Endpoints
Token requests use
application/x-www-form-urlencoded. API requests send the
access token through Authorization: Bearer <ACCESS_TOKEN>.
Client types
An OAuth access token selects its approved workspace automatically. The current
user must retain workspace access and every API request must pass the token’s
scope, workspace policy, plan, and quota checks.
Reference pages
Authorization request
Build the redirect and handle approval or denial.
Token endpoint
Exchange a code and rotate refresh tokens.
Connected workspace
Retrieve the user, connection, and workspace identity.
Scopes
Request the smallest granular permission set.
Revocation
Invalidate an installation and its tokens.
Errors
Handle OAuth protocol errors safely.

