> ## Documentation Index
> Fetch the complete documentation index at: https://docs.depict.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Approve an AI assistant's connection request

> Approves a request read with GET /mcp/consent: grants the MCP client the scopes it asked for and the user approved, on the request's store, and answers the client's OAuth redirect. Navigate the top-level window to `redirect_to` to finish connecting. Side effects: one OAuth grant for the store, replacing the approving user's earlier grants of the same client (other users' grants of it stay); it lasts 30 days, or 24 hours when a superuser approves; the client's registration is renewed for 90 days; the request is used up (approving it again answers 404).



## OpenAPI

````yaml /api-reference/openapi/lite.json post /mcp/consent
openapi: 3.1.0
info:
  title: Search & Merchandising API
  version: 1.0.0
  description: >-
    REST API behind Depict: Search & Merchandising, the native Shopify app:
    onboarding, collections, boost & bury, dashboards, A/B testing and
    multi-store management. Endpoints are served under the /api/lite prefix and
    are authenticated with the Shopify session token that App Bridge issues to
    the embedded app.
servers:
  - url: /api/lite
security:
  - ShopifySessionToken: []
paths:
  /mcp/consent:
    post:
      summary: Approve an AI assistant's connection request
      description: >-
        Approves a request read with GET /mcp/consent: grants the MCP client the
        scopes it asked for and the user approved, on the request's store, and
        answers the client's OAuth redirect. Navigate the top-level window to
        `redirect_to` to finish connecting. Side effects: one OAuth grant for
        the store, replacing the approving user's earlier grants of the same
        client (other users' grants of it stay); it lasts 30 days, or 24 hours
        when a superuser approves; the client's registration is renewed for 90
        days; the request is used up (approving it again answers 404).
      operationId: mcpConsentPost
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/McpConsentApproval'
      responses:
        '200':
          description: Granted; follow `redirect_to`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/McpConsentRedirect'
        '400':
          description: >-
            The body failed the schema or is not JSON, or the approval lacks
            `depict:read`, which every grant needs.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '401':
          description: Not authenticated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '403':
          description: >-
            The request is for another store, the Depict app is not installed on
            its store, AI assistants are not enabled for it, or this identity
            may not call the API.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/McpConsentRefusal'
        '404':
          description: >-
            No such request: unknown, older than 10 minutes, or already
            answered.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '415':
          description: Content-Type is not application/json.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '500':
          description: Internal error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
components:
  schemas:
    McpConsentApproval:
      type: object
      properties:
        txn:
          type: string
          pattern: ^[A-Za-z0-9_-]{20,}$
          description: >-
            The `mcp_txn` parameter of the Settings link the assistant's sign-in
            opened.
        scopes:
          type: array
          items:
            type: string
          description: >-
            The scopes the user approved; only those the assistant also asked
            for are granted.
      required:
        - txn
        - scopes
    McpConsentRedirect:
      type: object
      properties:
        redirect_to:
          type: string
          description: >-
            The assistant's OAuth redirect, carrying the authorization code;
            navigate the top-level window there to finish connecting.
      required:
        - redirect_to
    Detail:
      type: object
      properties:
        detail:
          type: string
      required:
        - detail
      description: 'Every 4xx/5xx body: `{detail}`.'
    McpConsentRefusal:
      type: object
      properties:
        detail:
          type: string
        client_name:
          type:
            - string
            - 'null'
          description: The name the assistant registered under.
        redirect_to:
          $ref: '#/components/schemas/McpRedirectTarget'
      required:
        - detail
      description: >-
        Why a 403. When the request exists but may not be answered here (another
        store's, the Depict app is not installed on its store, or AI assistants
        are off for it), it also names the assistant and where approving would
        send the browser; a 403 from authentication itself carries `detail`
        only.
    McpRedirectTarget:
      oneOf:
        - type: object
          properties:
            kind:
              type: string
              enum:
                - loopback
                - https
                - http
            host:
              type: string
              description: Its host name, the part a user can check.
            scheme:
              type: string
              description: >-
                Its scheme, colon included: `https:`, `http:` or an app's own,
                e.g. `cursor:`.
          required:
            - kind
            - host
            - scheme
        - type: object
          properties:
            kind:
              type: string
              enum:
                - custom
            host:
              type: 'null'
            scheme:
              type: string
              description: >-
                Its scheme, colon included: `https:`, `http:` or an app's own,
                e.g. `cursor:`.
          required:
            - kind
            - host
            - scheme
      description: >-
        Where approving sends the browser, and with it the authorization code,
        read from the redirect URI the client registered: its name is free text,
        this is where the code goes. `loopback`: an app on this computer (http
        or https on localhost, 127.0.0.1 or [::1]); `https`: a website; `http`:
        a website without TLS; `custom`: an app's own URL scheme, with no host.
  securitySchemes:
    ShopifySessionToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Shopify App Bridge session token of the embedded Depict: Search &
        Merchandising app. The shop in the token determines the merchant;
        merchant_id parameters must belong to that shop.

````