Connecting apps: OAuth and redirect URLs
Vista Social is a full OAuth 2.0 provider with dynamic client registration. Apps can register themselves with our server and get connected without us issuing credentials by hand, which is how tools like Claude, ChatGPT, Cursor, and VS Code connect on their own.
Because registration is open, we secure the other end of the flow: the redirect URL we send your authorization code to after you approve the connection. That code is a one-time key to your account, so we only deliver it to destinations we recognize. We allow approved platform domains over HTTPS, any localhost or 127.0.0.1 port (so desktop apps, IDEs, and CLI tools work automatically), and a few approved native app schemes.
If an app's redirect URL isn't approved yet
You'll see a Vista Social page titled "This app is not approved yet" instead of a login form. Nothing is sent to the app and no code is issued, so your account and profiles are untouched.
The page shows the app name, client ID, and redirect URL, plus a Contact support button that opens a prefilled email. Send it as is and we'll almost always approve it. It's a configuration change on our side, not a code release, so you can retry the connection shortly after we confirm.
If a connection fails without showing any Vista Social page, the app stopped before opening your browser. Contact support and tell us which app you were connecting.