API Overview

The HSP Support CMS API provides endpoints for approved workspace configuration, OAuth-style application registration, support ticket access, billing inquiry workflows, and policy report handling where enabled.

GET /api/oauth/scopes

Returns available OAuth-style permission scopes.

{
  "scopes": [
    { "key": "profile:read", "name": "Read profile", "description": "Read basic user profile information." }
  ]
}

POST /api/oauth/applications

Authenticated workspace owner submits an OAuth / SSO application for review.

{
  "app_name": "Example Workspace",
  "company_name": "Example Company",
  "website_url": "https://example.com",
  "contact_email": "[email protected]",
  "redirect_uri": "https://example.com/auth/callback",
  "requested_scopes": ["profile:read", "email:read"]
}

GET /api/oauth/applications

Returns OAuth / SSO applications owned by the authenticated user.

GET /api/oauth/applications/:id

Returns details for one OAuth / SSO application.

POST /api/oauth/applications/:id/redirect-uris

Adds a verified redirect URI to an application.

DELETE /api/oauth/applications/:id/redirect-uris/:uriId

Removes a redirect URI from an application.

Admin endpoints

  • GET /api/admin/oauth-applications
  • POST /api/admin/oauth-applications/:id/approve
  • POST /api/admin/oauth-applications/:id/reject
  • POST /api/admin/oauth-applications/:id/disable
  • POST /api/admin/oauth-applications/:id/regenerate-secret

Placeholder OAuth endpoints

These endpoints return safe not-enabled responses until a future phase enables authorization flows:

  • GET /oauth/authorize
  • POST /oauth/token
  • GET /oauth/userinfo