Authentication

POST /auth/extension/connect Browser extension only

Submit the consent decision and mint the extension’s session token.

Submitted by the consent screen’s own form, not called directly. On decision=allow, 302-redirects to redirect_uri with a session token in the URL fragment (never the query, so it is never logged or sent to a server); on anything else, redirects with error=access_denied. Not a JSON endpoint.

Body

redirect_uri string required
Must match the allowlisted redirect validated on the GET step.
state string
Opaque value echoed back.
decision string required
allow or cancel.Example allow
curl
# submitted by the consent page's own form, not called directly

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of HireAll is available