LinkedIn integration · owner authorization
LinkedIn OAuth Callback
This is the canonical HTTPS callback origin reserved for the EvidenceBound LinkedIn Developer App.
Current mode. This static endpoint intentionally does not inspect, display, store, or forward OAuth query parameters. Initial production acceptance may use LinkedIn Developer Portal token generation or another explicit owner-controlled authorization flow until a server-side exchange service is configured with approved secrets.
Security boundary
No credentials are rendered here.
Authorization codes
OAuth authorization codes are short-lived credentials. EvidenceBound does not intentionally expose them as page content, source-controlled records, or public logs.
State validation
Any future server-side OAuth exchange must validate a cryptographically unpredictable state value before exchanging an authorization code and must keep client credentials and tokens in server-side secret storage.
If you reached this page during an unfinished authorization attempt: do not paste any authorization code, access token, refresh token, or client secret into chat, issues, pull requests, or email. Return to the authorized EvidenceBound onboarding procedure.