> ## Documentation Index
> Fetch the complete documentation index at: https://docs.yume.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# Create consent

> The SPA's consent screen for an MCP client. `/authorize` sends the person there with a
signed `authorization`; the answer comes back here and leaves as the client's redirect.



## OpenAPI

````yaml /openapi/assistant.json post /v1/assistant/mcp/consent/
openapi: 3.0.3
info:
  title: Yume API — AI Ассистент
  version: 1.0.0
  description: SSE чат-шлюз и инструменты ассистента.
servers:
  - url: https://api.yume.cloud
    description: Production
  - url: https://api.stage.yume.cloud
    description: Stage
security: []
paths:
  /v1/assistant/mcp/consent/:
    post:
      tags:
        - mcp
      summary: Create consent
      description: >-
        The SPA's consent screen for an MCP client. `/authorize` sends the
        person there with a

        signed `authorization`; the answer comes back here and leaves as the
        client's redirect.
      operationId: mcp_consent_create
      parameters:
        - $ref: '#/components/parameters/TenantId'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ConsentDecision'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/ConsentDecision'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/ConsentDecision'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/McpConsentRedirect'
          description: ''
      security:
        - jwtAuth: []
components:
  parameters:
    TenantId:
      name: X-Tenant-Id
      in: header
      required: false
      schema:
        type: integer
      description: >-
        Компания, в контексте которой выполняется запрос — её id из `GET
        /v1/tenant/`. Пользователь должен состоять в этой компании: чужой id
        доступа к данным не даёт. Без заголовка компания определяется по домену
        запроса.
  schemas:
    ConsentDecision:
      type: object
      properties:
        authorization:
          type: string
        allow:
          type: boolean
        tenant:
          type: integer
      required:
        - allow
        - authorization
    McpConsentRedirect:
      type: object
      properties:
        redirect_to:
          type: string
      required:
        - redirect_to
  securitySchemes:
    jwtAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````