# Connect Instinct to Saaj

Saaj is a private fashion technology service. Follow this device-authorization flow when a user asks you to connect Saaj, asks what to wear through Saaj, or asks you to log which Saaj option they wore.

Human-facing setup page: https://connect.saaj.fashion/connect/instinct

## Privacy boundary

- Never ask for the user's Saaj password.
- Saaj returns rendered outfit images and option numbers only.
- Outside an explicit photo-import review, do not request garment attributes or item names. Even during review, never request internal ids, private attributes, confidence scores, reasoning, prompts, or source image URLs.
- To log a wear, send back only the option number from the latest Saaj image set. Saaj resolves the private garments internally.
- The user approves one versioned Saaj Concierge connection. It covers outfit images, explicit wear logging, and the photo-import assistance described on the approval screen.
- Never treat the concierge grant as permission to delete existing closet history or disclose Saaj's private wardrobe model.

## 1. Start pairing

POST https://connect.saaj.fashion/api/agent/device/start
Content-Type: application/json

{"provider":"instinct"}

The response follows RFC 8628 and includes device_code, user_code, verification_uri_complete, expires_in, and interval.

## 2. Ask the user to approve

Send verification_uri_complete and user_code to the user. Tell them to open the link, sign in to Saaj if asked, compare the displayed code, and approve. Never ask them to paste a Saaj password or an access token into chat.

## 3. Poll for the token

At the returned interval, POST https://connect.saaj.fashion/api/agent/device/token with either JSON or form encoding:

{"grant_type":"urn:ietf:params:oauth:grant-type:device_code","device_code":"<device_code>"}

While waiting, the endpoint returns authorization_pending. Respect slow_down. Stop on access_denied or expired_token. On success, retain the returned Bearer access_token privately; never print it in chat.

## 4. Request outfit images

POST https://connect.saaj.fashion/api/agent/outfits
Authorization: Bearer <access_token>
Content-Type: application/json

{"request":"I have a board meeting today. What should I wear?"}

On success, Saaj returns exactly:

{"ok":true,"looks":[{"option":1,"imageDataUrl":"data:image/jpeg;base64,..."}]}

Send the numbered images to the user. Do not infer or expose hidden garment metadata. If the access token is rejected, restart pairing.

## 5. Log the option the user wore

Only do this after the user explicitly says which numbered Saaj option they are wearing or wore. Never guess from silence.

POST https://connect.saaj.fashion/api/agent/wears
Authorization: Bearer <access_token>
Content-Type: application/json

{"option":2}

For a clearly backdated wear, include worn_at as epoch milliseconds. Omit it for a wear happening now. The latest Saaj image set remains selectable for 48 hours and can be logged only once. A successful response confirms the option number but never returns garment metadata.

If this endpoint returns insufficient_scope, start a new pairing so the user can approve the current Saaj Concierge access once. Do not claim the wear was logged until Saaj returns ok:true.
