AddThisFeature

OAuth Integration Connections

Let users connect an external service so the app can read their data.

involved Integrations

What it adds

An OAuth connect flow for third-party data access, showing exactly which external account is attached and what it can reach.

What your agent is told to do

6
  1. 1

    Build the authorization flow with a single-use state value bound to the user's session, and PKCE where the provider supports it. Reject any callback whose state does not match — an unvalidated callback lets someone attach their account to another user's workspace.

  2. 2

    Request the narrowest scopes that make the connection useful. Do not ask for write access to satisfy a read-only feature.

  3. 3

    After connecting, display the external account identity — the email, handle, or workspace name the provider returned — not just 'Connected'.

  4. 4

    Allow more than one connection to the same provider and keep each connection's tokens and data strictly separated. Store tokens encrypted and never render them in the UI or logs.

  5. 5

    This feature is OAuth for data access only. OAuth used as a sign-in method is owned by Social Sign-In; extend that rather than building a second identity path. Ongoing health display is owned by Integration Connection Health, and refresh mechanics by OAuth Token Refresh Recovery.

  6. 6

    Provide a disconnect action that revokes the token at the provider where the API allows it, rather than only deleting the local row.

Edge cases it handles

6
  • A user may approve some scopes and decline others. Detect partial consent and say which capability is missing, instead of treating the connection as complete.
  • The user may connect the wrong external account. Show the identity before anything syncs and offer a one-step swap.
  • Consent revoked at the provider's end will not tell you. The connection must degrade honestly the next time a call fails.
  • A user who connects the same external account twice should be merged into one connection, not left with two that fight over the same data.
  • The callback can arrive twice — from a refresh or a retried redirect. Treat the authorization code as single-use and make the second attempt idempotent, not an error page.
  • When the connecting user leaves the workspace, decide up front whether the connection dies with them or transfers. A shared integration silently owned by an ex-employee is a time bomb.

Definition of done

8
  • State is validated on every callback and PKCE is used where the provider supports it.
  • Requested scopes are the minimum the feature needs, and are listed to the user before authorization.
  • The connected external account is identified by name in the UI.
  • Multiple connections to one provider coexist without sharing tokens or data.
  • Partial or revoked consent produces a specific message, not a generic failure.
  • Tokens are encrypted at rest and never appear in logs, exports, or the UI.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.