PipesHub OAuth Provider API
PipesHub OAuth 2.0 Authorization Server implementing RFC 6749, RFC 7636 (PKCE), and OpenID Connect. **Supported Grant Types:** - `authorization_code` - Standard OAuth flow with PKCE support - `client_credentials` - Machine-to-machine authentication - `refresh_token` - Token refresh for long-lived access **Security Features:** - PKCE (Proof Key for Code Exchange) for public clients - State parameter for CSRF protection - Configurable token lifetimes - Token revocation and introspection **OpenID Connect:** - ID tokens with standard claims - UserInfo endpoint for profile data - Discovery endpoint for automatic configuration **Machine tokens (`client_credentials`) — gateway and downstream identity:** Access tokens may encode **`userId === client_id`**. The **Node.js API gateway** resolves the effective user to the OAuth **app creator**: first using the JWT **`createdBy`** claim when present, otherwise by loading the OAuth app by **`client_id`** from the registry. After verification it sets the authenticated session to that creator. **Python services:** Validate `Authorization: Bearer` as today and use the JWT payload’s **`userId`** as-is for scopes and user-scoped logic (which may still equal **`client_id`** for machine tokens). **Operational note:** Prefer tokens whose JWT already carries the creator as **`userId`**; use **`POST /oauth-clients/{appId}/revoke-all-tokens`** and obtain new tokens from **`POST /oauth2/token`** when rotating integrations.