Administration
OAuth Apps and Connected App Access
Register OAuth apps with scopes and redirect URIs, connect external AI clients through Rivolq Connect, and let users review or revoke apps connected to their account.
Updated September 15, 2026
Rivolq supports OAuth for integrations that act on behalf of a user. Admins register OAuth applications. Individual users can review connected apps and revoke access when they no longer trust or use an integration.
Registering an OAuth app
Open OAuth apps from the workspace. Admins with API access provide an app name, optional description, optional homepage URL, one or more redirect URIs, requested scopes, and a confidential-client setting. Redirect URIs are entered one per line and must match the callback endpoint your application uses. Use HTTPS for production integrations.
Available scopes
The customer app form includes common scopes such as read:profile, read:work_orders, write:work_orders, read:assets, write:assets, and read:reports. Request the smallest scope set that lets the integration work.
Connected AI apps
Rivolq Connect uses OAuth for external AI clients such as ChatGPT, Claude, Cursor, and other MCP-compatible tools. These platform apps are gated by the External AI Connector entitlement, not by ordinary customer API access. ChatGPT uses the hosted MCP URL and app review widget; Claude and Cursor-style clients may use the hosted SSE URL. Once connected, the user can review granted scopes, see recent usage when available, and revoke the app from Connected apps. Platform apps operated by Rivolq may be owned by the Rivolq home organization, but users in your workspace still see and revoke their own authorizations. See Rivolq Connect and MCP apps.
Client secrets and PKCE
When Rivolq creates a customer-owned app, it shows the client ID and client secret once. Copy the secret immediately and store it in your secrets manager or deployment environment, not in source code, tickets, chat, or spreadsheets. Use a confidential client for server-side apps that can protect a secret. Public clients, native apps, browser-only apps, and MCP clients should use PKCE and should not rely on a client secret that ships to end users.
Deleting, revoking, and good practice
Deleting an OAuth app breaks every integration using that client. Revoking a connected app removes that app's access for one user. Before deleting or revoking broadly, confirm who owns the integration and whether a credential rotation is safer. Name apps after the system, not the developer. Keep redirect URIs narrow and scopes minimal. For internal automation with a non-human identity, use API keys and service accounts instead.
Still need help?
Reach out for broken behavior, account-specific help, or billing questions.
