Administration
Developer Portal and API Reference
The developer portal explains how to connect external tools to Rivolq using OAuth, webhooks, and the REST API, with scope and event catalogs, rate limits, and Rivolq Connect expectations.
Updated September 15, 2026
The developer portal is the starting point for customer-owned integrations. It explains how approved developers can connect external tools to Rivolq using OAuth, webhooks, and the REST API.
Where to find it
Open app.rivolq.com/developers. In development environments it links to interactive API docs and a ReDoc reference; in production, API reference access may be request-based. The portal includes API documentation links or access requests, an OAuth quick-start flow, a webhook event catalog, an OAuth scope catalog, rate-limit expectations, and a link to register OAuth apps.
OAuth quick start
- 01Redirect the user to authorize with client_id, redirect_uri, response_type=code, requested scopes, state, and a PKCE challenge.
- 02Exchange the authorization code for tokens at the token endpoint.
- 03Call the API with the access token.
Use OAuth when the integration acts on behalf of a Rivolq user and should respect that user's granted scopes. Registration is covered in OAuth apps and connected app access.
Platform apps and Rivolq Connect
Some platform apps are registered and operated by Rivolq so external AI clients can connect across customer workspaces. They use the External AI Connector entitlement and the Rivolq Connect MCP service. ChatGPT and OpenAI Apps use the hosted /mcp/ transport and proposal widget metadata; Claude and Cursor-style clients may use /sse. They still follow least-privilege scopes, OAuth consent, revocation, tenant re-checks, short-lived connector sessions, and audit logging. See Rivolq Connect and MCP apps.
Catalogs and rate limits
The webhook event catalog lists event names and descriptions; use it to decide what a connector should subscribe to. Scopes define what an OAuth app can access; common examples include profile, work-order, asset, report, and connector-specific scopes. Request only what the app needs.
The portal shows a platform expectation of 600 requests per minute per session, with X-RateLimit headers on responses. Read those headers, back off when needed, and avoid retry storms. Rivolq Connect also has connector-side per-org and per-client limits.
Developer setup checklist
- Register an OAuth app with exact redirect URIs and least-privilege scopes.
- Keep client secrets out of source code.
- Subscribe only to events your destination will use.
- Test in a non-production workflow before routing operational data.
- Use Rivolq Connect rather than hand-rolled API glue for MCP-compatible AI clients.
Still need help?
Reach out for broken behavior, account-specific help, or billing questions.
