Workspace OAuth / SSO Documentation

HSP Support CMS provides OAuth-style application registration for approved workspaces. Applications must be reviewed before production access is enabled. Each application uses a unique client ID, verified redirect URLs, and permission-based scopes.

Overview

Workspace OAuth / SSO helps approved business systems connect users to the support CMS through a controlled sign-in workflow. Users can access support tickets, billing inquiries, account assistance, and policy reports from one secure support portal.

Integration steps

  1. Apply for workspace access
  2. Create an OAuth / SSO application
  3. Register verified redirect URLs
  4. Request permission-based scopes
  5. Wait for admin approval
  6. Use the assigned client_id in the authorized login flow once enabled

Application requirements

  • Application name
  • Company name
  • Website URL
  • Contact email
  • Redirect URI
  • Privacy Policy URL
  • Terms URL
  • Requested scopes

Client ID

Each approved application receives a unique client_id. The client_id identifies the workspace application during support portal login requests. Client IDs are public identifiers and should not be treated as secrets.

hsp_live_xxxxxxxxxxxxx
hsp_test_xxxxxxxxxxxxx

Redirect URI rules

  • Production redirect URIs must use HTTPS.
  • Sandbox may allow localhost for development.
  • Redirect URIs must be registered before use.
  • Unregistered redirect URIs should be rejected.
  • Wildcard redirect URIs are not allowed.

Scopes

  • profile:read Read basic user profile information.
  • email:read Read verified user email address.
  • support:tickets:read Read support ticket history where permitted.
  • support:tickets:write Create and update support tickets where permitted.
  • billing:inquiries:read Read billing inquiry status where permitted.

Environments

Applications may use sandbox or production mode. Production access requires manual review and approval.

Security requirements

  • Use HTTPS in production.
  • Keep secrets private.
  • Register exact redirect URLs.
  • Use state parameter for CSRF protection when authorization flow is enabled.
  • Do not expose tokens in frontend logs.
  • Review workspace access regularly.

Current availability

OAuth-style workspace access is available for approved workspaces and may require manual review before activation. Some authorization endpoints may be available only for enabled applications and approved environments. This is a developer preview full public OAuth provider functionality is not claimed.