OAUTHRELAY / 01
SYSTEM ONLINE
AUTHORIZATION LAYER / ONLINEGITHUB + BITBUCKET / READYSECRETS NEVER RENDEREDOAUTH 2.0 / CALLBACK GATEWAYAUTHORIZATION LAYER / ONLINE

Provider access, without the CMS

One clean OAuth layerfor your repos.

A focused control plane for connecting GitHub and Bitbucket identities to your product. Keep the experience simple for users and the access surface visible for operators.

02provider flows
01admin surface
0tokens in markup
RELAY_STATUS / 200
O2
Provider gateway0/2 connected
GH
GitHubREADY
BB
BitbucketREADY
> callback listenerwaiting for authorization...> token vaultsealed / masked

Built for the handoff

Everything your OAuth page needs.

[ 01 — 03 ]
01

Two provider paths

Give users a clear, branded start point for GitHub or Bitbucket while keeping the callback contract consistent.

/authorize → /callback
02

Operator visibility

See which provider is active, what scopes are requested, and where to rotate credentials from one quiet surface.

access / scope / revoke
03

Safe by default

Tokens are represented as masked values in the interface. Put the real exchange and secret storage behind your server.

secret !== client

The contract

Make access legible.

OAuth should feel like a small moment for the person signing in—and a well-instrumented system for the team operating it.