Showing all 51 providers.

Commerce7

Shopify

Built-in workflow

Use dedicated Shopify routes in this app for token exchange and verification.

  • Commerce
  • Refresh handled per provider

Stripe Connect

Automated OAuth form

Stripe Connect token exchange authenticates with your Stripe secret key and does not send client_id in the token request.

  • Commerce
  • Refresh handled per provider

PayPal

Automated OAuth form

Use sandbox endpoints in development by replacing host with api-m.sandbox.paypal.com.

  • Commerce
  • Refresh path included

Amazon SP-API

Manual / specialised flow

Requires Amazon's SP-API install callback fields and LWA token handling; not supported by the generic OAuth form.

  • Commerce
  • Refresh handled per provider

eBay

Automated OAuth form

Token verification can fail unless user-related scopes are granted.

  • Commerce
  • Refresh path included

Etsy

Automated OAuth form

Etsy requires S256 PKCE and an API key header on Open API v3 resource requests.

  • Commerce
  • Refresh path included

BigCommerce

Manual / specialised flow

BigCommerce app installation posts a code, scope, and store context to the app callback; it is not a normal user-entered authorization-code form.

  • Commerce
  • Refresh handled per provider

Productivity / Enterprise18

Google

Automated OAuth form

Use access_type=offline and prompt=consent for reliable refresh token issuance.

  • Productivity / Enterprise
  • Refresh path included

Microsoft Graph

Automated OAuth form

Tenant-specific endpoints may be required for enterprise scenarios.

  • Productivity / Enterprise
  • Refresh path included

Slack

Automated OAuth form

Slack bot tokens are commonly long-lived and refresh token support varies by app setup.

  • Productivity / Enterprise
  • Refresh path included

GitHub

Automated OAuth form

GitHub OAuth apps typically issue non-refreshable tokens unless using expiring user tokens with specific settings.

  • Productivity / Enterprise
  • Refresh path included

Atlassian

Automated OAuth form

Uses rotating refresh tokens with strict reuse rules.

  • Productivity / Enterprise
  • Refresh path included

GitLab

Automated OAuth form

This workflow targets GitLab.com. Self-managed GitLab instances require instance-specific endpoints.

  • Productivity / Enterprise
  • Refresh path included

Bitbucket Cloud

Automated OAuth form

OAuth consumer permissions are configured at the Bitbucket workspace rather than selected per authorization request.

  • Productivity / Enterprise
  • Refresh path included

Notion

Automated OAuth form

Public connections authorize a workspace and selected pages; the token response includes workspace and bot metadata.

  • Productivity / Enterprise
  • Refresh path included

Asana

Automated OAuth form

Requested scopes must first be enabled for the app in Asana's developer console.

  • Productivity / Enterprise
  • Refresh path included

Linear

Automated OAuth form

User authorization returns 24-hour access tokens and rotating refresh tokens; PKCE is also supported.

  • Productivity / Enterprise
  • Refresh path included

Airtable

Automated OAuth form

Airtable requires S256 PKCE, at least one registered scope, and explicit base or workspace resource selection.

  • Productivity / Enterprise
  • Refresh path included

Zoom

Automated OAuth form

This workflow covers confidential user authorization. Zoom Server-to-Server and public PKCE apps use different grant requirements.

  • Productivity / Enterprise
  • Refresh path included

DocuSign

Automated OAuth form

These endpoints target DocuSign production. Demo accounts use account-d.docusign.com until the integration passes go-live review.

  • Productivity / Enterprise
  • Refresh path included

monday.com

Automated OAuth form

This workflow uses monday.com's new OAuth 2.1 endpoint with mandatory S256 PKCE and rotating refresh tokens.

  • Productivity / Enterprise
  • Refresh path included

WordPress.com / Jetpack

Manual / specialised flow

WordPress.com authorization may target one blog or broader scopes, and token inspection requires both client ID and token query parameters.

  • Productivity / Enterprise
  • Refresh handled per provider

Auth0

Manual / specialised flow

Auth0 endpoints, audiences, connections, and token claims are tenant-specific; the workflow must start from the tenant issuer URL.

  • Productivity / Enterprise
  • Refresh path included

Okta

Manual / specialised flow

Okta uses tenant-specific issuers and may use the org authorization server or a named custom authorization server.

  • Productivity / Enterprise
  • Refresh path included

Adobe

Manual / specialised flow

Adobe IMS user authentication is product- and project-specific; APIs define their own scopes, approval rules, and production promotion requirements.

  • Productivity / Enterprise
  • Refresh path included

CRM / Finance11

HubSpot

Automated OAuth form

Uses HubSpot OAuth v3 token endpoints; token metadata verification embeds the access token in the URL path.

  • CRM / Finance
  • Refresh path included

Salesforce

Automated OAuth form

Use test.salesforce.com for sandbox orgs.

  • CRM / Finance
  • Refresh path included

QuickBooks

Automated OAuth form

realmId is required for many QuickBooks API calls after token exchange.

  • CRM / Finance
  • Refresh path included

Box

Automated OAuth form

Refresh tokens rotate frequently; store latest refresh token after each refresh.

  • CRM / Finance
  • Refresh path included

Dropbox

Automated OAuth form

Use token_access_type=offline to request refresh tokens.

  • CRM / Finance
  • Refresh path included

Xero

Automated OAuth form

After authorization, retrieve the Xero tenant list and retain the selected tenant ID with the token record.

  • CRM / Finance
  • Refresh path included

FreshBooks

Automated OAuth form

FreshBooks returns account and business identifiers that are required by later accounting API calls.

  • CRM / Finance
  • Refresh path included

Mailchimp

Automated OAuth form

Use the OAuth metadata response to discover the account-specific API endpoint and data-center prefix.

  • CRM / Finance
  • Refresh handled per provider

Klaviyo

Manual / specialised flow

Klaviyo requires mandatory PKCE, Basic client authentication, account-scoped tokens, API revision headers, and marketplace review rules.

  • CRM / Finance
  • Refresh path included

Zendesk

Manual / specialised flow

Zendesk OAuth endpoints are built from the customer's Zendesk subdomain, so a fixed generic provider endpoint is insufficient.

  • CRM / Finance
  • Refresh handled per provider

Freshdesk

Manual / specialised flow

Freshworks OAuth varies by product, account domain, and regional authorization host and needs a dedicated endpoint resolver.

  • CRM / Finance
  • Refresh path included

Social / Content15

Meta (Facebook/Instagram)

Automated OAuth form

Instagram long-lived token flow has provider-specific endpoints; use dedicated Instagram routes in this app.

  • Social / Content
  • Refresh path included

Instagram

Built-in workflow

Exchange a short-lived token for a 60-day long-lived token, verify it, and refresh it before expiry.

  • Social / Content
  • Refresh path included

LinkedIn

Automated OAuth form

Some LinkedIn APIs require product approvals beyond standard OAuth scopes.

  • Social / Content
  • Refresh handled per provider

TikTok

Automated OAuth form

TikTok often requires region and product-specific app enablement before scopes are usable.

  • Social / Content
  • Refresh path included

X (Twitter)

Automated OAuth form

PKCE is required for public clients in OAuth 2.0 flow.

  • Social / Content
  • Refresh path included

Discord

Automated OAuth form

Guild-level permissions may require additional bot flow setup beyond OAuth user auth.

  • Social / Content
  • Refresh path included

Canva

Automated OAuth form

Canva requires Authorization Code with S256 PKCE and explicit scopes enabled in the Developer Portal.

  • Social / Content
  • Refresh path included

Spotify

Automated OAuth form

Authorization Code is for confidential apps; desktop, mobile, and browser clients should use Spotify's PKCE flow.

  • Social / Content
  • Refresh path included

Vimeo

Automated OAuth form

Vimeo authorization-code tokens can remain active while used; this flow does not issue a standard refresh token.

  • Social / Content
  • Refresh handled per provider

Twitch

Automated OAuth form

This workflow generates a user access token; app tokens use the separate Client Credentials grant.

  • Social / Content
  • Refresh path included

YouTube Data API

Automated OAuth form

Enable YouTube Data API v3 in the Google Cloud project and request only the YouTube scopes the workflow needs.

  • Social / Content
  • Refresh path included

Figma

Automated OAuth form

Figma authorization codes expire after 30 seconds; exchange immediately after the callback.

  • Social / Content
  • Refresh path included

Patreon

Automated OAuth form

Use a Patreon API v2 client and v2 identity/member scopes; public API v1 retires on 7 October 2026.

  • Social / Content
  • Refresh path included

Reddit

Automated OAuth form

duration=permanent requests a refresh token; API requests with OAuth tokens use oauth.reddit.com.

  • Social / Content
  • Refresh path included

Pinterest

Manual / specialised flow

Pinterest production access and available scopes depend on app review and product approval, so the workflow needs approval-aware guidance.

  • Social / Content
  • Refresh path included