Developer docs
Integrate with Connect Hub
Register your application once in the console. From then on your users click “Connect Gmail” (or Facebook, Instagram, Google Business Profile) inside your product, authorize through Connect Hub, and your app calls provider APIs with a Hub access token. Provider refresh tokens never leave the Hub.
1. Send the user to Connect Hub
Your app never talks to Google or Meta directly. Request capabilities, not raw provider scopes.
https://connect.ivanshigo.com/api/public/oauth/authorize ?client_id=YOUR_CLIENT_ID &redirect_uri=https://yourapp.com/oauth/callback &response_type=code &provider=google &capabilities=google.gmail.send &state=RANDOM_STATE &code_challenge=BASE64URL_SHA256_OF_VERIFIER &code_challenge_method=S256
2. Exchange the Hub code for a Hub access token
The code is single-use and short-lived. PKCE is verified server-side.
curl -X POST https://connect.ivanshigo.com/api/public/oauth/token \
-H 'content-type: application/json' \
-d '{
"grant_type": "authorization_code",
"code": "HUB_CODE",
"redirect_uri": "https://yourapp.com/oauth/callback",
"client_id": "YOUR_CLIENT_ID",
"client_secret": "YOUR_CLIENT_SECRET",
"code_verifier": "YOUR_VERIFIER"
}'3. Inspect the connection and its assets
Returns non-sensitive metadata only — never a provider token.
curl https://connect.ivanshigo.com/api/v1/connection -H 'authorization: Bearer HUB_ACCESS_TOKEN' curl https://connect.ivanshigo.com/api/v1/assets -H 'authorization: Bearer HUB_ACCESS_TOKEN'
4. Send a real Gmail message
Requires the google.gmail.send capability on the grant.
curl -X POST https://connect.ivanshigo.com/api/v1/google/gmail/send \
-H 'authorization: Bearer HUB_ACCESS_TOKEN' \
-H 'content-type: application/json' \
-d '{ "to": "someone@example.com", "subject": "Hello", "body": "Sent via Connect Hub" }'5. Publish to a Facebook Page or Instagram
Page tokens are fetched on demand inside the Hub and never persisted.
curl -X POST https://connect.ivanshigo.com/api/v1/meta/facebook/page/publish \
-H 'authorization: Bearer HUB_ACCESS_TOKEN' \
-H 'content-type: application/json' \
-d '{ "page_id": "PAGE_ID", "message": "Hello from Connect Hub" }'
curl -X POST https://connect.ivanshigo.com/api/v1/meta/instagram/publish \
-H 'authorization: Bearer HUB_ACCESS_TOKEN' \
-H 'content-type: application/json' \
-d '{ "ig_user_id": "IG_ID", "image_url": "https://example.com/a.jpg", "caption": "Hi" }'6. Google Business Profile
Locations, reviews, replies and local posts share the same capability model.
curl https://connect.ivanshigo.com/api/v1/google/business/locations -H 'authorization: Bearer HUB_ACCESS_TOKEN'
curl 'https://connect.ivanshigo.com/api/v1/google/business/reviews?location=LOCATION_NAME' -H 'authorization: Bearer HUB_ACCESS_TOKEN'
curl -X POST https://connect.ivanshigo.com/api/v1/google/business/reviews/reply \
-H 'authorization: Bearer HUB_ACCESS_TOKEN' -H 'content-type: application/json' \
-d '{ "review": "REVIEW_NAME", "comment": "Thank you!" }'Guarantees
- Provider access and refresh tokens are AES-256-GCM encrypted at rest.
- Hub access tokens are scoped to a single grant and its immutable capability set.
- Capability sets cannot be widened after consent; users can revoke at any time.
- Every gateway call is audited with sanitized detail — never credentials.