Back to Documentation

Typebot Engine Configuration

Secure the engine to accept only OIDC tokens from ReplyBase

Required Settings

1. Disable Public Authentication

  • • Disable Google OAuth
  • • Disable Facebook OAuth
  • • Disable Email/Password login

2. Enable OIDC Provider

  • • Issuer: https://app.replybase.co.uk/api/oidc
  • • Client ID: typebot-engine
  • • Callback URL: https://engine.replybase.co.uk/api/auth/oauth/generic-oidc/callback
  • • Scopes: openid email profile plan subscription_status

3. Enforce Token Validation

All requests must validate token signature, issuer, audience, and subscription status before access is granted.

Verification Steps

  • • Access engine without token → should return 401/403
  • • Access via ReplyBase dashboard → should succeed
  • • Verify token validation logs in Typebot engine

Need deployment steps?

Use the deployment plan for a full environment setup checklist.

Deployment Plan