App Installs v1
An app install represents a Stripe App that is installed on an account. It reports the permissions, content security policy entries, and endpoints that the installing account has authorized, along with any that the app’s latest version requests but the account has not authorized yet. Use the Install API to install, reauthorize, and uninstall apps, and to check the state of existing installs.
Attributes
- idstring
Unique identifier for the object.
- accountstring
The ID of the account that the app install belongs to.
- appstring
The ID of the app installed.
- approval_
required booleanWhether the installer must authorize pending permissions, content security policy entries, or endpoints. For private apps,
approval_staysrequired false; creating or reauthorizing the install through the API installs the newest completed upload and grants its permissions. - channelenum
The distribution channel associated with the app install.
Possible enum valuesprivate_live A private app installed in live mode.
private_test A private app installed in test mode.
publicThe published version of the app.
reviewThe app as installed by Stripe for app review.
testingA pre-release version of the app installed for external testing.
- content_
security_ objectpolicy_ granted The content security policy entries authorized by the installer.
- permissions_
granted array of stringsThe permissions authorized by the installer.
- permissions_
pending array of stringsThe permissions requested by the latest app version that the installer has not authorized.
- statusenum
The status of the app install.
Possible enum valuesinstall_failed The install did not complete. The app cannot be used.
installedThe app is installed and can be used. Access that the installer has not authorized yet is listed in the pending fields.
installingThe install is in progress.
uninstall_failed The uninstall did not complete.
uninstallingThe uninstall is in progress.
More attributes
- objectstring, value is "apps.install"
- auth_
code nullable string - content_
security_ objectpolicy_ pending - createdtimestamp
- created_
by nullable string - endpoints_
granted array of strings - endpoints_
pending array of strings - livemodeboolean
{ "id": "appinst_test_61VGZmT4pXc8Rk2w41LUZiLcTVChK7Ab", "object": "apps.install", "account": "acct_1LQeGxLUZiLcTVCh", "app": "app_61VGZkQ7mRbN3xPa41LUZiLcTVChQ9Ye", "approval_required": false, "auth_code": null, "channel": "public", "content_security_policy_granted": { "connect_src": [ "https://api.example.com/" ], "image_src": [ "https://cdn.example.com/" ] }, "content_security_policy_pending": { "connect_src": [], "image_src": [] }, "created": 1725000000, "created_by": null, "endpoints_granted": [ "https://example.com/stripe/webhook" ], "endpoints_pending": [], "livemode": false, "permissions_granted": [ "customer_read", "event_read" ], "permissions_pending": [], "status": "installed"}Creates an app install. An account installs its own private app with its own key; public and testing installs are made from the Dashboard. An app developer acting on a connected account through Stripe-Account installs or reinstalls its app there, and an embedding platform can do the same once the app’s developer approves its request to embed the app. For a private app, creating an install installs the newest completed upload; when that version is already installed with nothing pending, the existing install is returned.
Parameters
- appstringRequired
The ID of the app to install.
- channelenum
The distribution channel to install from. Defaults to
public, which only app developers and embedding platforms can use. An account installing its own private app must passprivate_ortest private_, matching the mode of the API key.live Possible enum valuesprivate_live A private app installed in live mode.
private_test A private app installed in test mode.
publicThe published version of the app.
testingA pre-release version of the app installed for external testing.
- code_
challenge stringFor OAuth apps, the PKCE code challenge used to issue the
auth_returned on the install. Must be 43 to 128 characters and contain only letters, numbers,code -,.,_, and~. Only applies to installs made by the app developer or an embedding platform; ignored when an account installs its own private app. - code_
challenge_ stringmethod The method used to derive
code_. Required whenchallenge code_is provided, and must bechallenge S256.
Returns
Returns the app install
{ "id": "appinst_test_61VGZmT4pXc8Rk2w41LUZiLcTVChK7Ab", "object": "apps.install", "account": "acct_1LQeGxLUZiLcTVCh", "app": "app_61VGZkQ7mRbN3xPa41LUZiLcTVChQ9Ye", "approval_required": false, "auth_code": null, "channel": "public", "content_security_policy_granted": { "connect_src": [ "https://api.example.com/" ], "image_src": [ "https://cdn.example.com/" ] }, "content_security_policy_pending": { "connect_src": [], "image_src": [] }, "created": 1725000000, "created_by": null, "endpoints_granted": [ "https://example.com/stripe/webhook" ], "endpoints_pending": [], "livemode": false, "permissions_granted": [ "customer_read", "event_read" ], "permissions_pending": [], "status": "installing"}