Set Up a Custom OAuth ProviderBeta
Register a custom OAuth 2.0 provider to easily connect to any vendor from your Haystack Platform pipelines. OAuth providers are available to every workspace in your organization.
About This Task
Choose the custom provider when your vendor exposes standard OAuth 2.0 authorization and token endpoints and is not Microsoft, Google, Slack, or Notion. You enter every URL, scope, and credential yourself.
Prerequisites
- Make sure you meet the prerequisites for Configure External Connections.
- You need the OAuth client ID and client secret, or private key JWT credentials if the provider supports certificate-based clients, from your provider's developer console.
From your provider's developer documentation, collect:
- OAuth client ID and client secret (or private key JWT credentials if the provider supports certificate-based clients)
- Authorization endpoint URL
- Token endpoint URL
- Required scopes (often comma-separated)
- Whether the provider requires PKCE
Register the redirect URI from the Redirect URL field in the Add OAuth Provider dialog with your identity provider. Keep the default unless you embed the connect flow in your own frontend.
The callback is served by the deepset API, not the web app. On deepset Cloud, the default is https://api.cloud.deepset.ai/api/v2/connections/callback. On other deployments, use your organization's API base URL with the path /api/v2/connections/callback.
Register the Provider in Haystack Enterprise Platform
- Click your profile icon and choose Settings.
- Go to Organization and open Integrations.
- In External Connections, click Add OAuth Provider.
- Select Custom.
- Fill in every field:
- Provider Type — a unique slug, for example
acme-internal-idp. - Display Name — the label users see in the UI. Choose a name that will make it easy for users to identify the provider.
- Client ID and authentication credentials.
- Authorization URL and Token URL.
- Scopes — comma-separated list required by your integration.
- Redirect URL — keep the default unless your provider issued a different callback.
- PKCE Required — turn on if the provider rejects requests without PKCE. To learn more about PKCE, see Proof Key for Code Exchange (PKCE).
- Provider Type — a unique slug, for example
- Click Create.
What To Do Next
Was this page helpful?