Dashboard
OAuth apps
Authorize integrations for a single team.
Register an app
Use your installation’s dashboard origin for OAuth, not its REST API origin. Register exact callback URLs and explicit scopes: emails:send, full_access, or both.
curl "$OPENSEND_URL/oauth/register" -H "Content-Type: application/json" \
-d '{"client_name":"Example integration","redirect_uris":["https://example.com/callback"],"scope":"emails:send","token_endpoint_auth_method":"client_secret_basic"}'Authorize and exchange
Use authorization code with S256 PKCE for public and confidential clients. Generate a random state, validate it on return, and exchange the code within two minutes. Public clients use token_endpoint_auth_method none; confidential clients use client_secret_basic or client_secret_post.
Refresh and revoke
Access tokens last 15 minutes. Refresh tokens rotate and expire after 30 days. Save the replacement atomically. Reusing a consumed refresh token invalidates the authorization. Manage access in Profile → OAuth apps or Settings → Team → Authorized apps.
Limits
Each consent belongs to one team and verified member. Ordinary logout preserves integrations; password reset, membership removal, app maintenance, and SSO policy changes invalidate them. OAuth never grants account-security or membership-management access.