# PipesHub OAuth Provider API

**Canonical:** https://apis.io/apis/pipeshub/pipeshub-oauth-provider-api/  
**Provider:** PipesHub — https://apis.io/providers/pipeshub/  
**Base URL:** https://app.pipeshub.com/api/v1  
**Documentation:** https://docs.pipeshub.com/developer/api-reference

PipesHub OAuth Provider API is one of 51 APIs that [PipesHub](https://apis.io/providers/pipeshub/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. This API exposes 6 JSON Schema definitions. Tagged areas include OAuth Provider. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and 6 JSON Schemas.

PipesHub OAuth 2.0 Authorization Server implementing RFC 6749, RFC 7636 (PKCE), and OpenID Connect. **Supported Grant Types:** - `authorization_code` - Standard OAuth flow with PKCE support - `client_credentials` - Machine-to-machine authentication - `refresh_token` - Token refresh for long-lived access **Security Features:** - PKCE (Proof Key for Code Exchange) for public clients - State parameter for CSRF protection - Configurable token lifetimes - Token revocation and introspection **OpenID Connect:** - ID tokens with standard claims - UserInfo endpoint for profile data - Discovery endpoint for automatic configuration **Machine tokens (`client_credentials`) — gateway and downstream identity:** Access tokens may encode **`userId === client_id`**. The **Node.js API gateway** resolves the effective user to the OAuth **app creator**: first using the JWT **`createdBy`** claim when present, otherwise by loading the OAuth app by **`client_id`** from the registry. After verification it sets the authenticated session to that creator. **Python services:** Validate `Authorization: Bearer` as today and use the JWT payload’s **`userId`** as-is for scopes and user-scoped logic (which may still equal **`client_id`** for machine tokens). **Operational note:** Prefer tokens whose JWT already carries the creator as **`userId`**; use **`POST /oauth-clients/{appId}/revoke-all-tokens`** and obtain new tokens from **`POST /oauth2/token`** when rotating integrations.

## Operations (5)

| Method | Path | Summary |
|---|---|---|
| GET | `/oauth2/authorize` | Initiate OAuth authorization flow |
| POST | `/oauth2/authorize` | Submit authorization consent |
| POST | `/oauth2/token` | Exchange authorization code for tokens |
| POST | `/oauth2/revoke` | Revoke an access or refresh token |
| POST | `/oauth2/introspect` | Introspect a token |

## Machine-readable artifacts (8)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/openapi/pipeshub-oauth-provider-api-openapi.yml
- **Documentation** — https://docs.pipeshub.com/developer/api-reference
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/json-schema/pipeshub-get-record-by-id-response-schema-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/json-schema/pipeshub-record-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/json-schema/pipeshub-knowledge-hub-nodes-response-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/json-schema/pipeshub-agent-create-conversation-request-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/json-schema/pipeshub-conversation-schema.json
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/pipeshub/refs/heads/main/json-schema/pipeshub-create-conversation-request-schema.json

## Other PipesHub APIs (12)

- [PipesHub Agents API](https://apis.io/apis/pipeshub/pipeshub-agents-api/)
- [PipesHub AI Models Providers API](https://apis.io/apis/pipeshub/pipeshub-ai-models-providers-api/)
- [PipesHub Authentication Configuration API](https://apis.io/apis/pipeshub/pipeshub-authentication-configuration-api/)
- [PipesHub Configuration Manager API](https://apis.io/apis/pipeshub/pipeshub-configuration-manager-api/)
- [PipesHub Connector API](https://apis.io/apis/pipeshub/pipeshub-connector-api/)
- [PipesHub Connector Configuration API](https://apis.io/apis/pipeshub/pipeshub-connector-configuration-api/)
- [PipesHub Connector Control API](https://apis.io/apis/pipeshub/pipeshub-connector-control-api/)
- [PipesHub Connector Filters API](https://apis.io/apis/pipeshub/pipeshub-connector-filters-api/)
- [PipesHub Connector Instances API](https://apis.io/apis/pipeshub/pipeshub-connector-instances-api/)
- [PipesHub Connector OAuth API](https://apis.io/apis/pipeshub/pipeshub-connector-oauth-api/)
- [PipesHub Connector Registry API](https://apis.io/apis/pipeshub/pipeshub-connector-registry-api/)
- [PipesHub Connectors API](https://apis.io/apis/pipeshub/pipeshub-connectors-api/)

## Tags

OAuth Provider

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/pipeshub/pipeshub-oauth-provider-api/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/pipeshub/.
