Assinafy OAuth PKCE integration — technical review before publication
Status: Open · Asked by Bill Madeira on · 0 views
We are building an Assinafy integration using Pabbly's native OAuth 2.0 Authorization Code with PKCE S256 and preparing it for publication. Could the integration team confirm the following?
1. Does the native callback validate state and the authorization-response iss against the configured issuer? Assinafy's issuer is https://auth.assinafy.com.br.
2. Are refreshes serialized per connection, and are both rotated tokens persisted atomically? Assinafy rotates refresh tokens and invalidates a token family on reuse of an old refresh token.
3. What supported test method verifies expired authorization-code recovery and revoked connections? Assinafy authorization codes expire after 60 seconds.
4. Is there a controlled test method for 429/backoff and transport timeouts, including prevention of automatic retries for writes whose outcome is unknown?
5. The optional Custom API Request (Beta) reports Allowed domains: [none]. Where is its allowlist configured, or should it remain hidden for an initial release?
6. The developer FAQ describes Publish App, while the current app UI routes support requests to this forum. What is the current publication-review route, and how can dedicated reviewer access be provided securely?
Please respond with documentation or a supported verification procedure. We can provide app-specific details through your private secure channel if needed; this question does not authorize access to or modification of our account.