--- title: "Heroku Connection" description: "Learn how to configure a Heroku Connection for Infisical using OAuth or Auth Token methods." --- Infisical supports two methods for connecting to Heroku: **OAuth** and **Auth Token**. Choose the method that best fits your setup and security requirements. The OAuth method provides secure authentication through Heroku's OAuth flow. Using the Heroku Connection with OAuth on a self-hosted instance of Infisical requires configuring an API client in Heroku and registering your instance with it. **Prerequisites:** - A Heroku account with existing applications - Self-hosted Infisical instance Navigate to your user Account settings > Applications to create a new API client. ![Heroku config settings](/images/integrations/heroku/integrations-heroku-config-settings.png) ![Heroku config applications](/images/integrations/heroku/integrations-heroku-config-applications.png) ![Heroku config new app](/images/integrations/heroku/integrations-heroku-config-new-app.png) Create the API client. As part of the form, set the **OAuth callback URL** to `https://your-domain.com/organization/app-connections/heroku/oauth/callback`. The domain you defined in the OAuth callback URL should be equivalent to the `SITE_URL` configured in your Infisical instance. ![Heroku config new app form](/images/integrations/heroku/integrations-heroku-config-new-app-form.png) Obtain the **Client ID** and **Client Secret** for your Heroku API client. ![Heroku config credentials](/images/integrations/heroku/integrations-heroku-config-credentials.png) Back in your Infisical instance, add two new environment variables for the credentials of your Heroku API client: - `INF_APP_CONNECTION_HEROKU_OAUTH_CLIENT_ID`: The **Client ID** of your Heroku API client. - `INF_APP_CONNECTION_HEROKU_OAUTH_CLIENT_SECRET`: The **Client Secret** of your Heroku API client. Once added, restart your Infisical instance and use the Heroku Connection. ## Setup Heroku OAuth Connection in Infisical Navigate to the **App Connections** page in the desired project. ![App Connections Tab](/images/app-connections/general/add-connection.png) Select the **Heroku Connection** option from the connection options modal. ![Select Heroku Connection](/images/app-connections/heroku/heroku-select-connection.png) Select the **OAuth** method and click **Connect to Heroku**. ![Connect via Heroku OAuth](/images/app-connections/heroku/heroku-create-oauth-method.png) You will be redirected to Heroku to grant Infisical access to your Heroku account. Once granted, you will be redirected back to Infisical's App Connections page. ![Heroku Authorization](/images/integrations/heroku/integrations-heroku-auth.png) Your **Heroku Connection** is now available for use. ![Heroku OAuth Connection](/images/app-connections/heroku/heroku-connection.png) The Auth Token method uses a Heroku API token for authentication, providing a straightforward setup process. ## Setup Heroku Auth Token Connection in Infisical Log in to your Heroku account and navigate to Account Settings. Under the **Authorizations** section on the **Applications** tab, reveal and copy your Authorization token. If you don't have one, click **Create Authorization** to create a new token. Keep your Authorization token secure and do not share it. Anyone with access to this token can manage your Heroku applications. ![Heroku API Token](/images/app-connections/heroku/heroku-api-token.png) Navigate to the **App Connections** page in the desired project. ![App Connections Tab](/images/app-connections/general/add-connection.png) Select the **Heroku Connection** option from the connection options modal. ![Select Heroku Connection](/images/app-connections/heroku/heroku-select-connection.png) Select the **Auth Token** method and paste your Heroku Authorization token in the provided field. ![Configure Auth Token](/images/app-connections/heroku/heroku-create-token-method.png) Click **Connect** to establish the connection. Your **Heroku Connection** is now available for use. ![Heroku Auth Token Connection](/images/app-connections/heroku/heroku-connection.png) Auth Token connections require manual token rotation when your Heroku Authorization expires or is regenerated. Monitor your connection status and update the token as needed.