How-to — task-oriented recipe.
Overview
An OAuth app lets people in your organization connect a tool to Affinity by signing in with their own Affinity account. Nobody has to create, paste, or share an API key. Each person approves the connection on an Affinity consent screen, and the tool then acts as that person, with the same data access they already have. An OAuth app you create belongs to your organization. Only people in your organization can authorize it. Use an OAuth app when a tool acts on behalf of individual people, and each person should sign in as themselves. For example, an internal dashboard your deal team signs into, or an in-house assistant built on the Affinity MCP server. Use an API key when a script or integration runs as one account in the background, for example a nightly data sync.Prerequisites
Plan: Scale, Advanced, or Enterprise. Permissions required:- Manage all OAuth apps to create, edit, or revoke OAuth apps. Enterprise Admins and Admins have it by default.
- Manage IP allowlist to set or change an app’s IP allowlist, if your organization restricts who can set IP allowlists.
- Ask the developer building the tool for its redirect URI (the address Affinity sends people back to after they sign in) and whether it runs on a server or on people’s own devices.
- Decide which scopes the tool needs. Give it the fewest that work.
Part 1: Create an OAuth app
Step 1: Open Manage Apps
- Click Settings in the left navigation.
- Click Manage Apps.
- Click New App, then choose OAuth App. If you only see a New OAuth App button, click that instead.
Step 2: Fill in the app details
The Add New OAuth App form has four sections. App Information
Client Details
OAuth Details
IP Allowlist (optional)
Allowed IP Addresses and Ranges: one IP address or range per line, up to 100. Leave it blank to allow any address. When it’s set, requests from any other address are rejected.
Step 3: Add the app
- Click Add App.
- Confidential apps only: a Client Secret Created window shows the client secret. Click Copy client secret and store it somewhere secure, such as your password manager, then share it with the developer securely.
Step 4: Give the developer the Client ID
- In Manage Apps, open the app you created.
- Copy the Client ID from the OAuth Details card.
- Send the developer the Client ID (and, for a confidential app, the client secret).
Scopes
Scopes decide what the tool can do on each person’s behalf. A tool never gets more access than the person who authorized it.What your team sees when they connect
The first time someone uses the tool, it sends them to an Affinity sign-in page, followed by a consent screen:- The screen names the app and the Affinity organization it will connect to.
- It lists what the app will be able to do, one checkbox per scope. Everything is checked by default, and the person can uncheck any scope they don’t want to grant.
- They click Allow Access to connect, or Cancel.
Part 2: View and edit an OAuth app
- Go to Settings → Manage Apps. OAuth apps show OAuth in the Type column.
- Click the app to open it. You’ll see the Client ID, Redirect URIs, Allowed Scopes, and Allowed IP Addresses and Ranges, plus who created it, when, its Client Type, and its Default API Version.
- To change it, click Edit Details, make your changes, and click Save Changes.
Part 3: Revoke an OAuth app
Revoke an app when the tool is no longer used, when its client secret may have been exposed, or when you need to cut off its access.- Go to Settings → Manage Apps.
- Open the app, or click ⋯ on its row.
- Click Revoke App.
- Read the confirmation and click Revoke App.
- Immediately stops all API access for the app.
- Disconnects everyone in your organization who connected it.
- Can’t be undone. The app is removed, and its Client ID stops working.
Current limitations
- The client secret can’t be viewed again or reset. To replace it, revoke the app and create a new one.
- There’s no way to pause an app. Revoking removes it.
- The client type can’t be changed after the app is created.
- An IP allowlist applies to Affinity API v2 only.
- Requests from OAuth apps count toward your organization’s API usage and rate limits, the same as API keys.