The catalog
The built-in catalog has 164 apps, grouped by name below. The console always shows the current catalog, which can grow. Search it from Add integration on the Integrations page.A–C (34 apps)
A–C (34 apps)
D–G (29 apps)
D–G (29 apps)
H–M (22 apps)
H–M (22 apps)
N–R (30 apps)
N–R (30 apps)
S–Z (49 apps)
S–Z (49 apps)
Connect an app
Add the app with the tools agents may use, then sign in to it. Connecting is done in the console. The API can read, check, change, and disconnect connections, but it can’t add one.Open Add integration
Pick the app
Choose its tools
Review and create
Sign in to the app
Confirm the connection
Choose which tools agents may use
Each connection carries a tool allow-list: the tools the organization permits agents to use, chosen on the Integrations page. An agent can’t call a tool that isn’t on the list. In standalone Managed Agents, you can narrow this list when assigning the connection to an agent.- Start with read-only. Select read-only is the safest starting point. Add write tools only for tasks that need them.
- The organization list is the ceiling. Agents inherit all enabled tools unless you select a smaller set for an assignment. An agent’s selection never adds tools outside the organization list.
- The list can’t be empty. A connection always names at least one tool, and at most 200.
- Changes reach agents on their own. New sessions always use the new list. A session that’s already running may pick it up when its access is next renewed, so don’t count on a running session keeping the old list.
How tools are classified
How tools are classified
Change an app’s tools
- In the sidebar, click Integrations.
- Open the app’s row menu and click Tools.
- Tick or clear tools. The list applies to every agent using the app.
- Click Save tools. The console confirms that the app’s tools were updated for every agent using it.
When the catalog changes
When the catalog changes
Grant apps to an agent
A connection does nothing until an agent is granted it.- Console
- cURL
- In the sidebar, click Agents, then open the agent.
- On Configuration, find the Integrations section.
- Click Add integration access, search for the app, and click Select. A connection that isn’t active shows Reconnect first instead.
- Repeat for each app, and click Remove to take one away.
- Click Save new version.
200 response is the agent. It lists the granted connections. Some fields are left out here.
built_in_integrations, so every change publishes a new version. Running sessions keep the version they started with, and automations keep their pinned version, so a grant you remove still applies to an automation’s runs until you move it to the new version.
Rules for built_in_integrations
Rules for built_in_integrations
- Each entry names a connection by
connection_id. Get ids fromlistIntegrationConnections, or from the row on the Integrations page. - Every connection must be a built-in integration in your organization, be Active, and have at least one tool on its allow-list.
- An agent can name at most 25 entries, counted before duplicates are removed. A repeated id is kept once, and the order you send is kept.
- Leave out
toolsto inherit the connection’s current allow-list. To narrow access, supply 1 to 200 tool names from that list. New sessions intersect the saved selection with the current organization list, so removing a tool at the organization level removes it from agents too. - The list is part of the definition, so send it on every
createAgentVersion. Leaving it out publishes a version with no apps. See Update rules. - Built-in integrations aren’t vault grants. They never appear under an agent’s credential access, and
default_vault_idsandcredential_refsdon’t affect them.
What a session receives
When a session starts, it keeps the list of apps from its agent version for its whole life. For each app, the session gets:- Access to the allowed tools only. The agent can call the tools on the connection’s allow-list and nothing else in that app.
- Short-lived, scoped access. Access is limited to the apps the agent was granted, expires within an hour, and renews on its own while the session runs. You never handle a token. The access is available to commands in the sandbox, so treat it like anything else the agent can read: it works only for the granted apps and allowed tools, and only until it expires.
- A skill for using apps. Sessions of an agent with built-in integrations also load a skill that shows the agent how to find and call app tools. It takes one of the session’s 100 skill slots, so if the agent’s own skills already fill all 100, the last one is left out.
web_search, and web_fetch run outside the sandbox and don’t need that. See Control network access.Use apps in a session
Agents already know how to find the right tool in each granted app, check the inputs it needs, and call it. You don’t list tools in the prompt. Describe the outcome you want, and name the app when it matters:Test a connection
A check tries a fresh sign-in with the app, the same way a session does, and reports whether it worked. Use it after connecting, or when an agent can’t reach an app.- Console
- cURL
- In the sidebar, click Integrations.
- Open the app’s row menu and click Test connection. Test connection appears only for an active connection.
- Read the Connection check column: Connection check passed., or the reason it failed.
probeIntegrationConnection answers 200 even when the check fails, so read ok, not the status code.
ok and token_minted are both true, a session using the app will get access. For a built-in integration, resource_count is the number of tools on the allow-list. A failed check returns ok: false and a failure reason. If the app no longer accepts the sign-in, state comes back revoked; reconnect the app.
List and read connections
List and read connections
listIntegrationConnections returns every connection in your organization, native and built-in, including pending and revoked ones. Disconnected connections are left out. getIntegrationConnection returns one.external_idis the app’s slug from the catalog, andaccount_typeis its name.account_loginis the app’s name too, followed by the sign-in method when the app names one.permissionsis the tool allow-list, each tool with its level.usage.agentscounts the agents whose current version grants the app.provideridentifies the kind of connection. Every built-in connection shares one provider, whichlistIntegrationProviderslists as Built-in integrations.
Reconnect an app
Reconnect when a connection is Revoked, or to sign in to the app again. Reconnecting keeps the sameconnection_id, so the agents granted the app and its tool allow-list stay as they are.
- In the sidebar, click Integrations.
- Click Reconnect on the app’s row. For an active app, it’s in the row menu.
- In the Reconnect dialog, click Continue to sign-in.
- Sign in to the app and approve access.
Disconnect an app
Disconnecting removes the app’s sign-in and stops all access through it. Every agent granted the app loses it from its next session.- Console
- cURL
- In the sidebar, click Integrations.
- Open the app’s row menu and click Disconnect.
- In the Disconnect dialog, click Disconnect.
404 not_found on built_in_integrations. Connecting the app again starts from the catalog and creates a new connection, so agents must be granted the new one.
grants_revoked counts vault grants that used the connection, which applies to native integrations. It’s 0 for a built-in integration, because those are granted on the agent.
Connection states
A new connection starts Pending setup, becomes Active once someone signs in, and moves to Revoked if the sign-in stops working.What each state means
What each state means
Native integrations
Native integrations connect a service by signing in to it directly. Each session gets a short-lived token limited to the access you grant, and the connection’s own permissions at the service are always the ceiling.listIntegrationProviders returns the same list, with configured: true for each service your organization can connect. Jira, Confluence, Loom, and LaunchDarkly fix the access level when you connect (preset_fixed_at_authorization); to change it, reconnect with the new level. GitHub tools are selected on the connection and narrowed per agent. Slack levels are chosen per grant. An existing Slack installation can be granted either level without reconnecting.
Test, reconnect, or disconnect a native connection
Test, reconnect, or disconnect a native connection
resource_count, and missing_permissions the service hasn’t granted yet. For GitHub, resource_count is the number of repositories in the repository list. Disconnecting GitHub doesn’t uninstall the app from your GitHub account.Connect a service
Start the connection
Approve at the service
Choose an account if asked
Confirm
listIntegrationConnections with state: "active". Connecting grants nothing to any agent; next, grant it to an agent. Connecting GitHub or Slack also adds an event source that automations can listen to.
Start a connection from the API
Start a connection from the API
startIntegrationInstall returns the service’s authorization url and a single-use state. Open the url in a browser where the same person is signed in to the console; after approval the console completes the connection. The state expires after 15 minutes.option is the access level for a service that fixes it at connect time. For a new GitHub installation, send {"option":"install"} to open GitHub’s App installation page; omit option to connect an existing installation. Send connection_id to re-authorize an existing connection in place, keeping its id so agents that use it keep working.Grant a native integration to an agent
Access is saved with the agent version, so saving it creates a new version.- Console
- cURL
- Open the agent. On Configuration, find Integrations and click Add integration access.
- Click Select next to the connection. A connection that isn’t active shows Reconnect first.
- In Configure access, choose the Access level for services that offer one. For GitHub, select the agent’s tools and keep All authorized repositories or pick repositories.
- Click Use this access. For services other than GitHub, the checkbox named for the connection’s MCP tools controls whether sessions get them.
- Click Save new version.
nativeIntegrations fields and MCP tools
nativeIntegrations fields and MCP tools
disabled_integration_mcp_providers lists services whose MCP tools sessions don’t get while the grant still works for everything else. GitHub can’t be listed there: its MCP tools are how a GitHub grant works, so github in the list is ignored. On a new version, leaving it out turns every service’s MCP tools on. See Tools.Grant through a vault
Grant a connection per session through a vault with anintegration credential. Use it when different sessions of one agent need different accounts or repositories.
integration_permission is left out, the service’s least privileged level applies. For Slack, the agent’s Integrations section grants trigger_thread or workspace_tools access without a vault credential; a vault grant is also available when access must vary by session.
How grants combine in a session
How grants combine in a session
- A session gets the agent version’s
nativeIntegrationsplus anyintegrationcredentials in its granted vaults. - Each connection is used once. If the agent and a vault both grant it, the agent’s grant wins. Among vaults, the first in
vault_idswins. - Several connections to one service, such as two GitHub organizations, all work in one session.
- A grant whose connection isn’t active is skipped, and the session starts without it.
List GitHub repositories and pull requests
For a GitHub connection, list the repositories it can reach and their pull requests, for example to fill a repository picker. For an installation on selected repositories, the list is the installation’s own repositories, the same list the console’s repository pickers show. Results come from GitHub, 100 per page, with the 1-basedpage query parameter.
state is open (the default), closed, or all. Use full_name values in resources.
MCP servers
For a service that isn’t in the catalog, or when you want the token kept out of the sandbox entirely, add its MCP server to the agent. The token lives in a vault and is attached to requests outside the sandbox. See Connect MCP servers and Vaults.What can go wrong
The most common problems:- The row stays Pending setup, or the sign-in couldn’t be confirmed. Nobody finished signing in, or the sign-in link expired or was already used. Click Connect on the row again, and finish the sign-in within a few minutes.
- The row shows Revoked, or the agent says the app must be reconnected. The app no longer accepts the sign-in. Reconnect the app.
- The agent says a tool isn’t available. The tool isn’t on the app’s allow-list, or the app isn’t granted to the agent. Add the tool on Integrations, or grant the app and start a new session.
- A built-in app’s tool fails with a network error. The environment has No access to the internet. Set its Internet access to Enabled, or limit it to specific hosts.
Every integration error
Every integration error