Dev now; Staging and Production next release.
Who can register an App
Company admins with theapps.manage permission. The company admin role
and the super admin have it. A custom role can’t be given it.
Any company admin can approve the install on the consent screen, as for
any App.
How a company App differs from an Octogle App
Octogle registers Apps that any company can install, such as Leadey. Your company registers its own.
To any other company, your App doesn’t exist. Its admins get the same
error on the consent screen as for an unknown
client_id
(invalid_client), so they can’t install it. If an admin of several
companies opens your install link while another company is selected, they
get that error too. They can switch to your company in Workchats and open
the link again.
Where things are
The examples below use Production. Until company Apps reach Production, use
https://app.dev.workchats.com and https://public-api.dev.workchats.com
instead.
Register the App
In the admin console, open Apps and choose Register an app. Fill in:
You can edit every field later. An edit that changes nothing is not
recorded.
Save the secrets
Registering shows three values:- Client ID,
app_…. Not secret. It’s always shown on the App’s page, andGET /v1/auth/testreturns it asapp_id. - Client secret,
wc_cs_…. Your App sends it with theclient_idto exchange an install code for a token. - Signing secret,
whsec_…. Your App uses it to verify callbacks.
Install it in your company
A company admin installs the App through the consent screen, the same OAuth install as any App. Send the admin to:redirect_uri with code and
state, and your App exchanges the code for a bot token on
POST /oauth/token.
Each App has one installation in your company, and its bot user. To change
the bot’s groups, its push setting, or to uninstall it, a company admin
uses Settings → Apps in Workchats, as for any App.
Install without a web server
A script or a scheduled job has no web server to receive the redirect. Use a static page that shows the code instead, then exchange the code yourself withcurl. There’s no install button in the admin console.
-
Host this page at an
https://address your company controls, such as GitHub Pages or a storage bucket behind HTTPS, and add its address to the App’s redirect URIs.Keep analytics and other third-party scripts off this page. The code is in its address. -
Open the authorize URL above in a browser, signed in as a company admin,
with this page as
redirect_uri. Approve. -
The page shows
codeandstate. Checkstateis the value you sent. -
Within 10 minutes, exchange the code:
On a shared machine,
-ushows the secret to anyone who lists processes while curl runs. Putuser = "CLIENT_ID:CLIENT_SECRET"in a file only you can read and pass it with-K <file>instead.REDIRECT_URIis the static page’s address, exactly as registered. The answer carriesaccess_token. Store it where your script reads its configuration. It doesn’t expire. -
Check it:
app_idin the answer is yourclient_id.
Rotate a secret
On the App’s page, rotate either secret. The new one is shown once, like at registration.
See Callbacks & signature verification
for checking two signatures.
Disable, enable and delete
Limits
Your company can have at most 10 Apps. Disabled Apps count. A deleted App doesn’t. The Apps screen shows whether your company can register another App. It reads one of four states, checked in this order:
In every state you can still edit, rotate, disable, enable and delete the
Apps your company already has.
Every registration, edit, rotation, disable, enable and delete is recorded
in your company’s audit log, with the admin who did it. No entry contains a
secret.