OAuth Apps
OAuth is configured on a custom app: create the app, add OAuth settings, then use it for Log in with One Horizon, Connect One Horizon, or user-approved API access.
After a workspace member approves your app, your app receives user-scoped tokens. Those tokens can read workspace data or take workspace actions the member is allowed to take, such as listing initiatives, creating comments, updating bugs, or starting agent sessions.
View OAuth login example
Add login to a custom app
Custom App explains the larger integration shape around OAuth.
| What you are building | Setup |
|---|---|
| Add Log in with One Horizon to your product | Custom app with OAuth |
| Let users connect a workspace to your product | Custom app with OAuth |
| Read or update data as the signed-in member | OAuth access token |
| Run internal automation for one workspace | Workspace API key |
| Build a local or cloud agent | Start with Building Agents |
Create the app
Workspace admins manage custom apps from Settings → Apps. Choose Native iOS (public) for App Store or Simulator apps (client ID only, no secret, PKCE S256 required) or Confidential backend for server-side integrations. Add the app identity users see during consent: name, logo, homepage, privacy policy, and terms URL. Then configure callback URLs and OAuth settings.
Public clients never receive a client secret. The client type cannot change after creation; create a new app to switch between Native iOS and confidential.
Create separate apps for production and staging so callback URLs, secrets, webhook keys, and delivery logs stay isolated.
Endpoints
| Step | URL |
|---|---|
| Authorization | https://onehorizon.ai/app/auth/authorize |
| Token exchange and refresh | https://onehorizon.ai/app/auth/token |
Use the authorization code flow with PKCE (S256) and a state value. The API reference lists the parameters.
OAuth settings
Add each callback URL that your app can return to after authorization. Keep callback URLs exact; do not rely on broad redirects. Public Native iOS clients may register HTTPS URLs and private-use custom schemes (for example myapp://oauth/callback). Prefer claimed HTTPS Universal Links on iOS 17.4+ for production apps.
Confidential clients store the client secret on the server only. If the app cannot originate PKCE itself, use dashboard-managed PKCE only for the clients that need it.
OAuth clients created automatically by tools such as MCP or the CLI can also appear in app management so users can inspect or revoke access.
Example apps
The OAuth login example is a server-side TypeScript app. It sends users to One Horizon, verifies the callback with state and PKCE, exchanges the code on the server, and keeps the client secret and tokens out of browser code.
For iOS, the Native OAuth example handles ASWebAuthenticationSession, Keychain storage, and token refresh, and configures the Swift SDK with the user's bearer token.
User control
Users can review connected OAuth clients and revoke access. Revoking access stops that app from using the user's token for workspace data or actions. OAuth apps follow the workspace Permissions.