Skip to documentation

Dashboard

OAuth apps

Authorize integrations for a single team.

Register an app

Use your installation’s dashboard origin for OAuth, not its REST API origin. Register exact callback URLs and explicit scopes: emails:send, full_access, or both.

bash
curl "$OPENSEND_URL/oauth/register" -H "Content-Type: application/json" \
  -d '{"client_name":"Example integration","redirect_uris":["https://example.com/callback"],"scope":"emails:send","token_endpoint_auth_method":"client_secret_basic"}'

Authorize and exchange

Use authorization code with S256 PKCE for public and confidential clients. Generate a random state, validate it on return, and exchange the code within two minutes. Public clients use token_endpoint_auth_method none; confidential clients use client_secret_basic or client_secret_post.

Refresh and revoke

Access tokens last 15 minutes. Refresh tokens rotate and expire after 30 days. Save the replacement atomically. Reusing a consumed refresh token invalidates the authorization. Manage access in Profile → OAuth apps or Settings → Team → Authorized apps.

Limits

Each consent belongs to one team and verified member. Ordinary logout preserves integrations; password reset, membership removal, app maintenance, and SSO policy changes invalidate them. OAuth never grants account-security or membership-management access.