Skip to main content

User consent

Consent types​

Implicit consent​

For trusted first-party applications:

  • The user is not shown a consent screen
  • Authorization is granted automatically
  • Suitable for internal applications

Explicit consent​

For third-party applications (default):

  • The user sees a consent screen showing:
    • The application's name and logo
    • The requested permissions (scopes)
    • Allow / Deny buttons
  • The user must explicitly approve access
  • Consent is remembered for future requests

The consent screen​

When explicit consent is required, users see:

┌─────────────────────────────────────────────┐
│ │
│ "My App" wants access to your account │
│ │
│ This application will be able to: │
│ │
│ ✓ View your profile information │
│ (name, profile picture) │
│ │
│ ✓ View your email address │
│ │
│ ✓ Stay signed in (offline access) │
│ │
│ ┌──────────┐ ┌──────────┐ │
│ │ Deny │ │ Allow │ │
│ └──────────┘ └──────────┘ │
│ │
└─────────────────────────────────────────────┘

Managing granted permissions​

Users can view and revoke application access:

  1. Sign in to the user portal
  2. Go to "Authorized applications"
  3. View the list of applications with granted access
  4. Click "Revoke" to remove an application's access

The prompt parameter​

Control consent behavior with the prompt parameter:

ValueBehavior
noneSilent authentication – fails if consent is required
loginForce re-authentication
consentForce the consent screen even if it was previously granted
(omitted)Show consent only if it wasn't previously granted

Example – forcing consent:

https://your-sso-domain.com/connect/authorize?
client_id=my-app&
redirect_uri=https://myapp.com/callback&
response_type=code&
scope=openid%20profile&
prompt=consent

Silent authentication error (consent required):

https://myapp.com/callback?error=consent_required&error_description=User%20consent%20is%20required

Handling consent in your application​

Standard flow​

Most applications should not use the prompt parameter, which lets the system show consent only when needed.

Silent authentication​

For background token renewal in an SPA, use prompt=none:

// Attempt silent authentication
const authUrl = new URL('https://your-sso-domain.com/connect/authorize');
authUrl.searchParams.set('prompt', 'none');
// ... other parameters

// If a consent_required error is returned, show the sign-in UI
if (error === 'consent_required' || error === 'login_required') {
showLoginButton();
}

Forcing re-consent​

When your application adds new scopes, you may want to force re-consent:

const authUrl = new URL('https://your-sso-domain.com/connect/authorize');
authUrl.searchParams.set('prompt', 'consent');
authUrl.searchParams.set('scope', 'openid profile email new_scope');