# Render the consent page (200, text/html):
curl "https://phosra-api-sandbox-production.up.railway.app/oauth/authorize?redirect_uri=https://example.com/cb&state=xyz123"
# Machine path — approve and capture the 302 Location:
curl -sD - -o /dev/null "https://phosra-api-sandbox-production.up.railway.app/oauth/authorize?redirect_uri=https://example.com/cb&state=xyz123&decision=approve" | grep -i '^location:'const BASE = "https://phosra-api-sandbox-production.up.railway.app"
const res = await fetch(`${BASE}/oauth/authorize?redirect_uri=https://example.com/cb&state=xyz123&decision=approve`, { redirect: "manual" })
const code = new URL(res.headers.get("location")).searchParams.get("code")
console.log(res.status, code) // 302 sbxauth_…
import requests
url = "https://phosra-api-sandbox-production.up.railway.app/oauth/authorize"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://phosra-api-sandbox-production.up.railway.app/oauth/authorize",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://phosra-api-sandbox-production.up.railway.app/oauth/authorize"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://phosra-api-sandbox-production.up.railway.app/oauth/authorize")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://phosra-api-sandbox-production.up.railway.app/oauth/authorize")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body<!doctype html><meta charset="utf-8"><meta name="viewport" content="width=device-width,initial-scale=1">
<title>Phosra Sandbox — Connect</title>
<style>body{font:16px/1.5 system-ui,sans-serif;max-width:30rem;margin:3rem auto;padding:0 1.25rem;color:#0f172a}
h1{font-size:1.25rem}.card{border:1px solid #e2e8f0;border-radius:12px;padding:1.25rem}
ul{padding-left:1.1rem}.act{display:flex;gap:.75rem;margin-top:1.25rem}
a.btn{flex:1;text-align:center;text-decoration:none;padding:.7rem 1rem;border-radius:10px;font-weight:600}
.ap{background:#4f46e5;color:#fff}.dn{background:#f1f5f9;color:#334155}
.tag{display:inline-block;background:#eef2ff;color:#4338ca;border-radius:999px;padding:.1rem .6rem;font-size:.75rem}</style>
<div class="card"><span class="tag">Sandbox reference provider</span>
<h1>Connect your family to this app?</h1>
<p>Approving shares these sandbox child profiles so the app can receive their safety policy:</p>
<ul><li>Mia <small>(child)</small></li><li>Leo <small>(child)</small></li><li>Ava <small>(child)</small></li></ul>
<div class="act"><a class="btn ap" href="/oauth/authorize?decision=approve&redirect_uri=https%3A%2F%2Fexample.com%2Fcb&state=xyz123">Approve</a>
<a class="btn dn" href="/oauth/authorize?decision=deny&redirect_uri=https%3A%2F%2Fexample.com%2Fcb&state=xyz123">Deny</a></div></div>{
"error": "Bad Request",
"message": "redirect_uri is required",
"code": 400
}404 page not found
{
"error": "Too Many Requests",
"message": "rate limit exceeded",
"code": 429
}{
"error": "Internal Server Error",
"message": "internal error",
"code": 500
}{
"error": "Bad Gateway",
"message": "downstream provider error",
"code": 502
}{
"error": "Service Unavailable",
"message": "downstream provider unavailable",
"code": 503
}Reference parent-consent authorize leg (sandbox)
SANDBOX-ONLY reference OAuth provider hosted on the census host root (NOT /api/v1). With no decision, renders an HTML consent page seeded with the sandbox test family (Mia/Leo/Ava). MACHINE-USABLE CONTRACT: re-request with decision=approve and the census issues an authorization code and 302-redirects to redirect_uri?code=…&state=… — so CI can automate the approval with no HTML scraping. decision=deny 302s with error=access_denied&state=…. Custom mobile schemes (e.g. propagate://) are allowed as redirect_uri. Stateless (opaque sbxauth_ code). Gated on the Restricted band — 404 on dev/staging/production. Source: internal/ocsshttp/handler_sandbox_oauth.go Authorize().
# Render the consent page (200, text/html):
curl "https://phosra-api-sandbox-production.up.railway.app/oauth/authorize?redirect_uri=https://example.com/cb&state=xyz123"
# Machine path — approve and capture the 302 Location:
curl -sD - -o /dev/null "https://phosra-api-sandbox-production.up.railway.app/oauth/authorize?redirect_uri=https://example.com/cb&state=xyz123&decision=approve" | grep -i '^location:'const BASE = "https://phosra-api-sandbox-production.up.railway.app"
const res = await fetch(`${BASE}/oauth/authorize?redirect_uri=https://example.com/cb&state=xyz123&decision=approve`, { redirect: "manual" })
const code = new URL(res.headers.get("location")).searchParams.get("code")
console.log(res.status, code) // 302 sbxauth_…
import requests
url = "https://phosra-api-sandbox-production.up.railway.app/oauth/authorize"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://phosra-api-sandbox-production.up.railway.app/oauth/authorize",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://phosra-api-sandbox-production.up.railway.app/oauth/authorize"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://phosra-api-sandbox-production.up.railway.app/oauth/authorize")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://phosra-api-sandbox-production.up.railway.app/oauth/authorize")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body<!doctype html><meta charset="utf-8"><meta name="viewport" content="width=device-width,initial-scale=1">
<title>Phosra Sandbox — Connect</title>
<style>body{font:16px/1.5 system-ui,sans-serif;max-width:30rem;margin:3rem auto;padding:0 1.25rem;color:#0f172a}
h1{font-size:1.25rem}.card{border:1px solid #e2e8f0;border-radius:12px;padding:1.25rem}
ul{padding-left:1.1rem}.act{display:flex;gap:.75rem;margin-top:1.25rem}
a.btn{flex:1;text-align:center;text-decoration:none;padding:.7rem 1rem;border-radius:10px;font-weight:600}
.ap{background:#4f46e5;color:#fff}.dn{background:#f1f5f9;color:#334155}
.tag{display:inline-block;background:#eef2ff;color:#4338ca;border-radius:999px;padding:.1rem .6rem;font-size:.75rem}</style>
<div class="card"><span class="tag">Sandbox reference provider</span>
<h1>Connect your family to this app?</h1>
<p>Approving shares these sandbox child profiles so the app can receive their safety policy:</p>
<ul><li>Mia <small>(child)</small></li><li>Leo <small>(child)</small></li><li>Ava <small>(child)</small></li></ul>
<div class="act"><a class="btn ap" href="/oauth/authorize?decision=approve&redirect_uri=https%3A%2F%2Fexample.com%2Fcb&state=xyz123">Approve</a>
<a class="btn dn" href="/oauth/authorize?decision=deny&redirect_uri=https%3A%2F%2Fexample.com%2Fcb&state=xyz123">Deny</a></div></div>{
"error": "Bad Request",
"message": "redirect_uri is required",
"code": 400
}404 page not found
{
"error": "Too Many Requests",
"message": "rate limit exceeded",
"code": 429
}{
"error": "Internal Server Error",
"message": "internal error",
"code": 500
}{
"error": "Bad Gateway",
"message": "downstream provider error",
"code": 502
}{
"error": "Service Unavailable",
"message": "downstream provider unavailable",
"code": 503
}/api/v1) and gated on PHOSRA_ENV==sandbox — 404 on dev, staging, and production.decision it renders an HTML consent page. Its machine-usable contract: add
decision=approve and the census issues an authorization code and 302-redirects to
redirect_uri?code=…&state=… — so CI can automate approval with no HTML scraping.
decision=deny redirects with error=access_denied&state=…. Custom mobile schemes (e.g.
propagate://) are allowed as redirect_uri.

The seeded sandbox consent page rendered by GET /oauth/authorize (no decision param).
Worked example
Fully runnable — this leg is unsigned:# Render the consent page (200, text/html):
curl "https://phosra-api-sandbox-production.up.railway.app/oauth/authorize?redirect_uri=https://example.com/cb&state=xyz123"
# Machine path — approve and capture the 302 Location header:
curl -sD - -o /dev/null \
"https://phosra-api-sandbox-production.up.railway.app/oauth/authorize?redirect_uri=https://example.com/cb&state=xyz123&decision=approve" \
| grep -i '^location:'
const BASE = "https://phosra-api-sandbox-production.up.railway.app"
const res = await fetch(
`${BASE}/oauth/authorize?redirect_uri=https://example.com/cb&state=xyz123&decision=approve`,
{ redirect: "manual" },
)
const location = res.headers.get("location")
const code = new URL(location).searchParams.get("code") // sbxauth_…
console.log(res.status, code) // 302 sbxauth_QBmKueI14KzQj9PM-2M9naWGkh2OU6WL
302 on approve (captured from the hosted sandbox):
HTTP/2 302
location: https://example.com/cb?code=sbxauth_QBmKueI14KzQj9PM-2M9naWGkh2OU6WL&state=xyz123
sbxauth_… code at POST /oauth/token.Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Query Parameters
Where the 302 sends the code (https, http, or a custom mobile scheme).
Opaque value echoed back verbatim in the redirect (CSRF binding).
Omit to render the consent page. approve → 302 with ?code=&state=. deny → 302 with ?error=access_denied&state=.
approve, deny Response
Consent page (text/html) — shown when decision is omitted.
The response is of type string.