Arc0 Connect
The hosted flow your users see when they authorize an app, how to generate its link, and what the consent screen shows them.
Arc0 Connect is the flow your users see when they authorize an app. It runs on connect.arc0.ai by default, or your own domain on a paid plan, and it carries your logo and colors from the moment it loads.
What your user sees
A connect link opens a hosted page at /c/{id}. If the app uses OAuth 2, the user is sent on to the provider — Google, Slack, Salesforce, and so on — to sign in and reach the consent screen, then back to Arc0. Apps that only take an API key or basic auth ask for the credential directly on the same page, with no redirect. See Branding for every field you control on this page.
Creating a link
A connect link is single-use and scoped to one user, one customer, and one app. Create one with the SDK or the API.
import { Arc0 } from '@arc0/sdk';
const arc0 = new Arc0({ apiKey: process.env.ARC0_API_KEY });
const link = await arc0.connect.createLink({
user: 'u_8f2',
customer: 'northwind',
app: 'gmail',
});
console.log(link.url);Both return an id, a url in the form https://connect.arc0.ai/c/{id} (or your custom domain), and an expires_at. Send the user to url however fits your product: a redirect, a link in an email, a button in your app.
An API key with Connect links only access can call this endpoint — see API keys.
The redirect after connecting
When the user finishes, the hosted page redirects them to the URL set in After connecting on the branding editor. Pass redirect_url when you create the link to override that for one link, for example to send the user back to the exact page they started from.
The consent screen
For OAuth apps, the screen between the provider's sign-in and the redirect back to you is the consent screen:
- A header with your org's name, and a headline —
Connect your tools to {name}by default, or your own text. {name} wants to connect to your {App}, with the host shown under a lock icon.- One line per requested scope, tagged
READ,WRITE, orDESTRUCTIVE. A scope you didn't request still appears, taggedNOT REQUESTEDand struck through. - Cancel and Continue buttons.
You can disconnect {App} from {name} at any time.- A footer with your privacy policy, terms, support email, and "Powered by Arc0" if you've left that on.
See Scopes and actions for how the scope list is built, and Branding for every field on this screen.
Embedding it in your app
The link is a plain URL, so there's nothing to install. Open it in a new tab, a popup, or an iframe inside your own UI, whichever fits your onboarding flow. The page is responsive either way.