> ## Documentation Index
> Fetch the complete documentation index at: https://nango.dev/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# How to register your own HitPay OAuth app

> Register an OAuth app with HitPay and connect it to Nango

This guide shows you how to register your own app with HitPay to obtain your OAuth credentials (client id & secret). These are required to let your users grant your app access to their HitPay business.

<Steps>
  <Step title="Sign in to the HitPay dashboard">
    Sign in to the [HitPay dashboard](https://dashboard.hit-pay.com) with an account that is an **Owner** or **Admin** of the business that will own the app.

    <Note>
      To test against HitPay's sandbox, repeat this guide in the [HitPay sandbox dashboard](https://dashboard.sandbox.hit-pay.com). Sandbox apps have their own client ID and secret, so create a separate Nango integration for them and select `sandbox.hit-pay.com` as the environment when connecting. The same applies to staging: use the [HitPay staging dashboard](https://dashboard.staging.hit-pay.com) and select `staging.hit-pay.com`.
    </Note>
  </Step>

  <Step title="Create a new app">
    1. Go to **Payments** -> **Developers** and open the **App Builder** tab.
    2. Click **New App**.
    3. Fill in the **App Name** and optionally the **Developer website** and an icon.
    4. Under **Redirect URIs**, add the Nango callback URL: `https://api.nango.dev/oauth/callback`.
    5. Choose the **Availability**: **Private** limits the app to your own business, **Public** lets other HitPay businesses connect.
    6. Click **Create**.
  </Step>

  <Step title="Get your credentials">
    Copy the **Client ID** and the **Client Secret**. The secret is only shown once; if you lose it, use **Regenerate Secret** on the app.
  </Step>

  <Step title="Configure scopes in Nango">
    When configuring the integration in Nango, add the scopes your app needs. Available scopes are `business:read`, `payments`, `commerce`, and `customer`, plus their granular variants (e.g. `payments:read`, `payments:refund`). A parent scope such as `payments` also grants all of its `payments:*` children.

    <Note>
      New apps can use `business:read`, `payments`, and `commerce` (and their children). HitPay silently drops any other scope the app hasn't been granted, so request access to `customer` scopes from HitPay before relying on them.
    </Note>
  </Step>

  <Step title="Pre-set the environment (recommended)">
    Your credentials only work with one HitPay environment, so set it when you [create the connect session](/docs/reference/backend/http-api/connect/sessions/create) instead of asking users to pick it. The Connect UI then hides the **Environment** field:

    ```json theme={null}
    {
        "integrations_config_defaults": {
            "<INTEGRATION-ID>": {
                "connection_config": {
                    "environment": "hit-pay.com"
                }
            }
        }
    }
    ```

    Use `hit-pay.com` for production, `sandbox.hit-pay.com` for sandbox, or `staging.hit-pay.com` for staging, matching the credentials of `<INTEGRATION-ID>`.
  </Step>

  <Step title="Next">
    Follow the [*Quickstart*](/docs/getting-started/quickstart) to connect your first account.
  </Step>
</Steps>

## Good to know

* Each Nango integration holds one set of credentials. Use one integration per HitPay environment, and choose the matching environment when connecting.
* Only business **Owners** and **Admins** can authorize a connection. During authorization, the user picks which business to connect.
* Access and refresh tokens are valid for one year. Each refresh issues a new refresh token.

For more details, see the [HitPay OAuth documentation](https://docs.hitpayapp.com/platforms/oauth).

***
