Create an application
- Open Workspace settings → OAuth Apps.
- Select Create OAuth app.
- Add the application name, slug, description, overview, developer name, and website.
- Add the URL where users can begin installing the integration.
- Register every exact callback URL used after authorization.
- Enable Allow PKCE when the application runs in a browser, mobile app, or desktop client that cannot protect a secret.
- Add an icon and optional screenshots, then create the application.
Callback URLs
Callback URLs must match the authorization request exactly, including scheme, hostname, port, path, and trailing slash.- Use HTTPS in production.
- HTTP is accepted only for localhost and loopback development.
- Add each development, staging, and production callback separately.
- Remove callback URLs that are no longer deployed.
Client ID and secret
The application details page shows the client ID. Creating an application does not reveal its initial client secret. When a confidential server application is ready to connect, open the application menu and select Regenerate secret. The new secret is shown once. Copy it directly into a server-side secret manager. Regenerating the secret invalidates the previous client secret, so deploy the replacement deliberately. Public clients use S256 PKCE and must not receive a client secret.Edit the application listing
Open an application and select Configuration to change its listing, callback URLs, media, or PKCE setting. The save action remains disabled until the page differs from the saved application. Saving shows a confirmation and keeps you on the configuration page. The name, developer, icon, description, requested permissions, and verification status can appear on the authorization screen. Write them for users who need to decide whether they trust the connection.Remove an application
Removing an OAuth application:- prevents new authorization requests;
- revokes every active connection created by that application;
- invalidates its access and refresh tokens;
- removes webhook endpoints owned by those OAuth connections; and
- deletes the application’s uploaded icon and screenshots.

