Skip to content

DABYTE DATA DESK · devtools

Retool OAuth2 Custom Domain Failure: What the Data Shows

Answer. Retool Cloud's OAuth2 resource authentication flow failed for custom domains on 25 March 2026. Retool identified the cause at 17:05 UTC and posted resolution at 20:36 UTC, 3 hours 31 minutes later. Only 1 outlet — Retool's own incident feed — reported it, so no independent corroboration exists. In DABYTE's SaaS & AI Tools AI Visibility Index, measured 28 July 2026, Retool scores 4.2 at rank 17, with 8.3 on OpenAI and 0.0 on Perplexity, and commercial intent of 62.

Event · Published (+127d) · Useful through ?

Where these brands stand in our index

Share of AI answers naming each brand, measured 2026-07-28 across openai, perplexity.
BrandShare of answer openaiperplexityRankQuadrant
Retool4.2%8.3%0.0%17Low performance

These figures come from a fixed panel of prompts re-run on a schedule, most recently on 2026-07-28. The measurement is independent of this event: any position or movement shown here is reported alongside the event, not caused by it, and we make no causal claim between a single event and a panel measurement.

Who reported it, and when we saw it

1 source in our monitored set. First seen by us at 2026-07-31 00:04 UTC; our polling resolution is one hour, so this is when we observed it, not when it was published.
SourceLink
inc_retoolhttps://status.retool.com/incidents/61f71m1m8thn

Key facts

What Retool reported

Retool logged an incident affecting the OAuth2 resource authentication flow on Retool Cloud, specific to custom domains, on 25 March 2026. The published timeline shows two states: an entry at 17:05 UTC marking the cause identified with a fix in progress, and an entry at 20:36 UTC marking the incident resolved. The interval between those two posts is 3 hours and 31 minutes. Retool did not disclose the root cause, the number of affected organisations, the regions involved, or whether authentication tokens issued during the window needed to be reissued. OAuth2 resource authentication is the mechanism Retool applications use to connect to external data sources on a user's behalf, so a failure in that flow blocks resource connections rather than the Retool editor itself — though Retool did not describe the user-facing symptom in the notice DABYTE recorded. No compensation, credit, or post-incident report was referenced in the status entries.

Corroboration count is one

Corroboration for the Retool OAuth2 event stands at 1. The single source is inc_retool, Retool's own incident and status channel. No independent publication, competitor status aggregator, or trade outlet in DABYTE's monitored set carried the same event. A corroboration count of 1 with a first-party source means the facts are authoritative on what happened but unverified on scope: the vendor controls both the description and the severity label, and there is no external account of how many customers noticed. For readers building automated monitoring, that matters. First-party-only events are the most common class of infrastructure disclosure and the least likely to be picked up by AI answer engines, because engines weight sources that appear in multiple places. An incident with corroboration of 1 rarely enters the training or retrieval surface that shapes what an assistant says about a vendor's reliability.

Retool's position in the index

Retool holds a visibility score of 4.2 and rank 17 in DABYTE's SaaS & AI Tools AI Visibility Index, measured 28 July 2026. The score is the share of AI-generated answers in which Retool is named across the two engines DABYTE queries. The per-engine split is uneven: 8.3 on OpenAI and 0.0 on Perplexity. Retool's delta since the previous measurement is 0.0, meaning no movement in either direction. DABYTE places Retool in the Low performance quadrant. Commercial intent on the queries where Retool surfaces is 62, indicating that a majority of the prompts that name Retool are evaluation- or purchase-shaped rather than purely informational. The combination — a mid-table rank, meaningful buyer intent, and zero presence on one of two engines — describes a brand whose AI-channel exposure depends almost entirely on a single retrieval pipeline.

Why the Perplexity zero matters

Perplexity returns Retool in 0.0% of the measured answers, against 8.3% on OpenAI. A hard zero on one engine is a different problem from a low score. Low scores respond to content and mention volume; a zero suggests Retool is absent from the citation pool that engine draws on for the query set DABYTE runs, which includes commercially framed prompts at intent 62. For an incident like the OAuth2 custom domain failure, the consequence is asymmetric. Anyone asking an OpenAI-backed assistant about Retool's reliability draws on a retrieval surface where Retool appears; anyone asking Perplexity gets answers built without Retool named at all. Status-page events with corroboration of 1 do not change either figure on their own, and Retool's delta of 0.0 confirms no measured movement. Closing a per-engine zero requires third-party coverage, not first-party notices.

How long this stays decision-relevant

DABYTE assigns the Retool OAuth2 event a shelf life of 336 hours, or 14 days, from the 25 March 2026 report date. Resolved single-incident authentication failures decay quickly as decision inputs: once the fix ships and no follow-up notice appears, the event stops informing procurement questions and becomes background. Within that 336-hour window, the event is legitimately usable in two contexts — reliability diligence on Retool Cloud's OAuth2 path for custom domains, and incident-frequency tracking for teams that log vendor status history. Outside the window, the useful residue is the index position rather than the outage: visibility 4.2, rank 17, OpenAI 8.3, Perplexity 0.0, commercial intent 62, delta 0.0 as of 28 July 2026. Those figures move on a measurement cadence, not an incident cadence, and DABYTE does not treat a single resolved status entry as evidence of a reliability trend.

Questions this answers

Was the Retool OAuth2 custom domain issue fixed?

Yes. Retool posted a resolved status for the OAuth2 resource authentication incident affecting custom domains at 20:36 UTC on 25 March 2026, three hours and thirty-one minutes after identifying the cause at 17:05 UTC. Retool did not disclose the root cause, the number of affected accounts, or whether a post-incident report would follow. No further status entries on the event were recorded in DABYTE's monitoring.

How many sources reported the Retool outage?

One. The event carries a corroboration count of 1, and the single source is inc_retool, Retool's own incident and status feed. No independent publication in DABYTE's monitored set covered it. First-party-only reporting means the timeline is authoritative but the scope — how many customers were affected and in which regions — is undisclosed and unverified by any outside account.

How visible is Retool in AI-generated answers?

Retool is named in 4.2% of AI answers across the engines DABYTE measures, placing it at rank 17 in the SaaS & AI Tools AI Visibility Index as of 28 July 2026. The split by engine is uneven: 8.3% on OpenAI and 0.0% on Perplexity. Commercial intent on the prompts where Retool appears is 62, and the brand's change since the previous measurement is 0.0.

Does a resolved status incident change a brand's AI visibility score?

Not on its own. Retool's delta is 0.0, meaning no measured movement around this event. Visibility scores in the SaaS & AI Tools AI Visibility Index reflect how often a brand is named across a query set, which shifts with citation volume and third-party coverage. An incident reported by a single first-party source rarely enters the retrieval pool that AI engines draw from.

Machine access