# Auth

Instead, our core customers are digital marketing agencies and consultants who: This section explains how to generate a Test Link for a specific app version in the Developer Marketplace and use it to install the app into a...

## Pages in this folder

| Page | Local file | Summary |
| --- | --- | --- |
| Understanding HighLevel’s Go-To-Market Model | [understanding-highlevel-s-go-to-market-model.md](understanding-highlevel-s-go-to-market-model.md) | HighLevel is not a standalone SaaS platform sold directly to end-users. Instead, our core customers are digital marketing agencies and consultants who: |
| Timezone | [timezone.md](timezone.md) | Timezone |
| Step 4: Installing and Testing a Marketplace App | [step-4-installing-and-testing-a-marketplace-app.md](step-4-installing-and-testing-a-marketplace-app.md) | This section explains how to generate a Test Link for a specific app version in the Developer Marketplace and use it to install the app into a specific location/agency account for testing. |
| Step 2: Create a Marketplace App | [step-2-create-a-marketplace-app.md](step-2-create-a-marketplace-app.md) | This section walks you through creating a Marketplace App in HighLevel—from creating the app record in the Developer Portal, to completing your listing, generating OAuth credentials, and installing the app for testing. |
| Start OAuth Flow (Step 1 of 3) | [start-oauth-flow-step-1-of-3.md](start-oauth-flow-step-1-of-3.md) | ## OAuth Connection Flow - Step 1: Initiate OAuth |
| Publishing your App to HighLevel Marketplace | [publishing-your-app-to-highlevel-marketplace.md](publishing-your-app-to-highlevel-marketplace.md) | App review guidelines to make your app public and gain discovery via the HighLevel Platform. |
| One doc tagged with "OAuth 2.0" | [one-doc-tagged-with-oauth-2-0.md](one-doc-tagged-with-oauth-2-0.md) | --------------](https://marketplace.gohighlevel.com/docs/Authorization/Scopes) Here is a list of the scopes you require to access the API Endpoints and Webhook Events. |
| OAuth \ Generic | [oauth-generic.md](oauth-generic.md) | OAuth \ Generic |
| About PKCE[​](https://marketplace.gohighlevel.com/docs/oauth/external-auth/OAuth2#about-pkce "Direct link to About PKCE") | [oauth2.md](oauth2.md) | OAuth v2 is the recommended External Authentication method. HighLevel redirects the user to your authorization page, where they grant access. Your provider returns an authorization code, HighLevel exchanges it for an access/refresh token pair, stores the tokens securely, and includes them in the external calls your app makes (for example, in your Workflow Actions and Triggers). |
| o-auth-2-0 | [o-auth-2-0.md](o-auth-2-0.md) | OAuth 2.0 |
| Important: App Install Webhook[​](https://marketplace.gohighlevel.com/docs/Authorization/OAuth2.0#important-app-install-webhook "Direct link to Important: App Install Webhook") | [oauth2-2.md](oauth2-2.md) | OAuth 2.0 is a standard protocol that authorizes a client application (like a third-party app) to access specific resources on behalf of a user, without sharing the user’s password. It’s widely used for APIs that need secure, delegated access. |
| OAuth 2.0 v3 | [oauth-2-0-v3.md](oauth-2-0-v3.md) | Documentation for OAuth 2.0 API |
| Migrate external authentication connection | [migrate-external-authentication-connection.md](migrate-external-authentication-connection.md) | Migrates an external authentication connection credentials (basic or oauth2) for a specific app and location. This endpoint validates the app configuration, stores credentials safely in CRM's native encrypted storage. With this the lifecycle of the token is managed by CRM. |
| Marketplace App Distribution Model | [marketplace-app-distribution-model.md](marketplace-app-distribution-model.md) | This guide covers the new, simplified Marketplace distribution model and the OAuth flow you’ll need to implement to obtain the correct access tokens. |
| Key Concepts | [key-concepts.md](key-concepts.md) | Before you build and submit your first HighLevel App Marketplace app, it’s important to understand how the HighLevel ecosystem is structured and how Marketplace apps are installed and used. HighLevel is primarily used by agencies who manage multiple sub-accounts (locations) for their clients—often under the agency’s own white-labeled brand—so “who installs” and “who uses” your app can vary by setup. |
| Introduction | [introduction.md](introduction.md) | Welcome to the API documentation. This developer portal is your reference for |
| How to Update Your App | [how-to-update-your-app.md](how-to-update-your-app.md) | This document explains how app versioning and updates work in the HighLevel Marketplace, using simple language and clear steps. It is meant for developers publishing or updating apps. |
| Getting Started | [getting-started.md](getting-started.md) | HighLevel is growing at a rapid scale. We have over 70000+ agencies 600,000+ businesses actively using our product. |
| Get Location where app is installed | [get-location-where-app-is-installed.md](get-location-where-app-is-installed.md) | This API allows you fetch location where app is installed upon |
| Get Location Access Token from Agency Token | [get-location-access-token-from-agency-token.md](get-location-access-token-from-agency-token.md) | This API allows you to generate locationAccessToken from AgencyAccessToken |
| Get Access Token | [get-access-token.md](get-access-token.md) | Use Access Tokens to access CRM resources on behalf of an authenticated location/company. |
| FAQs | [faqs.md](faqs.md) | Here you will find answers to commonly encountered questions. |
| External Authentication | [external-authentication.md](external-authentication.md) | What is External Authentication? |
| External Auth Migration | [external-auth-migration.md](external-auth-migration.md) | External Auth Migration |
| Code Mode | [code-mode.md](code-mode.md) | Code Mode lets you write JavaScript to fully customize an OAuth request when the form builder isn't flexible enough. Instead of filling in fields for the URL, headers, params, and body, you write a short script that builds the request (or the authorization URL), runs it, and returns the result. |
| Changelog | [changelog.md](changelog.md) | 2026-08-10 |
| App Testing Guide | [app-testing-guide.md](app-testing-guide.md) | This guide walks you through testing a Marketplace App in HighLevel using Sandbox (App Test) accounts. It covers how to create and use a test environment, install and validate your app, and verify key behaviors like OAuth, scopes, API calls, webhooks, and workflows. It’s written to be practical and easy to follow, so you can catch issues early, iterate quickly, and confidently ship to production. |
| App Creation Guide | [app-creation-guide.md](app-creation-guide.md) | This guide walks you through creating a Marketplace App in HighLevel, from registering as a developer to setting up OAuth (scopes, redirect URLs, and client keys). It’s written to be practical and easy to follow, so you can build and test quickly, then publish when you’re ready. |
| App Billing Management | [app-billing-management.md](app-billing-management.md) | App Billing Management |
| API Key / Basic Auth | [api-key-basic-auth.md](api-key-basic-auth.md) | Use API Key / Basic Auth when your provider authenticates requests with a username and password, an API key, or other custom credentials sent on each call. During installation, HighLevel collects the credentials you ask for and sends them to your authentication endpoint to verify them. If the endpoint responds with a success status, the install proceeds and the credentials are stored for later use. |
| **Scopes** | [scopes.md](scopes.md) | Here is a list of the scopes you require to access the API Endpoints and Webhook Events. |
| 1.1 Standard / Non-Whitelabel Apps[​](https://marketplace.gohighlevel.com/docs/oauth/AppReviewGuidelines#11-standard--non-whitelabel-apps "Direct link to 1.1 Standard / Non-Whitelabel Apps") | [appreviewguidelines.md](appreviewguidelines.md) | **App review guidelines to make your app public and gain discovery via the HighLevel Platform.** his document outlines the requirements for apps listed in the HighLevel App Marketplace. |
| Example[​](https://marketplace.gohighlevel.com/docs/oauth/Billing#example "Direct link to Example") | [billing.md](billing.md) | This webhook is essential for externally billed apps within our marketplace. |
| configureyourfields | [configureyourfields.md](configureyourfields.md) | **Configure Your Fields** lets you collect custom inputs from the user during installation. |
| App Name[​](https://marketplace.gohighlevel.com/docs/oauth/CreateMarketplaceApp#app-name "Direct link to App Name") | [createmarketplaceapp.md](createmarketplaceapp.md) | This section walks you through creating a Marketplace App in HighLevel—from creating the app record in the Developer Portal, to completing your listing, generating OAuth credentials, and installing th... |
| A real-world example[​](https://marketplace.gohighlevel.com/docs/oauth/ExternalAuthentication#a-real-world-example "Direct link to A real-world example") | [externalauthentication.md](externalauthentication.md) | What is External Authentication?​ External Authentication lets your Marketplace app verify a HighLevel user against **your own system** before the app is installed. |
| FAQs - HighLevel API | [faqs-highlevel-api.md](faqs-highlevel-api.md) | Here you will find answers to commonly encountered questions. > If you are having trouble and cannot find a suitable answer, please reach out to support. |
| Available Version States[​](https://marketplace.gohighlevel.com/docs/oauth/HowToUpdateYourAPP#available-version-states "Direct link to Available Version States") | [howtoupdateyourapp.md](howtoupdateyourapp.md) | This document explains how app versioning and updates work in the HighLevel Marketplace, using simple language and clear steps. |
| Mapping the response fields[​](https://marketplace.gohighlevel.com/docs/oauth/external-auth/MultiAccountSupport#mapping-the-response-fields "Direct link to Mapping the response fields") | [multiaccountsupport.md](multiaccountsupport.md) | This section covers two related capabilities that work for both OAuth 2. |
| o-auth-generic | [o-auth-generic.md](o-auth-generic.md) | Reference page. |
| OAuth 2.0 v3 | [oauth-2-0-v-3.md](oauth-2-0-v-3.md) | Documentation for OAuth 2.0 API |
| OAuth - Generic | [oauth-generic.md](oauth-generic.md) | OAuth - Generic |
| Steps[​](https://marketplace.gohighlevel.com/docs/oauth/SandboxAccount#steps "Direct link to Steps") | [sandboxaccount.md](sandboxaccount.md) | A Sandbox account is a non-production HighLevel environment created for Marketplace developers. |
| Key characteristics[​](https://marketplace.gohighlevel.com/docs/oauth/SandboxPIT#key-characteristics "Direct link to Key characteristics") | [sandboxpit.md](sandboxpit.md) | A **Private Integration Token (PIT)** is a **scoped authentication token** that provides **secure server-to-server** access to **HighLevel APIs**. |