289 karma · joined September 23, 2013
Building integrations comes with specific challenges (security, ETL, etc.), which are usually not the core competency of SaaS teams.
We often see that problems related to building integrations are underestimated and can spiral in terms of engineering costs. Authorization in itself is complex, data synchronization even more so!
"Rather our customers would get into situations where they inadvertently revoked access, the user that authorized the integration initially left the company and it was automatically disabled, etc. and there was no notification that it happened. Basically all of the lifecycle management side that couldn't be automated down to "refresh my token when it's about to expire" sucked. So anything you're looking to support there would be a huge value-add IMO."
I can definitely see value in notifying that API access has been revoked. If you think of any other case you'd like covered, I am interested!
We made this doc when we were focusing on syncing data, which was much more intensive.
Though in the future, we plan to offer a proxy that would funnel your external requests and would require more processing power. The advantages of a proxy are that we can automatically authenticate requests, handle retries & rate limits, monitor & alert, etc.
The part we focus on (for now) is getting access to all endpoints of external APIs, on behalf of users, so you can enrich your product with integrations.
This involves 1. getting users to login to external systems, from inside your app 2. storing/refreshing access tokens so you can access all endpoints of external APIs
This means we're less focus on the Single Sign-On use-case for now!
At a glance: Nango's frontend SDK only handles redirects for the OAuth flow, the Nango server actually gets called by the OAuth provider (using a callback URL). That's when the token exchange happens. Tokens are stored in a Postgres (by default we create the Postgres, but you can easily connect your own).
Before triggering the OAuth flow for an end-user, you indeed assign it a unique user-specific key, so that you can retrieve this user's token later on!
- Lazy Lantern is a virtual data analyst for product teams
- Pure data product with many challenges around AI & Big Data
- Founders with experience at leading Silicon Valley companies
- Several unicorn customers, dataset of billions of events
- Backed by top-tier US & European investors, incl. Y Combinator
- No requirement to speak French
Contact: bb@lazylantern.com
We work on providing automated insights to product teams. We have many challenges around Big Data & AI. Founders are ex-Uber senior/staff engineers. Several unicorn customers, dataset of 200bn+ events We offer above-market pay and equity. No requirement to speak French, 100% English at the work place.
Reach out: bb@lazylantern.com
We work on autonomous product analytics & predictions.
We have many challenges around Big Data & AI.
Founders are ex-Uber senior/staff engineers.
Several unicorn customers, dataset of 200bn+ events
We offer above-market pay and equity.
No requirement to speak French (100% English spoken at the work place)
Reach out: bb@lazylantern.com
We work on autonomous product analytics.
Technical challenges entail sophisticated data-capture SDKs, scaled data infrastructure, multiple AI use cases (e.g. screen recognition).
Founders are ex-Uber senior/staff engineers.
Our work-style is flexible but committed.
We offer above-market pay and equity.
Reach out to bb@lazylantern.com if you're interested to know more!