Create a new OAuth application
curl --request POST \
--url https://api.example.com/oauth/apps \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "My Integration",
"scopes": [
"read:organization",
"write:organization"
],
"description": "Integration for managing organization data",
"redirectUri": "https://example.com/callback"
}
'import requests
url = "https://api.example.com/oauth/apps"
payload = {
"name": "My Integration",
"scopes": ["read:organization", "write:organization"],
"description": "Integration for managing organization data",
"redirectUri": "https://example.com/callback"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'My Integration',
scopes: ['read:organization', 'write:organization'],
description: 'Integration for managing organization data',
redirectUri: 'https://example.com/callback'
})
};
fetch('https://api.example.com/oauth/apps', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/oauth/apps",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'My Integration',
'scopes' => [
'read:organization',
'write:organization'
],
'description' => 'Integration for managing organization data',
'redirectUri' => 'https://example.com/callback'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/oauth/apps"
payload := strings.NewReader("{\n \"name\": \"My Integration\",\n \"scopes\": [\n \"read:organization\",\n \"write:organization\"\n ],\n \"description\": \"Integration for managing organization data\",\n \"redirectUri\": \"https://example.com/callback\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/oauth/apps")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"My Integration\",\n \"scopes\": [\n \"read:organization\",\n \"write:organization\"\n ],\n \"description\": \"Integration for managing organization data\",\n \"redirectUri\": \"https://example.com/callback\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/oauth/apps")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"My Integration\",\n \"scopes\": [\n \"read:organization\",\n \"write:organization\"\n ],\n \"description\": \"Integration for managing organization data\",\n \"redirectUri\": \"https://example.com/callback\"\n}"
response = http.request(request)
puts response.read_bodyOAuth
Create OAuth Application
⚠️ SECURITY: Creates an OAuth2 application. Only OWNERS and ADMINS can create OAuth apps. Returns client secret ONCE - store it securely!
POST
/
oauth
/
apps
Create a new OAuth application
curl --request POST \
--url https://api.example.com/oauth/apps \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "My Integration",
"scopes": [
"read:organization",
"write:organization"
],
"description": "Integration for managing organization data",
"redirectUri": "https://example.com/callback"
}
'import requests
url = "https://api.example.com/oauth/apps"
payload = {
"name": "My Integration",
"scopes": ["read:organization", "write:organization"],
"description": "Integration for managing organization data",
"redirectUri": "https://example.com/callback"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'My Integration',
scopes: ['read:organization', 'write:organization'],
description: 'Integration for managing organization data',
redirectUri: 'https://example.com/callback'
})
};
fetch('https://api.example.com/oauth/apps', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/oauth/apps",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'My Integration',
'scopes' => [
'read:organization',
'write:organization'
],
'description' => 'Integration for managing organization data',
'redirectUri' => 'https://example.com/callback'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/oauth/apps"
payload := strings.NewReader("{\n \"name\": \"My Integration\",\n \"scopes\": [\n \"read:organization\",\n \"write:organization\"\n ],\n \"description\": \"Integration for managing organization data\",\n \"redirectUri\": \"https://example.com/callback\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/oauth/apps")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"My Integration\",\n \"scopes\": [\n \"read:organization\",\n \"write:organization\"\n ],\n \"description\": \"Integration for managing organization data\",\n \"redirectUri\": \"https://example.com/callback\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/oauth/apps")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"My Integration\",\n \"scopes\": [\n \"read:organization\",\n \"write:organization\"\n ],\n \"description\": \"Integration for managing organization data\",\n \"redirectUri\": \"https://example.com/callback\"\n}"
response = http.request(request)
puts response.read_bodyCreates a new OAuth2 application for your organization. Only OWNERS and ADMINS can create OAuth apps.
The client secret is returned ONCE in the response. Store it securely
immediately - it cannot be retrieved later!
Permissions
Only OWNERS and ADMINS can create OAuth applications.Request Body
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Application name (1-100 characters) |
description | string | No | Application description (max 500 characters) |
redirectUri | string | No | Redirect URI for OAuth flow |
scopes | array | Yes | OAuth scopes requested |
Available Scopes
read:user- Read user informationwrite:user- Modify user informationread:organization- Read organization datawrite:organization- Modify organization dataread:members- Read member informationwrite:members- Modify membersread:webhooks- Read webhook configurationwrite:webhooks- Manage webhooksadmin:organization- Full organization admin accessadmin:all- Full system access
Example Request
curl -X POST https://api.timbrix.mx/oauth/apps \
-H "Authorization: Bearer <token>" \
-H "Content-Type: application/json" \
-d '{
"name": "My Integration",
"description": "Integration for managing organization data",
"redirectUri": "https://example.com/callback",
"scopes": ["read:organization", "write:organization"]
}'
import { Timbrix } from "@timbrix/sdk"
const client = new Timbrix({ bearerToken: "<token>" })
const app = await client.oauth.createApp({
name: "My Integration",
description: "Integration for managing organization data",
redirectUri: "https://example.com/callback",
scopes: ["read:organization", "write:organization"],
})
console.log(app)
Example Response
{
"clientId": "app_1234567890abcdef",
"clientSecret": "cs_1234567890abcdef",
"name": "My Integration",
"description": "Integration for managing organization data",
"redirectUri": "https://example.com/callback",
"scopes": ["read:organization", "write:organization"],
"isActive": true,
"createdAt": "2025-01-26T10:00:00Z"
}
Security Notes
- The
clientSecretis only returned once during creation - Store the secret securely (environment variables, secret manager)
- Never commit secrets to version control
- Rotate secrets if compromised
Common Errors
400 Bad Request
Invalid input data or validation errors.401 Unauthorized
Authentication required.403 Forbidden
Only owners and admins can create OAuth applications.Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
application/json
Application name
Required string length:
1 - 100Example:
"My Integration"
OAuth scopes requested
Available options:
read:user, write:user, read:organization, write:organization, read:members, write:members, read:webhooks, write:webhooks, admin:organization, admin:all Example:
["read:organization", "write:organization"]
Application description
Maximum string length:
500Example:
"Integration for managing organization data"
Redirect URI for OAuth flow
Example:
"https://example.com/callback"
Response
OAuth application created successfully. Client secret returned only once - save it immediately!