Developer docs

Integrate with Connect Hub

Register your application once in the console. From then on your users click “Connect Gmail” (or Facebook, Instagram, Google Business Profile) inside your product, authorize through Connect Hub, and your app calls provider APIs with a Hub access token. Provider refresh tokens never leave the Hub.

1. Send the user to Connect Hub

Your app never talks to Google or Meta directly. Request capabilities, not raw provider scopes.

https://connect.ivanshigo.com/api/public/oauth/authorize
  ?client_id=YOUR_CLIENT_ID
  &redirect_uri=https://yourapp.com/oauth/callback
  &response_type=code
  &provider=google
  &capabilities=google.gmail.send
  &state=RANDOM_STATE
  &code_challenge=BASE64URL_SHA256_OF_VERIFIER
  &code_challenge_method=S256

2. Exchange the Hub code for a Hub access token

The code is single-use and short-lived. PKCE is verified server-side.

curl -X POST https://connect.ivanshigo.com/api/public/oauth/token \
  -H 'content-type: application/json' \
  -d '{
    "grant_type": "authorization_code",
    "code": "HUB_CODE",
    "redirect_uri": "https://yourapp.com/oauth/callback",
    "client_id": "YOUR_CLIENT_ID",
    "client_secret": "YOUR_CLIENT_SECRET",
    "code_verifier": "YOUR_VERIFIER"
  }'

3. Inspect the connection and its assets

Returns non-sensitive metadata only — never a provider token.

curl https://connect.ivanshigo.com/api/v1/connection -H 'authorization: Bearer HUB_ACCESS_TOKEN'
curl https://connect.ivanshigo.com/api/v1/assets -H 'authorization: Bearer HUB_ACCESS_TOKEN'

4. Send a real Gmail message

Requires the google.gmail.send capability on the grant.

curl -X POST https://connect.ivanshigo.com/api/v1/google/gmail/send \
  -H 'authorization: Bearer HUB_ACCESS_TOKEN' \
  -H 'content-type: application/json' \
  -d '{ "to": "someone@example.com", "subject": "Hello", "body": "Sent via Connect Hub" }'

5. Publish to a Facebook Page or Instagram

Page tokens are fetched on demand inside the Hub and never persisted.

curl -X POST https://connect.ivanshigo.com/api/v1/meta/facebook/page/publish \
  -H 'authorization: Bearer HUB_ACCESS_TOKEN' \
  -H 'content-type: application/json' \
  -d '{ "page_id": "PAGE_ID", "message": "Hello from Connect Hub" }'

curl -X POST https://connect.ivanshigo.com/api/v1/meta/instagram/publish \
  -H 'authorization: Bearer HUB_ACCESS_TOKEN' \
  -H 'content-type: application/json' \
  -d '{ "ig_user_id": "IG_ID", "image_url": "https://example.com/a.jpg", "caption": "Hi" }'

6. Google Business Profile

Locations, reviews, replies and local posts share the same capability model.

curl https://connect.ivanshigo.com/api/v1/google/business/locations -H 'authorization: Bearer HUB_ACCESS_TOKEN'
curl 'https://connect.ivanshigo.com/api/v1/google/business/reviews?location=LOCATION_NAME' -H 'authorization: Bearer HUB_ACCESS_TOKEN'
curl -X POST https://connect.ivanshigo.com/api/v1/google/business/reviews/reply \
  -H 'authorization: Bearer HUB_ACCESS_TOKEN' -H 'content-type: application/json' \
  -d '{ "review": "REVIEW_NAME", "comment": "Thank you!" }'

Guarantees

  • Provider access and refresh tokens are AES-256-GCM encrypted at rest.
  • Hub access tokens are scoped to a single grant and its immutable capability set.
  • Capability sets cannot be widened after consent; users can revoke at any time.
  • Every gateway call is audited with sanitized detail — never credentials.