---
title: Team Chat API Platform (planned)
---
# Team Chat API Platform (planned)

## What it is

**Status:** In-development (architecture documented, no OAuth2 layer built yet). Registered as unreleased feature `team-chat-api-platform`.

### Why it matters

Third-party integrations (bots, workflow tools, monitoring dashboards) currently cannot access Team Chat programmatically. The internal CLI routes are fully functional but restricted to same-machine bearer-token auth, making them inaccessible to external services.

### Current state

The feature is registered in `UNRELEASED_FEATURES` with setting key `teamChatApiPlatformEnabled` and gated via the standard unreleased-feature mechanism. No OAuth2 code exists yet.

## Where to find it

Nothing to open — this is planned work with no screen in the product. The Team Chat routes it would expose are reachable today only through the local control server.

## How it behaves

### What it will do

Expose Team Chat's existing 13+ CLI messaging routes to third-party integrations via an OAuth2 authorization layer with scoped access tokens. The routes themselves are production-grade today (Zod validation, typed errors, pagination, idempotency, content deduplication) -- the gap is solely the auth surface for external consumption.

### Current readiness

The following infrastructure is already in place on the CLI control server (loopback bearer-token auth):

- **Channel CRUD**: create, list, edit, archive, delete channels.
- **Message CRUD**: send, list (paginated), get by id, edit, delete.
- **Reactions**: add/remove emoji reactions.
- **Threading**: send with parentId, list threads.
- **Pin/Save**: pin/unpin, save/unsave messages.
- **Search**: full-text message search via Cloud Function.
- **Read state**: get unread count, mark channel as read.
- **DM inbox**: list DM conversations.
- **Members**: list org members (mention resolution).

All mutation routes enforce source provenance (`X-AMC-Source-Session-Id`) and agent-write gating (D22 Layer 2).

### What is needed

1. **OAuth2 provider implementation** -- register an authorization server (likely Firebase Auth custom tokens + OAuth2 consent screen) that issues scoped access tokens for third-party apps.
2. **Scope definitions** -- define granular scopes (e.g. `team-chat:read`, `team-chat:write`, `team-chat:admin`) that map to route groups.
3. **Token validation middleware** -- replace/augment the current loopback bearer-token check with OAuth2 token introspection for external callers.
4. **Rate limiting** -- per-app rate limits (the current per-user pacing is insufficient for a platform API).
5. **Developer portal** -- app registration, API key management, webhook subscriptions.

## Related

Team Chat itself covers the product these routes serve, and the export page is the other planned Team Chat capability.
