1. Send the admin to the consent screen
- On approve: redirects to
redirect_uri?code=<code>&state=<state>. - On deny: redirects to
redirect_uri?error=access_denied&state=<state>.
redirect_uri must match what you registered with Octogle exactly. A code
is single-use, expires in 10 minutes, and is bound to your client_id — a
second redemption attempt gets invalid_grant and doesn’t revoke the token
already issued, so retrying a timed-out exchange is safe.
2. Exchange the code for a token
client_id / client_secret in the body or as HTTP Basic credentials.
grant_type must be authorization_code — Workchats tokens don’t expire, so
there is no refresh_token grant; using one returns
400 unsupported_grant_type.
200
expires_in. Store access_token now — it’s shown once.
3. Send it as a bearer token
Authorization header is accepted. A token in a query parameter
(?token= or ?access_token=) gets 400 token_in_query — see
Security.
Disconnecting
200 {"ok": true}, including for an unknown or already
revoked token. This disconnects: every token on the installation stops
working immediately, but the bot stays in its groups and channels, so
reconnecting later reuses the same bot and the same memberships. Nothing
else removes the bot — only a company admin uninstalling your App in
Workchats Settings, or Octogle disabling it, does that.
No callback is sent for a revoke today. Until Phase 1b ships
app.uninstalled, treat a 401 token_revoked response on any call as
“disconnected” — see
Callbacks & signature verification.
Who your bot can message
Your bot can DM active or onboarding people whose email is visible to it (subject tousers:read.email’s release rule — see
Concepts). DMs to guests ship
in a later phase. Sending to a group or channel requires your bot to be an
active member of it — the admin’s picks at install time, or later additions
in Workchats Settings → Apps.
Bot DMs are read-only for people: they see “this bot sends notifications
here, replies aren’t delivered” instead of a composer. That’s enforced on
the server, not just hidden in the client.