OAuth apps: “Connect to Sayweek” in your own app
Register your own app and let people allow it with their own Sayweek account – no passwords, no API keys to copy.
Updated:
Want a “Connect to Sayweek” button in your product, your agency tool or a client's system? Register an OAuth app. Any Sayweek user can connect it to their own workspace: a consent screen shows what the app asks for, and one click allows it. Nobody has to copy an API key.
Register an app
- Open Settings → All integrations and click the REST API card (owner permission and a plan with the API needed).
- Under OAuth apps, click Register an app.
- Enter the App name – this is what users see; it can't contain the word “Sayweek”. Logo and homepage must be
https://addresses. - Under Redirect URLs, add one address per line:
https://, orhttp://localhost/http://127.0.0.1for development. It has to match exactly. - Tick the scopes under What may the app ask for?, and under App type choose server-side or browser/mobile.
- Click Save and copy the Client ID and the Client secret – shown only now (for apps with a secret).
Server-side or public client?
- Server-side (with a secret) – your server exchanges the code with the client secret and PKCE. Keep the secret on the server, never in a browser or an app.
- Browser, mobile or CLI (no secret) – it can't keep a secret, so PKCE alone protects it. If you need a secret later, New secret turns it into a confidential app.
How connecting works
- Send the user to
/oauth/authorizewithresponse_type=code,client_id,redirect_uri,scope(e.g.read write),stateand, for PKCE,code_challenge+code_challenge_method=S256. - The user signs in to Sayweek and sees your app's name, logo and the scopes it asks for on the consent screen – and can narrow them.
- After they allow it, we redirect to your
redirect_uriwith a one-timecode(valid for 10 minutes). - Your server exchanges the code at
/api/oauth/tokenwith thecode_verifier(and the secret): you get a 1-hour access token and a 30-day refresh token. Refreshing gives you new ones – the old refresh token can't be used again.
Scopes
read– Read: brands, channels, week plan, posts, ideas, analytics.write– Drafts and ideas: writes and edits drafts without publishing; can also subscribe to webhooks.approve– Approve: real scheduling, only if the workspace allows it. Never asked for by default – only whenscopenames it.
Revoking connections
Users see which apps can access their workspace under Connected apps on the REST API card; Revoke invalidates the tokens at once and also deletes the webhooks the app created. As the developer, Switch off on your app pauses every connection and Delete ends them for good. From code, the /api/oauth/revoke endpoint revokes a token.
Was this article helpful?
Related articles
- REST API: API keys and scopesCreate an API key, understand the read / write / approve scopes, the main endpoints and how to revoke a key.
- Developer portal: reference, try-it console, Postman, clientsThe /developers page has the full API reference, lets you try calls with your own account, and offers the Postman collection.
- Webhooks (n8n and your own server)Signed JSON to your URL on every event you pick – with retries, a delivery log and a test button.
- Claude and ChatGPT (MCP)Connect Sayweek to Claude or ChatGPT: the assistant sees your plan and writes drafts that wait for your approval.