openapi: 3.2.0 info: title: Pipeshub OAuth Configuration API version: 1.0.0 contact: name: API Support email: support@pipeshub.com description: 'Operations tagged OAuth Configuration across 2 of this provider''s published API definitions: pipeshub-openapi.yaml, pipeshub-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL security: - bearerAuth: [] - oauth2: [] tags: - name: OAuth Configuration description: Admin management of OAuth credentials for connector types paths: /toolsets/oauth-configs/{toolsetType}: get: tags: - OAuth Configuration summary: List OAuth configs by toolset type description: List OAuth client configurations registered for a specific toolset type. operationId: listToolsetOAuthConfigs security: - bearerAuth: [] parameters: - name: toolsetType in: path required: true schema: type: string responses: '200': description: OAuth configs retrieved successfully '401': description: Unauthorized '403': description: Forbidden servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /toolsets/oauth-configs/{toolsetType}/{oauthConfigId}: put: tags: - OAuth Configuration summary: Update OAuth config description: Update an OAuth client configuration for a specific toolset type. operationId: updateToolsetOAuthConfig security: - bearerAuth: [] parameters: - name: toolsetType in: path required: true schema: type: string - name: oauthConfigId in: path required: true schema: type: string requestBody: required: true description: Updated OAuth client configuration fields. content: application/json: schema: type: object additionalProperties: true responses: '200': description: OAuth config updated successfully '401': description: Unauthorized '403': description: Forbidden '404': description: OAuth config not found delete: tags: - OAuth Configuration summary: Delete OAuth config description: Delete an OAuth client configuration for a specific toolset type. operationId: deleteToolsetOAuthConfig security: - bearerAuth: [] parameters: - name: toolsetType in: path required: true schema: type: string - name: oauthConfigId in: path required: true schema: type: string responses: '200': description: OAuth config deleted successfully '401': description: Unauthorized '403': description: Forbidden '404': description: OAuth config not found '409': description: OAuth config is in use by one or more toolset instances servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /oauth/registry: get: tags: - OAuth Configuration summary: List OAuth-capable connector types description: 'Get all connector types that support OAuth authentication. Admin Use: Admins use this to see which connector types need OAuth credentials to be configured before users can authenticate.' operationId: getOAuthRegistry security: - bearerAuth: [] parameters: - name: page in: query schema: type: integer minimum: 1 default: 1 - name: limit in: query schema: type: integer minimum: 1 maximum: 200 default: 20 - name: search in: query schema: type: string responses: '200': description: OAuth connector types retrieved content: application/json: schema: type: object properties: success: type: boolean connectors: type: array items: $ref: '#/components/schemas/ConnectorType' pagination: $ref: '#/components/schemas/ConnectorPagination' '401': description: Unauthorized servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /oauth/registry/{connectorType}: get: tags: - OAuth Configuration summary: Get OAuth connector type details description: Get details for a specific OAuth-capable connector type. operationId: getOAuthConnectorType security: - bearerAuth: [] parameters: - name: connectorType in: path required: true schema: type: string responses: '200': description: Connector type retrieved content: application/json: schema: type: object properties: success: type: boolean connector: $ref: '#/components/schemas/ConnectorType' '401': description: Unauthorized '404': description: Connector type not found servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /oauth: get: tags: - OAuth Configuration summary: List OAuth configurations description: 'List all OAuth configurations for the organization. Security: Admins see full configuration including credentials Non-admins see only essential fields (client ID, not secret)' operationId: listOAuthConfigs security: - bearerAuth: [] parameters: - name: page in: query schema: type: integer minimum: 1 default: 1 - name: limit in: query schema: type: integer minimum: 1 maximum: 200 default: 20 - name: search in: query schema: type: string responses: '200': description: OAuth configurations retrieved content: application/json: schema: type: object properties: success: type: boolean oauthConfigs: type: array items: $ref: '#/components/schemas/OAuthConfig' pagination: $ref: '#/components/schemas/ConnectorPagination' '401': description: Unauthorized servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /oauth/{connectorType}: get: tags: - OAuth Configuration summary: List OAuth configs for connector type description: Get all OAuth configurations for a specific connector type. operationId: listOAuthConfigsByType security: - bearerAuth: [] parameters: - name: connectorType in: path required: true schema: type: string - name: page in: query schema: type: integer minimum: 1 default: 1 - name: limit in: query schema: type: integer minimum: 1 maximum: 200 default: 20 - name: search in: query schema: type: string responses: '200': description: OAuth configurations retrieved content: application/json: schema: type: object properties: success: type: boolean oauthConfigs: type: array items: $ref: '#/components/schemas/OAuthConfig' pagination: $ref: '#/components/schemas/ConnectorPagination' '401': description: Unauthorized '404': description: Connector type not found post: tags: - OAuth Configuration summary: Create OAuth configuration description: 'Create a new OAuth configuration for a connector type. Admin Only: Only admins can create OAuth configurations. These provide the OAuth credentials needed for users to authenticate connectors. Use Case: Before users can create Google Drive connectors with OAuth, an admin must create an OAuth configuration with the Google OAuth client ID and secret.' operationId: createOAuthConfig security: - bearerAuth: [] parameters: - name: connectorType in: path required: true schema: type: string requestBody: required: true description: Request payload content: application/json: schema: $ref: '#/components/schemas/CreateOAuthConfigRequest' responses: '201': description: OAuth configuration created content: application/json: schema: type: object properties: success: type: boolean oauthConfig: $ref: '#/components/schemas/OAuthConfig' message: type: string '400': description: Invalid configuration or duplicate name '401': description: Unauthorized '403': description: Admin access required '404': description: Connector type not found servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL /oauth/{connectorType}/{configId}: get: tags: - OAuth Configuration summary: Get OAuth configuration description: Get a specific OAuth configuration by ID. operationId: getOAuthConfig security: - bearerAuth: [] parameters: - name: connectorType in: path required: true schema: type: string - name: configId in: path required: true schema: type: string responses: '200': description: OAuth configuration retrieved content: application/json: schema: type: object properties: success: type: boolean oauthConfig: $ref: '#/components/schemas/OAuthConfig' '401': description: Unauthorized '404': description: Configuration not found put: tags: - OAuth Configuration summary: Update OAuth configuration description: 'Update an OAuth configuration. Admin Only: Only the creator or another admin can update.' operationId: updateOAuthConfig security: - bearerAuth: [] parameters: - name: connectorType in: path required: true schema: type: string - name: configId in: path required: true schema: type: string requestBody: required: true description: Request payload content: application/json: schema: type: object properties: oauthInstanceName: type: string config: type: object properties: clientId: type: string clientSecret: type: string tenantId: type: string responses: '200': description: OAuth configuration updated content: application/json: schema: type: object properties: success: type: boolean oauthConfig: $ref: '#/components/schemas/OAuthConfig' '400': description: Invalid configuration '401': description: Unauthorized '403': description: Admin access required '404': description: Configuration not found delete: tags: - OAuth Configuration summary: Delete OAuth configuration description: 'Delete an OAuth configuration. Warning: Cannot delete if the configuration is used by active connectors. Disable or delete dependent connectors first.' operationId: deleteOAuthConfig security: - bearerAuth: [] parameters: - name: connectorType in: path required: true schema: type: string - name: configId in: path required: true schema: type: string responses: '200': description: OAuth configuration deleted content: application/json: schema: type: object properties: success: type: boolean message: type: string '400': description: Cannot delete - used by active connectors '401': description: Unauthorized '403': description: Admin access required '404': description: Configuration not found servers: - url: '{instance_url}/api/v1' description: Base API URL variables: instance_url: default: https://app.pipeshub.com description: Base server URL (without /api/v1) - url: '{instance_url}' description: Root URL (used for MCP endpoints mounted at /mcp) variables: instance_url: default: https://app.pipeshub.com description: Base server URL components: schemas: OAuthConfig: type: object description: 'OAuth configuration for a connector type. Created by admins to enable OAuth authentication for connectors. ' properties: configId: type: string description: Unique configuration ID connectorType: type: string description: Connector type this config applies to oauthInstanceName: type: string description: Name for this OAuth configuration example: Production Google OAuth orgId: type: string createdBy: type: string config: type: object description: OAuth credentials (admin-only view) properties: clientId: type: string clientSecret: type: string description: Redacted for non-admin users tenantId: type: string description: For Microsoft/Azure connectors baseUrl: type: string description: Base URL for self-hosted instances createdAt: type: string format: date-time updatedAt: type: string format: date-time ConnectorType: type: object description: 'A connector type from the registry. Represents an available integration that can be configured as a connector instance. ' properties: connectorType: type: string description: Unique identifier for this connector type example: google-drive displayName: type: string description: Human-readable name example: Google Drive description: type: string description: What this connector does appGroupId: type: string description: Application group identifier appGroup: type: string description: Application group name (e.g., "Google Workspace") authTypes: type: array items: $ref: '#/components/schemas/ConnectorAuthType' description: Supported authentication methods supportedScopes: type: array items: $ref: '#/components/schemas/ConnectorScope' description: Supported scope types supportsSync: type: boolean description: Whether connector supports data synchronization supportsAgent: type: boolean description: Whether connector supports AI agent integration supportsRealtime: type: boolean description: Whether connector supports real-time updates iconPath: type: string description: Path to connector icon categories: type: array items: type: string description: Categories (e.g., "Storage", "Communication") isBeta: type: boolean description: Whether this is a beta connector ConnectorAuthType: type: string description: 'Authentication method required by the connector:
' enum: - OAUTH - OAUTH_ADMIN_CONSENT - API_TOKEN - USERNAME_PASSWORD - NONE ConnectorScope: type: string description: 'Scope determines visibility and access control for connectors:
' enum: - team - personal example: team ConnectorPagination: type: object description: Pagination information for connector lists properties: page: type: integer description: Current page number limit: type: integer description: Items per page total: type: integer description: Total number of items hasMore: type: boolean description: Whether more pages exist CreateOAuthConfigRequest: type: object description: Request to create OAuth configuration (admin only). Stores credentials that users select when setting up connectors. required: - oauthInstanceName - config properties: oauthInstanceName: type: string description: Display name for this OAuth configuration (e.g., 'Production Google OAuth') minLength: 1 maxLength: 100 example: Production Google OAuth Credentials config: type: object description: OAuth application credentials required: - clientId - clientSecret properties: clientId: type: string description: OAuth client ID from your OAuth application example: 123456789-abc.apps.googleusercontent.com clientSecret: type: string description: OAuth client secret (stored encrypted, never returned in responses) example: GOCSPX-xxxxxxxxxxxxx tenantId: type: string description: Azure tenant ID (required only for Microsoft connectors) example: 12345678-1234-1234-1234-123456789abc baseUrl: type: string description: Base URL for self-hosted instances (e.g., GitLab Self-Managed) format: uri example: https://gitlab.mycompany.com securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'JWT Bearer token for authenticated requests. A personal access token (see the **Personal Access Tokens** tag) is a `phpat_`-prefixed variant of this same JWT — e.g. `phpat_eyJhbGci...`. The prefix is display-only, added for secret-scanner detectability; the gateway strips it before verifying the token, so send it exactly as issued, prefix included. ' scopedToken: type: http scheme: bearer bearerFormat: JWT description: 'Scoped JWT token for service-to-service authentication. Format: "Bearer {scoped_token}" Required scopes vary by endpoint. ' oauth2: type: oauth2 description: 'OAuth 2.0 authentication with fine-grained scopes. Supports authorization_code (with PKCE) and client_credentials flows. OAuth tokens are Bearer JWTs — use the same Authorization header as regular tokens. For **client_credentials**, machine JWTs may use `userId === client_id`; the Node gateway resolves the OAuth app creator — see **OAuth Provider** tag. ' flows: authorizationCode: authorizationUrl: /api/v1/oauth2/authorize tokenUrl: /api/v1/oauth2/token refreshUrl: /api/v1/oauth2/token scopes: openid: OpenID Connect authentication profile: User profile information email: User email address offline_access: Offline access (refresh tokens) org:read: Read organization information org:write: Update organization settings org:admin: Full organization administration user:read: Read user profiles user:write: Update user profiles user:invite: Invite new users user:delete: Delete users usergroup:read: Read user groups usergroup:write: Create and manage user groups team:read: Read team information team:write: Create and manage teams kb:read: Read knowledge bases and records kb:write: Create and update knowledge bases kb:delete: Delete knowledge bases and records kb:upload: Upload files to knowledge bases semantic:read: Read semantic search results and history semantic:write: Execute semantic search semantic:delete: Delete semantic search history conversation:read: Read conversations conversation:write: Create and manage conversations conversation:chat: Send messages in conversations project:read: Read projects and their conversations project:write: Create and manage projects project:delete: Delete projects agent:read: Read AI agents agent:write: Create and manage AI agents agent:execute: Execute AI agents connector:read: Read connector configurations connector:write: Create and update connectors connector:sync: Trigger connector synchronization connector:delete: Delete connectors config:read: Read system configuration config:write: Update system configuration crawl:read: Read crawling jobs crawl:write: Create and manage crawling jobs crawl:delete: Delete crawling jobs clientCredentials: tokenUrl: /api/v1/oauth2/token scopes: openid: OpenID Connect authentication profile: User profile information email: User email address offline_access: Offline access (refresh tokens) org:read: Read organization information org:write: Update organization settings org:admin: Full organization administration user:read: Read user profiles user:write: Update user profiles user:invite: Invite new users user:delete: Delete users usergroup:read: Read user groups usergroup:write: Create and manage user groups team:read: Read team information team:write: Create and manage teams kb:read: Read knowledge bases and records kb:write: Create and update knowledge bases kb:delete: Delete knowledge bases and records kb:upload: Upload files to knowledge bases semantic:write: Execute semantic search semantic:read: Read semantic search results and history semantic:delete: Delete semantic search history conversation:read: Read conversations conversation:write: Create and manage conversations conversation:chat: Send messages in conversations project:read: Read projects and their conversations project:write: Create and manage projects project:delete: Delete projects agent:read: Read AI agents agent:write: Create and manage AI agents agent:execute: Execute AI agents connector:read: Read connector configurations connector:write: Create and update connectors connector:sync: Trigger connector synchronization connector:delete: Delete connectors config:read: Read system configuration config:write: Update system configuration crawl:read: Read crawling jobs crawl:write: Create and manage crawling jobs x-refined-from: - pipeshub-openapi.yaml - pipeshub-openapi.yml