OAuth apps

Arc0-managed vs. your own OAuth app, the fields on each, and per-provider setup for five providers.

Every OAuth app on Arc0 runs one of two ways: Arc0's own registered client, or one you register yourself with the provider.

Arc0-managed vs. your own

Arc0-managed is the default and needs nothing from you — Arc0 already has a verified OAuth client with each provider, and your users see Arc0's name on the provider's consent screen alongside yours.

Launch and Scale

Available on the Launch and Scale plans. See pricing.

Your own OAuth app replaces that with a client you register. Two things change once you do:

  • The consent screen names you. The provider's own dialog — the one Arc0 sends the user to — shows your app's name and icon, not Arc0's. For a user connecting Gmail, that's the difference between "Acme wants to access your Google Account" and a stranger's name doing the asking.
  • Tokens are portable. Because the OAuth client is registered under your own credentials, the grants your users make belong to your app, not to Arc0's. If you ever move a connection or export its tokens, they work the same way they would if you'd built the OAuth flow yourself.

The fields

On the Credentials tab, switching to Your own OAuth app reveals:

FieldLabelNotes
clientIdClient IDFrom the provider's console
clientSecretHintClient secretOnly the last 4 characters are shown; Rotate replaces it
redirectUriRedirect URIMust match exactly what you register with the provider

The redirect URI is https://connect.arc0.ai/oauth/callback by default, or https://connect.acme.com/oauth/callback once you're on a custom domain — copy whichever one is shown, since it has to match character for character on the provider's side.

Apps that authenticate with an API key instead of OAuth skip all of this and show a single API key panel instead.

Setting up each provider

Each provider's console asks for slightly different things. A panel on the Credentials tab, titled Set up in Google Cloud (or Azure, Slack, Salesforce Setup, Zendesk, depending on the app), walks through it — the outline is the same everywhere: create a client, paste in the redirect URI shown above, and copy the resulting ID and secret back into Arc0.

Create an OAuth client in Google Cloud Console under APIs & Services → Credentials, application type "Web application." Add the redirect URI shown on this tab, enable the Gmail (or other) API you need, and copy the client ID and secret back here.

Gmail's Credentials tab, set to Your own OAuth app, with the client ID, secret, and redirect URI fields
Gmail's Credentials tab, using a customer's own OAuth app.

On this page