PipesHub OAuth Apps API

Manage OAuth 2.0 client applications registered with PipesHub. OAuth apps allow third-party applications to access PipesHub APIs on behalf of users or organizations. Each app receives a client ID and secret for authentication. **Who can see which apps** - **Everyone (including org admins)** sees and manages only OAuth apps **they created** (`createdBy`). Other members' apps are hidden (not listed; individual operations return not found). **Session only** - Every `/oauth-clients/*` route requires the user's interactive session JWT. OAuth access tokens and personal access tokens (`phpat_...`) are rejected with `403`, so a token issued to a client can never register, reconfigure, or revoke clients on its own. **Who authorizes vs. client credentials** - **Authorization code:** Any authenticated user in the workspace may complete consent for a valid `client_id`; issued tokens represent **that user**. - **Client credentials:** Access tokens represent the **OAuth app creator** (who registered the client), not the caller. **Scopes** - `GET /oauth-clients/scopes` returns scopes grouped by category for the **signed-in user's role**. - **Org admins** may register apps that request additional **admin-only** scopes; non-admins cannot select those scopes when creating or updating an app. **App Types:** - **Confidential clients**: Server-side apps that can securely store secrets - **Public clients**: Browser/mobile apps that cannot securely store secrets (use PKCE) **App Lifecycle:** - Create apps with name, redirect URIs, allowed scopes, and optional URLs (homepage, privacy, terms) - Regenerate secrets if compromised - Suspend/activate apps to control access - Revoke all tokens for emergency access removal

Operations 12

GET /oauth-clients List OAuth apps #
POST /oauth-clients Create OAuth app #
GET /oauth-clients/scopes List available scopes #
GET /oauth-clients/{appId} Get OAuth app details #
PUT /oauth-clients/{appId} Update OAuth app #
DELETE /oauth-clients/{appId} Delete OAuth app #
POST /oauth-clients/{appId}/regenerate-secret Regenerate client secret #
POST /oauth-clients/{appId}/suspend Suspend OAuth app #
POST /oauth-clients/{appId}/activate Activate suspended OAuth app #
GET /oauth-clients/{appId}/tokens List app tokens #
POST /oauth-clients/{appId}/revoke-all-tokens Revoke all app tokens #
PUT /oauth-clients/{appId}/token-identity Choose whose identity this app's client_credentials tokens carry #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/pipeshub:pipeshub-oauth-apps-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

pipeshub-oauth-apps-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Pipeshub OAuth Apps API
  version: 1.0.0
  contact:
    name: API Support
    email: support@pipeshub.com
  description: 'Operations tagged OAuth Apps across 2 of this provider''s published API definitions: pipeshub-openapi.yaml, pipeshub-openapi.yml. Each path carries the servers of the definition it was published in.'
servers:
- url: '{instance_url}/api/v1'
  description: Base API URL
  variables:
    instance_url:
      default: https://app.pipeshub.com
      description: Base server URL (without /api/v1)
- url: '{instance_url}'
  description: Root URL (used for MCP endpoints mounted at /mcp)
  variables:
    instance_url:
      default: https://app.pipeshub.com
      description: Base server URL
security:
- bearerAuth: []
- oauth2: []
tags:


# --- truncated at 32 KB (54 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/openapi/pipeshub-oauth-apps-api-openapi.yml