← Integration Hub

Spotify

Action requiredSetup requiredMOCK

Now Playing, transport controls, volume, device targeting and the up-next queue.

How it connects
Sign in with the provider
Health
healthy
Integration status
connected
Credential
Not configured
Last sync
never
Connected
not yet

1 of 4 steps done

Setup

  1. Create an app in the Spotify developer dashboard

    You are hereNot done yet
    Administrator (once)Provider console (one time)

    developer.spotify.com/dashboard → Create app. Add exactly the redirect URI shown here under Redirect URIs — Spotify matches it exactly, and a mismatch returns only “INVALID_CLIENT: Invalid redirect URI” with no hint about which value was sent.

    Open the provider's console

    Paste this exactly

    https://crm.gopaxx.de/api/integrations/spotify/callback

    Paste this exactly — the provider matches it byte-for-byte, including scheme, case and any trailing slash, and a mismatch fails at the provider with an error that never says which value it received.

  2. Client ID and secret saved in PAXX

    Not done yet
    Administrator (once)In the Hub

    Paste both into the form below. The secret is sealed before it is stored.

  3. Encrypted credential storage initialized

    Done
    Administrator (once)In the Hub

    Credentials are sealed with AES-256-GCM before they reach the database, and PAXX refuses to store them at all without a key. Initialize it with one click in the Integration Hub, or set the key in the server environment if you would rather manage it yourself. There is deliberately no env-only path to a real Spotify connector: it needs a user grant, which only ever arrives on the callback and has to be stored.

  4. Sign in and approve playback access

    Not done yet
    YouIn the Hub

    Press Connect. You will see the permissions in plain language here first, then Spotify's own consent screen, which is the authoritative grant.

Once per deployment · owner only

Administrator configuration

Shared values every user of this PAXX instance connects through. Spotify needs them before anyone can authorize an account, and they replace the environment variables an operator would otherwise have to set over SSH.

From your app in the Spotify developer dashboard. Not a secret — it travels to the browser during authorization — so it is stored in the clear and shown back to you.

Stored encrypted and used server-side only, to exchange the authorization code and refresh the access token.

Only needed if a proxy rewrites paths. Leave blank to use the callback URL shown above — which is also the value to register with Spotify.

Secret values are sealed with AES-256-GCM before they reach the database and are never sent back to the browser, so a field that is set shows only that it is set. Changing one requires the owner role and is recorded in the audit log by key, never by value.

Sign in with the provider

Connect

Press Connect, sign in to Spotify and approve playback access.

Setup required

developer.spotify.com/dashboard → Create app. Add exactly the redirect URI shown here under Redirect URIs — Spotify matches it exactly, and a mismatch returns only “INVALID_CLIENT: Invalid redirect URI” with no hint about which value was sent.

callback URL to register: https://crm.gopaxx.de/api/integrations/spotify/callback

Live check

Connection test

GET https://api.spotify.com/v1/me/player/devices with the stored token, refreshing it first if it has expired. The device list rather than the player, because Spotify answers the player with an empty 204 when nothing is playing — an idle player is a working connection, not a failure.

3 declared

Permissions

What PAXX asks the provider for. The provider's own consent screen is the authoritative grant — this list is what will be requested, and after connecting, what was actually returned.

  • readRead playbacknot requested yetWhat's playing, on which device, at what volume.
  • readRead current tracknot requested yetTrack title, artist, album art and progress.
  • writeControl playbacknot requested yetPlay, pause, skip, volume, shuffle, repeat and device transfer.

Capabilities

What you get

  • Now Playing

    readNot available

    Track, artist, album art and live progress.

    Available once this provider is connected.

    Dashboard → Spotify
  • Playback control

    writeNot available

    Play, pause, skip, volume, shuffle and repeat. These are real writes to your Spotify account and are audited.

    Available once this provider is connected.

    Dashboard → Spotify
  • Devices and queue

    readNot available

    The device list with transfer, and what is up next.

    Available once this provider is connected.

    Dashboard → Spotify

Requirements

Diagnostics

Administrator requirements

One-time work for whoever administers this PAXX instance.

  • Create an app in the Spotify developer dashboard

    Not satisfied
    Administrator (once)Provider console (one time)

    developer.spotify.com/dashboard → Create app. Add exactly the redirect URI shown here under Redirect URIs — Spotify matches it exactly, and a mismatch returns only “INVALID_CLIENT: Invalid redirect URI” with no hint about which value was sent.

    Open
  • Client ID and secret saved in PAXX

    Not satisfied
    Administrator (once)In the Hub

    Paste both into the form below. The secret is sealed before it is stored.

    clientId
  • Encrypted credential storage initialized

    Satisfied
    Administrator (once)In the Hub

    Credentials are sealed with AES-256-GCM before they reach the database, and PAXX refuses to store them at all without a key. Initialize it with one click in the Integration Hub, or set the key in the server environment if you would rather manage it yourself. There is deliberately no env-only path to a real Spotify connector: it needs a user grant, which only ever arrives on the callback and has to be stored.

Your requirements

Per-person steps — the authorization is yours, not the deployment's.

  • Sign in and approve playback access

    Not satisfied
    YouIn the Hub

    Press Connect. You will see the permissions in plain language here first, then Spotify's own consent screen, which is the authoritative grant.