Spotify
Action requiredSetup requiredMOCKNow Playing, transport controls, volume, device targeting and the up-next queue.
- How it connects
- Sign in with the provider
- Health
- healthy
- Integration status
- connected
- Credential
- Not configured
- Last sync
- never
- Connected
- not yet
1 of 4 steps done
Setup
Create an app in the Spotify developer dashboard
You are hereNot done yetAdministrator (once)Provider console (one time)developer.spotify.com/dashboard → Create app. Add exactly the redirect URI shown here under Redirect URIs — Spotify matches it exactly, and a mismatch returns only “INVALID_CLIENT: Invalid redirect URI” with no hint about which value was sent.
Open the provider's consolePaste this exactly
https://crm.gopaxx.de/api/integrations/spotify/callbackPaste this exactly — the provider matches it byte-for-byte, including scheme, case and any trailing slash, and a mismatch fails at the provider with an error that never says which value it received.
Client ID and secret saved in PAXX
Not done yetAdministrator (once)In the HubPaste both into the form below. The secret is sealed before it is stored.
Encrypted credential storage initialized
DoneAdministrator (once)In the HubCredentials are sealed with AES-256-GCM before they reach the database, and PAXX refuses to store them at all without a key. Initialize it with one click in the Integration Hub, or set the key in the server environment if you would rather manage it yourself. There is deliberately no env-only path to a real Spotify connector: it needs a user grant, which only ever arrives on the callback and has to be stored.
Sign in and approve playback access
Not done yetYouIn the HubPress Connect. You will see the permissions in plain language here first, then Spotify's own consent screen, which is the authoritative grant.
Once per deployment · owner only
Administrator configuration
Shared values every user of this PAXX instance connects through. Spotify needs them before anyone can authorize an account, and they replace the environment variables an operator would otherwise have to set over SSH.
Sign in with the provider
Connect
Press Connect, sign in to Spotify and approve playback access.
Setup required
developer.spotify.com/dashboard → Create app. Add exactly the redirect URI shown here under Redirect URIs — Spotify matches it exactly, and a mismatch returns only “INVALID_CLIENT: Invalid redirect URI” with no hint about which value was sent.
callback URL to register: https://crm.gopaxx.de/api/integrations/spotify/callback
Live check
Connection test
GET https://api.spotify.com/v1/me/player/devices with the stored token, refreshing it first if it has expired. The device list rather than the player, because Spotify answers the player with an empty 204 when nothing is playing — an idle player is a working connection, not a failure.
3 declared
Permissions
What PAXX asks the provider for. The provider's own consent screen is the authoritative grant — this list is what will be requested, and after connecting, what was actually returned.
- readRead playbacknot requested yetWhat's playing, on which device, at what volume.
- readRead current tracknot requested yetTrack title, artist, album art and progress.
- writeControl playbacknot requested yetPlay, pause, skip, volume, shuffle, repeat and device transfer.
Capabilities
What you get
Now Playing
readNot availableTrack, artist, album art and live progress.
Available once this provider is connected.
Dashboard → SpotifyPlayback control
writeNot availablePlay, pause, skip, volume, shuffle and repeat. These are real writes to your Spotify account and are audited.
Available once this provider is connected.
Dashboard → SpotifyDevices and queue
readNot availableThe device list with transfer, and what is up next.
Available once this provider is connected.
Dashboard → Spotify
Requirements
Diagnostics
Administrator requirements
One-time work for whoever administers this PAXX instance.
Create an app in the Spotify developer dashboard
Not satisfiedAdministrator (once)Provider console (one time)developer.spotify.com/dashboard → Create app. Add exactly the redirect URI shown here under Redirect URIs — Spotify matches it exactly, and a mismatch returns only “INVALID_CLIENT: Invalid redirect URI” with no hint about which value was sent.
OpenClient ID and secret saved in PAXX
Not satisfiedAdministrator (once)In the HubPaste both into the form below. The secret is sealed before it is stored.
clientIdEncrypted credential storage initialized
SatisfiedAdministrator (once)In the HubCredentials are sealed with AES-256-GCM before they reach the database, and PAXX refuses to store them at all without a key. Initialize it with one click in the Integration Hub, or set the key in the server environment if you would rather manage it yourself. There is deliberately no env-only path to a real Spotify connector: it needs a user grant, which only ever arrives on the callback and has to be stored.
Your requirements
Per-person steps — the authorization is yours, not the deployment's.
Sign in and approve playback access
Not satisfiedYouIn the HubPress Connect. You will see the permissions in plain language here first, then Spotify's own consent screen, which is the authoritative grant.