When you need this
If you are building for one organization—your own—you can skip this page. Your API key is already the tenant boundary, and connector requests without extra headers operate in that organization’s own namespace. You need installations when one Case.dev organization serves many customer organizations. A practice-management product with hundreds of firms behind a single Case.dev account is the case this exists for. Without installations, every firm’s connections and links would share one namespace. An installation is one customer tenant inside your Case.dev organization.Ensure an installation
Installations are created just in time and idempotently. Call this on a tenant’s first connector use; calling it again returns the same installation.Endpoint
cURL
Returns
201 when created, 200 when it already existed. Either way you get the installation id.
Application keys are global. The first organization to register a key owns it; another organization asking for the same key gets
403. Pick something specific to your product.Send the installation on every request
Header
An unknown id and another organization’s id return the same error, so the API cannot be used to probe for which installations exist.
Grant vaults to an installation
An installation cannot touch a vault until you grant it. Grants are explicit and checked twice: when a link is created, and again every time a run executes.Endpoint
cURL
Which capability does what
Grant the narrowest set that supports the flows you actually offer. An import-only integration does not need
can_manage.
Reconciliation never revokes
PUT only ever adds or updates. If your reconcile pass omits a vault it granted last time, nothing is revoked—a transient glitch in your provisioning job cannot silently cut off access.
Revocation is always the explicit call:
Endpoint
What happens when access goes away
Disabling an installation or revoking a grant pauses the affected links. Nothing is deleted, no documents move, and no ledger state is lost. Restore the grant and resume the link, and it picks up from its cursor.Scoping to a user within a tenant
The installation is the tenant boundary. If you also need to keep one user’s provider credentials from being used by another user in the same tenant, send a subject assertion:Header
^[A-Za-z0-9_-]{1,255}$; anything else returns 400 connector_subject_invalid.
Scoping is exact—a request carrying a subject can never fall through to an organization-scoped connection, and omitting the header cannot reach a subject-scoped one.
Checklist for a multi-tenant integration
- Ensure the installation on first use, and cache the id against your own tenant record
- Send
X-Case-Installation-Idon every connector request—there is no fallback - Grant each vault explicitly, with the narrowest capabilities
- Derive
return_urland any subject assertion server-side, never from client input - Treat
403 installation_requiredas a bug in your request path, not a permissions problem to work around
Next steps
Connect an Account
Hosted OAuth, scoped to an installation
Import & Export
Create links against a granted vault
Errors & Recovery
Grant failures, access loss, and paused links

