OAuth Integration Connections
Let users connect an external service so the app can read their data.
What it adds
An OAuth connect flow for third-party data access, showing exactly which external account is attached and what it can reach.
What your agent is told to do
6
What your agent is told to do
6-
1
Build the authorization flow with a single-use state value bound to the user's session, and PKCE where the provider supports it. Reject any callback whose state does not match — an unvalidated callback lets someone attach their account to another user's workspace.
-
2
Request the narrowest scopes that make the connection useful. Do not ask for write access to satisfy a read-only feature.
-
3
After connecting, display the external account identity — the email, handle, or workspace name the provider returned — not just 'Connected'.
-
4
Allow more than one connection to the same provider and keep each connection's tokens and data strictly separated. Store tokens encrypted and never render them in the UI or logs.
-
5
This feature is OAuth for data access only. OAuth used as a sign-in method is owned by Social Sign-In; extend that rather than building a second identity path. Ongoing health display is owned by Integration Connection Health, and refresh mechanics by OAuth Token Refresh Recovery.
-
6
Provide a disconnect action that revokes the token at the provider where the API allows it, rather than only deleting the local row.
Edge cases it handles
6
Edge cases it handles
6- A user may approve some scopes and decline others. Detect partial consent and say which capability is missing, instead of treating the connection as complete.
- The user may connect the wrong external account. Show the identity before anything syncs and offer a one-step swap.
- Consent revoked at the provider's end will not tell you. The connection must degrade honestly the next time a call fails.
- A user who connects the same external account twice should be merged into one connection, not left with two that fight over the same data.
- The callback can arrive twice — from a refresh or a retried redirect. Treat the authorization code as single-use and make the second attempt idempotent, not an error page.
- When the connecting user leaves the workspace, decide up front whether the connection dies with them or transfers. A shared integration silently owned by an ex-employee is a time bomb.
Definition of done
8
Definition of done
8- State is validated on every callback and PKCE is used where the provider supports it.
- Requested scopes are the minimum the feature needs, and are listed to the user before authorization.
- The connected external account is identified by name in the UI.
- Multiple connections to one provider coexist without sharing tokens or data.
- Partial or revoked consent produces a specific message, not a generic failure.
- Tokens are encrypted at rest and never appear in logs, exports, or the UI.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
Contentful Entry Sync
Contentful Entry Sync
Create and update Contentful entries against the connected space, environment, and locale.
What it does
A sync that writes app records into Contentful entries using the connected space's content model and locale configuration.
How it works
- 1 Have the operator select the space, the environment, and the default locale during connection, and store all three, because writing production content into a sandbox environment is an easy and expensive mistake.
- 2 Fetch the content model at connection time and again before each sync run, map app fields to entry fields by their stable identifiers, and validate the value type against the model before attempting the write.
- 3 Write every localized field under an explicit locale rather than relying on whatever the space treats as default, and state clearly which locales the app owns and which it leaves to editors.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/contentful-entry-sync
Typesense Index Sync
Typesense Index Sync
Keep a search index in step with your records so results stay current and correctly scoped.
What it does
A one-way sync from the app's records into a Typesense collection, with server-enforced tenant filtering and a rebuild path.
How it works
- 1 Identify every model users search today and declare the indexed shape explicitly: the fields people type into, the fields they filter and sort on, and nothing more. Treat a missing or newly added field as absent rather than letting the document fail validation.
- 2 Reuse the app's existing background-job system to push creates, updates, and deletes. Do not index inside the request cycle; a slow or unreachable search service must never make a save fail or hang.
- 3 Build the tenant, workspace, and permission filter on the server at query time and attach it to every search. Do not accept a filter, collection name, or scope value from a client-supplied parameter, because anything the browser can set the browser can change.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/typesense-index-sync
Mapbox Geocoding
Mapbox Geocoding
Convert typed locations into coordinates and structured addresses the app can use.
What it does
Forward and reverse geocoding with confirmed matches, controlled result bias, and coordinate precision rules.
How it works
- 1 Separate the two directions explicitly: text to coordinates for entry and search, coordinates to address for a dropped pin or a device location. They take different inputs, carry different confidence, and fail differently.
- 2 Present ambiguous matches as a list the user confirms. Silently taking the first result is how a record ends up in the wrong country with nobody noticing for months.
- 3 Bias results toward a location only when the app genuinely knows one, such as a workspace address or the map viewport the user is already looking at.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/mapbox-geocoding
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.