PipesHub OAuth Apps API
Manage OAuth 2.0 client applications registered with PipesHub. OAuth apps allow third-party applications to access PipesHub APIs on behalf of users or organizations. Each app receives a client ID and secret for authentication. **Who can see which apps** - **Everyone (including org admins)** sees and manages only OAuth apps **they created** (`createdBy`). Other members' apps are hidden (not listed; individual operations return not found). **Session only** - Every `/oauth-clients/*` route requires the user's interactive session JWT. OAuth access tokens and personal access tokens (`phpat_...`) are rejected with `403`, so a token issued to a client can never register, reconfigure, or revoke clients on its own. **Who authorizes vs. client credentials** - **Authorization code:** Any authenticated user in the workspace may complete consent for a valid `client_id`; issued tokens represent **that user**. - **Client credentials:** Access tokens represent the **OAuth app creator** (who registered the client), not the caller. **Scopes** - `GET /oauth-clients/scopes` returns scopes grouped by category for the **signed-in user's role**. - **Org admins** may register apps that request additional **admin-only** scopes; non-admins cannot select those scopes when creating or updating an app. **App Types:** - **Confidential clients**: Server-side apps that can securely store secrets - **Public clients**: Browser/mobile apps that cannot securely store secrets (use PKCE) **App Lifecycle:** - Create apps with name, redirect URIs, allowed scopes, and optional URLs (homepage, privacy, terms) - Regenerate secrets if compromised - Suspend/activate apps to control access - Revoke all tokens for emergency access removal