Developer Docs Logo

App Setup in the CRM Dashboard

This document walks through creating and configuring a third-party app in the CRM Dashboard, step by step. Do this before writing any integration code - you need the credentials that Developer Configuration generates.


Step 1: Navigate to 3rd Party Apps

  1. Log in to the CRM Dashboard
  2. Navigate to: 3rd Party Apps → Your Apps

Third Party Apps list showing the Yours and Marketplace tabs


Step 2: Create Your App

Click "Create New App". Fill in a name and description for your app, then click "Create New App" to confirm.

Creating a New App form, Name and Description fields

Only Name and Description are required at creation time. All other configuration is done in the next step.


Step 3: Open the App Configuration

After creation, the app appears in your app list. Click the app to open its details page, then click "Developer Configuration" to open Developer Configuration.

App Details page showing the Reinstall and Developer Configuration buttons


Step 4: Fill In Basic App Information

You are now in Developer Configuration, on the Basic Information tab.

Basic Information tab with tab navigation visible

FieldWhat to EnterNotes
App IconA square image representing your appShown on the consent screen, app list, and sidebar
NameShort, descriptive name (e.g. "Telegram Support Bot")Shown on the OAuth consent screen
Short DescriptionOne-line summary of what your app doesShown alongside your app's name in listings
Long DescriptionFull explanation of your app's functionalityUp to 3500 characters; shown on the consent screen and app detail page
App ImagesScreenshots or preview images of your appOptional; see below for format rules

Basic Information form fields, App Icon, Name, Short Description, Long Description, and App Images

App Images rules:

  • Supported file types: png, jpg, jpeg, webp, gif, svg.
  • Upload up to 10 files, max 10MB each.
  • Follow the in-app guidelines link for recommended dimensions and content for App Preview.
FieldWhat to EnterNotes
App Dashboard URLURL of your admin settings pageThe CRM redirects agents here to configure your app
App Menu URLURL shown when users click your app icon in the sidebarOptional

App Dashboard URL and App Menu URL fields

App Credentials

Still on the Basic Information tab, scroll to the App Credentials section. Developer Configuration generates and displays:

  • App ID - internal identifier (used in OAuth URL construction)
  • Client ID - your app's public OAuth identifier
  • Client Secret - your app's OAuth secret; never expose this client-side
  • Signing Secret - used to verify that incoming CRM webhooks are genuine

App Credentials section showing App ID, Client ID, Client Secret, and Signing Secret

Copy all four values and store them in your backend environment variables (CRM_APP_ID, CRM_CLIENT_ID, CRM_CLIENT_SECRET, CRM_CLIENT_SIGNED_KEY).

Keep secrets secret. Never commit them to source control. Both Client Secret and Signing Secret have a Regenerate button, use it if either is compromised.


Step 5: Configure Redirect URLs

Redirect URLs are the HTTPS endpoints on your backend that the CRM will redirect the browser to after an admin authorizes your app. You must configure at least one before you can initiate OAuth flows.

Where to set it: your app → OAuth & Permission tab → Redirect URLs.

OAuth & Permission tab showing Redirect URLs and Permission Scopes

What to add:

https://your-3pa.app/oauth2/crm/callback

Or if you have a separate admin dashboard:

https://your-3pa-dashboard.app/oauth2/crm

Rules:

  • Must be a valid URL with a proper domain and TLD (e.g. https://your-app.com/callback).
  • localhost and bare IP addresses like 127.0.0.1 cannot be registered. The form requires a real domain with a TLD. For local development, use a tunneling tool such as ngrok or Cloudflare Tunnel to expose your local server under a public domain, then register that tunneled URL.
  • Must exactly match the redirect_uri you pass when building the authorization URL.
  • You can register multiple URLs (e.g. your ngrok tunnel for local dev, staging, and production).
  • Wildcards are not supported - register each URL explicitly.

Note: The redirect_uri in the OAuth flow must exactly match one of the registered URLs. Any mismatch causes the OAuth flow to fail with an invalid_request error.


Step 6: Configure Permission Scopes

Scopes define what your app is allowed to do in a workspace. The admin sees these on the consent screen. Request only the scopes you actually need - over-requesting scopes reduces admin trust.

Where to set it: your app → OAuth & Permission tab → Permission Scopes.

To understand which scopes you actually need, you can check the OpenAPI specification, which will show you the available endpoints and their required scopes.

Which scopes you need depends on your integration type. See your integration guide for the list, for example, Customer Chat Integration covers the minimum scopes required for a chat channel third-party app.

What Scopes Look Like to the Admin

When the admin clicks Install, they will see a consent screen listing your requested scopes in plain language. Only select scopes that are clearly necessary - admins regularly abandon installations that request excessive permissions.

Permission Scopes section showing available scopes with checkboxes


Step 7: Configure Interactivity & App Actions (Optional)

The Interactivity & App Actions tab lets your app receive data when agents interact with custom actions, or when automation rules trigger them. This is optional, only configure it if your integration needs to respond to CRM-initiated actions.

Where to set it: your app → Interactivity & App Actions tab.

Interactivity & App Actions tab showing App Action Request URL and App Actions list

App Action Request URL

Set the HTTPS endpoint on your backend that will receive HTTP POST requests when an app action is triggered, either manually by an agent or via an automation rule.

https://your-3pa.app/receive-hook-endpoint

App Actions

App actions extend CRM functionality by giving agents or automation rules a named, triggerable action. Each action has:

FieldDescription
NameDisplay name shown in the CRM (e.g. "Send Message To Slack")
DescriptionWhat the action does
KeyMachine-readable identifier sent in the webhook payload (e.g. message_to_channel)
LocationWhere the action appears in the CRM (e.g. "Automation Rules - Ticket Created")
TypeThe input type - e.g. Dynamic Select for a dropdown populated from your API

Click "Create App Action" to add a new action.

Create App Action form with Name, Description, Key, Location, and Type fields

Select Menus

If any of your app actions use a Dynamic Select type, the CRM needs to know where to fetch the options from. Set the Options Load URL, the CRM will POST to this URL whenever an agent opens a dynamic select menu for your app.

https://your-3pa.app/menu/options

App Actions list and Select Menus section with Options Load URL field


Step 8: Configure Webhook Events (Request URL & Subscriptions)

Webhook event subscriptions tell the CRM where to send notifications when activities occur in a workspace. This is how your third-party app learns about and decides to respond to various activities within the CRM.

Where to set it: your app → Event Subscriptions tab.

Enable Webhook Events

Toggle Enable Webhook Events to on. This activates webhook event delivery to your app.

Event Subscriptions tab with Enable Events toggle off

Event Subscriptions tab with Enable Events toggle on and Request URL field visible

Request URL

This is the HTTPS endpoint on your backend that receives CRM webhook event payloads. The field is labelled Request URL:

https://your-3pa.app/webhooks/crm/events

All subscribed webhook events from all installed workspaces are delivered to this single URL. Each webhook event's data object always includes a workspace_id so you can route to the correct workspace.

Requirements:

  • Must be HTTPS.
  • Must return HTTP 200 within a reasonable timeout (aim for < 5 seconds). Return 200 immediately after queuing the webhook event if your processing is slow.
  • Must be publicly reachable from the CRM servers.

Development tip: Use ngrok or a similar tunnel to expose your local server during development:

ngrok http 8000
# Then set Request URL to https://abc123.ngrok.io/webhooks/crm/events

Choosing Which Webhook Events to Subscribe To

Click "Add User Event" to subscribe to webhook events. Which webhook events you need depends on your integration type. You can check the webhook events documentation to see what webhook events you might need. For a chat channel integration, see Outgoing Message Flow.

Create App Event dialog showing available event types to subscribe to

Event Subscriptions tab after a Conversation Created event has been added


Step 9: Summary of Credentials to Store

After completing the above steps, you should have the following values stored as environment variables in your third-party app backend:

Environment VariableWhere to Get ItNotes
CRM_APP_IDBasic Information → App CredentialsUsed in authorization URL construction
CRM_CLIENT_IDBasic Information → App CredentialsSent in OAuth token exchange
CRM_CLIENT_SECRETBasic Information → App CredentialsSent in OAuth token exchange; keep server-side only
CRM_CLIENT_SIGNED_KEYBasic Information → App Credentials → Signing SecretUsed to verify X-Data-Signature on incoming CRM webhooks

Step 10: (Optional) Publish Your App

Distribution is covered in depth in Distribution.

Publish App tab showing the contact us option to publish


Full Configuration Checklist

  1. App name and description filled in
  2. App Dashboard URL set (your admin settings page)
  3. All four credentials copied to env vars: App ID, Client ID, Client Secret, Signing Secret
  4. At least one Redirect URL added (matches your OAuth callback endpoint)
  5. Required scopes selected (see your integration guide for the list)
  6. Enable Webhook Events toggled on
  7. Request URL set to your public HTTPS endpoint
  8. Webhook events subscribed (see your integration guide for the list)

Next Step

Once your app is created and you have the credentials, proceed to OAuth Flow to implement the install flow on your backend.

On this page