Skip to content

Forge OAuth 2.0 (3LO) for external APIs: scopes, storage, Marketplace

October 2, 2026

about-workspace

When a Forge app must call HubSpot, Exact, or your own API as a named customer tenant, you usually need OAuth 2.0 (3LO)—user/admin consent—not only Forge app scopes for Jira.

What 3LO buys you

  • Per-install tokens for an external provider.
  • Revocable access when a customer uninstalls.
  • Clearer Marketplace privacy story (“we access X on your behalf”).

Implementation guardrails

  • Store refresh tokens encrypted; never in issue fields.
  • Least-privilege scopes; document each scope in the privacy policy.
  • Handle consent denial gracefully in admin UI.
  • Rotate client secrets with a dual-key window.

Marketplace review expectations

Reviewers look for matching scopes, egress hosts, and honest data-use copy. If your remote backend holds tokens, say so—do not imply “Forge-only, we never see data” while refresh tokens live on your VPS.

Need this built? HostHob ships production integrations and Marketplace-ready apps from Rotterdam. See our services or Implement Forge 3LO the right way.

Need help shipping your platform?

HostHob engineers WordPress, Laravel, and enterprise stacks with measurable outcomes.

Start a Project