Files
stargue-publishing-engine/docs/linkedin-apps.md
T
Angelo B. J. Luidens c24ea815f3 docs: record Gate 0.8 resolution + Gate 0.9 LinkedIn app / CMA progress
- deferred-gates.md: Gate 0.8 RESOLVED — clean-room Postgres 17 + Redis 7 in a
  dedicated Dokploy project; service names, hosts, env-var locations recorded.
- linkedin-apps.md: app created (Client ID 78s8f53y5spyo4), company-page +
  business-email verified, Community Management API Development Tier submitted
  (review in progress). Notes that other products grey out while CMA is pending.
- docs/handoffs/2026-05-13-handoff.md: committed (was untracked).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-03 15:31:02 -04:00

95 lines
7.6 KiB
Markdown

# LinkedIn Developer Portal — Application Registry
**Status tracker for Stargue's LinkedIn apps.** Every row must stay current — Claude Code verifies against this file during Stage 0 DoD 0.9.
## App: Stargue Publishing Engine (created 2026-06-03)
- **Client ID:** `78s8f53y5spyo4`
- **Client Secret:** present on Auth tab (Primary Client Secret) — copy to Dokploy secret `LINKEDIN_CLIENT_SECRET`, never commit
- **App type:** Standalone app
- **LinkedIn Page:** Stargue (`urn:li:organization:2605890`) — association is permanent, **NOT yet verified** (see below)
- **Privacy policy URL:** https://stargue.com/privacy (live 2026-06-03) ✅
- **Business email:** `info@stargue.com`**verified 2026-06-03** ✅ (required for CMA)
- **Access-token TTL:** 2 months / 5,184,000 s (confirms the 60-day re-auth design; programmatic refresh is MDP-gated)
- **Authorized redirect URLs:** none added yet
- **OAuth scopes:** none yet
## Status update — 2026-06-03 13:15
**Community Management API (Development Tier) = SUBMITTED → "Review in progress."** Access form completed (legal name `Stargue N.V.`, Curaçao address Dwarsweg 9 Julianadorp LP71, website stargue.com, 3 use cases: Page management + Page analytics + Profile management, first-party compliance description). Decision comes by email to `info@stargue.com`. (Note: the Qualtrics "session expired" end-screen was a false alarm — it did submit.)
**⚠️ NEW OBSERVATION — once CMA was requested, ALL other products greyed out** (Share on LinkedIn, Sign In with OpenID Connect, etc. now show disabled "Request access"). **Uncertain (not yet confirmed) whether this is:**
- (a) **temporary** — a lock while CMA is in review, that lifts on approval; or
- (b) **permanent** — CMA apps are meant to be CMA-only (consistent with FAQ #1/#2 treating CMA + other products as a separate-app pattern).
**Architecture decision deferred pending CMA outcome:**
- If other products **un-grey** after CMA approval → keep single app, add Sign In + Share here.
- If they **stay greyed****two-app split** after all: this app = CMA (company + profile posting via CMA), a **second app** = Sign In (OIDC identity) + Share on LinkedIn (`w_member_social`).
- **Possible simplification:** CMA's *Profile management* use case may already cover posting to Angelo's own profile, reducing/eliminating the need for a separate "Share on LinkedIn" product. Confirm when wiring OAuth scopes.
## ⚠️ Why the Community Management API is greyed — VERIFIED (2026-06-03)
The app has **no other products**, so FAQ #4 ("greyed because the app already has other products") is **not** the cause here. The real prerequisites — confirmed against LinkedIn docs and visible on the app's **Settings** tab — are:
1. **Company-Page verification (PRIMARY GATE).** Settings shows *"This app is not verified as being associated with this company"* + a **Verify** button. A **super-admin of the Stargue Company Page** must approve the app↔page association. CMA stays greyed until done. **Dependency: Angelo must be, or have access to, a super-admin of the Stargue Page.**
2. **Business-email verification.** Settings banner: *"Update your business email…"*. The CMA access form requires a **verified business email**.
3. **Access-form requirements.** CMA is for **registered legal organizations, commercial use only**. Form asks for: legal org name, registered address (Curaçao), website, **privacy policy URL** (✅ live), verified business email.
4. **Secondary — product order (FAQ #4).** If an app *already has* other products, the CMA request greys out. Not our cause today (clean app), but it means: **request CMA before adding Share/Sign In**, or keep CMA on its own app.
### Corrected recommendation: single app, CMA-first
1. **Verify** the app ↔ Stargue Page (super-admin approves).
2. **Set + verify** the business email.
3. Request **Community Management API first** → complete access form → **Development Tier** (limits: 500 req/app, 100 req/member).
4. Apply **Standard Tier** (access form + screencast demonstrating each use case).
5. **Then** add **Share on LinkedIn** + **Sign In with OpenID Connect** (instant) for personal posting + identity.
(Two-app split — CMA on its own app, Share/Sign In on another — remains a fallback if Page verification cannot be completed on this app.)
## Products — observed state (2026-06-03 Products tab)
| Product | Needed for | Self-service? | State on this app |
|---|---|---|---|
| Community Management API | Company-page posts (`w_organization_social`, `r_organization_social`) | No — needs verification + Dev→Standard | **🔒 Greyed** — pending Page verification + business email |
| Sign In with OpenID Connect | Identity / `whoami` (`openid profile email`) | Yes (instant) | Available — request AFTER CMA |
| Share on LinkedIn | Personal-profile posts (`w_member_social`) | Yes (instant) | Available — request AFTER CMA |
| Marketing Developer Platform / Advertising / Lead / Conversions | Programmatic refresh tokens; marketing | No (partner review) | Greyed; optional (60-day re-auth fallback exists) |
Other products present but not needed: LinkedIn Ad Library, Verified on LinkedIn (available); Live Events, Events Mgmt, Member/Pages Data Portability (greyed).
## OAuth redirect URIs
Add under the app's **Auth** tab (not yet done):
- Production: `https://publishing.stargue.net/auth/linkedin/callback` (note: `publishing.stargue.net` subdomain is Stage 5+; admin app not built yet)
- Local dev: `http://localhost:3002/auth/linkedin/callback`
## Client credentials
Dokploy secrets on `sg-paas-s1.stargue.net` (project `stargue-publishing-engine`, once app services exist in Stage 5+):
- `LINKEDIN_CLIENT_ID` = `78s8f53y5spyo4`
- `LINKEDIN_CLIENT_SECRET` = (from Auth tab — pending copy)
- `LINKEDIN_TOKEN_ENCRYPTION_KEY` (32-byte; **AES-256-GCM** per D-001 — see `deferred-gates.md`)
## Manual setup checklist (Stage 0.9)
1. ✅ Sign in to `https://www.linkedin.com/developers/` as Angelo.
2. ✅ Create app "Stargue Publishing Engine" linked to Page `urn:li:organization:2605890` (Client ID `78s8f53y5spyo4`).
3. ✅ Privacy policy URL live at https://stargue.com/privacy.
4.**Verify app ↔ Company Page** (done 2026-06-03 — un-greyed all products). PRIMARY gate for CMA.
5.**Business email verified**`info@stargue.com` (2026-06-03).
6.**← NEXT:** Request **Community Management API FIRST**: add product → complete access form (legal name Stargue Inc., Curaçao address, website, privacy URL, business email `info@stargue.com`) → Dev Tier → apply Standard Tier later (screencast).
7. ☐ THEN request **Sign In + Share on LinkedIn** (instant).
8.**Auth tab:** add redirect URIs above.
9. ☐ Copy **Client Secret** → Dokploy secret `LINKEDIN_CLIENT_SECRET` (never commit).
10. ☐ Keep this file current with app IDs + states.
## References
- [LinkedIn Developer Portal](https://www.linkedin.com/developers/)
- [Community Management — Overview + FAQ (Microsoft Learn)](https://learn.microsoft.com/en-us/linkedin/marketing/community-management/community-management-overview)
- [Organizations & Brands Overview (Microsoft Learn)](https://learn.microsoft.com/en-us/linkedin/marketing/community-management/organizations)
- [Increasing Access — tiers & app review](https://learn.microsoft.com/en-us/linkedin/marketing/increasing-access)
- [Quick Start — Apply for API Access](https://learn.microsoft.com/en-us/linkedin/marketing/quick-start)
- [Posts API](https://learn.microsoft.com/en-us/linkedin/marketing/community-management/shares/posts-api)
- [Programmatic Refresh Tokens](https://learn.microsoft.com/en-us/linkedin/shared/authentication/programmatic-refresh-tokens)