OAuth 2.1

Authorize

Sends the user to the consent screen (signing in first if needed). On approval it redirects to redirect_uri?code=…&state=…; on denial error=access_denied. PKCE (S256) is mandatory.

GET/oauth/authorize

Authorization

No authentication required.

Query parameters

response_typestringrequired
Only code.
Valuescode
client_idstringrequired
Client id from registration or a CIMD URL.
redirect_uristringrequired
A registered redirect URI.
scopestringoptional
crm.read crm.write (and optional offline_access). Both when empty.
statestringoptional
Client CSRF value (echoed back).
code_challengestringrequired
BASE64URL(SHA256(code_verifier)).
code_challenge_methodstringrequired
Only S256.
ValuesS256
resourcestringoptional
The MCP resource (https://<install>/mcp) — leave empty for REST.
Request
https://ornek.solk.app/oauth/authorize?response_type=code&client_id=crm_Jq8w…&redirect_uri=https%3A%2F%2Fuygulamaniz.com%2Foauth%2Fcallback&scope=crm.read%20crm.write&state=xyz123&code_challenge=E9Melhoa2Owv…&code_challenge_method=S256
Response
HTTP/1.1 302 Found
Location: https://uygulamaniz.com/oauth/callback?code=Zx8…&state=xyz123