Join our Newsletter — 33% off our NHI Course

Notion page access without OAuth: what changes for IAM teams?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Applications can fetch Notion pages with a refreshed access token while WorkOS Pipes handles OAuth flow, token storage, and refresh logic, reducing the integration burden for B2B apps that need user context from Notion without building credential plumbing themselves, according to WorkOS. The identity lesson is that delegation convenience does not remove governance responsibility.

Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Fetch Notion pages without OAuth using WorkOS Pipes”.

Key questions

Q: What breaks when teams treat delegated SaaS access like a normal API key?

A: They lose the lifecycle controls that make delegated access safe.

Q: When should organisations reauthorise external service connections?

A: Organisations should reauthorise external service connections when the business purpose changes, the user’s role changes, the connected provider changes scope requirements, or the integration has been idle for an extended period.

Q: What are the signs that a connected workspace integration is too broad?

A: A broad integration usually shows up as more data than the user expected, weak explanations of why pages are visible, and support tickets about missing or unexpectedly visible content.

Practitioner guidance

  • Define delegated SaaS access as an NHI lifecycle Inventory every connected workspace token as a managed non-human credential, with ownership, renewal logic, and revocation responsibility assigned to a team.
  • Separate integration capability from user sharing Document what the provider integration can do in its developer portal and what the end user actually shared at the page or database level.
  • Handle revoked connections as a governance event Route getAccessToken failures, expired grants, and disconnected workspaces into a reauthorization path that is visible to support and security teams.

Bottom line: Delegated access through refreshed tokens shifts risk from password handling to lifecycle governance over connected SaaS identities.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 11 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20967
 

Delegated app access is an NHI governance problem, not just an integration pattern. WorkOS Pipes changes who implements OAuth mechanics, but it does not change the fact that a machine-held token is now acting on behalf of a user. That places the integration squarely in NHI governance because the meaningful control questions are issuance, refresh, scope, and revocation. The practitioner conclusion is simple: if a connected SaaS app can read user data, it needs the same lifecycle accountability as any other non-human credential path.

A few things that frame the scale:

A question worth separating out:

Q: How should IAM teams govern page-level access in SaaS integrations?

A: They should map the actual authorization boundary first, then align product behaviour, logging, and support flows to that boundary. For Notion-like systems, that means distinguishing integration capability, user-selected sharing, and the token that lets the app call the API so reviews reflect the true access path.

👉 Read our full editorial: WorkOS Pipes shifts Notion access from OAuth plumbing to token use


This post was modified 11 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.