Tokens
- Treat
access_tokenlike a password. It’s shown once, in thePOST /oauth/tokenresponse — Workchats doesn’t store it in a form you can retrieve again. - Send it only in the
Authorization: Bearerheader. A token in a query parameter (?token=or?access_token=) is rejected with400 token_in_query— Workchats won’t even read it from there, so it can’t leak into a server access log via the URL. - A bot token is scoped to exactly one company. It doesn’t expire, so treat
a leaked token as a live incident: call
POST /oauth/revokeimmediately, then reinstall to get a new one.
Client credentials
client_id and client_secret authenticate your App itself, at
POST /oauth/token and (optionally) POST /oauth/revoke. Keep
client_secret server-side — never in a browser bundle, mobile app, or
public repository. GitHub’s secret scanning and gitleaks-style tools
recognize the wc_bot_live_ / wc_bot_test_ token prefixes, so a leaked
token in a public repo gets flagged.
Scopes
Request only the scopes your integration needs.users:read.email in
particular exposes people’s email addresses (subject to their own
visibility setting) — don’t request it if you only need names and ids.