: AI
  - name: ai-serving
    x-group: AI serving
  - name: anomalies
    x-group: Anomalies
  - name: auth
    x-group: Auth
  - name: billing
    x-group: Billing
  - name: billing-export
    x-group: Billing export
  - name: budgets
    x-group: Budgets
  - name: ci
    x-group: CI
  - name: compute-recommendations
    x-group: Compute recommendations
  - name: config
    x-group: Config
  - name: cost
    x-group: Cost
  - name: gpus
    x-group: GPUs
  - name: graphai
    x-group: Graph AI
  - name: infracost
    x-group: Infracost
  - name: integrations
    x-group: Integrations
  - name: invitations
    x-group: Invitations
  - name: kubernetes-clusters
    x-group: Kubernetes clusters
  - name: marketplace
    x-group: Marketplace
  - name: network-requests
    x-group: Network requests
  - name: notifications
    x-group: Notifications
  - name: oauth
    x-group: OAuth
  - name: oauth-clients
    x-group: OAuth clients
  - name: opencost
    x-group: OpenCost
  - name: organization
    x-group: Audit log
  - name: organizations
    x-group: Organizations
  - name: placement-alternatives
    x-group: Placement alternatives
  - name: reports
    x-group: Reports
  - name: service-map
    x-group: Service map
  - name: settings
    x-group: Settings
  - name: sso
    x-group: Single sign-on
  - name: tenants
    x-group: Tenants
  - name: user
    x-group: Users
  - name: virtual-machines
    x-group: Virtual machines
  - name: virtual-tags
    x-group: Virtual tags
  - name: workflows
    x-group: Workflows
paths:
  /api/v1/oauth/authorize:
    post:
      tags:
        - oauth
      summary: Approve an OAuth authorization request
      description: >-
        Called by the consent page with the signed-in user's decision. decision
        defaults to approve, which mints an authorization code and returns the
        client's redirect URI with code and state appended. decision=deny
        validates the client and redirect URI the same way, creates no code, and
        returns the redirect URI with error=access_denied and state. An empty
        scope means all of the client's allowed scopes; a scope outside the
        client's allowed list redirects with error=invalid_scope. A client owned
        by another tenant returns 403. nonce is echoed into the id_token. The
        browser navigates to redirect_url either way. Every redirect carries
        iss, the issuer URL. client_id may be a client ID metadata document URL,
        which must already have been loaded through the preview. resource, when
        given, must be an absolute https URL.
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/controllers.AuthorizeRequest'
        description: Authorization request
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/responses.SuccessResponse'
                  - type: object
                    properties:
                      data:
                        $ref: '#/components/schemas/controllers.AuthorizeResponse'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
      security:
        - BearerAuth: []
components:
  schemas:
    controllers.AuthorizeRequest:
      type: object
      required:
        - client_id
        - code_challenge
        - code_challenge_method
        - redirect_uri
        - tenant_id
      properties:
        client_id:
          type: string
        code_challenge:
          type: string
          maxLength: 128
          minLength: 43
        code_challenge_method:
          type: string
        decision:
          type: string
          enum:
            - approve
            - deny
        nonce:
          type: string
          maxLength: 256
        redirect_uri:
          type: string
        resource:
          type: string
        scope:
          type: string
        state:
          type: string
        tenant_id:
          type: string
    responses.SuccessResponse:
      type: object
      required:
        - message
        - status
      properties:
        data: {}
        message:
          type: string
          example: some message
        status:
          type: string
          example: success
    controllers.AuthorizeResponse:
      type: object
      required:
        - redirect_url
      properties:
        redirect_url:
          type: string
    responses.ErrorResponse:
      type: object
      required:
        - message
        - status
      properties:
        message:
          type: string
          example: some message
        status:
          type: string
          example: error
  securitySchemes:
    BearerAuth:
      description: Enter "Bearer {token}"
      type: apiKey
      name: Authorization
      in: header

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.