Skip to main content
Connect Your AI

Connected Apps: shared AI app authorizations

A connected app is a shared AI application one of your team members has authorized to reach your workspace. Admins manage these authorizations — revoke or reinstate each one — on the Team page…

Written By Christopher Scaminaci

Last updated 3 days ago

A connected app is a shared AI application one of your team members has authorized to reach your workspace. Admins manage these authorizations — revoke or reinstate each one — on the Team page (/team): expand a member's row (the chevron) to see that member's Connected apps, alongside their member credentials and AI sessions. Each row is one app for one member, and revoking it affects only that pairing — not the app for anyone else, and not the member's other connections.

Connected apps used to be a standalone Connected Apps page, then briefly a section of the MCP Setup page. Management now lives per member on the Team page. The old /connected-apps address still works — it forwards to /endpoints, where each user sees a read-only Your AI connections self-view of only their own connections (no management there).

Per-install sign-in connections (the more common kind) are not connected apps — they are read-only AI sessions, controlled by member-level revocation. See OIDC sessions and revoking AI access.

What counts as a "connected app"

Some AI products identify themselves to StackJack with a single published app identity (a URL) that is the same for every user of that product, rather than registering a private identity per installation. When one of your team members signs in through such an app — passing the consent screen — StackJack records an individual authorization for that specific app + team member combination. Each time a member authorizes an app they have not connected before, StackJack also emails the account owner a security heads-up naming the app and that member. The notice is per app and per member — if several people connect the same app, the owner gets one heads-up for each of them; later sign-ins through an app that member has already connected are silent.

Those authorizations are what the Connected apps part of each member's Team row lists.

Who can manage them

Managing connected apps — the Revoke / Reinstate controls — is for owners, co-owners, and Administrators, on the Team page. A plain member has no management controls; they can only see their own connections, read-only, in the Your AI connections card on the MCP Setup page (/endpoints).

Because management is per member, an admin reaches a given authorization by expanding that member's row in Active Members. If the person is no longer a team member (a removed member, or the primary owner without a member row), their authorizations are in the managers-only Unattributed connections area below the members grid instead — nothing becomes unmanageable when someone leaves.

Reading a connected-app row

Each connected-app row shows:

FieldMeaning
AppThe app's display name (it falls back to the identity URL the app presents when it has no name)
Client IDThe identity URL the app presents
AuthorizedWhen the member first authorized this app
LastThe most recent time they signed in through it
StatusActive, or Revoked
ActionsRevoke on active rows; Reinstate on revoked rows (or the sticky support notice — see below)

Inside a single member's row the acting user is implied (it is that member). In the Unattributed connections area, each row additionally shows a resolved owner label, since those rows are not grouped under one member.

Revoked authorizations are hidden by default — the family header count shows only live authorizations. Tick Show revoked to reveal them. Revoking retains the record (it is not deleted), so a revoked row stays available for your audit trail and can be reinstated.

Revoke an authorization

  1. On the Team page, expand the member's row and find the connected-app row you want to cut off (or open Unattributed connections if the person has left).
  2. Select Revoke and confirm the dialog.

Effects:

  • The app stops working for that user on its next request.
  • Background token refresh for that connection is denied ("Authorization has been revoked").
  • The user cannot re-authorize the app by signing in again — new sign-in attempts through that app are refused until the row is reinstated.

Everything else stays intact: the user's team membership, portal access, other AI connections, and other users of the same app are unaffected.

The revoked row drops out of the default view (tick Show revoked to see it again); the record itself is retained, so you can reinstate it later.

Reinstate an authorization

Select Reinstate on a revoked row to restore the authorization. If the app still holds a live session it works again on its next request; otherwise the user simply signs in through the app again, which is no longer refused.

Exception — revocations made by StackJack support are sticky. If the row shows "Disabled by StackJack support — contact support to restore," it was revoked at the platform level and cannot be reinstated from the Team page. Contact support@stackjack.io.

How this interacts with member removal

  • Revoke Access on the Team page also revokes all of that member's connected-app authorizations automatically (along with everything else — see the revocation recipes).
  • Reactivating the member later restores only the authorizations that the removal itself revoked. Any authorization you had individually revoked here beforehand — or that StackJack support revoked — stays revoked.

Blocking an app product entirely

Connected Apps controls one app for one user at a time. If you believe an AI product should be blocked outright — for every user — contact StackJack support, which can block the app for every user.