The apps you have allowed
const url = 'https://api.sloose.com/auth/account/consents';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://api.sloose.com/auth/account/consents \ --header 'Authorization: Bearer <token>'Every grant you have given an MCP client, in every org: which app, which org, and your role there, which is what it acts at. Yours whatever your role — revoking one is yours too. Session only.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”Your grants, newest first.
object
object
The client’s id — for a Client ID Metadata Document client, the HTTPS URL of that document.
The org the app was allowed into.
object
Your role there now, which is what the app acts at. Null when you are no longer in the org: the grant does nothing while you are out of it, and would work again were you invited back.
Example
{ "consents": [ { "org": { "role": "operator" } } ]}No bearer, or one that is expired, revoked or no longer resolves to a member.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}An API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org (code: STAFF_VIEW).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}