Skip to content
/oauth/authorize

Authorize — server-rendered login + consent page

OAuth 2.1 authorization endpoint. GET renders a login + consent page (PKCE S256 required; CSRF-protected; framebusting). POST authenticates the user against the FinRadar login and, on Allow, redirects to `redirect_uri?code=...&state=...`. Loopback `redirect_uri` (http://127.0.0.1:<any-port>/...) is allowed for native clients (RFC 8252).

free

Parameters

NameInRequiredDefaultAllowedDescriptionExample
response_typequeryrequiredMust be `code`.code
client_idqueryrequiredRegistered client id.cursor
redirect_uriqueryrequiredMust match a registered redirect (loopback any-port allowed).http://127.0.0.1:51000/callback
scopequeryoptionalmcpSingle `mcp` scope.mcp
statequeryrequiredCSRF/correlation value echoed back.xyz
code_challengequeryrequiredPKCE S256 challenge (base64url SHA-256 of the verifier).E2okHPeE...
code_challenge_methodqueryrequiredMust be `S256` (plain is rejected).S256

Response schema

FieldTypeNullableDescription
(GET) HTML login + consent pagetext/htmlnoGET returns a server-rendered HTML page (HTTP 200) — an interactive login + consent form (framebusted, CSRF-protected). It is NOT a JSON body: the user completes it in a browser. A request missing PKCE `code_challenge`/`code_challenge_method=S256` returns 400 with `{error, error_description}` instead of the page.
(POST → Allow) redirect: codestringnoOn successful login + Allow, the endpoint issues a 302 redirect to the registered `redirect_uri` with a one-time authorization `code` in the query string. The client exchanges it at `/oauth/token`.
(POST → Allow) redirect: statestringnoThe `state` value from the request, echoed back on the redirect query string for CSRF/correlation. On Deny, the redirect carries `error=access_denied` (and `state`) instead of a code.

Errors

StatusLabelDescription
200OKRequest succeeded.
400Bad RequestInvalid query, body, or path parameter.
401UnauthorizedMissing or invalid Authorization header / api_Token.
402Payment RequiredInsufficient token balance for this call. Top up
429Too Many RequestsRate limit exceeded for your tier (see /pricing for tier limits). Tier limits
500Server ErrorUnexpected server-side failure. Retry with backoff; report if persistent.

Code samples

curl "https://api.finradar.ai/oauth/authorize?response_type=code&client_id=cursor&redirect_uri=http%3A%2F%2F127.0.0.1%3A51000%2Fcallback&scope=mcp&state=xyz&code_challenge=E2okHPeE...&code_challenge_method=S256" \
  -H "Authorization: Bearer YOUR_JWT_TOKEN"

Generate an API key in /account/credentials to run live queries (literal YOUR_API_KEY placeholder shown until then).