When to bring your own OAuth app (Google, Microsoft, Meta) and how

Google, Microsoft and Meta gate shared OAuth apps behind review. An org admin registers your own app: paste client_id and client_secret, match the scopes.

Illustration: A human hand clicks its own orange padlock onto a slate blue wooden gate.

Bring your own OAuth app means connecting a vendor through an OAuth application your organization registered in the vendor's console. An org admin pastes the app's client_id and client_secret once. Every new connection in the organization then authorizes through that app. It is the route for vendors whose review gates a shared app: Google, Microsoft and Meta among them.

Your own OAuth app in five steps
  1. 1
    Open the connector's setup dialog
    Dashboard, Connectors, as an org admin
    It lists the required scopes and the redirect URI.
  2. 2
    Create the app in the vendor console
    add the redirect URI; grant every listed scope
    Any vendor review is between you and the vendor.
  3. 3
    Paste client_id and client_secret
    save the dialog
  4. 4
    Connect an account to verify
    a scope shortfall fails with the exact difference
    Nothing is stored on a failed connect.
  5. 5
    Tell members to connect
    credential_source.active becomes org
    Calls through your app are not metered by CoreSpeed.
An org admin pastes client_id and client_secret once; every new connection uses your app.

When do you need your own app?

CoreSpeed opens this mechanism on specific connectors. The authenticated index tells you where a connector stands through credential_source.active.

credential_source.activeMeaningWhat members see
"platform"CoreSpeed's own app serves this connectorthe normal Connect button
"org"your organization's app is configuredConnect, through your app
"none"the mechanism is open and nothing is configureda setup prompt until an admin finishes it

You need your own app in two cases. The first is a vendor whose review process gates a shared app, so the connector shows "none" until your organization supplies one. Your own app needs no review from CoreSpeed. The second is a vendor where you want calls to run under your organization's registration for your own reasons, such as the scopes and branding your users see on the consent screen.

{ "credential_source": { "active": "org" } }

Billing follows the app. Calls made through your own OAuth app are not metered by CoreSpeed. Holds and the activity trail still apply: a billing hold on the organization still refuses the call, and every call still lands in Dashboard → Activity.

How do you register it?

  1. Sign in as an org admin. Open Dashboard → Connectors and pick the connector. Open its setup dialog. The dialog lists the connector's required scopes and the redirect URI to register with the vendor.
  2. In the vendor's console, create an OAuth app for your organization. Add the redirect URI from the dialog. Grant every scope the dialog lists. Any review the vendor requires for those scopes is between you and the vendor.
  3. Paste the app's client_id and client_secret into the dialog and save.
  4. Connect an account yourself to verify. If your app grants fewer scopes than the connector's tools need, the connect fails with the exact difference and stores nothing. Add the missing scopes in the vendor console and connect again.
  5. Tell members to connect. Each new connection in the organization authorizes through your app, with the usual choice of private or shared visibility. The index now reports credential_source.active as "org".

The agent side does not change. The connector's tools keep their names, tools/list stays caller-specific, and the agent receives tools, never the token. The connectors page describes all three ways to connect.

What happens when you rotate or replace the app?

The lifecycle is deliberately blunt, so plan the two cases apart.

Rotating the secret under the same client_id disturbs nothing. Paste the new client_secret and existing connections keep working.

Replacing the client_id, or deleting the app, moves every connection issued through it to needs_reauth. The confirmation states how many connections that is. Members then reconnect through the new source from Dashboard → Connectors. Until they do, the connector's tools stay visible in tools/list and calls fail. Do not rotate the CoreSpeed API key and do not rewrite client configuration when this happens; neither is broken.

So: rotate secrets whenever you like. Replace the app only when you can tell every affected member to reconnect.

What changes for billing and audit?

Two things stay, one thing goes.

The activity trail stays. Every call through your app is recorded with action, actor, outcome and time, visible to the member for their own calls and to org admins for the org. If Smart Approval is on, writes through your app are judged against your policy like any other write. Reads are never gated.

Holds stay. Past the billing threshold the organization's metered calls answer payment_required, and a key past its monthly cap answers key_spend_limit_exceeded. Both are enforced before the tool runs, whichever app the connector uses.

CoreSpeed's per-call metering goes. Calls through your own app are not charged to your credit balance. What the vendor charges you for API use is unchanged. The billing page has the full boundary.

FAQ

Can any member register the organization's app? No. Only an org admin can paste client_id and client_secret. Once it is configured, any member can connect through it.

Does my own app change which tools appear? No. The tool surface is the connector's. If your app grants fewer scopes than those tools need, the connect fails with the difference and nothing is stored, so a working connection always has what the tools require.

Does CoreSpeed review my app? No. Your own app needs no review from CoreSpeed. The vendor's own review, where it applies, is yours to complete in the vendor console.

What do existing connections do when I switch from CoreSpeed's app to mine? Connections made through CoreSpeed's app keep working until something invalidates them. New connections go through your app. Replacing or deleting your app later is what moves its connections to needs_reauth; see the activity page for how each outcome is recorded.