OAuth apps for the Voholabs Studio API
An OAuth app lets your product act for other Studio users without asking for their API keys. Create the app in Settings › Connect Agent › Apps, send users to studio.voholabs.com/oauth/authorize, then exchange the returned code at /api/oauth/token for a pos_ token that works with the API, MCP and CLI.
Use an OAuth app when your product needs to post for people who have their own Studio accounts. To automate your own workspace, your API key is simpler.
How do I create an OAuth app?#
- In Studio, open Settings › Connect Agent and choose the Apps tab.
- Fill in App Name (up to 100 characters), an optional Description (up to 500) and Profile Picture, and the Redirect URL your users return to.
- Create the app. Studio shows your client ID, which starts with
pca_, and your client secret, which starts withpcs_. - Copy the client secret straight away. Studio only shows it once.
How does a user authorise my app?#
-
Send the user to the consent page:
Text https://studio.voholabs.com/oauth/authorize?client_id=YOUR_CLIENT_ID&response_type=code&state=RANDOM_STATEresponse_typemust becode. Usestateto tie the answer to the user's session. -
The user signs in to Studio if needed, sees your app's name, description and picture, and approves or denies.
-
Studio sends the user back to your redirect URL. On approval it carries
?code=...&state=...; on denial?error=access_denied&state=.... -
Exchange the code within 10 minutes, from your server:
Terminal curl https://studio.voholabs.com/api/oauth/token \ -H "Content-Type: application/json" \ -d '{ "grant_type": "authorization_code", "code": "THE_CODE", "client_id": "YOUR_CLIENT_ID", "client_secret": "YOUR_CLIENT_SECRET" }' -
Store the
access_tokenfrom the response. It starts withpos_. The response also returns the workspace ID asid, andtoken_typeisbearer.
How do I call the API with a token?#
Use the token exactly where an API key would go.
- Public API: send it on its own in the header,
Authorization: pos_.... See the public API. - MCP server: send
Authorization: Bearer pos_.... See the MCP server. - CLI: set
VOHOLABS_API_KEYto the token. See the CLI.
How does a user disconnect my app?#
In Settings › Approved Apps, which lists the applications they have authorised. Revoking stops the token immediately, so handle HTTP 401 "Invalid OAuth token" by asking the user to authorise again.
Frequently asked questions
- Do OAuth tokens expire?
No. A
pos_token stays valid until the user revokes your app in Settings › Approved Apps. There is no refresh token to manage.- Can I ask for limited permissions?
No. The flow has no scopes. A token can do whatever the user's API key can do in the workspace they chose.
- How many OAuth apps can a workspace have?
One. Only admins of the workspace can create, edit or delete it.
- I lost my client secret. What now?
The secret is only shown when you create or rotate it. Rotate it in Settings › Connect Agent › Apps and update your server with the new one.