When defining a Paragon API Resource, choose User-Level if each of your customers connects their own account (separate OAuth tokens per user), and App-Level only if one service account serves everyone. Picking App-Level for per-user auth means every customer shares one credential and tokens collide. For OAuth 2.0, fill in the Access Token URL for refresh plus client ID and secret, and if your provider does not use a Basic Authorization header for the token request, disable the Include Client ID and Secret setting.

Context: Official docs (Paragon, API Resources): the User-Level vs App-Level decision that breaks multi-tenant auth if you get it wrong. User-Level Resources need separate API credentials saved per Connected User via the SDK/API, use this when each user has their own OAuth tokens or API keys. App-Level Resources use one set of credentials for all Connected Users, only correct when a single service account authenticates everyone. For OAuth 2.0 you must provide the Access Token URL Paragon uses to refresh tokens, plus client ID and secret.