Compare access methods
The two interactive methods provide the same per-user sign-in experience. They differ only in how the AI platform’s OAuth client is configured. Automated workflows run without a person and do not use an individual SeekOut identity.
Interactive access
Self-service interactive connection
This is the default for clients that support OAuth discovery and Dynamic Client Registration. The client registers itself with SeekOut, opens a browser for sign-in, and uses OAuth 2.1 with PKCE. You do not create or enter a client secret. Use the setup guide for Claude, ChatGPT, Amazon Quick, or developer, CLI, and desktop tools.Managed enterprise connection
Some enterprise platforms require a pre-registered confidential OAuth client. SeekOut works with your platform administrator to configure a client ID, client secret, redirect URI, authorization URL, token URL, and themcp:tools scope. Users still sign in individually, and each session uses that user’s SeekOut permissions.
See Gemini Enterprise for the provisioning and administrator setup process.
Automated workflows
Use automated workflow credentials for CI/CD pipelines, scheduled jobs, backend services, and other environments where no person is available to sign in. Your service exchanges a provisioned client ID and client secret for a short-lived bearer token by using the OAuth 2.0client_credentials grant.
See API access for automated workflows for provisioning, token exchange, renewal, and credential-storage guidance.
Permissions
- Interactive access uses the signed-in user’s SeekOut permissions.
- Automated access uses permissions and rate limits assigned to the service credential.