Skip to main content

Connecting Qvasa to Zendesk with Global OAuth

Written by Amer Shalan

Connecting Qvasa to Zendesk with Global OAuth

OAuth is the modern, more secure way for Qvasa to connect to your Zendesk instance, and it replaces the long-lived Zendesk API token. When you authorize the connection, Zendesk issues Qvasa short-lived access tokens scoped to your subdomain only. Qvasa stores them encrypted and rotates them automatically — no passwords or API tokens are ever exchanged, and there is nothing for you to renew or maintain.

Zendesk is deprecating and deleting unused API tokens, so OAuth is the recommended way to keep your Qvasa analytics connected going forward.

Before you start

You'll need three things:

  • The Qvasa team has enabled the Global OAuth feature for your account (the setting below only appears once they have — reach out to us if you don't see it).

  • You are an admin in Qvasa.

  • You are signed in to your Zendesk instance as a Zendesk admin in the same browser.

Step 1 — Turn it on in Account Settings

Go to Settings → Account Settings and enable Zendesk Global OAuth Connection.

As soon as you enable it, Qvasa takes you straight to the Zendesk OAuth Connection page. (You can always get back to it later under Settings → Integrations.)

Step 2 — Connect

The connection page explains exactly what will happen before you click anything. When you're ready, click Connect Qvasa to Zendesk via OAuth. You'll be sent to Zendesk's own consent screen on your subdomain, where you approve Qvasa's access as a Zendesk admin — your Zendesk credentials are never shared with Qvasa.

Step 3 — Qvasa tests the connection automatically

Right after you approve, Qvasa automatically tests the new connection: a handful of read-only checks against core Zendesk endpoints, plus a single audit-log call on a recent ticket. Nothing is created or modified in Zendesk. You'll see the progress and the results live.

If every check passes, your account is switched to OAuth automatically — there's nothing else to click.

What done looks like

When everything is working, the Zendesk OAuth Connection page shows two green indicators: the connection is Connected, and live API traffic is Using OAuth Bearer token.

Your existing Zendesk API token stays saved in Qvasa as an automatic fallback — if OAuth ever fails, Qvasa instantly falls back to it, so there is no risk to your data syncing. Once you've confirmed the OAuth connection is working as expected, you can delete the API token from both Qvasa and Zendesk.

The page also shows token expiration dates. These are informational only: Qvasa refreshes the tokens automatically during normal operation and the dates continually move forward on their own. You never need to do anything.

If a check doesn't pass

You stay safely on your API token — a failed test never changes how Qvasa talks to your Zendesk. A couple of things you might see:

  • If your account doesn't have a recent ticket to test with, Qvasa shows a short form where you can enter any real Zendesk ticket ID and run the same test manually.

  • If checks keep failing, use the Run Connection Test button on the connection page to see exactly which endpoint is failing, and reach out to the Qvasa team — we're happy to help.

Did this answer your question?