# Authorize

`GET /oauth/authorize`

Sends the user to the consent screen (signing in first if needed). On approval it redirects to `redirect_uri?code=…&state=…`; on denial `error=access_denied`. PKCE (S256) is mandatory.

## Query parameters

| Field | Type | Description |
|---|---|---|
| `response_type` (required) | string | Only `code`. Values: `code` |
| `client_id` (required) | string | Client id from registration or a CIMD URL. |
| `redirect_uri` (required) | string | A registered redirect URI. |
| `scope` | string | `crm.read crm.write` (and optional `offline_access`). Both when empty. |
| `state` | string | Client CSRF value (echoed back). |
| `code_challenge` (required) | string | BASE64URL(SHA256(code_verifier)). |
| `code_challenge_method` (required) | string | Only `S256`. Values: `S256` |
| `resource` | string | The MCP resource (`https://<install>/mcp`) — leave empty for REST. |

## Response

```json 302
HTTP/1.1 302 Found
Location: https://uygulamaniz.com/oauth/callback?code=Zx8…&state=xyz123
```
