OAuth applications
Another application that asks a member of an account for access, and gets only what the member allows.
Step by step
- Open “Integrations” and, in the “OAuth applications” card, choose “Register an application”.
- Fill in the name and the redirect addresses: up to 5 HTTPS addresses separated by spaces; http only for localhost.
- Choose “Create” and keep the client ID and the client secret, which is shown only once.
- The application sends a person to “Allow access” through the authorization code flow with PKCE. A member of any account can allow it, not only a member of yours.
- There they see who asks, as whom it will act and the access it asks for, and pick under “Account it may act in” the account it will act in. They choose “Allow” or “Deny”.
- Once allowed, the application gets a code at its redirect address and exchanges it for a token.
Good to know
The application acts only in the account the member picked, and only within that member’s role there.
The owner of that account revokes its access under “Integrations”, in “Applications with access”; the person who allowed it revokes it on their profile, under “Applications you allowed”.
When you remove the application under “Integrations”, its tokens stop working at once, in every account that allowed it.
Related articles
- API credentialsFor a script or service of your own: it acts as you, only in this account, and only as far as you choose.
- Connect an AI assistantConnect Claude, ChatGPT, Cursor or another assistant that takes a custom MCP connector, and work with your invoicing in a conversation.
- WebhooksLearn at once that an invoice was issued, sent or paid: we send a POST to your address.