OAuth provider redirect callback
Public endpoint the OAuth provider redirects to with code and state. Verifies signed state, exchanges the code, persists credentials, and redirects to the SPA. No bearer auth.
Authorizations
Authorization: Bearer <token>. Token types resolve to the same scoped credential: a user-generated API key (casa_…, from Account settings — recommended for machines and MCP clients), a WorkOS AuthKit session JWT (the web app; org and role come from verified token claims), or a static token. API keys are group-scoped, optionally pinned to one property at creation. MCP OAuth connector tokens authenticate the MCP server only and are rejected on these REST routes.
Response
Redirect to the SPA integrations page (oauth=success or oauth=error).