It rendered on every authorization regardless of client, and the request
contract carries no signal for which clients actually reuse a grant across
workspaces.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The tick after the app name is gone while `is_verified` stays on the request
contract and in the mocks. An unverified publisher still raises the trust
warning.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
One details card of key-value rows replaces the identity and organization
cards, reusing the row treatment from the MCP secrets interstitial. The
permissions card renders each scope group as a monospace level label above
its human-readable name, separated by hairlines rather than badges and raw
scope rows.
The project picker now uses the MultiSelector from ui-patterns rather than a
hand-rolled popover, following the badge combo box pattern from the design
system docs. Selection still caps at ten by disabling unselected options.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Approve now takes { slug, auth_id, project_refs } and returns { url } only,
so the success screen is fed from what the screen already knows rather than
from a grant on the mutation response. Roles moved per project, so the
identity card and receipt read the org-level default_role.
Also shows the selection counter only from eight selected onward. The hard
stop and helper text at ten are unchanged.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The AuthorizeResult union and its guards were never wired into the approve
flow, so knip reported the file as dead. Reintroduce it alongside the error
state that uses it.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>