OAuth 2.1
For assistants that sign in on their own: Claude and ChatGPT connectors and other directory clients.
- Leave any client ID and secret fields empty. The assistant discovers Leitvik's authorization server from the endpoint and registers itself with a client ID metadata document or dynamic client registration.
- Authorization code with PKCE
S256only; there is no client-credentials grant. - On the consent screen you choose one workspace and the scopes. Requested reads are preselected; writes stay off until you turn them on. Every authorization asks again.
- Access tokens last one hour. Refresh tokens last 30 days and rotate on every use.
- To disconnect, open Settings > API tokens > Connected applications.