# Yetkilendir

`GET /oauth/authorize`

Kullanıcıyı onay ekranına götürür (oturum yoksa önce giriş). Onaylanınca `redirect_uri?code=…&state=…` adresine döner; reddedilirse `error=access_denied`. PKCE (S256) zorunludur.

## Sorgu parametreleri

| Alan | Tür | Açıklama |
|---|---|---|
| `response_type` (zorunlu) | string | Yalnız `code`. Değerler: `code` |
| `client_id` (zorunlu) | string | Kayıtta alınan kimlik ya da CIMD adresi. |
| `redirect_uri` (zorunlu) | string | Kayıtlı dönüş adresi. |
| `scope` | string | `crm.read crm.write` (ve isteğe bağlı `offline_access`). Boşsa ikisi birden. |
| `state` | string | İstemcinin CSRF değeri (aynen döner). |
| `code_challenge` (zorunlu) | string | BASE64URL(SHA256(code_verifier)). |
| `code_challenge_method` (zorunlu) | string | Yalnız `S256`. Değerler: `S256` |
| `resource` | string | MCP kaynağı (`https://<kurulum>/mcp`) — REST için boş bırakın. |

## Yanıt

```json 302
HTTP/1.1 302 Found
Location: https://uygulamaniz.com/oauth/callback?code=Zx8…&state=xyz123
```
