Dexby

Auth configs

Decide how your users sign in to a connector, with Dexby's OAuth app or your own.

An auth config is one way your users connect one connector. It fixes the auth method, the OAuth app, the API host and which tools are allowed. Every connection goes through exactly one auth config, so a user cannot connect a connector until it has one. Connectors that need no credential are the exception.

Create an auth config

Open the form

In the dashboard, open Build → Catalog and click Set up on the connector, or open Build → Auth configs and add one there.

Set the key

The Key is how code and connect links pick this config, for example quickbooks-sandbox. Lowercase letters and numbers joined by -, _, : or ., up to 64 characters, unique in the project. The form suggests the connector id, then <connector>-2, <connector>-3.

Pick the auth method

Choose one of the methods the connector declares, such as OAuth 2.0 or API key. See auth methods.

Choose the OAuth app, then save

For OAuth methods, pick an OAuth app (below), adjust Scopes if needed, and click Add auth config.

Managed or your own OAuth app

OptionWhat users seeWhat you do
Dexby's managed OAuth appDexby on the consent pageNothing. Offered only when the deployment has a client for it.
Your own OAuth appYour app's nameRegister an app with the provider, enter Client ID and Client secret.

The managed app is fine for development. Switch to your own before launch. The client secret is encrypted and never shown again.

Some apps also need a value that belongs to the OAuth app, entered with its client. Google Ads asks for the Developer token from your manager account's API Center. It is stored and shown the same way as the secret.

With your own app, register this redirect URL with the provider. The form shows it under Redirect URL to register with a copy button:

Redirect URL
https://api.dexby.ai/api/dashboard/oauth/callback

The URL is the same for every connector and auth config in your project.

Token refreshes use the config's current OAuth app. Some providers reject refresh tokens issued to another client, so after you switch apps, affected users may need to reconnect.

Scopes

Scopes starts with the connector's default scopes. Edit the list to request fewer or more, up to 200. Users are asked to grant exactly these.

Use the key

Pass the key where you choose which auth config a user connects through:

WhereField
Connect linkauthConfigs: ['<auth-config-key>'] offers only those configs.
POST /v1/connectionsauthConfig. Without it, the connector's first config is used.

<auth-config-key> is the Key from Build → Auth configs. It is not the config's internal uuid.

Other settings

  • Host (optional): send this config's calls to another host, such as a sandbox or regional API. It must be a public https URL.
  • Actions: untick tools this config must not run. A call to one fails with 403 ACTION_DISABLED.
  • Auth method can change only while no accounts are connected through the config. To offer another method, add another config.
  • Global connection: Connect for everyone connects one account for the whole project. Every user in the project can use it, and calls still record which user made them. See Global connections.
  • Delete disconnects every account connected through the config, global accounts included, and erases their credentials. It cannot be undone.

On this page