> ## Documentation Index
> Fetch the complete documentation index at: https://docs.attio.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authorize

<h4 style={{borderBottom:"none"}}>Query Parameters</h4>

<ParamField path="client_id" type="string" required>
  Your app's client ID. You can find this in your app's settings pages at
  [build.attio.com](https://build.attio.com).
</ParamField>

<ParamField path="response_type" type="string" required>
  The response type. This should always be `"code"`.
</ParamField>

<ParamField path="redirect_uri" type="string" required>
  The URL to redirect to after the user authorizes access to your app. This URL must exactly match
  one of the registered redirect URLs in your app's settings pages at
  [build.attio.com](https://build.attio.com).
</ParamField>

<ParamField path="state" type="string">
  A random string to prevent CSRF attacks. Set this when starting the OAuth flow and verify it
  matches when the user is redirected back to your app.
</ParamField>

<ParamField path="token_level" type="string" default="workspace">
  The [level](/rest-api/guides/authentication#token-levels) of the access token, either
  `"workspace"` or `"user"`. A `"user"` token requires `code_challenge` and `code_challenge_method`.
</ParamField>

<ParamField path="code_challenge" type="string">
  A [PKCE](https://datatracker.ietf.org/doc/html/rfc7636) code challenge: the base64url-encoded
  SHA-256 hash of a code verifier. Required when `token_level` is `"user"`. Pass the code verifier
  as `code_verifier` when you exchange the code at the [token endpoint](/docs/oauth/token).
</ParamField>

<ParamField path="code_challenge_method" type="string">
  The PKCE code challenge method. This should always be `"S256"`. Required when `code_challenge` is
  set.
</ParamField>

<h4 style={{borderBottom:"none"}}>Response</h4>

<ResponseField name="302" type="Redirect">
  After the user approves the connection, they are redirected to the `redirect_uri` with a `code`
  query parameter. If provided, the original `state` is also included.
</ResponseField>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.