> ## Documentation Index
> Fetch the complete documentation index at: https://docs.depict.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Decline an AI assistant's connection request

> Declines a request read with GET /mcp/consent: nothing is granted. The client is told (`redirect_to` carries `error=access_denied`) only when its redirect URI is on this computer (loopback): anyone can register any other, and following it would turn a click on Cancel into a redirect to a stranger's page. Works while AI assistants are off for the store or the Depict app is not installed on it, so a refused request can still be answered. Side effect: the request is used up (declining it again answers 404).



## OpenAPI

````yaml /api-reference/openapi/lite.json delete /mcp/consent
openapi: 3.1.0
info:
  title: Search & Merchandising API
  version: 1.0.0
  description: >-
    REST API behind Depict: Search & Merchandising, the native Shopify app:
    onboarding, collections, boost & bury, dashboards, A/B testing and
    multi-store management. Endpoints are served under the /api/lite prefix and
    are authenticated with the Shopify session token that App Bridge issues to
    the embedded app.
servers:
  - url: /api/lite
security:
  - ShopifySessionToken: []
paths:
  /mcp/consent:
    delete:
      summary: Decline an AI assistant's connection request
      description: >-
        Declines a request read with GET /mcp/consent: nothing is granted. The
        client is told (`redirect_to` carries `error=access_denied`) only when
        its redirect URI is on this computer (loopback): anyone can register any
        other, and following it would turn a click on Cancel into a redirect to
        a stranger's page. Works while AI assistants are off for the store or
        the Depict app is not installed on it, so a refused request can still be
        answered. Side effect: the request is used up (declining it again
        answers 404).
      operationId: mcpConsentDeny
      parameters:
        - schema:
            type: string
            pattern: ^[A-Za-z0-9_-]{20,}$
            description: >-
              The `mcp_txn` parameter of the Settings link the assistant's
              sign-in opened.
          required: true
          description: >-
            The `mcp_txn` parameter of the Settings link the assistant's sign-in
            opened.
          name: txn
          in: query
      responses:
        '200':
          description: Declined; follow `redirect_to` when it is not null.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/McpConsentDecline'
        '400':
          description: '`txn` is missing or malformed; `detail` carries zod''s messages.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '401':
          description: Not authenticated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '403':
          description: >-
            The request is for another store, or this identity may not call the
            API.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/McpConsentRefusal'
        '404':
          description: >-
            No such request: unknown, older than 10 minutes, or already
            answered.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '500':
          description: Internal error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
components:
  schemas:
    McpConsentDecline:
      type: object
      properties:
        redirect_to:
          type:
            - string
            - 'null'
          description: >-
            The assistant's OAuth redirect carrying `error=access_denied`, for a
            redirect URI on this computer (loopback): navigate the top-level
            window there so the assistant stops waiting. Null for any other
            redirect URI, which anyone can register: nothing is sent, and the
            assistant times out on its own.
      required:
        - redirect_to
    Detail:
      type: object
      properties:
        detail:
          type: string
      required:
        - detail
      description: 'Every 4xx/5xx body: `{detail}`.'
    McpConsentRefusal:
      type: object
      properties:
        detail:
          type: string
        client_name:
          type:
            - string
            - 'null'
          description: The name the assistant registered under.
        redirect_to:
          $ref: '#/components/schemas/McpRedirectTarget'
      required:
        - detail
      description: >-
        Why a 403. When the request exists but may not be answered here (another
        store's, the Depict app is not installed on its store, or AI assistants
        are off for it), it also names the assistant and where approving would
        send the browser; a 403 from authentication itself carries `detail`
        only.
    McpRedirectTarget:
      oneOf:
        - type: object
          properties:
            kind:
              type: string
              enum:
                - loopback
                - https
                - http
            host:
              type: string
              description: Its host name, the part a user can check.
            scheme:
              type: string
              description: >-
                Its scheme, colon included: `https:`, `http:` or an app's own,
                e.g. `cursor:`.
          required:
            - kind
            - host
            - scheme
        - type: object
          properties:
            kind:
              type: string
              enum:
                - custom
            host:
              type: 'null'
            scheme:
              type: string
              description: >-
                Its scheme, colon included: `https:`, `http:` or an app's own,
                e.g. `cursor:`.
          required:
            - kind
            - host
            - scheme
      description: >-
        Where approving sends the browser, and with it the authorization code,
        read from the redirect URI the client registered: its name is free text,
        this is where the code goes. `loopback`: an app on this computer (http
        or https on localhost, 127.0.0.1 or [::1]); `https`: a website; `http`:
        a website without TLS; `custom`: an app's own URL scheme, with no host.
  securitySchemes:
    ShopifySessionToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Shopify App Bridge session token of the embedded Depict: Search &
        Merchandising app. The shop in the token determines the merchant;
        merchant_id parameters must belong to that shop.

````