Skip to content

OAuth apps: “Connect to Sayweek” in your own app

Register your own app and let people allow it with their own Sayweek account – no passwords, no API keys to copy.

Updated:

Want a “Connect to Sayweek” button in your product, your agency tool or a client's system? Register an OAuth app. Any Sayweek user can connect it to their own workspace: a consent screen shows what the app asks for, and one click allows it. Nobody has to copy an API key.

Register an app

  1. Open Settings → All integrations and click the REST API card (owner permission and a plan with the API needed).
  2. Under OAuth apps, click Register an app.
  3. Enter the App name – this is what users see; it can't contain the word “Sayweek”. Logo and homepage must be https:// addresses.
  4. Under Redirect URLs, add one address per line: https://, or http://localhost / http://127.0.0.1 for development. It has to match exactly.
  5. Tick the scopes under What may the app ask for?, and under App type choose server-side or browser/mobile.
  6. Click Save and copy the Client ID and the Client secret – shown only now (for apps with a secret).

Server-side or public client?

  • Server-side (with a secret) – your server exchanges the code with the client secret and PKCE. Keep the secret on the server, never in a browser or an app.
  • Browser, mobile or CLI (no secret) – it can't keep a secret, so PKCE alone protects it. If you need a secret later, New secret turns it into a confidential app.

How connecting works

  1. Send the user to /oauth/authorize with response_type=code, client_id, redirect_uri, scope (e.g. read write), state and, for PKCE, code_challenge + code_challenge_method=S256.
  2. The user signs in to Sayweek and sees your app's name, logo and the scopes it asks for on the consent screen – and can narrow them.
  3. After they allow it, we redirect to your redirect_uri with a one-time code (valid for 10 minutes).
  4. Your server exchanges the code at /api/oauth/token with the code_verifier (and the secret): you get a 1-hour access token and a 30-day refresh token. Refreshing gives you new ones – the old refresh token can't be used again.

Scopes

  • read – Read: brands, channels, week plan, posts, ideas, analytics.
  • write – Drafts and ideas: writes and edits drafts without publishing; can also subscribe to webhooks.
  • approve – Approve: real scheduling, only if the workspace allows it. Never asked for by default – only when scope names it.

Revoking connections

Users see which apps can access their workspace under Connected apps on the REST API card; Revoke invalidates the tokens at once and also deletes the webhooks the app created. As the developer, Switch off on your app pauses every connection and Delete ends them for good. From code, the /api/oauth/revoke endpoint revokes a token.

Open in Sayweek

Was this article helpful?

Can't find the answer?

Write to us: hello@sayweek.com

OAuth apps: “Connect to Sayweek” in your own app | Sayweek