Skip to main content

Authorize External Application Access

Applications that access the Agility API must be registered and given an authentication grant. This allows them to operate within Agility on your behalf with your existing Role and Project Memberships.

Security considerations: Authorized applications act with your permissions. Only authorize applications you trust. Review and revoke access for applications you no longer use. Administrators create public applications; individual members create personal applications.

Application types:

  • Public application: Created by an administrator and available for use by anyone within the system
  • Personal application: Created by an individual member for themselves only. Not available to other members.

Member Details page

Access the Applications page​

Click the profile icon on the header and click Applications.

View authorized applications​

The My Personal Applications and My Public Applications sections show applications that already have access to your Agility instance. You can see basic details about each application, download OAuth2 JSON files, or revoke application access.

Generate application access grants​

  1. Click the profile icon on the header and click Applications.
  2. In Step 1, select an application type:
    • Choose Public to use an application setup by your Agility administrator for everyone.
    • Choose Personal to create an application for your personal use only.
  3. In Step 2:
    • If you selected Public, select an application from the drop-down list.
    • If you selected Personal, enter the application name.
  4. Click Add.

Troubleshooting​

Why don't I see any public applications in the dropdown?​

Public application availability depends on administrator setup:

  • No applications configured: Your administrator hasn't created any public applications yet. Contact your administrator to request setup for the integration you need.
  • Permissions: Some public applications may be restricted to specific roles or projects. Verify you have the necessary project memberships.
  • Create personal application: If you need API access immediately, create a personal application instead of waiting for public application setup.

Why does my application keep getting "Access Denied" errors?​

Authorization and permission issues:

  • Token expired: OAuth2 tokens may expire. Revoke the old application access and regenerate a new access grant to get fresh tokens.
  • Insufficient permissions: The application acts with your permissions. If you lack access to certain projects or assets, the application cannot access them either. Contact your administrator to verify your role and project assignments.
  • Application revoked: Someone may have revoked the application's access. Check the Applications page to confirm the application still has an active grant.
  • API configuration: For on-premises installations, the API endpoint may not be configured correctly. Verify the application is using the correct Agility URL.

How do I revoke access for an application I no longer use?​

Security best practice for removing unused access:

  1. Click the profile icon and select Applications.
  2. Locate the application in either My Personal Applications or My Public Applications section.
  3. Click the delete or revoke button next to the application.
  4. Confirm the revocation.

The application will immediately lose access to Agility on your behalf. You can regenerate access later if needed.

What's the difference between downloading OAuth2 JSON and copying tokens?​

Both provide application credentials but in different formats:

  • OAuth2 JSON file: Contains all credentials (client ID, client secret, token endpoint) in a standardized format. Most modern integrations accept JSON files directly. This is the recommended approach.
  • Individual tokens: Some older applications require you to manually copy/paste individual values. Only use this if the application cannot accept JSON files.
  • Security: Treat both as passwords. Never share JSON files or tokens in emails, chat, or public repositories. Store them securely.

Why can't I create a personal application?​

Personal application creation may be restricted:

  • Permissions: Your administrator may have disabled personal application creation for security reasons. Only public applications created by admins are allowed.
  • Account type: Some restricted account types (like read-only guests) cannot create API applications.
  • Request public application: Contact your administrator to create a public application that you and others can use.