Problem
Currently there is no way for third party services to request access to a user's applications via OAuth2. This makes it difficult to build tools or platforms that need to verify bot ownership or display information about bots a user owns without requiring them to manually provide their bot's ID or token
Proposed solution
Introduce a new applications OAuth2 scope that, when granted, allows the requesting service to read basic details about the applications owned by the authenticating user. This would include fields such as the application ID, name, avatar, and description. No sensitive fields like the bot token should ever be exposed
Comments
No comments yet.