Ga naar inhoud

Approve or deny the `bl login`

POST
/api/v1/cli/consent
curl --request POST \
--url https://example.com/api/v1/cli/consent \
--header 'Content-Type: application/json' \
--data '{ "user_code": "example", "approve": true }'

The explicit answer on the confirmation page (RFC 8628 §5.4): only this approves a bl login, never the login at the identity provider by itself. Needs the cookie of GET /api/v1/cli/consent, a request from a page of this service (Sec-Fetch-Site: same-origin, or else Origin or Referer), and to approve, the user code the page showed. The login is used once, also when denied.

  • None
Media typeapplication/json
object
user_code
required

The code the page showed and the user compared with the terminal.

string
approve
required

true approves, false denies.

boolean

Example generated

{
"user_code": "example",
"approve": true
}

OK.

Media typeapplication/json
object
approved
required
boolean

Example generated

{
"approved": true
}

The code does not match; nothing approved.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

From another site.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

No login waits for confirmation in this browser; it may have expired.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}