OAuth proxy returning 403 on /api/v2/integrations/actions

Okay, so the proxy is meant to handle the TOKEN exchange so the frontend doesn’t expose secrets.
SvelteKit server route is doing the fetch, but it’s FAILING.
I’m calling GET /api/v2/integrations/actions to populate the widget.
It’s a basic permissions issue normally, but the client ID has the right roles.

{
 "status": 403,
 "errorCode": "Forbidden",
 "message": "You do not have permission to access this resource."
}

This happens if the SCOPE is missing from the CLIENT_ID setup! You need to check the OAUTH_GRANT and make sure the permission is linked to the correct ROLE! :rocket:

{
 "name": "ProxyClient",
 "grantTypes": ["client_credentials"],
 "scopes": ["integrations:action:view"]
}
1 Like