When to bring your own OAuth app (Google, Microsoft, Meta) and how
Google, Microsoft and Meta gate shared OAuth apps behind review. An org admin registers your own app: paste client_id and client_secret, match the scopes.

Bring your own OAuth app means connecting a vendor through an OAuth application your organization registered in the vendor's console. An org admin pastes the app's client_id and client_secret once. Every new connection in the organization then authorizes through that app. It is the route for vendors whose review gates a shared app: Google, Microsoft and Meta among them.
- 1Open the connector's setup dialogDashboard, Connectors, as an org adminIt lists the required scopes and the redirect URI.
- 2Create the app in the vendor consoleadd the redirect URI; grant every listed scopeAny vendor review is between you and the vendor.
- 3Paste client_id and client_secretsave the dialog
- 4Connect an account to verifya scope shortfall fails with the exact differenceNothing is stored on a failed connect.
- 5Tell members to connectcredential_source.active becomes orgCalls through your app are not metered by CoreSpeed.
When do you need your own app?
CoreSpeed opens this mechanism on specific connectors. The authenticated index tells you where a connector stands through credential_source.active.
credential_source.active | Meaning | What members see |
|---|---|---|
"platform" | CoreSpeed's own app serves this connector | the normal Connect button |
"org" | your organization's app is configured | Connect, through your app |
"none" | the mechanism is open and nothing is configured | a setup prompt until an admin finishes it |
You need your own app in two cases. The first is a vendor whose review process gates a shared app, so the connector shows "none" until your organization supplies one. Your own app needs no review from CoreSpeed. The second is a vendor where you want calls to run under your organization's registration for your own reasons, such as the scopes and branding your users see on the consent screen.
{ "credential_source": { "active": "org" } }
Billing follows the app. Calls made through your own OAuth app are not metered by CoreSpeed. Holds and the activity trail still apply: a billing hold on the organization still refuses the call, and every call still lands in Dashboard → Activity.
How do you register it?
- Sign in as an org admin. Open Dashboard → Connectors and pick the connector. Open its setup dialog. The dialog lists the connector's required scopes and the redirect URI to register with the vendor.
- In the vendor's console, create an OAuth app for your organization. Add the redirect URI from the dialog. Grant every scope the dialog lists. Any review the vendor requires for those scopes is between you and the vendor.
- Paste the app's
client_idandclient_secretinto the dialog and save. - Connect an account yourself to verify. If your app grants fewer scopes than the connector's tools need, the connect fails with the exact difference and stores nothing. Add the missing scopes in the vendor console and connect again.
- Tell members to connect. Each new connection in the organization authorizes through your app, with the usual choice of private or shared visibility. The index now reports
credential_source.activeas"org".
The agent side does not change. The connector's tools keep their names, tools/list stays caller-specific, and the agent receives tools, never the token. The connectors page describes all three ways to connect.
What happens when you rotate or replace the app?
The lifecycle is deliberately blunt, so plan the two cases apart.
Rotating the secret under the same client_id disturbs nothing. Paste the new client_secret and existing connections keep working.
Replacing the client_id, or deleting the app, moves every connection issued through it to needs_reauth. The confirmation states how many connections that is. Members then reconnect through the new source from Dashboard → Connectors. Until they do, the connector's tools stay visible in tools/list and calls fail. Do not rotate the CoreSpeed API key and do not rewrite client configuration when this happens; neither is broken.
So: rotate secrets whenever you like. Replace the app only when you can tell every affected member to reconnect.
What changes for billing and audit?
Two things stay, one thing goes.
The activity trail stays. Every call through your app is recorded with action, actor, outcome and time, visible to the member for their own calls and to org admins for the org. If Smart Approval is on, writes through your app are judged against your policy like any other write. Reads are never gated.
Holds stay. Past the billing threshold the organization's metered calls answer payment_required, and a key past its monthly cap answers key_spend_limit_exceeded. Both are enforced before the tool runs, whichever app the connector uses.
CoreSpeed's per-call metering goes. Calls through your own app are not charged to your credit balance. What the vendor charges you for API use is unchanged. The billing page has the full boundary.
FAQ
Can any member register the organization's app? No. Only an org admin can paste client_id and client_secret. Once it is configured, any member can connect through it.
Does my own app change which tools appear? No. The tool surface is the connector's. If your app grants fewer scopes than those tools need, the connect fails with the difference and nothing is stored, so a working connection always has what the tools require.
Does CoreSpeed review my app? No. Your own app needs no review from CoreSpeed. The vendor's own review, where it applies, is yours to complete in the vendor console.
What do existing connections do when I switch from CoreSpeed's app to mine? Connections made through CoreSpeed's app keep working until something invalidates them. New connections go through your app. Replacing or deleting your app later is what moves its connections to needs_reauth; see the activity page for how each outcome is recorded.