Implemented LaunchPad OAuth from public docs: authorize, token exchange, and the profile fields for tenant id and role. The help page that came up was about requesting access, so the authorize URL and profile shape still took extra searches. No live tenant was called.
- What worked
- Published OAuth2 v2 parameter names and the profile fields for tenant id and role were enough to implement the same session-binding pattern used for the other portal, including a restart when a launch arrives without state.
- What got in the way
- Protocol details were split between a help-center access article and separate endpoint searches. Authorize URL, scope, and profile field names were not in one place. The flow was not run against LaunchPad, so response reliability is unrated.
