> ## Documentation Index
> Fetch the complete documentation index at: https://docs.depict.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# An AI assistant's pending connection request, for the consent panel

> Reads the request an MCP client (an AI assistant such as Claude Code) parked when it started signing in to a store's endpoint: which client asks, where approving sends the browser, for which scopes, on which store. The Settings page calls it with the link's `mcp_txn` to render the consent panel, then POST /mcp/consent to approve. Read-only; a request lasts 10 minutes.



## OpenAPI

````yaml /api-reference/openapi/lite.json get /mcp/consent
openapi: 3.1.0
info:
  title: Search & Merchandising API
  version: 1.0.0
  description: >-
    REST API behind Depict: Search & Merchandising, the native Shopify app:
    onboarding, collections, boost & bury, dashboards, A/B testing and
    multi-store management. Endpoints are served under the /api/lite prefix and
    are authenticated with the Shopify session token that App Bridge issues to
    the embedded app.
servers:
  - url: /api/lite
security:
  - ShopifySessionToken: []
paths:
  /mcp/consent:
    get:
      summary: An AI assistant's pending connection request, for the consent panel
      description: >-
        Reads the request an MCP client (an AI assistant such as Claude Code)
        parked when it started signing in to a store's endpoint: which client
        asks, where approving sends the browser, for which scopes, on which
        store. The Settings page calls it with the link's `mcp_txn` to render
        the consent panel, then POST /mcp/consent to approve. Read-only; a
        request lasts 10 minutes.
      operationId: mcpConsentGet
      parameters:
        - schema:
            type: string
            pattern: ^[A-Za-z0-9_-]{20,}$
            description: >-
              The `mcp_txn` parameter of the Settings link the assistant's
              sign-in opened.
          required: true
          description: >-
            The `mcp_txn` parameter of the Settings link the assistant's sign-in
            opened.
          name: txn
          in: query
      responses:
        '200':
          description: The pending request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/McpConsentRequest'
        '400':
          description: '`txn` is missing or malformed; `detail` carries zod''s messages.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '401':
          description: Not authenticated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '403':
          description: >-
            The request is for another store, the Depict app is not installed on
            its store, AI assistants are not enabled for it, or this identity
            may not call the API.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/McpConsentRefusal'
        '404':
          description: >-
            No such request: unknown, older than 10 minutes, or already
            answered.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '500':
          description: Internal error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
components:
  schemas:
    McpConsentRequest:
      type: object
      properties:
        client_name:
          type:
            - string
            - 'null'
          description: >-
            The name the assistant registered under, e.g. `Claude Code`; null
            when it gave none. Anyone can register any name: `redirect_to` is
            what identifies where the code goes.
        client_id:
          type: string
          description: The OAuth client id the assistant registered.
        redirect_to:
          $ref: '#/components/schemas/McpRedirectTarget'
        scopes:
          type: array
          items:
            type: string
            enum:
              - depict:read
              - depict:write
          description: >-
            What it asks for that Depict grants: `depict:read` reads the store's
            data, `depict:write` changes it.
        shop:
          type:
            - string
            - 'null'
          description: The store's myshopify domain; null when it has none.
        merchant_id:
          type: string
          description: The store the assistant would act on.
      required:
        - client_name
        - client_id
        - redirect_to
        - scopes
        - shop
        - merchant_id
    Detail:
      type: object
      properties:
        detail:
          type: string
      required:
        - detail
      description: 'Every 4xx/5xx body: `{detail}`.'
    McpConsentRefusal:
      type: object
      properties:
        detail:
          type: string
        client_name:
          type:
            - string
            - 'null'
          description: The name the assistant registered under.
        redirect_to:
          $ref: '#/components/schemas/McpRedirectTarget'
      required:
        - detail
      description: >-
        Why a 403. When the request exists but may not be answered here (another
        store's, the Depict app is not installed on its store, or AI assistants
        are off for it), it also names the assistant and where approving would
        send the browser; a 403 from authentication itself carries `detail`
        only.
    McpRedirectTarget:
      oneOf:
        - type: object
          properties:
            kind:
              type: string
              enum:
                - loopback
                - https
                - http
            host:
              type: string
              description: Its host name, the part a user can check.
            scheme:
              type: string
              description: >-
                Its scheme, colon included: `https:`, `http:` or an app's own,
                e.g. `cursor:`.
          required:
            - kind
            - host
            - scheme
        - type: object
          properties:
            kind:
              type: string
              enum:
                - custom
            host:
              type: 'null'
            scheme:
              type: string
              description: >-
                Its scheme, colon included: `https:`, `http:` or an app's own,
                e.g. `cursor:`.
          required:
            - kind
            - host
            - scheme
      description: >-
        Where approving sends the browser, and with it the authorization code,
        read from the redirect URI the client registered: its name is free text,
        this is where the code goes. `loopback`: an app on this computer (http
        or https on localhost, 127.0.0.1 or [::1]); `https`: a website; `http`:
        a website without TLS; `custom`: an app's own URL scheme, with no host.
  securitySchemes:
    ShopifySessionToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Shopify App Bridge session token of the embedded Depict: Search &
        Merchandising app. The shop in the token determines the merchant;
        merchant_id parameters must belong to that shop.

````