CustomDomain™ docs
API referenceAgents

Approve an agent and mint its authorization code

POST
/agent/consent

Called by the console's server after a person signs in and approves, with that member's tenant API key (a widget token is refused, because it lives in browsers). The key's member needs agent:manage (owners and admins), and member_id must belong to the workspace. The approved scopes are a subset of what was requested. The grant is bound to one application_id of the workspace. domains:purchase also needs a spend_cap_cents and a saved card. Persistent access is the default; persist: false ends it after expires_days. The authorization code is single use and is exchanged at POST /oauth/agent/token.

AuthorizationBearer <token>

Long-lived tenant API key, cd_live_… (production) or cd_test_… (staging, development), stored hashed. Keys created before the switch to cd_ start with sk_live_… / sk_test_… and are still accepted. Scoped to the owning application's tenant.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

The body is decoded with unknown fields rejected.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/agent/consent" \  -H "Content-Type: application/json" \  -d '{    "request": "string",    "member_id": "string",    "application_id": "string",    "scopes": [      "domains:read"    ]  }'
{  "redirect_uri": "string",  "code": "string",  "state": "string",  "grant_id": "string"}
{  "code": "string",  "title": "string",  "details": "string"}
{  "code": "string",  "title": "string",  "details": "string"}
{  "code": "string",  "title": "string",  "details": "string"}
{  "code": "string",  "title": "string",  "details": "string"}
{  "code": "string",  "title": "string",  "details": "string"}