Application registration
Public and confidential clients, exact redirects and credential lifecycle.
Delete a disabled app
App management is available only to Business accounts. Disable the app before deleting it in the console or through DELETE /v1/integrations/apps/{client_id}. An active app returns 409. Deletion is permanent and removes connections, OAuth credentials, webhooks and the icon.
Create an app in the console
Sign in with a Business account and open Developer in the Pura console, choose a recognizable name, upload a PNG icon and register one to ten HTTPS redirects. POST /v1/integrations/apps requires the owner’s account session, not an inference token.
curl https://ai.puradigital.it/v1/integrations/apps \
-H "Authorization: Bearer $PURA_CONSOLE_TOKEN" \
-F 'name=Example SaaS' \
-F 'redirect_uris=["https://your-app.example/pura/callback"]' \
-F 'confidential=true' \
-F 'icon=@app-icon.png;type=image/png'Choose a client type
Public: token_endpoint_auth_method=none, no secret, PKCE required. Confidential: token_endpoint_auth_method=client_secret_post, secret sent in the token endpoint form body and kept on the backend. The secret is returned at registration and rotation; it is not recoverable from the app list.
Redirects and environments
The redirect must exactly match a registered URI, including path and query. Wildcards, fragments, embedded credentials and non-HTTPS redirects are rejected. An unknown URI does not receive an error redirect either: Pura returns the error directly.
For development use a dedicated HTTPS callback. Do not share production client secrets with preview environments or browser-delivered code.
Rotation and suspension
Rotation invalidates the previous client secret without revoking existing grants. Keep the new secret in your secret store. Suspension revokes the app’s connections and requires fresh user authorization. Reactivating the app does not automatically restore revoked grants.