---
title: "Available Agent Skills"
url: "https://docs.unified.to/skills/available"
description: "Agent Skills for Claude Code, Codex, Cursor, and other AI coding agents: ready-to-use SKILL.md packages for building against the Unified.to APIs, from the quick start to CRM, ATS, HRIS, accounting, payments, commerce, messaging, calendar, ticketing, RAG, and debugging, plus OAuth2 app-registration skills for 80+ vendor developer portals. Install with one command."
---
# Available Agent Skills

 Each skill is a ready-to-use `SKILL.md` file that teaches an AI coding agent how to build against a Unified.to API for a common use case. To add them to your agent, see [Install](/skills/install). 

### Add Unified.to integrations to an app

 Quick start

Start here: activate integrations in the Sandbox, embed the Authorization component, store connection IDs, make the first API call with an SDK, and verify it end to end — using the Core MCP server when it is connected.

Sandbox setup & authorizationFirst API call with an SDKWebhooks & going to production

[View SKILL.md](/skills/unified-quickstart/SKILL.md "View the raw SKILL.md file")[Quick start guide](/quick-start "Quick start guide")

### Build a payments / fintech app

 Payment

Accept payments, manage subscriptions, and reconcile payouts and refunds across Stripe, GoCardless, and other providers with the Unified Payment API.

One-time paymentsSubscriptions & billingPayouts & refund reconciliation

[View SKILL.md](/skills/unified-payments/SKILL.md "View the raw SKILL.md file")[Payment API](/payment/overview "Payment API")[Guide](/guides/how%5Fto%5Fbuild%5Fa%5Ffintech%5Fapplication%5Fwith%5Funified%5Fpayments%5Fapi "Read the source How-To guide")

### Build an e-commerce product integration

 Commerce

Sync products, variants, collections, and inventory across Shopify, WooCommerce, Amazon, and more with the Unified Commerce API.

Product & variant catalog syncInventory levelsCollections & sales channels

[View SKILL.md](/skills/unified-ecommerce/SKILL.md "View the raw SKILL.md file")[Commerce API](/commerce/overview "Commerce API")[Guide](/guides/how%5Fto%5Fbuild%5Fan%5Fe%5Fcommerce%5Fproduct%5Fintegration%5Fwith%5Funified "Read the source How-To guide")

### Build a candidate sourcing or job board app

 ATS

Read jobs, post candidates, and manage applications across Greenhouse, Lever, Workable, Ashby, and other ATS platforms with the Unified ATS API.

Job board / careers pageCandidate sourcingApplication status sync

[View SKILL.md](/skills/unified-ats-jobboard/SKILL.md "View the raw SKILL.md file")[ATS API](/ats/overview "ATS API")[Guide](/guides/how%5Fto%5Fbuild%5Fa%5Fcandidate%5Fsourcing%5For%5Fjob%5Fboard%5Fapp%5Fwith%5Funified "Read the source How-To guide")

### Build an invoicing system

 Accounting

Create and reconcile invoices, bills, contacts, and payments across QuickBooks, Xero, NetSuite, and other accounting platforms with the Unified Accounting API.

Invoice creation & syncContacts & accountsReconciliation & reporting

[View SKILL.md](/skills/unified-accounting-invoicing/SKILL.md "View the raw SKILL.md file")[Accounting API](/accounting/overview "Accounting API")[Guide](/guides/how%5Fto%5Fbuild%5Fan%5Finvoicing%5Fsystem%5Fwith%5Funified "Read the source How-To guide")

### Build a candidate assessment product

 Assessment

Receive assessment orders from within an ATS, deliver assessments, and push results back with the Unified Assessment API.

Skills & aptitude testingBackground checksBehavioral assessments

[View SKILL.md](/skills/unified-assessment/SKILL.md "View the raw SKILL.md file")[Assessment API](/assessment/overview "Assessment API")[Guide](/guides/how%5Fto%5Fbuild%5Fa%5Fcandidate%5Fassessment%5Fproduct%5Fwith%5Funified "Read the source How-To guide")

### Build enterprise search with RAG

 Storage & KMS

Ingest documents, pages, and files from Google Drive, Notion, Confluence, and other sources into a vector store to power Retrieval-Augmented Generation with the Unified Storage and KMS APIs.

Enterprise / knowledge searchRAG data ingestionReal-time document sync

[View SKILL.md](/skills/unified-enterprise-search-rag/SKILL.md "View the raw SKILL.md file")[Storage & KMS API](/kms/overview "Storage & KMS API")[Guide](/guides/how%5Fto%5Fbuild%5Fenterprise%5Fsearch%5Fusing%5Frag "Read the source How-To guide")

### Build a CRM / sales-sync app

 CRM

Read and write contacts, companies, deals, leads, and pipelines across HubSpot, Salesforce, Pipedrive, and other CRMs with the Unified CRM API.

Two-way contact syncDeal & pipeline managementLead capture

[View SKILL.md](/skills/unified-crm/SKILL.md "View the raw SKILL.md file")[CRM API](/crm/overview "CRM API")

### Build an HR / employee-data app

 HRIS

Sync employees, groups, time off, and payroll data across Workday, BambooHR, Gusto, and other HRIS platforms with the Unified HRIS API.

Employee directory syncTime-off & attendanceOnboarding / provisioning

[View SKILL.md](/skills/unified-hris/SKILL.md "View the raw SKILL.md file")[HRIS API](/hris/overview "HRIS API")[Guide](/guides/how%5Fto%5Faccess%5Femployees%5Fand%5Fusers "Read the source How-To guide")

### Build a chat / support bot

 Messaging

Send and receive messages across channels in Slack, Microsoft Teams, Discord, Telegram, and other platforms with the Unified Messaging API.

Support / chat botsNotifications & alertsMessage archiving

[View SKILL.md](/skills/unified-messaging/SKILL.md "View the raw SKILL.md file")[Messaging API](/messaging/overview "Messaging API")[Guide](/guides/how%5Fto%5Fbuild%5Fa%5Fdiscord%5Fsupport%5Fbot%5Fwith%5Funified%5Fand%5Flangbase "Read the source How-To guide")

### Build a helpdesk / ticketing integration

 Ticketing

Create and sync tickets, customers, and notes across Zendesk, Jira, Freshdesk, and other helpdesk platforms with the Unified Ticketing API.

Two-way ticket syncSupport automationCustomer / note management

[View SKILL.md](/skills/unified-ticketing/SKILL.md "View the raw SKILL.md file")[Ticketing API](/ticketing/overview "Ticketing API")

### Add "Sign in with Unified" to your app

 Auth

Let users sign in to your application with Google, Microsoft, and other OAuth2 or SAML providers, and verify them with a signed JWT, using the Unified Authentication API.

Social / OAuth2 sign-inSAML single sign-onJWT user verification

[View SKILL.md](/skills/unified-auth-signin/SKILL.md "View the raw SKILL.md file")[Auth API](/auth/overview "Auth API")[Guide](/guides/use%5Funified%5Fto%5Fsign%5Fin%5Fyour%5Fusers%5Finto%5Fyour%5Fapplication "Read the source How-To guide")

### Build a scheduling / calendar app

 Calendar

Read and create calendars, events, and scheduling links, and check availability across Google Calendar, Outlook, and other providers with the Unified Calendar API.

Event & meeting syncAvailability / busy timesScheduling links & webinars

[View SKILL.md](/skills/unified-calendar/SKILL.md "View the raw SKILL.md file")[Calendar API](/calendar/overview "Calendar API")

### Debug webhooks & connections

 Debugging

Diagnose and fix unhealthy connections and webhooks: interpret health statuses, read API call logs, resolve 401/403/404/429/5xx errors, validate webhook signatures, and understand native vs virtual webhook retries.

Unhealthy connectionsFailing / delayed webhooksSignature validation

[View SKILL.md](/skills/unified-debug-webhooks-connections/SKILL.md "View the raw SKILL.md file")[Webhooks reference](/reference/webhooks "Webhooks reference")[Guide](/guides/how%5Fto%5Ftroubleshoot%5Funhealthy%5Fwebhooks "Read the source How-To guide")

### Build against the Unified.to API

 API basics

Learn the REST fundamentals shared by every category — authentication, connections, request shape, pagination, filtering, field selection, and error handling — for building directly against the Unified.to API.

REST request basicsAuth & connectionsPagination, filtering & field selection

[View SKILL.md](/skills/unified-api/SKILL.md "View the raw SKILL.md file")[REST reference](/reference/rest "REST reference")

### Use the Unified.to SDKs

 SDKs

Install and call the official SDKs (TypeScript, Python, PHP, Java, Go, C#, Ruby): client construction and JWT auth, method naming, request/response shapes, pagination, retries, and error handling.

Install & authenticate an SDKList / create / update via typed methodsRetries & error handling

[View SKILL.md](/skills/unified-sdks/SKILL.md "View the raw SKILL.md file")[SDKs reference](/reference/sdks "SDKs reference")

## OAuth2 app registration skills

One skill per vendor developer portal. Each walks your agent through registering your own OAuth2 app with that vendor — developer account, redirect URIs, scopes, client ID and secret, and any review or partner gates — so you can add the credentials to the integration in Unified.to. **OAuth2 base** skills hold the portal mechanics shared by several products (Google, Microsoft, Atlassian, Zoho, and Meta); load the base skill first, then the product skill.

### Apollo.io API Credentials

 OAuth2 app

Establishes which Apollo.io credential a connector actually needs and obtains it — the OAuth 2.0 client registered in-product and approved by Apollo (the model Apollo intends for platforms acting on behalf of other organizations), or per-customer API keys with their master-vs-scoped split — with the four-redirect-URL cap, the locked-in scope set, the hash-routed authorize URL, the plan and credit gates, rate limits and a safe credential handoff.

[View SKILL.md](/skills/apollo-oauth-app/SKILL.md "View the raw SKILL.md file")

### Asana OAuth2 App Registration

 OAuth2 app

Creates or signs in to an Asana account and registers an app in the Asana developer console to obtain OAuth2 client ID and client secret — with redirect URLs, the granular-scopes-vs-Full-permissions decision, workspace distribution settings, token behaviour and a safe credential handoff.

[View SKILL.md](/skills/asana-oauth-app/SKILL.md "View the raw SKILL.md file")

### Atlassian Developer Console — shared OAuth 2.0 (3LO) registration mechanics

 OAuth2 base

The shared Atlassian Developer Console / OAuth 2.0 (3LO) mechanics behind every Atlassian Cloud product registration — creating the app and enabling 3LO, the single callback URL per app, account-level vs resource-level grants, the classic and granular scope families, offline\_access, rotating refresh tokens, the cloudid indirection and /ex/{product}/{cloudid}/... addressing, scope changes forcing re-consent, distribution and Marketplace approval. Read this first when registering any Atlassian Cloud OAuth app; the product skills (Atlassian Jira, Atlassian Confluence) build on it and cover only what their product adds. Use directly when the task is a plain Atlassian 3LO app with no particular product named. Covers Atlassian Cloud only — Data Center / Server uses a different auth model entirely.

[View SKILL.md](/skills/atlassian-cloud-oauth/SKILL.md "View the raw SKILL.md file")

### Atlassian Confluence Cloud OAuth 2.0 (3LO) App Registration

 OAuth2 app

The Confluence Cloud layer on top of the shared atlassian-cloud-oauth skill — the Confluence scope family and why a v2-era app ends up granular rather than classic, the v1/v2 REST split and what still only exists in v1, space/page/blogpost/attachment/comment addressing through /ex/confluence/{cloudid}, the space- and page-level permission model that makes a valid token see an empty wiki, data security policy app access rules, and Confluence's rate-limit budget.

[View SKILL.md](/skills/atlassian-confluence-oauth-app/SKILL.md "View the raw SKILL.md file")

### Atlassian Jira Cloud OAuth 2.0 (3LO) App Registration

 OAuth2 app

The Jira Cloud layer on top of the shared atlassian-cloud-oauth skill — the Jira classic scope set and its granular counterparts, the split between the Jira platform, Jira Software, Jira Service Management, Confluence and Assets APIs, /ex/jira/{cloudid}/rest/api/3/... addressing, and the 3LO limitations that are Jira's alone.

[View SKILL.md](/skills/atlassian-jira-oauth-app/SKILL.md "View the raw SKILL.md file")

### Attio OAuth2 App Registration

 OAuth2 app

Creates or signs in to an Attio account and registers an app in the Attio Developer console (build.attio.com) to obtain an OAuth2 client ID and client secret — with redirect URIs, the app-configured scope catalogue, the object/attribute data model, non-expiring tokens with no refresh token, workspace-level admin-only installs, API-created webhooks, and a safe credential handoff.

[View SKILL.md](/skills/attio-oauth-app/SKILL.md "View the raw SKILL.md file")

### BambooHR API Credentials

 OAuth2 app

Obtains BambooHR API credentials — either an OAuth2 client ID and secret registered in the BambooHR Developer Portal (self-registration has been open since April 2025), or the per-customer API key plus company subdomain that most BambooHR integrations still run on. Covers redirect URIs, the 220-scope catalog, the permission inheritance that silently returns partial data, rate limits, sandbox access, and the Marketplace listing gate.

[View SKILL.md](/skills/bamboohr-oauth-app/SKILL.md "View the raw SKILL.md file")

### Bitbucket Cloud OAuth 2.0 Consumer Registration

 OAuth2 app

Registers a Bitbucket Cloud OAuth 2.0 consumer to obtain OAuth2 credentials — the consumer Key and Secret, the single callback URL, and the permission checkboxes that become the token's scopes — for a platform that connects many customers' Bitbucket workspaces.

[View SKILL.md](/skills/bitbucket-oauth-app/SKILL.md "View the raw SKILL.md file")

### Box OAuth2 App Registration

 OAuth2 app

Creates or signs in to a Box developer account and registers a Box Platform App with User Authentication (OAuth 2.0) to obtain a client ID and client secret — with exact-match redirect URIs, console-selected scopes, the enterprise admin app-authorization gate, single-use rotating refresh tokens, and a safe credential handoff.

[View SKILL.md](/skills/box-oauth-app/SKILL.md "View the raw SKILL.md file")

### Brex OAuth2 App Registration

 OAuth2 app

Obtains Brex OAuth 2.0 credentials — client ID, client secret, redirect URIs and scopes — for a platform that connects other organizations' Brex accounts. Covers the fact that Brex OAuth apps are partner-gated rather than self-serve (there is no developer portal that issues credentials), the route into the partner programme, the per-customer user-token alternative and its admin runbook, the full scope catalogue and its read/write split, staging access, 1-hour access tokens with rotating 90-day refresh tokens, rate limits, and a safe credential handoff.

[View SKILL.md](/skills/brex-oauth-app/SKILL.md "View the raw SKILL.md file")

### Bullhorn API Credentials

 OAuth2 app

Establishes whether a Bullhorn OAuth2 credential can legitimately be obtained at all and, if so, obtains it — client ID, client secret, API username and API-user password, all issued by hand by Bullhorn Support or the Bullhorn Alliances team, never from a developer portal — with the per-customer data-centre swimlane that must be discovered at runtime, the two-step OAuth-token-then-BhRestToken session dance, single-use refresh tokens that must be explicitly enabled on the key, the entitlements model that replaces scopes, per-client-ID rate limits shared across every customer, and a safe credential handoff.

[View SKILL.md](/skills/bullhorn-oauth-app/SKILL.md "View the raw SKILL.md file")

### Calendly OAuth2 App Registration

 OAuth2 app

Creates a Calendly developer account and registers a Calendly OAuth application to obtain a client ID, client secret and webhook signing key — with redirect URIs, the OAuth 2.1 scope catalogue, Sandbox vs Production apps, single-use rotating refresh tokens, the plan and role gating that decides what a customer's token can actually see, and a safe credential handoff.

[View SKILL.md](/skills/calendly-oauth-app/SKILL.md "View the raw SKILL.md file")

### ClickUp OAuth2 App Registration

 OAuth2 app

Signs in to ClickUp and registers an OAuth app inside a Workspace's Settings → Apps to obtain an OAuth2 client ID and client secret — with redirect URLs, the fact that ClickUp has no OAuth scopes at all, the Workspace-selection consent model, non-expiring tokens with no refresh token, per-plan rate limits and a safe credential handoff.

[View SKILL.md](/skills/clickup-oauth-app/SKILL.md "View the raw SKILL.md file")

### Discord OAuth2 App Registration

 OAuth2 app

Creates a Discord application in the developer portal and obtains OAuth2 client ID and client secret plus a bot token — with the right redirect URIs, scope strings, the bot scope and its permissions bitfield, privileged gateway intents, app verification and a safe credential handoff.

[View SKILL.md](/skills/discord-oauth-app/SKILL.md "View the raw SKILL.md file")

### Dropbox OAuth2 App Registration

 OAuth2 app

Creates or signs in to a Dropbox account and registers a Dropbox app in the App Console to obtain an OAuth2 app key and app secret (client ID and client secret) — with the irreversible App folder vs Full Dropbox access-type choice, redirect URIs, scoped permissions, token\_access\_type=offline for refresh tokens, and the development-to-production approval path.

[View SKILL.md](/skills/dropbox-oauth-app/SKILL.md "View the raw SKILL.md file")

### Facebook (Pages) OAuth2 App Registration

 OAuth2 app

The Facebook Pages layer on top of the shared meta-graph-app skill — read that one first for the Meta developer account, the app, redirect-URI rules, access levels, the four review regimes, the App ID and Secret, appsecret\_proof and Graph API versioning. This file covers only what Facebook adds: the Page access token that most Page endpoints actually require and the /me/accounts exchange that mints it, Page tasks as a second authorization axis that permissions do not satisfy, the pages\_\* permission family and which entries need Tech Provider verification, the "Manage everything on your Page" use case and the business\_management it force-adds, Facebook Login for Business versus classic Facebook Login and the config\_id-replaces-scope change, Page webhooks needing a per-Page subscribed\_apps install on top of an app-level subscription, and the Page Insights metric deprecations.

[View SKILL.md](/skills/facebook-oauth-app/SKILL.md "View the raw SKILL.md file")

### Fathom OAuth2 App Registration

 OAuth2 app

Registers a Fathom (fathom.video AI meeting notetaker) OAuth2 app to obtain a client ID and client secret — covering the self-serve marketplace-application form, the one-production-redirect-URI rule that forces one app per data center, the single public\_api scope, one-time-use rotating refresh tokens, and the per-customer API-key route that is the alternative.

[View SKILL.md](/skills/fathom-oauth-app/SKILL.md "View the raw SKILL.md file")

### FreshBooks OAuth2 App Registration

 OAuth2 app

Creates or signs in to a FreshBooks account and registers a FreshBooks OAuth2 app to obtain a client ID and client secret — with redirect URIs, the portal-side user:<object>:<action> scope picker, the account-id / business-id / business-UUID indirection behind /auth/api/v1/users/me, one-time-use rotating refresh tokens, and a safe credential handoff.

[View SKILL.md](/skills/freshbooks-oauth-app/SKILL.md "View the raw SKILL.md file")

### GitHub OAuth2 App Registration

 OAuth2 app

Registers a GitHub OAuth App or a GitHub App to obtain OAuth2 credentials — client ID, client secret, and for a GitHub App the private key that mints installation tokens — with the right callback URLs, scopes or fine-grained permissions, org approval path, and a safe credential handoff.

[View SKILL.md](/skills/github-oauth-app/SKILL.md "View the raw SKILL.md file")

### Gmail OAuth2 App Registration

 OAuth2 app

The Gmail API layer on top of the shared google-cloud-console-oauth skill — why every mailbox-reading Gmail scope is restricted and there is no drive.file-style escape hatch, the one genuinely narrow scope (gmail.send) and what it cannot do, the permitted application types that gate Gmail restricted scopes, refresh tokens dying on a user's password change, Pub/Sub push registration, Gmail quota units and sending limits, and the Workspace admin controls that block Gmail API access specifically.

[View SKILL.md](/skills/gmail-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google Ads API OAuth2 App Registration

 OAuth2 app

Google Ads API credentials, on top of the shared google-cloud-console-oauth skill — read that one first for the Cloud project, consent app, Web application client, redirect URIs and verification. This file covers only what Google Ads adds: the API access level that replaced the developer token at the 9 September 2026 sunset, the Test / Explorer / Basic / Standard ladder and its blocked services, brand verification as a prerequisite for Basic, the Google Ads manager (MCC) account and its Terms of Service, the single adwords scope, the login-customer-id header, and the 2SV and passkey mandates.

[View SKILL.md](/skills/google-ads-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google Analytics (GA4) OAuth2 App Registration

 OAuth2 app

The Google Analytics (GA4) layer on top of the shared google-cloud-console-oauth skill — the analytics.\* scope family and which API accepts which member, the Universal Analytics sunset and the legacy scopes and endpoints it left behind, the Data API / Admin API split and their separate enablements, property IDs vs measurement IDs vs stream IDs and the one call that discovers what a user can see, the per-property token quota that a multi-tenant reader hits once per customer, and the sampling, cardinality and thresholding effects that change a report's numbers without changing its status code.

[View SKILL.md](/skills/google-analytics-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google Business Profile — API access and OAuth specifics

 OAuth2 app

Builds on the google-cloud-console-oauth base skill (read that first — it owns the Cloud project, OAuth client, redirect URIs, secret and verification mechanics) and covers only what the Google Business Profile APIs add: the mandatory API access request that gates everything, quota pinned at 0 QPM until a human approves it, approval bound to a Cloud project number, the seven-plus-one APIs to enable, the single business.manage read-and-write scope, profile-role and Workspace permission failures, quota-increase rules, v4 sunset history and the no-sandbox validateOnly path.

[View SKILL.md](/skills/google-business-profile-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google Calendar OAuth2 App Registration

 OAuth2 app

The Google Calendar API layer on top of the shared google-cloud-console-oauth skill — the Calendar scope family and the fact that all of it is sensitive rather than restricted (verification, but no CASA assessment), the granular scopes that narrow a request further, which APIs to enable, where Google Meet and conferencing scopes touch Calendar events, what a token can actually see across primary, secondary, shared and delegated calendars, freebusy as a minimal-access alternative, watch channels and quotas, and the Workspace admin settings that block Calendar specifically.

[View SKILL.md](/skills/google-calendar-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google Cloud Console — shared OAuth2 registration mechanics

 OAuth2 base

The shared Google Cloud Console / Google Auth Platform mechanics behind every Google OAuth2 registration — creating the project, configuring the consent app, creating a Web application client, redirect-URI rules, scope tiers and declaration, the one-time client secret, Testing vs In production, verification and the restricted-scope security assessment. Read this first when registering any Google OAuth client; the product skills (Google APIs, Google Ads, Google Business Profile, Google Drive) build on it and cover only what is specific to their API. Use directly when the task is a plain Google OAuth client with no particular Google product named.

[View SKILL.md](/skills/google-cloud-console-oauth/SKILL.md "View the raw SKILL.md file")

### Google Contacts (People API) OAuth2 App Registration

 OAuth2 app

The Google Contacts / People API layer on top of the shared google-cloud-console-oauth skill — the People scope family and why none of it is restricted (so no CASA assessment), the two-rung least-privilege ladder (contacts.readonly and contacts, with no narrow write scope), the "other contacts" corpus that explains why an app sees far fewer people than the user does, Workspace directory people and the admin switch behind them, personFields/readMask, seven-day sync tokens, contact groups, and quota.

[View SKILL.md](/skills/google-contacts-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google Docs OAuth2 App Registration

 OAuth2 app

The Google Docs API layer on top of the shared google-cloud-console-oauth skill — the two documents scopes and why they are only sensitive, the Drive dependency that decides the whole project's tier (the Docs API addresses a document by ID and cannot list or search, so discovery needs drive.readonly and a CASA assessment, or drive.file and a Picker, or no Drive scope and document IDs from elsewhere), the structural-element and index model behind batchUpdate, export going through Drive rather than Docs, and the Docs quotas.

[View SKILL.md](/skills/google-docs-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google Drive OAuth2 App Registration

 OAuth2 app

The Google Drive API layer on top of the shared google-cloud-console-oauth skill — which Drive scopes are restricted and which are not, the drive.file per-file escape hatch and what it cannot do, the permitted-application-type rule that gates restricted Drive scopes regardless of paperwork, the verification exemptions, shared-drive access, and the Search Console domain-ownership problem for a customer bringing their own Google app.

[View SKILL.md](/skills/google-drive-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google Meet OAuth2 App Registration

 OAuth2 app

The Google Meet layer on top of the shared google-cloud-console-oauth skill — the authoritative sensitivity tier of every Meet scope (meetings.space.created and meetings.space.readonly sensitive, meetings.space.settings non-sensitive, all Meet Media API scopes restricted), the three different things people call "Meet support" and what each costs, the Meet REST API surface (spaces, conferenceRecords, recordings, transcripts, participants), why recordings and transcripts are Drive files and therefore restricted-tier, which APIs to enable, the Workspace editions that must exist before an artifact exists at all, event subscriptions, and quotas.

[View SKILL.md](/skills/google-meet-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google OAuth2 App Registration — Gmail, Calendar/Meet, Contacts/People, Drive/Sheets

 OAuth2 app

The multi-API Google connector layer on top of the shared google-cloud-console-oauth skill — the combined scope set a connector requests when one Google connection spans several APIs at once (identity, Gmail, Calendar/Meet, Contacts/People, Drive/Sheets), and the tier that union lands in. Read the base skill first. Use this when the job is a Google connection covering several products or you need the combined scope picture; for a single product use its own skill — gmail-oauth-app, google-calendar-oauth-app, google-drive-oauth-app, google-sheets-oauth-app, google-docs-oauth-app, google-contacts-oauth-app, google-meet-oauth-app, google-tasks-oauth-app, google-analytics-oauth-app, google-ads-oauth-app or google-business-profile-oauth-app. For a plain Google OAuth client with no product named, the base skill alone is the whole job. For any other vendor's developer portal, use that vendor's skill instead.

[View SKILL.md](/skills/google-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google Sheets OAuth2 App Registration

 OAuth2 app

The Google Sheets API layer on top of the shared google-cloud-console-oauth skill — the two Sheets scopes and why both are sensitive but neither is restricted, the Drive scope an app adds to \*find\* a spreadsheet and how that one choice decides whether the project needs an annual CASA assessment, A1 versus grid ranges, batch methods and the per-minute quotas that punish per-cell calls, the spreadsheet hard limits, and the Apps Script and add-on paths that change which OAuth client is even in play.

[View SKILL.md](/skills/google-sheets-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google Slides OAuth2 App Registration

 OAuth2 app

The Google Slides API layer on top of the shared google-cloud-console-oauth skill — the two presentations scopes and why they are only sensitive, the Drive scope that decides the whole project's tier (the Slides API addresses a presentation by ID and cannot list, search, copy, move or export one, so discovery and rendering come from Drive), the per-slide thumbnail method and its 30-minute URLs, caller-supplied object IDs and why index arithmetic across batchUpdate calls is fragile, the separate "expensive read" quota bucket, and the things people assume the API does and it does not.

[View SKILL.md](/skills/google-slides-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google Tasks OAuth2 App Registration

 OAuth2 app

The Google Tasks API layer on top of the shared google-cloud-console-oauth skill — the two Tasks scopes and the tier they actually sit in (sensitive, not restricted, so no CASA assessment), the tasklists/tasks model and the undocumented @default alias, hierarchy and ordering that only the separate move call can write, the completed/hidden/deleted/assigned flags that silently drop tasks out of a list response, the documented quota and data caps, and why tasks appearing in Google Calendar does not mean you need a Calendar scope.

[View SKILL.md](/skills/google-tasks-oauth-app/SKILL.md "View the raw SKILL.md file")

### Google Workspace Directory OAuth2 App Registration

 OAuth2 app

The Admin SDK Directory API layer on top of the shared google-cloud-console-oauth skill — why this API only works against a Google Workspace account and never a consumer Gmail one, the admin.directory.\* scope family and the finding that none of it appears on Google's restricted list, the admin role that is checked \*in addition\* to the scope (and the one domain-public read a non-admin can do), domain-wide delegation as a per-customer super-admin task rather than something registered once, the customer=my\_customer convention, users vs members vs org units, the absence of any delta or sync token and what to use instead, and the Directory-specific quotas and page-size caps.

[View SKILL.md](/skills/google-workspace-directory-oauth-app/SKILL.md "View the raw SKILL.md file")

### Greenhouse API Credentials

 OAuth2 app

Establishes which Greenhouse credential a connector actually needs and obtains it — Harvest v3 partner OAuth (issued only by Greenhouse Partner Support under a signed partnership agreement), customer-created Harvest v3 client-credentials, legacy Harvest v1/v2 API keys, Job Board tokens, Ingestion and Assessment partner keys — with scopes, the Site Admin rule, rate limits, IP allowlisting and a safe credential handoff.

[View SKILL.md](/skills/greenhouse-oauth-app/SKILL.md "View the raw SKILL.md file")

### HiBob (Bob) API Credentials

 OAuth2 app

Establishes which HiBob (Bob) credential a connector can actually get and obtains it — the per-customer service user ID and token that any integration can use today, or the partner-gated OAuth 2.0 client ID and secret that only approved HiBob Marketplace and technology partners are issued — with the service-user permission-group runbook, field-level permissions and the silent-omission trap that returns 200 OK with missing data, token lifetimes and rotation, sandbox, rate limits and the WAF block on repeated 401s.

[View SKILL.md](/skills/hibob-oauth-app/SKILL.md "View the raw SKILL.md file")

### HighLevel OAuth2 App Registration

 OAuth2 app

Creates or signs in to a HighLevel (GoHighLevel / LeadConnector) developer marketplace account and registers a marketplace app to obtain OAuth2 client ID and client secret — with the irreversible Agency-vs-Sub-Account target-user decision, redirect URL, scopes, private-app install cap, token and Version-header behaviour, and a safe credential handoff.

[View SKILL.md](/skills/highlevel-oauth-app/SKILL.md "View the raw SKILL.md file")

### HubSpot OAuth2 App Registration

 OAuth2 app

Creates or signs in to a HubSpot developer account and registers a HubSpot app to obtain OAuth2 client ID and client secret — with the right redirect URLs, required vs optional scopes, install limits, and a safe credential handoff.

[View SKILL.md](/skills/hubspot-oauth-app/SKILL.md "View the raw SKILL.md file")

### iCIMS API Credentials

 OAuth2 app

Establishes whether an iCIMS API credential can legitimately be obtained for a given platform and, if so, obtains it — an API username and password for HTTP Basic, an HMAC key, or an OAuth 2.0 client ID and secret used with the client-credentials grant, all configured and issued by hand by iCIMS staff, never from a self-serve developer portal — with the paid Technology Partner Program that gates any repeatable multi-customer integration, the per-customer Customer ID that must be collected before the first call, the regional US/EU/Canada auth and API hosts, the Integration User group and Security Rules model that silently returns partial data instead of errors, the 10,000-call daily licence limit, and a safe credential handoff.

[View SKILL.md](/skills/icims-oauth-app/SKILL.md "View the raw SKILL.md file")

### Instagram (Meta) OAuth2 App Registration

 OAuth2 app

The Instagram Platform layer on top of the shared meta-graph-app skill — read that one first for the Meta developer account, the app, redirect-URI rules, access levels, the review regimes, appsecret\_proof and Graph API versioning. This file covers only what Instagram adds: picking between Instagram API with Instagram Login and Instagram API with Facebook Login for Business, the instagram\_business\_\* permission strings, the separate Instagram App ID and Instagram App Secret that are not the Meta app's, graph.instagram.com, and the 1-hour → 60-day → refresh token ladder.

[View SKILL.md](/skills/instagram-oauth-app/SKILL.md "View the raw SKILL.md file")

### Intercom OAuth2 App Registration

 OAuth2 app

Creates or signs in to an Intercom development workspace and registers an Intercom app in the Developer Hub to obtain OAuth2 client ID and client secret — enabling OAuth on the app, adding every HTTPS redirect URL, selecting the per-app permission scopes, handling US/EU/AU regional hosting, pinning the API version, and a safe credential handoff.

[View SKILL.md](/skills/intercom-oauth-app/SKILL.md "View the raw SKILL.md file")

### JobAdder OAuth2 App Registration

 OAuth2 app

Registers a JobAdder partner/developer account and an application to obtain OAuth2 client ID and client secret — covering the approval gate that blocks credentials until JobAdder says yes, authorised redirect URIs, the per-object scope list and offline\_access, rotating refresh tokens, and the per-account API base URL returned in the token response.

[View SKILL.md](/skills/jobadder-oauth-app/SKILL.md "View the raw SKILL.md file")

### Lever API Credentials

 OAuth2 app

Establishes which Lever credential a connector actually needs and obtains it — partner-gated OAuth2 (client ID and secret issued by hand by the Lever integrations team, only after the partner program and a sandbox account), customer-created Data API keys, and the public unauthenticated Postings API — with the mandatory audience parameter, the <resource>:<action>:admin scope grammar, the Super Admin rule, sandbox-vs-production hosts that are not interchangeable, refresh-token lifetimes and a safe credential handoff.

[View SKILL.md](/skills/lever-oauth-app/SKILL.md "View the raw SKILL.md file")

### Linear OAuth2 App Registration

 OAuth2 app

Creates or signs in to a Linear workspace and registers an OAuth2 application in Linear's workspace API settings to obtain a client ID and client secret — with redirect URIs, the comma-delimited scope list, private vs public distribution, the actor=user vs actor=app decision, 24-hour access tokens with rotating refresh tokens, app-level webhooks, and a safe credential handoff.

[View SKILL.md](/skills/linear-oauth-app/SKILL.md "View the raw SKILL.md file")

### LinkedIn OAuth2 App Registration

 OAuth2 app

Creates or signs in to a LinkedIn developer account and registers a LinkedIn app to obtain OAuth2 client ID and client secret — covering the mandatory LinkedIn Page association and super-admin app verification, the per-Product access requests that actually unlock scopes, exact-match redirect URLs, 60-day tokens and programmatic refresh tokens, and a safe credential handoff.

[View SKILL.md](/skills/linkedin-oauth-app/SKILL.md "View the raw SKILL.md file")

### Mailchimp OAuth2 App Registration

 OAuth2 app

Creates or signs in to a Mailchimp account and registers an app on the Registered Apps page to obtain an OAuth2 client ID and client secret — with the redirect URI, the fact that Mailchimp has no scopes, the per-account data-centre prefix that must be discovered after token exchange, non-expiring tokens with no refresh token, rotation, and a safe credential handoff.

[View SKILL.md](/skills/mailchimp-oauth-app/SKILL.md "View the raw SKILL.md file")

### Meta Ads (Marketing API) OAuth2 App Registration

 OAuth2 app

The Marketing API layer on top of the shared meta-graph-app skill — read that one first for the developer account, the app, redirect URIs, access levels, the four review regimes, the App ID and Secret, and Graph API versioning. This file covers only what Meta Ads adds: the Business app type plus the Marketing API product and a Facebook Login for Business configuration, the ads\_read / ads\_management / business\_management permissions, the Limited→Full Marketing API access tier and its 500-call threshold, the \~60-day user token versus the never-expiring Business Integration System User token, the Marketing API's own 90-day version clock, and the per-ad-account and insights throttles.

[View SKILL.md](/skills/meta-ads-oauth-app/SKILL.md "View the raw SKILL.md file")

### Meta App Dashboard — shared OAuth2 registration mechanics

 OAuth2 base

The shared Meta App Dashboard registration mechanics behind every Meta Graph connector — registering a developer account, the business portfolio that claims the app, the app-creation wizard and its two irreversible choices, exact-match redirect URIs, Standard vs Advanced Access, the four review regimes (App Review, Business Verification, Access Verification / Tech Provider, Ongoing Review and Data Use Checkup), the App ID and App Secret, appsecret\_proof and rotation, Graph API versioning, and the #4 / #10 / #17 / #100 / #190 / #200 and 80000-series error codes. Read this first for any Meta product, then the product skill — meta-ads-oauth-app (Marketing API) or instagram-oauth-app (Instagram Platform).

[View SKILL.md](/skills/meta-graph-app/SKILL.md "View the raw SKILL.md file")

### Dynamics 365 / Dataverse (Microsoft Entra ID) OAuth2 App Registration

 OAuth2 app

Registers a Microsoft Entra ID application for Dynamics 365 / Microsoft Dataverse access. Builds on the microsoft-entra-app-registration base skill, which holds the shared Entra mechanics (supported account types, redirect URIs, delegated vs application permissions, admin consent, client secrets, publisher verification); read that first. This skill covers only what Dynamics adds: the per-customer, per-environment Dataverse resource URL and discovering it through the Global Discovery Service, the user\_impersonation / .default resource-scoped scopes, the application user plus security role step that a customer admin must do before an app-only token works at all, Dataverse row-level security as an intersection with the OAuth grant, the product-family split (Sales, Customer Service / Customer Engagement, Contact Center, Customer Insights, Business Central, Finance & Operations, GP), Web API versioning and service protection limits.

[View SKILL.md](/skills/microsoft-dynamics-oauth-app/SKILL.md "View the raw SKILL.md file")

### Microsoft Entra ID — shared app-registration mechanics

 OAuth2 base

The shared Microsoft Entra ID (formerly Azure AD) app-registration mechanics behind every Microsoft OAuth2 client — the Entra admin center, registering the app, supported account types and what they cap, redirect-URI platform types, delegated vs application permissions, admin consent and who is allowed to grant it, the 24-month client secret and its one-time Value, certificates, offline\_access, publisher verification, and the AADSTS errors these produce. Read this first when registering any Entra app for Microsoft Graph; the product skills — Microsoft Graph sign-in, SharePoint — build on it and cover only what their product adds. Use directly when the task is a plain Entra ID / Microsoft Graph OAuth client and no particular Microsoft product is named.

[View SKILL.md](/skills/microsoft-entra-app-registration/SKILL.md "View the raw SKILL.md file")

### Entra ID directory data (users, groups, org) through Microsoft Graph

 OAuth2 app

The Microsoft Graph permission and query model for reading Microsoft Entra ID directory data — users, groups, memberships, managers and org profile — for a connector that syncs a customer's directory. Builds on the microsoft-entra-app-registration base skill, which covers how to register an Entra app at all (account types, redirect URIs, secrets, publisher verification); read that first. The base answers "how do I register an app"; this file answers "which directory permissions do I ask for, what does each one actually return, and why will the customer's security team say no". Covers the User.\*, Group.\*, GroupMember.\*, Directory.\* and Organization.Read.All families and which need admin consent, the least-privilege ladder from User.ReadBasic.All up to Directory.Read.All, guest/B2B behavior, $select/$filter and ConsistencyLevel: eventual, delta queries for sync, manager and direct-report expansion, on-premises-synced attributes, and directory throttling.

[View SKILL.md](/skills/microsoft-entra-directory-oauth-app/SKILL.md "View the raw SKILL.md file")

### Microsoft Graph OAuth2 App Registration

 OAuth2 app

The Microsoft Graph sign-in layer on top of the shared microsoft-entra-app-registration skill — the tenant-agnostic common authority, the openid email profile User.Read scope set, prompt=select\_account, and why an authentication connector receives no refresh token. Read the base skill first. Use this when the job is Microsoft sign-in / identity, or a general Graph connector with no specific product named; for a product use its own skill — microsoft-outlook-oauth-app (mail and calendar), microsoft-onedrive-oauth-app (files), microsoft-sharepoint-oauth-app (sites and libraries), microsoft-teams-oauth-app, microsoft-entra-directory-oauth-app (users and groups) or microsoft-dynamics-oauth-app. For any other vendor's developer portal, use that vendor's skill instead.

[View SKILL.md](/skills/microsoft-oauth-app/SKILL.md "View the raw SKILL.md file")

### OneDrive (Microsoft Graph files) OAuth2 App Registration

 OAuth2 app

Registers a Microsoft Entra ID application for OneDrive and the Microsoft Graph files APIs (drives, driveItems, uploads, delta, sharing links). Builds on the microsoft-entra-app-registration base skill, which holds the shared Entra mechanics (supported account types, redirect URIs, delegated vs application permissions, admin consent, client secrets, publisher verification); read that first. This skill covers only what OneDrive adds: the Files.\* permission family and which of the "Selected" scopes are current versus legacy, why Files.\*.All reaches every user's OneDrive \*and\* every SharePoint site, OneDrive personal versus OneDrive for Business and what that forces on the supported-account-types choice, drive and driveItem addressing, large-file upload sessions, delta sync, sharing links and per-item permissions, and OneDrive's per-user throttling limits.

[View SKILL.md](/skills/microsoft-onedrive-oauth-app/SKILL.md "View the raw SKILL.md file")

### Outlook (Microsoft Entra ID) OAuth2 App Registration

 OAuth2 app

Registers a Microsoft Entra ID application for Outlook mail and calendar access through Microsoft Graph. Builds on the microsoft-entra-app-registration base skill, which holds the shared Entra mechanics (supported account types, redirect URIs, delegated vs application permissions, admin consent, client secrets, offline\_access, publisher verification); read that first. This skill covers only what Outlook adds: the Mail.\* / Calendars.\* / .Shared permission families and the naming traps in them, the fact that every Outlook \*application\* permission reaches every mailbox in the tenant, the two documented ways to narrow that (RBAC for Applications, and the legacy application access policies), shared / delegated / room / group mailboxes, per-mailbox throttling and concurrency, change-notification lifetimes, and the EWS and Outlook REST retirement dates.

[View SKILL.md](/skills/microsoft-outlook-oauth-app/SKILL.md "View the raw SKILL.md file")

### SharePoint (Microsoft Entra ID) OAuth2 App Registration

 OAuth2 app

Registers a Microsoft Entra ID application for SharePoint Online access through Microsoft Graph. Builds on the microsoft-entra-app-registration base skill, which holds the shared Entra mechanics (supported account types, redirect URIs, delegated vs application permissions, admin consent, client secrets, publisher verification); read that first. This skill covers only what SharePoint adds: the Sites.Selected per-site grant model and the three conditions it needs, the broad Sites.\*.All alternatives and how security reviews react to them, the expanded Selected-scopes family and its permission-inheritance cost, the retired Azure ACS / SharePoint Add-In auth model, Graph site/drive/list addressing, and SharePoint's throttling economics.

[View SKILL.md](/skills/microsoft-sharepoint-oauth-app/SKILL.md "View the raw SKILL.md file")

### Microsoft Teams (Microsoft Entra ID) OAuth2 App Registration

 OAuth2 app

Registers a Microsoft Entra ID application for Microsoft Teams access through Microsoft Graph. Builds on the microsoft-entra-app-registration base skill, which holds the shared Entra mechanics (supported account types, redirect URIs, delegated vs application permissions, admin consent, client secrets, offline\_access, publisher verification); read that first. This skill covers only what Teams adds: the Teams Graph permission families and which ones a tenant admin will actually approve, the protected export APIs and the metering that was switched off in August 2025 (plus the licenses that still bite), resource-specific consent as the narrow alternative and what it cannot reach, application access policies for online meetings and virtual events, change notifications with resource data, and Teams' four-dimension throttling.

[View SKILL.md](/skills/microsoft-teams-oauth-app/SKILL.md "View the raw SKILL.md file")

### monday.com OAuth2 App Registration

 OAuth2 app

Signs in to monday.com and registers an app in the Developer Center to obtain OAuth2 client ID and client secret — with redirect URLs, the per-app-version scope list, the admin-install prerequisite, the two parallel OAuth flows (legacy non-expiring tokens vs the opt-in OAuth 2.1 flow with PKCE and refresh tokens), the dated API-Version header, the complexity budget and a safe credential handoff.

[View SKILL.md](/skills/monday-oauth-app/SKILL.md "View the raw SKILL.md file")

### NetSuite OAuth 2.0 App Registration

 OAuth2 app

Creates a NetSuite integration record and obtains OAuth 2.0 client ID and client secret (the consumer key and consumer secret) for a platform that connects many customers' NetSuite accounts — covering the account that owns the integration record and how it reaches other accounts, the account-specific hostnames, the features and role permissions that must exist before a token works, the three coarse scopes, the seven-day refresh token, and a safe credential handoff.

[View SKILL.md](/skills/netsuite-oauth-app/SKILL.md "View the raw SKILL.md file")

### Notion OAuth2 App Registration

 OAuth2 app

Creates or signs in to a Notion account and registers a public connection (Notion's OAuth app) in the Notion Developer portal to obtain an OAuth client ID and client secret — with redirect URIs, capabilities, the page-sharing permission model, token and refresh-token behaviour, and a safe credential handoff.

[View SKILL.md](/skills/notion-oauth-app/SKILL.md "View the raw SKILL.md file")

### Pennylane API Credentials

 OAuth2 app

Establishes which Pennylane credential a connector actually needs and obtains it — partner-gated OAuth 2.0 client credentials issued by Pennylane's Partnerships team, or the self-serve Company and Firm API tokens each customer generates — with the company-vs-firm consent model, the v2 scope catalogue and the retired ledger scope, 24-hour access tokens with rotating 90-day refresh tokens, the v1 sunset and the 2026 behaviour migration, rate limits and a safe credential handoff.

[View SKILL.md](/skills/pennylane-oauth-app/SKILL.md "View the raw SKILL.md file")

### Pipedrive OAuth2 App Registration

 OAuth2 app

Creates a Pipedrive developer sandbox account and registers an app in Developer Hub to obtain OAuth2 client ID and client secret — with the single-callback-URL constraint, the public-vs-private app decision, app-level scope selection, the per-company api\_domain, token and refresh behaviour, Marketplace review and a safe credential handoff.

[View SKILL.md](/skills/pipedrive-oauth-app/SKILL.md "View the raw SKILL.md file")

### QuickBooks Online (Intuit) OAuth2 App Registration

 OAuth2 app

Creates or signs in to an Intuit Developer account and registers a QuickBooks Online app to obtain OAuth2 client ID and client secret — covering the sandbox/production key split, redirect URIs, the com.intuit.quickbooks.\* scopes, the realmId returned on the callback, rotating refresh tokens, and the app assessment questionnaire that gates production access.

[View SKILL.md](/skills/quickbooks-oauth-app/SKILL.md "View the raw SKILL.md file")

### RingCentral OAuth2 App Registration

 OAuth2 app

Creates or signs in to a RingCentral developer-enabled account and registers a REST API app in the RingCentral Developer Console to obtain client ID and client secret — with the public-vs-private choice that cannot be edited after creation, the exact Redirect URI list, the permission (scope) catalogue and its "requires permission" approval tickets, the "Issue refresh tokens" toggle that is off by default, the retired sandbox and what replaced it, the segregated AT&T Office@Hand / Verizon API host, and RingCentral's per-API-group rate limits.

[View SKILL.md](/skills/ringcentral-oauth-app/SKILL.md "View the raw SKILL.md file")

### Rippling OAuth Credentials

 OAuth2 app

Establishes how a Rippling OAuth 2.0 client ID and secret is actually obtained — not from a self-serve developer console but from an App Shop partner application that Rippling approves by hand, after which credentials appear inside a partner company's app listing (sandbox pair first, production pair only after beta approval) — and covers the two API generations (legacy V1 vs the current REST API), the scope catalog and its public/private split, the install-not-consent flow, redirect URLs, token and refresh lifetimes, rate limits, test companies, and a symptom-to-cause table.

[View SKILL.md](/skills/rippling-oauth-app/SKILL.md "View the raw SKILL.md file")

### Sage Accounting OAuth2 App Registration

 OAuth2 app

Creates or signs in to a Sage App Registry (developer self-service) account and registers a Sage Accounting app to obtain OAuth2 client ID and client secret — covering the UK/IE/CA country routing that decides which authorization server a customer hits, the coarse readonly / full\_access scope pair, the X-Business header that picks which of a customer's businesses you read, five-minute access tokens with single-use rotating refresh tokens that die after 31 days, and the Marketplace validation call.

[View SKILL.md](/skills/sage-accounting-oauth-app/SKILL.md "View the raw SKILL.md file")

### Sage Intacct OAuth 2.0 App Registration

 OAuth2 app

Registers a Sage Intacct application in the Sage developer console and obtains OAuth 2.0 client ID and client secret for a platform that connects many customers' Intacct companies — covering the Web Services license (sender ID and sender password) that is a prerequisite to registering at all, the immutable Production/Non-production client scope, the per-customer Web Services subscription and sender-ID authorization without which a valid token still fails, the single offline\_access scope, entity context in multi-entity companies, the revoke blast radius, and a safe credential handoff.

[View SKILL.md](/skills/sage-intacct-oauth-app/SKILL.md "View the raw SKILL.md file")

### Salesforce OAuth2 App Registration

 OAuth2 app

Creates a Salesforce Developer Edition org and registers an External Client App (the successor to Connected Apps) to obtain OAuth2 consumer key and consumer secret — with callback URLs, scopes, the mandatory PKCE / refresh-token-rotation / TTL / IP-binding controls, the uninstalled-app restriction, and a safe credential handoff.

[View SKILL.md](/skills/salesforce-oauth-app/SKILL.md "View the raw SKILL.md file")

### ServiceNow OAuth2 App Registration

 OAuth2 app

Produces working ServiceNow OAuth 2.0 credentials — an OAuth application registry entry, redirect URL, client ID and client secret — for a platform that connects many customers' ServiceNow instances. Covers the fact that decides the whole shape of the task: the registry lives inside each customer's own instance, so every customer generates their own client ID and secret and there is no central or shared ServiceNow OAuth client to obtain.

[View SKILL.md](/skills/servicenow-oauth-app/SKILL.md "View the raw SKILL.md file")

### Shopify OAuth2 App Registration

 OAuth2 app

Creates or signs in to a Shopify partner/developer organization and registers a Shopify app to obtain OAuth2 client ID and client secret — with the right app type and distribution, redirect URLs, access scopes, protected customer data approval, offline access tokens, HMAC verification, the mandatory compliance webhooks, and a safe credential handoff.

[View SKILL.md](/skills/shopify-oauth-app/SKILL.md "View the raw SKILL.md file")

### Slack OAuth2 App Registration

 OAuth2 app

Creates a Slack app and obtains OAuth2 client ID and client secret — with the right redirect URLs, bot vs user token scopes, public distribution, and a safe credential handoff.

[View SKILL.md](/skills/slack-oauth-app/SKILL.md "View the raw SKILL.md file")

### SmartRecruiters API Credentials

 OAuth2 app

Establishes which SmartRecruiters credential a connector actually needs and obtains it — customer-generated SmartToken API keys and customer-generated OAuth Client Credentials (both self-serve, Administrator-only, per-company), the partner-gated General Partner Integration that replaced the now-deprecated Authorization Code flow, and legacy Partner API Keys — with the scope catalogue, the System role rule, rate limits and a safe credential handoff.

[View SKILL.md](/skills/smartrecruiters-oauth-app/SKILL.md "View the raw SKILL.md file")

### Stripe OAuth2 App Registration

 OAuth2 app

Registers a Stripe App (the current model) or a legacy Connect OAuth application to obtain Stripe OAuth credentials — client ID, client secret, permissions, redirect URIs, app review, and a safe credential handoff.

[View SKILL.md](/skills/stripe-oauth-app/SKILL.md "View the raw SKILL.md file")

### TikTok OAuth2 App Registration

 OAuth2 app

Registers an app in the TikTok for Developers portal to obtain OAuth2 credentials — the client key (TikTok's name for the client ID) and client secret — for Login Kit, the Display API and the Content Posting API, including sandbox testing, per-scope app review, exact-match redirect URIs, and a safe credential handoff.

[View SKILL.md](/skills/tiktok-oauth-app/SKILL.md "View the raw SKILL.md file")

### TrackerRMS API Credentials

 OAuth2 app

Establishes which TrackerRMS credential a connector actually needs and obtains it — the customer-generated bearer token from Tools & Settings (self-serve, one per database, regenerating kills the old one) or the OAuth 2.0 authorization-code flow whose client secret TrackerRMS issues on request — plus the mandatory token-for-JWT exchange step, the three regional host pairs, the read/write scope pair, rate limits, sandbox access and a safe credential handoff.

[View SKILL.md](/skills/trackerrms-oauth-app/SKILL.md "View the raw SKILL.md file")

### Workable API Credentials

 OAuth2 app

Establishes which Workable credential a connector actually needs and obtains it — customer-generated API access tokens (self-serve, Admin-only, expiring), partner tokens, or partner-gated OAuth 2.0 authorization-code credentials issued by Workable — with the subdomain/account model, the scope list, the member\_id permission trap, rate limits and a safe credential handoff.

[View SKILL.md](/skills/workable-oauth-app/SKILL.md "View the raw SKILL.md file")

### Workday OAuth 2.0 Credentials

 OAuth2 app

Obtains working Workday OAuth 2.0 credentials for a multi-tenant connector — where the client ID and secret are registered by each customer's own Workday administrator inside their own tenant, not by you in a central developer portal. Covers the Register API Client and Register API Client for Integrations tasks, the tenant-specific authorize/token/API hosts, functional-area scopes and the domain security policies underneath them, the Integration System User and security group model that decides whether a valid token returns data or nothing, non-expiring refresh tokens, tenant refreshes, RaaS, and the REST-vs-SOAP fork.

[View SKILL.md](/skills/workday-oauth-app/SKILL.md "View the raw SKILL.md file")

### Xero OAuth2 App Registration

 OAuth2 app

Creates or signs in to a Xero developer account and registers a Xero OAuth2 app to obtain a client ID and client secret — with redirect URIs, the accounting/payroll/files scope families, the tenant (organisation) indirection, the tiered connection ceiling and certification gates, and a safe credential handoff.

[View SKILL.md](/skills/xero-oauth-app/SKILL.md "View the raw SKILL.md file")

### Zendesk OAuth2 App Registration

 OAuth2 app

Registers a Zendesk OAuth client to obtain a client ID (unique identifier) and client secret — covering the one thing that decides whether a multi-tenant connector works at all: a normal Zendesk OAuth client lives inside a single Zendesk account and only authorizes that one subdomain, so connecting many customers requires a global OAuth client, which Zendesk grants by request and not self-serve.

[View SKILL.md](/skills/zendesk-oauth-app/SKILL.md "View the raw SKILL.md file")

### Zoho API Console — shared OAuth2 registration mechanics

 OAuth2 base

The shared Zoho API Console mechanics behind every Zoho OAuth2 registration — Server-based vs Self Client vs JavaScript client types, the multi-data-centre domain model and the Multi DC toggle that lets one client ID serve every region, the per-DC client secret, the location / accounts-server parameters on the callback, redirect-URI rules, the comma-delimited scope.operation grammar, access\_type=offline plus prompt=consent, the Zoho-oauthtoken header, the 20-refresh-tokens-per-user cap that silently revokes the oldest connection, and rate limits as a per-organization concept. Read this first when registering any Zoho OAuth client; the product skills (Zoho CRM, Zoho Books, Zoho Recruit) build on it and cover only what their product adds. Use directly when the task is a plain Zoho OAuth client with no particular Zoho product named.

[View SKILL.md](/skills/zoho-api-console-oauth/SKILL.md "View the raw SKILL.md file")

### Zoho Books OAuth2 App Registration

 OAuth2 app

The Zoho Books layer on top of the shared zoho-api-console-oauth skill — the Books scope families and the absence of a documented full-access scope, the organization\_id parameter required on every single API call and the two ways to discover it, why a multi-organization customer breaks a connector that picks the first one, the country-edition model that gates whole endpoint families and cannot be changed after signup, the per-organization request and concurrency limits, and the Books / Invoice / Inventory surface split where three products share one data model but not one scope namespace.

[View SKILL.md](/skills/zoho-books-oauth-app/SKILL.md "View the raw SKILL.md file")

### Zoho CRM OAuth2 App Registration

 OAuth2 app

The Zoho CRM layer on top of the shared zoho-api-console-oauth skill — the CRM scope families (modules, settings, users, org, bulk, coql, notifications) and the two-level module scope grammar, standard versus custom modules and why the module list must be discovered at run time, the v2-to-v8 API version ladder and what the version in your URL actually changes, the Production / Sandbox / Developer environment split that makes every token organization-specific, and the credit-and-concurrency limit model that belongs to the customer's org rather than to your client.

[View SKILL.md](/skills/zoho-crm-oauth-app/SKILL.md "View the raw SKILL.md file")

### Zoho People OAuth2 App Registration

 OAuth2 app

The Zoho People layer on top of the shared zoho-api-console-oauth skill — the forms/record data model where employee data lives in customer-configured forms addressed by formLinkName, so a single forms scope reaches every form and what it actually returns depends on the customer's configuration and the authorizing user's role; the seven documented scope families and the two more that exist only on endpoint pages; the three co-existing API generations (legacy forms, v2 leavetracker, v3) and the /people/api/ versus /api/ path split; the people.zoho.\* product hosts that api\_domain does not give you; the organization date format that every date parameter is expressed in; and the per-endpoint threshold-and-lock rate model that has nothing to do with CRM credits.

[View SKILL.md](/skills/zoho-people-oauth-app/SKILL.md "View the raw SKILL.md file")

### Zoho Recruit OAuth2 App Registration

 OAuth2 app

The Zoho Recruit layer on top of the shared zoho-api-console-oauth skill — the Recruit scope families and the singular-versus-plural module-name inconsistency that makes scope strings fail, the candidate / job-opening / application / interview module model and the Staffing Agency versus Corporate HR edition split that decides which modules exist at all, the dedicated recruit.zoho.\* API host that disagrees with the api\_domain the token response returns, the five-refresh-tokens-per-minute ceiling, and the credit model whose concurrency limit is counted per user rather than per organization.

[View SKILL.md](/skills/zoho-recruit-oauth-app/SKILL.md "View the raw SKILL.md file")

### Zoom OAuth2 App Registration

 OAuth2 app

Creates or signs in to a Zoom developer-enabled account and registers a General (OAuth) app on the Zoom App Marketplace to obtain client ID and client secret — with the OAuth allow list, admin-managed vs user-managed choice, granular scopes, the separate development and production credential pairs, the deauthorization endpoint requirement, the private/beta install caps, and Marketplace review.

[View SKILL.md](/skills/zoom-oauth-app/SKILL.md "View the raw SKILL.md file")

### Zoom Phone OAuth2 App Registration

 OAuth2 app

The Zoom Phone layer on top of the shared zoom-oauth-app skill — the Zoom Phone license and account-plan prerequisite that makes every phone endpoint 403 without it, the phone: granular scope family and its admin/user split, the call-log APIs sunset in June 2025 and the call-history APIs that replaced them, recording and transcript scopes, and Zoom Phone's own rate-limit table.

[View SKILL.md](/skills/zoom-phone-oauth-app/SKILL.md "View the raw SKILL.md file")
