Connecting apps
Listing, creating, revoking and approving apps connected to your organisation.
An integration is another app that can read your organisation's data in Supporter Club, such as an AI assistant or a tool your developer builds. This page covers the Integrations screen, creating an integration for a developer, revoking one, and the screen you see when an app asks for access. For the technical details a developer needs, see Integrations, OAuth and scopes. If the app is an AI assistant that connects through MCP (Model Context Protocol, the standard many AI assistants use to connect to other systems), also send your developer Connecting an AI agent (MCP).
The Integrations list
Click Integrations in the sidebar, outside any club.
The list shows every app connected to your organisation, in name order. That includes integrations created on this screen and apps that registered themselves, such as AI assistants. An app that registered itself without giving a name is listed as "MCP Client".
| Column | What it shows |
|---|---|
| Name | The integration's name. |
| Scopes | The permissions the integration can ask for. Empty if none were set, in which case the integration can ask for any permission. |
| Last used | When one of the integration's tokens that has not been revoked was last used. Shows "Never" if none has been used, or once all its tokens are revoked. |
| Active tokens | How many access tokens the integration holds that have not been revoked. Expired tokens are counted until they are revoked. |
Each row ends with Revoke if the integration has tokens that have not been revoked, or Delete if it has none.
If nothing is connected yet, the list shows "No integrations yet."
Creating an integration
Create an integration when a developer asks you for credentials to connect their app. Ask the developer which redirect addresses and permissions they need before you start.
- Go to Integrations and click New integration.
- Under Integration details, fill in:
- Name: a label that tells you what the integration is.
- Redirect URI: the address the developer gives you, where people are sent back after they approve the app. Its hint says "Separate multiple URIs with a newline.", but the field is a single line, so you can't start a new line in it. To enter more than one address, separate them with a space.
- Confidential client: on by default. Leave it on if the developer's app runs on a server and can keep a secret. Turn it off if the developer tells you their app can't keep a secret, for example an app installed on a phone or computer.
- The permissions: tick each one the integration needs. The choices are View API documentation, View organisation details, View clubs, View club memberships and View donations. If you tick none, the integration isn't limited to these: it can ask for any permission Supporter Club has, including ones not offered here.
- Click Create integration.
A redirect address that starts with http:// must point to the developer's own computer (an address such as http://127.0.0.1 or http://localhost). Any other http:// address is refused: the integration isn't created, and the Redirect URI field is marked with an error. Addresses that start with https://, and addresses that use an app's own scheme (as some apps installed on a phone or computer do), are accepted.
Copying the credentials
The Integration created screen shows the Client ID and the Client secret. It shows both whether or not the integration is a confidential client.
The client secret is shown only once. Copy both and send them to your developer securely before you leave the screen. Click Back to integrations when you're done.
If the secret is lost, you can't see it again. Create a new integration to get new credentials, and revoke the old one.
Revoking an integration
Revoking stops the access an integration has now.
- Go to Integrations.
- Click Revoke on the integration's row.
- The Revoke integration screen asks "Are you sure you want to revoke access for" the integration. Click Revoke integration.
Every token the integration holds is revoked straight away. Any app using those tokens loses access.
If the integration has no tokens left, its row shows Delete instead. Clicking Delete and confirming "Delete integration?" also only revokes tokens.
Neither action removes the integration or its credentials:
- The integration stays in the list.
- Its client ID and client secret still work. The app can get a new token with them straight away, without anyone approving it: a confidential client uses its client ID and secret, and a non-confidential one its client ID alone. It can also get a new token if someone approves it again.
The revoke screen says the integration "will lose access to your organisation". It loses only the access it has at that moment. To stop an app for good, also ask its developer to stop using the integration's credentials.
Approving an app
Not every app goes through this screen: an app can also get access with its own credentials, without anyone approving it (see Revoking an integration). When an app asks to connect to your organisation through this screen, the person connecting it sees a screen headed "Authorize" followed by the app's name. It says the app "will be able to access" your organisation "on your behalf, with the following permissions:", followed by the list of permissions it asks for.
- Click Authorize to give the app access to every permission listed. You can't untick any of them.
- Click Deny to refuse.
The person approving must be signed in to your organisation. Anyone who can sign in can approve, not only administrators: donors and supporters who sign in, for example to their membership page, can approve too. If they are not signed in, they are sent to the sign-in screen instead. The login link emailed to them does not bring them back to this screen, so once they are signed in they need to start connecting the app again. See Signing in.
Organisation settings — account, representative, disclosure, mission
The organisation Settings tabs, your account details, default membership options, the public contact form and your own account.
Integrations, OAuth and scopes
How an app gets an OAuth access token for your organisation, which scopes exist, and how apps can register themselves.