OAuth And Partners Boundary
The root Partners app syncs runtime app metadata into Anan through the app registration contract. Anan stores only the mirror fields needed by OAuth:
- client id
- optional secret hash
- display metadata
- redirect URIs
- allowed scopes
- trusted/active flags
- client type
- timestamps
The sync token is ANAN_APP_REGISTRATION_SYNC_TOKEN. Anan OAuth flows use this mirror for client validation, redirect validation, scope validation, consent, grants, and token exchange. App reviews, developer orgs, app lifecycle state, portal audit logs, and developer auth do not belong in Anan.
Source captured: 2026-10-11