> ## Documentation Index
> Fetch the complete documentation index at: https://docs.costgraph.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Preview an OAuth authorization request

> Returns the client, the requested permissions with descriptions, which of them the user has not yet granted to this client for this tenant (is_new), and already_authorized when nothing new is requested. client_id may be a client ID metadata document URL: the document is fetched and validated (400 if it cannot be verified, 429 when the signed-in user fetches too many documents), verified_host is the host serving it, redirect_host is the host of the requested redirect_uri, which must be registered for the client (400 otherwise), and local_only is true when the requested redirect_uri points at this computer; already_authorized is then always false. For an application owned by a tenant, tenant_id is ignored and the preview is evaluated in that tenant; for other applications tenant_id is required (400 if missing). Returns 403 when the signed-in user cannot access the effective tenant.



## OpenAPI

````yaml /api-reference/costgraph/openapi.json get /api/v1/oauth/authorize/preview
openapi: 3.0.0
info:
  description: Read and manage your CostGraph organization, spend, alerts, and settings.
  title: CostGraph API
  contact: {}
  version: '1.0'
servers:
  - url: https://api.costgraph.ai
security: []
tags:
  - name: ai
    x-group: AI
  - name: ai-serving
    x-group: AI serving
  - name: anomalies
    x-group: Anomalies
  - name: auth
    x-group: Auth
  - name: billing
    x-group: Billing
  - name: billing-export
    x-group: Billing export
  - name: budgets
    x-group: Budgets
  - name: ci
    x-group: CI
  - name: compute-recommendations
    x-group: Compute recommendations
  - name: config
    x-group: Config
  - name: cost
    x-group: Cost
  - name: gpus
    x-group: GPUs
  - name: graphai
    x-group: Graph AI
  - name: infracost
    x-group: Infracost
  - name: integrations
    x-group: Integrations
  - name: invitations
    x-group: Invitations
  - name: kubernetes-clusters
    x-group: Kubernetes clusters
  - name: marketplace
    x-group: Marketplace
  - name: network-requests
    x-group: Network requests
  - name: notifications
    x-group: Notifications
  - name: oauth
    x-group: OAuth
  - name: oauth-clients
    x-group: OAuth clients
  - name: opencost
    x-group: OpenCost
  - name: organization
    x-group: Audit log
  - name: organizations
    x-group: Organizations
  - name: placement-alternatives
    x-group: Placement alternatives
  - name: reports
    x-group: Reports
  - name: service-map
    x-group: Service map
  - name: settings
    x-group: Settings
  - name: sso
    x-group: Single sign-on
  - name: tenants
    x-group: Tenants
  - name: user
    x-group: Users
  - name: virtual-machines
    x-group: Virtual machines
  - name: virtual-tags
    x-group: Virtual tags
  - name: workflows
    x-group: Workflows
paths:
  /api/v1/oauth/authorize/preview:
    get:
      tags:
        - oauth
      summary: Preview an OAuth authorization request
      description: >-
        Returns the client, the requested permissions with descriptions, which
        of them the user has not yet granted to this client for this tenant
        (is_new), and already_authorized when nothing new is requested.
        client_id may be a client ID metadata document URL: the document is
        fetched and validated (400 if it cannot be verified, 429 when the
        signed-in user fetches too many documents), verified_host is the host
        serving it, redirect_host is the host of the requested redirect_uri,
        which must be registered for the client (400 otherwise), and local_only
        is true when the requested redirect_uri points at this computer;
        already_authorized is then always false. For an application owned by a
        tenant, tenant_id is ignored and the preview is evaluated in that
        tenant; for other applications tenant_id is required (400 if missing).
        Returns 403 when the signed-in user cannot access the effective tenant.
      parameters:
        - description: Client ID
          name: client_id
          in: query
          required: true
          schema:
            type: string
        - description: Redirect URI the client will return to
          name: redirect_uri
          in: query
          required: true
          schema:
            type: string
        - description: Tenant ID, required unless the client is owned by a tenant
          name: tenant_id
          in: query
          schema:
            type: string
        - description: Space-separated scopes
          name: scope
          in: query
          schema:
            type: string
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/responses.SuccessResponse'
                  - type: object
                    properties:
                      data:
                        $ref: '#/components/schemas/oauth.ConsentPreview'
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
        '429':
          description: Too Many Requests
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/responses.ErrorResponse'
      security:
        - BearerAuth: []
components:
  schemas:
    responses.SuccessResponse:
      type: object
      required:
        - message
        - status
      properties:
        data: {}
        message:
          type: string
          example: some message
        status:
          type: string
          example: success
    oauth.ConsentPreview:
      type: object
      required:
        - client
        - redirect_host
        - scopes
      properties:
        already_authorized:
          type: boolean
        client:
          $ref: >-
            #/components/schemas/github_com_baselinehq_backend_internal_oauth.Client
        local_only:
          type: boolean
        redirect_host:
          type: string
        scopes:
          type: array
          items:
            $ref: '#/components/schemas/oauth.ConsentScope'
        verified_host:
          type: string
    responses.ErrorResponse:
      type: object
      required:
        - message
        - status
      properties:
        message:
          type: string
          example: some message
        status:
          type: string
          example: error
    github_com_baselinehq_backend_internal_oauth.Client:
      type: object
      required:
        - allowed_scopes
        - client_id
        - client_name
        - client_type
        - created_at
        - redirect_uris
      properties:
        allowed_scopes:
          type: array
          items:
            type: string
        client_id:
          type: string
        client_name:
          type: string
        client_type:
          type: string
        created_at:
          type: string
        created_by_name:
          type: string
        homepage_url:
          type: string
        logo_url:
          type: string
        metadata_url:
          type: string
        policy_url:
          type: string
        redirect_uris:
          type: array
          items:
            type: string
        tenant_id:
          type: string
        tos_url:
          type: string
    oauth.ConsentScope:
      type: object
      required:
        - description
        - name
      properties:
        description:
          type: string
        is_new:
          type: boolean
        name:
          type: string
  securitySchemes:
    BearerAuth:
      description: Enter "Bearer {token}"
      type: apiKey
      name: Authorization
      in: header

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.