---
title: OAuth apps
description: How approved apps like Zapier connect to Finerlise workspaces with OAuth 2.0.
icon: shield-check
search:
  keywords: [oauth, authorize, client id, access token, refresh token, scopes]
---

Finerlise runs an OAuth 2.0 authorization server so approved apps can act on a user's behalf without handling passwords or API keys. Today it's used by the [Zapier integration](/integrations/zapier).

:::note OAuth clients are registered by Finerlise; there's no self-serve client registration yet. If you're building a public integration, contact [support@finerlise.com](mailto:support@finerlise.com). For your own server, use an [API key](/developers/authentication-api-keys). :::

## Endpoints

|  | URL |
| --- | --- |
| Authorization | `https://finerlise.com/oauth/authorize` |
| Token | `https://finerlise.com/api/oauth/token` |
| Revocation | `https://finerlise.com/api/oauth/revoke` |
| Server metadata | `https://finerlise.com/.well-known/oauth-authorization-server` |

## Flow

1. Send the user to `/oauth/authorize` with `response_type=code`, your `client_id`, `redirect_uri`, `scope` and `state`.
2. The user signs in, picks a workspace and approves access.
3. Exchange the returned `code` (valid for 5 minutes) at the token endpoint with `grant_type=authorization_code`. Authenticate with `client_secret_basic` or `client_secret_post`.
4. Call the API with the access token (`fnr_oat_…`, valid for 1 hour).
5. Get a new access token with `grant_type=refresh_token` and the refresh token (`fnr_ort_…`).

## Scopes

| Scope            | Allows                                           |
| ---------------- | ------------------------------------------------ |
| `responses:read` | Read completed responses.                        |
| `forms:read`     | List the workspace's forms.                      |
| `hooks:write`    | Subscribe to and unsubscribe from new responses. |

If no scope is requested, all three are granted. Workspace admins can disconnect an app at any time under **Settings → API keys → Connected apps**.
