Hanzo
OpenapiIntegrations

OAuth return for any connector

The single address every connector's OAuth flow returns to.

GET /v1/integrations/{provider}/callback

Addresshttps://api.hanzo.ai/v1/integrations/{provider}/callback
MethodGET
Operationget_integrations_by_provider_callback
AuthAuthorization: Bearer $HANZO_API_KEY

The single address every connector's OAuth flow returns to. It exchanges the authorization the provider granted, records the connection, and ALWAYS redirects the browser back to the console — on success and on every labeled failure alike, so a user never lands on a raw JSON dead end.

It is public and carries no principal, so the org is taken ONLY from the signed state minted when the flow began; no header is trusted here. That state is single-use and is burned BEFORE the exchange, so one authorization is one attempt and a replayed return fails instead of exchanging twice.

Tokens are sealed into the org's KMS namespace BEFORE the connection row is written, so a failure of the secret store leaves no half-connected integration advertising a credential that was never stored. Token values never appear in the redirect, in a log line or in an error.

One generalization is worth knowing: a GitHub App installation returns an installation identifier instead of an OAuth code, and it is accepted in the code's place so the App model needs no second address.

Request

1 field.

FieldInTypeRequiredDescription
providerpathstringyes

Response

The document declares no response body for this operation. It answers 200 on success and the platform error shape on failure — see Errors.

Examples

hanzo integrations callback <provider>

Integrations API · All Hanzo APIs · Interactive reference

How is this guide?

On this page