Integrations & Automation

OAuth

OAuth is an open standard that lets you give an app limited access to your account on another service without sharing your password.

Updated Sep 27, 2026
TL;DR

The consent flow behind every “Connect your LinkedIn account” button: the app gets a token with specific permissions, never your password.

Key Points

  • ✓OAuth 2.0 lets a user grant an app scoped access to an account without sharing a password
  • ✓The app receives an access token, often with a refresh token, instead of credentials
  • ✓LinkedIn access tokens last 60 days; the authorization code is valid for 30 minutes
  • ✓The MCP authorization spec builds on OAuth 2.1 and requires PKCE

OAuth is an open standard that lets you give an app limited access to your account on another service without sharing your password. OAuth 2.0 is defined in RFC 6749. 1 When a tool asks you to “Connect your LinkedIn account”, it is using OAuth.

How the OAuth flow works

  1. The app sends you to the service’s own login and consent page.
  2. You see which permissions (scopes) the app wants and approve them.
  3. The service sends the app a short-lived authorization code.
  4. The app exchanges that code for an access token, and often a refresh token.
  5. The app uses the token to call the API on your behalf.

LinkedIn is a typical example: the authorization code is valid for 30 minutes, and access tokens are currently issued with a 60-day lifespan. 2

Why OAuth is safer than passwords

  • The app never sees your password.
  • Access is limited to the scopes you approved.
  • You can revoke one app without changing your password.
  • Tokens expire, so a leaked token stops working on its own.

Apps that cannot keep a secret, such as mobile or desktop apps, add PKCE: a one-time secret pair that stops a stolen authorization code from being redeemed by someone else. 3

OAuth for AI agents

AI assistants now connect to tools the same way. The Model Context Protocol authorization spec is based on OAuth 2.1, requires PKCE and recommends dynamic client registration, so an agent can connect to a new MCP server in the browser without manual setup. 4 See OAuth for agents for more.

OAuth in Publora

You connect each social account once, through that network’s own OAuth screen in the Publora dashboard. Publora keeps the tokens, so your code and your agents work with Publora instead of with each network’s tokens. The Publora MCP server also supports OAuth 2.1 with dynamic client registration and PKCE, so Claude, ChatGPT, Cursor and other clients can connect in the browser. 5

Publora and OAuth

The Publora API and MCP server publish and schedule posts to 10 networks from your own code or from AI assistants like Claude, ChatGPT and Cursor.

See the Publora API →

Related Terms

  • API

    An API (Application Programming Interface) is a set of rules that enables software applications to communicate and exchange data, allowing social media platforms to integrate with third-party marketing tools.

  • API Key

    An API key is a secret string that identifies the app or person calling an API. It is sent with every request so the service knows who is asking.

  • Access Token

    An access token is a credential an app sends with API requests to act on your behalf. It is issued through OAuth, limited to specific permissions and set to expire.

  • MCP Server

    MCP Server (Model Context Protocol Server) is a specialized connector that enables AI models to securely access and interact with external marketing tools and data sources in real-time.

  • OAuth for Agents

    OAuth for Agents is an authorization framework enabling AI-powered marketing tools to securely access social media platforms using tokens instead of passwords, allowing automated posting, analytics, and campaign management.

Last updated: