Skip to main content
Corsair only differs between modes in one place: the surfaces that need a public URL (OAuth callbacks, approval pages). Everything else (calling APIs, withTenant, hooks, the database layer, encryption) is identical.
  • Hub is the recommended path. Corsair hosts the connect, callback, and approval surfaces for you, and your users’ API tokens land in your database, not Hub. See Hub overview for the credential split.
  • Manual is the self-hosted alternative. You host those surfaces yourself. It is fully featured, with no external dependency.
The picker is config on createCorsair: pass manual or hub.

What each mode asks you to build

Credential storage barely changes. Your users’ API tokens live in your database under your KEK in both modes. Hub relays the public-URL surfaces and hands the tokens to your app, keeping none itself. It does hold the app-level OAuth client id and secret (managed or bring-your-own) that run the flow. See Where your credentials live.

Config side by side

corsair.ts
You also build the connect page, the OAuth callback route, and the approval review page. See OAuth Process for the full implementation.
Both modes use the same createLink API to start a connect flow. Only where the returned connectUrl points changes. See Connect / OAuth.

The connect flow in each mode

In both lanes the tokens end up in your database. Hub removes the two pages you would otherwise build, nothing more.

Choosing a mode

Choose manual when you want full control of the connect and approval surfaces, need everything inside your own domain, or cannot add an external hop in the auth path. Choose hub when you would rather not build and host those surfaces, or when you want one provider callback to cover local development and production at once. You can also mix: connect through Hub while keeping approvals manual, or the reverse. The two surfaces are configured independently.

What’s next

Hub overview

What Hub is and where your credentials live.

Environments

Development vs production keys and delivery.

OAuth process

The full manual-mode implementation with security best practices.

Connect / OAuth

The unified createLink API and its error codes.

Permissions

Approval policies, modes, and the review flow.