Create a client
Tenant admins create clients in Settings > OAuth clients.- A confidential client runs on a server and can keep a secret. CostGraph shows the client secret a single time, at creation. Rotate it to get a new one.
- A public client, such as a single-page or desktop app, has no secret and sends only its
client_id.
Endpoints
Read every endpoint from the discovery document:/.well-known/oauth-authorization-server.
Sign in
CostGraph uses the authorization code flow with PKCE. TheS256 method is required.
1
Send the user to CostGraph
Generate a random The user reviews the permissions and approves. CostGraph redirects to your
code_verifier, then derive code_challenge as the base64url SHA-256 of it. Redirect the user to the authorization endpoint:redirect_uri with code and state. The code expires after 1 minute.2
Exchange the code for tokens
Confidential clients authenticate with The response contains
client_secret_basic or client_secret_post. Public clients omit the secret and send client_id in the body.access_token, refresh_token, expires_in, and, when you requested openid, id_token.3
Call CostGraph
Send the access token as a bearer token. The user info endpoint requires the
openid permission and returns 403 without it.Permissions
Request permissions with thescope parameter. The user sees them on the approval screen.
Tokens
The following table lists the lifetime of each credential.
Exchange a refresh token with
grant_type=refresh_token. Each exchange returns a new refresh token, and you must store it. If you present a refresh token that was already exchanged (the previous one), CostGraph signs the user out of your app. Older tokens fail with invalid_grant.
The id_token carries these claims:
Sign out
Revoke a token when the user signs out of your app. Confidential clients authenticate with the client secret:client_id instead:
200.
Users can also remove your app themselves in Settings > Connected apps. If a tenant admin deletes the client, everyone is signed out of it.
Errors
Errors come from three places: the sign-in redirect, the token endpoints, and API calls.Sign-in errors
The following errors are returned to yourredirect_uri as the error query parameter.
Token errors
The token and revocation endpoints return these errors as JSON.API errors
If you call an endpoint that your granted permissions don’t cover, CostGraph returns403 with the message This application is not allowed to access this resource. Request the missing scope and have the user approve it again.
Next steps
MCP
Connect an AI agent to CostGraph.