Skip to content
POST
/v1/organizations/{organizationId}/integration-applications

Register an Organization-owned OAuth application

Register a connected-data provider application and its write-only OAuth client secret for the Organization.

Authentication

Send an API key as a Bearer token in the Authorization header.

Parameters

NameLocationRequiredDescription
organizationIdpathYes
The Organization to address.
stringA Cantora Organization identifier, prefixed with `org_`.
  • maximum length 64
  • pattern ^org_[\s\S]+$

Request body

Required.

application/json
object
  • unknown properties allowed false
providerrequired
IntegrationProviderThe connected-data provider this OAuth application belongs to.
providerClientIdrequired
stringThe provider's stable OAuth client identifier.
  • maximum length 512
  • minimum length 1
  • pattern ^[!-~]+$
displayNamerequired
stringThe human-readable integration application name.
  • maximum length 200
  • minimum length 1
clientSecretrequired
stringThe write-only OAuth client secret used for token exchange and refresh.
  • maximum length 8192
  • minimum length 1
  • write only true

Responses

201IntegrationApplicationCreated
400The request path, headers, query, or JSON body did not satisfy the published schema
401Unauthorized
application/json
403Forbidden
application/json
404NotFound
application/json
409Conflict
application/json

Reusable schemas

IntegrationApplicationCreatedEncoded

object
  • unknown properties allowed false
integrationApplicationIdrequired
stringThe Organization-owned integration application identifier.
  • maximum length 64
  • pattern ^integration_app_[\s\S]+$
organizationIdrequired
stringThe Organization identifier.
  • maximum length 64
  • pattern ^org_[\s\S]+$
providerrequired
IntegrationProviderThe model, Surface, or integration provider key.
providerClientIdrequired
stringThe provider's stable OAuth client identifier.
displayNamerequired
stringThe human-readable resource name.
credentialGenerationrequired
integerThe current credential generation, incremented on rotation.
  • greater than 0
credentialEtagrequired
stringThe strong ETag for the current provider-credential generation.
  • maximum length 12
  • pattern ^"(?:[1-9][0-9]{0,9})"$
statusrequired
IntegrationApplicationStatusThe current lifecycle status.
createdAtrequired
stringWhen the resource was created, in UTC.
  • format date-time

UnauthorizedEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Unauthorized"
reasonrequired
stringA safe explanation of why the credential was rejected.

ForbiddenEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Forbidden"
permissionrequired
stringThe permission required by the refused operation.

NotFoundEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "NotFound"
resourcerequired
stringThe resource type relevant to the error.
idrequired
stringThe identifier supplied for the resource that was not found.

ConflictEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Conflict"
resourcerequired
stringThe resource type relevant to the error.
reasonrequired
stringA safe explanation of the state conflict.

IntegrationProvider

string
  • allowed values "gmail", "googleCalendar", "twitter"

IntegrationApplicationStatus

string
  • allowed values "active", "disabled"