> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Internal links on these pages omit the .md extension. Append .md to a docs page URL, or send an Accept: text/markdown header, to get that page as markdown.

# Set connector scopes

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Sets the app's connection for a connector to exactly the scopes you send, and returns a link to authorize them when that takes a new authorization.

[Start connector connection](/api-reference/start-connector-connection) adds scopes to what the app already has. This endpoint replaces them, so scopes you leave out are dropped once the new authorization completes. Scopes Base44's OAuth app doesn't allow for the connector are dropped without an error, and scopes the connector always needs are added.

Read `already_authorized` and `error` first:
- When you already have an active connection with exactly these scopes and connection values, `already_authorized` is `true` and there's nothing to open. Calling again changes nothing.
- When another collaborator's active connection has exactly these scopes, the call reports `different_user`. To replace it with yours, use Start connector connection with `force_reconnect`.
- Otherwise, including when the scopes or connection values differ from another collaborator's connection, a new authorization starts. Completing it replaces the app's current connection.

To authorize, open `redirect_url` in a browser, approve the scopes within five minutes of the call, and poll [Get connector connection status](/api-reference/get-connector-connection-status) with `connection_id` until it's `ACTIVE` or `FAILED`. The link stops working after 10 minutes. Until the authorization completes, each call starts a new one with a new link.

<Warning>Treat `redirect_url` as a credential. Whoever approves access through it connects their provider account to the app.</Warning>

The call is refused when the workspace has turned off builder connections for the connector. It works only for connectors that Base44's OAuth app can connect: a `connector_mode` of `all` or `shared_only` in [List connectors](/api-reference/list-connectors), with an `auth_method` other than `platform_credentials`.

This is limited to 15 requests a minute per caller. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key belonging to a user with editor access to the app. A read-only key is refused, and workspace API keys are not accepted.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json put /api/apps/{app_id}/external-auth/integrations/{integration_type}
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/external-auth/integrations/{integration_type}:
    put:
      summary: Set connector scopes
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Sets the app's connection for a connector to exactly the scopes you
        send, and returns a link to authorize them when that takes a new
        authorization.


        [Start connector connection](/api-reference/start-connector-connection)
        adds scopes to what the app already has. This endpoint replaces them, so
        scopes you leave out are dropped once the new authorization completes.
        Scopes Base44's OAuth app doesn't allow for the connector are dropped
        without an error, and scopes the connector always needs are added.


        Read `already_authorized` and `error` first:

        - When you already have an active connection with exactly these scopes
        and connection values, `already_authorized` is `true` and there's
        nothing to open. Calling again changes nothing.

        - When another collaborator's active connection has exactly these
        scopes, the call reports `different_user`. To replace it with yours, use
        Start connector connection with `force_reconnect`.

        - Otherwise, including when the scopes or connection values differ from
        another collaborator's connection, a new authorization starts.
        Completing it replaces the app's current connection.


        To authorize, open `redirect_url` in a browser, approve the scopes
        within five minutes of the call, and poll [Get connector connection
        status](/api-reference/get-connector-connection-status) with
        `connection_id` until it's `ACTIVE` or `FAILED`. The link stops working
        after 10 minutes. Until the authorization completes, each call starts a
        new one with a new link.


        <Warning>Treat `redirect_url` as a credential. Whoever approves access
        through it connects their provider account to the app.</Warning>


        The call is refused when the workspace has turned off builder
        connections for the connector. It works only for connectors that
        Base44's OAuth app can connect: a `connector_mode` of `all` or
        `shared_only` in [List connectors](/api-reference/list-connectors), with
        an `auth_method` other than `platform_credentials`.


        This is limited to 15 requests a minute per caller. Some workspaces have
        a different limit.


        <Note>This endpoint accepts a personal API key belonging to a user with
        editor access to the app. A read-only key is refused, and workspace API
        keys are not accepted.</Note>
      operationId: >-
        set_integration_api_apps__app_id__external_auth_integrations__integration_type__put
      parameters:
        - name: integration_type
          in: path
          required: true
          schema:
            anyOf:
              - type: string
                enum:
                  - googlecalendar
                  - google_classroom
                  - googledrive
                  - gmail
                  - googlesheets
                  - googledocs
                  - googleslides
                  - googlebigquery
                  - googlemeet
                  - googletasks
                  - googleads
                  - google_analytics
                  - google_search_console
                  - slack
                  - notion
                  - salesforce
                  - hubspot
                  - linkedin
                  - tiktok
                  - instagram
                  - discord
                  - slackbot
                  - wix
                  - github
                  - gitlab
                  - bamboohr
                  - dropbox
                  - clickup
                  - wrike
                  - box
                  - outlook
                  - linear
                  - airtable
                  - microsoft_teams
                  - share_point
                  - one_drive
                  - typeform
                  - splitwise
                  - hugging_face
                  - calendly
                  - contentful
                  - supabase
                  - snowflake
                  - databricks
                  - quickbooks
                  - square
              - type: string
                maxLength: 80
                minLength: 1
                pattern: ^[a-z0-9_]+$
            description: >-
              ID of the connector, from `integration_type` in [List
              connectors](/api-reference/list-connectors).
            title: Integration Type
          description: >-
            ID of the connector, from `integration_type` in [List
            connectors](/api-reference/list-connectors).
          example: googlecalendar
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app.
            title: App Id
          description: ID of the app.
          example: 6820f3a4e7b91d003c45a1f2
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SetIntegrationRequest'
      responses:
        '200':
          description: >-
            The authorization was started, or the response says why none was
            needed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SetIntegrationResponse'
        '400':
          description: >-
            The connector can't be connected through Base44's OAuth app, or a
            `connection_config` value is missing or invalid.
        '401':
          description: Missing or invalid credentials.
        '402':
          description: The app's workspace plan doesn't include connectors.
        '403':
          description: >-
            You don't have editor access to this app, you're a viewer in its
            workspace, your API key is read-only, or you used a workspace API
            key. Also returned when the workspace has turned off builder
            connections for the connector.
        '404':
          description: App not found, or the connector isn't available to you.
        '409':
          description: >-
            The app's store already uses this provider, so its connector can't
            also be connected, or the app's workspace requires an unlocked SSO
            session.
        '422':
          description: >-
            `integration_type` isn't a valid connector ID, or the body has a
            missing or wrongly typed field.
        '429':
          description: Rate limit reached. Retry later.
components:
  schemas:
    SetIntegrationRequest:
      properties:
        scopes:
          items:
            type: string
          type: array
          title: Scopes
          description: >-
            Every OAuth scope the connection should have. Scopes the app's
            current connection has and this list leaves out are dropped. Send an
            empty list for the connector's default scopes.
          example:
            - https://www.googleapis.com/auth/calendar.readonly
        connection_config:
          anyOf:
            - additionalProperties:
                type: string
              type: object
            - type: 'null'
          title: Connection Config
          description: >-
            Values the connector needs before authorization, keyed by the `name`
            of each field from [Get connector connection
            fields](/api-reference/get-connector-connection-fields). Leave it
            out for connectors that have no fields. Values that differ from the
            saved ones start a new authorization.
          example:
            subdomain: acme-prod
      type: object
      required:
        - scopes
      title: SetIntegrationRequest
      description: The scopes, and any connection values, the app's connection should have.
    SetIntegrationResponse:
      properties:
        redirect_url:
          anyOf:
            - type: string
            - type: 'null'
          title: Redirect Url
          description: >-
            Link to open in a browser so the user can sign in to the provider
            and approve the scopes. It expires after 10 minutes. Treat it as a
            credential. The value is `null` when no authorization was started.
          example: >-
            https://app.base44.com/api/external-auth/connect/3f9c2a7e5b8d4c1fa6e0d2b7c9a1e4f3
        connection_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Connection Id
          description: >-
            ID of the connection being authorized. Pass it to [Get connector
            connection status](/api-reference/get-connector-connection-status).
            When `already_authorized` is `true` it's the existing connection.
            The value is `null` when `error` is set.
          example: base44_6820f3a4e7b91d003c45a1f7
        already_authorized:
          type: boolean
          title: Already Authorized
          description: >-
            Whether you already have an active connection with exactly these
            scopes and connection values (`true`), so there's nothing to open,
            or not (`false`).
          default: false
          example: false
        error:
          anyOf:
            - type: string
            - type: 'null'
          title: Error
          description: >-
            Why no authorization was started, or `null` if one was. Either
            `different_user`, when another collaborator's active connection
            already has exactly these scopes, or `service_unavailable`, when the
            provider can't be reached. Retry later.
          example: different_user
        error_message:
          anyOf:
            - type: string
            - type: 'null'
          title: Error Message
          description: >-
            Readable explanation of `error`. It can be `null` even when `error`
            is set, so branch on `error`.
          example: >-
            Integration googlecalendar is already authorized by a different user
            for this app.
      type: object
      required:
        - redirect_url
        - connection_id
      title: SetIntegrationResponse
      description: >-
        The authorization that sets the app's connection to the requested
        scopes, or why none was needed.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.