Skip to main content
For the complete documentation index for agents and LLMs, see llms.txt.

Set Up a Custom OAuth ProviderBeta

Beta
This is coming — this page describes a feature that's still being rolled out and may not be available to you yet.

Register a custom OAuth 2.0 provider to easily connect to any vendor from your Haystack Platform pipelines. OAuth providers are available to every workspace in your organization.


About This Task​

Choose the custom provider when your vendor exposes standard OAuth 2.0 authorization and token endpoints and is not Microsoft, Google, Slack, or Notion. You enter every URL, scope, and credential yourself.

Prerequisites​

  • Make sure you meet the prerequisites for Configure External Connections.
  • You need the OAuth client ID and client secret, or private key JWT credentials if the provider supports certificate-based clients, from your provider's developer console.

From your provider's developer documentation, collect:

  • OAuth client ID and client secret (or private key JWT credentials if the provider supports certificate-based clients)
  • Authorization endpoint URL
  • Token endpoint URL
  • Required scopes (often comma-separated)
  • Whether the provider requires PKCE
Redirect URL

Register the redirect URI from the Redirect URL field in the Add OAuth Provider dialog with your identity provider. Keep the default unless you embed the connect flow in your own frontend.

The callback is served by the deepset API, not the web app. On deepset Cloud, the default is https://api.cloud.deepset.ai/api/v2/connections/callback. On other deployments, use your organization's API base URL with the path /api/v2/connections/callback.

Register the Provider in Haystack Enterprise Platform​

  1. Click your profile icon and choose Settings.
  2. Go to Organization and open Integrations.
  3. In External Connections, click Add OAuth Provider.
  4. Select Custom.
  5. Fill in every field:
    • Provider Type — a unique slug, for example acme-internal-idp.
    • Display Name — the label users see in the UI. Choose a name that will make it easy for users to identify the provider.
    • Client ID and authentication credentials.
    • Authorization URL and Token URL.
    • Scopes — comma-separated list required by your integration.
    • Redirect URL — keep the default unless your provider issued a different callback.
    • PKCE Required — turn on if the provider rejects requests without PKCE. To learn more about PKCE, see Proof Key for Code Exchange (PKCE).
  6. Click Create.

What To Do Next​