Skip to content

Synq is pre-launch. Early access is by request. Ask for early access

Apps

Every app, every API, exact scopes.

Register each app your team ships with its type and exact redirect URIs, and each of your APIs with its scopes. You decide which app may ask for which scope of which API.

Built

Five kinds of app

Web apps, single-page apps, native apps, machine-to-machine services and agents. The type sets what each may do.

Tokens for one API

An access token asked for an API is a JWT meant for that API alone, living 5 to 15 minutes, as the API says.

Scopes never trimmed

An app asking for a scope it may not have is refused, never silently given less.

Secrets shown once

Confidential apps get a secret that is shown once, stored hashed, and rotated with an overlap so nothing breaks.

MCP hosts and other apps that register themselves

Apps that aren’t yours, such as MCP hosts, can register themselves. They are public, ask for consent, reach only the APIs you open to them, and are removed after 30 days unused.

Read next

Want it before it is finished?

Tell us what you are building and which sign-in your users need.