Connecting accounts

A connector is one account the platform holds credentials for. Connect it once and any agent in the workspace can be given access to it.

Connectors belong to the workspace, not to an agent. Attaching one to an agent grants access; it does not copy anything. Deleting a connector affects every agent using it.

Gmail and Google Calendar

Uses a Google App Password - a 16-character credential you generate from your Google Account. The platform connects directly over IMAP (read mail) and SMTP (send mail), and CalDAV (calendar). No Google consent screen, no expiring tokens.

  1. Go to myaccount.google.com/security and make sure 2-Step Verification is turned on.
  2. Go to myaccount.google.com/apppasswords, select Mail, click Generate.
  3. Copy the 16-character password and paste it into the connector form along with your Gmail address.

Google Workspace accounts

If your email ends in a company domain (not @gmail.com), the App Passwords page may say the setting is not available. Your Google Workspace admin must enable it under Admin Console → Security → Less secure apps.

Mail. Agents can read unread inbox messages (with full body content), search mail, send new messages, reply in-thread, and archive emails (removed from inbox, never deleted).

Calendar. List events between two dates and create new events, optionally with attendees. Times use the calendar's default timezone unless the agent specifies one.

If it breaks. The App Password never expires on its own. If you delete the App Password from your Google Account, or change your Google password, the connector will fail. Generate a new App Password and reconnect from the Connectors page.

Telegram Bot

A bot you create yourself through @BotFather in Telegram. Paste the token it gives you, then send your bot a message so it can learn which chat to talk to.

A bot can only message one chat

The chat you linked at setup is the only place the bot can send to. It cannot message your customers, and it cannot start a conversation with someone who has not written to it first. Treat a bot as a notification channel for yourself or your team, not as a way to reach the outside world.

Telegram Account

This logs in as you, using your phone number and a code Telegram sends you (plus your two-step password, if you have one set). Because it acts as your real account, it can read and reply to ordinary conversations the way you would.

  • You can end the session at any time from Telegram itself, under Settings → Devices → Active Sessions. Doing so immediately breaks the connector.
  • Telegram rate-limits accounts that send a lot of messages quickly, and automated use of a personal account is a grey area in their terms. Keep the volume modest.

Twilio

Paste your Account SID, Auth Token and the Twilio phone number you want messages to come from. Every number - the sender and every recipient - must be in international format with the country code, like +14155551234.

Twilio charges you per message sent. An agent with a bug and a schedule can become expensive here faster than anywhere else on the platform, so keep the daily budget low while you are still testing.

OpenAI and Anthropic

These are the agent's brain rather than something it acts on, and one of them is required. Paste an API key from your own account; the model dropdown then loads the live list of models that key can use, so it never offers you something that has been retired.

You are billed by OpenAI or Anthropic directly, at their prices. The platform does not resell tokens or mark anything up.

MCP servers

Remote HTTPS tool servers (GitHub, Linear, Notion, Slack, Atlassian, Zapier, or a URL you run). Auth is probed — OAuth, a pasted token, or none. The tool list is frozen on connect. See MCP servers for the full rules.

Inbound Webhook

Any external system — a form, a Shopify store, a custom script — can trigger an agent by making an HTTP POST request to a unique URL. Click Connecton the Inbound Webhook card to generate a URL and a signing secret.

  • The URL and secret are shown once. Copy both before closing the dialog.
  • If you lose the secret, click Regenerate on the connector row. The old secret stops working immediately.
  • To verify requests come from the right source, the sender should include an X-Hub-Signature-256: sha256=<hex> header signed with the secret. Requests without a valid signature are rejected when a secret is set.

The agent receives the full JSON body of the POST as its trigger message. The payload is pretty-printed and capped at 4 000 characters.

Slack

Lets an agent post messages to a Slack channel using an Incoming Webhook URL.

  1. In Slack, go to Apps → Incoming Webhooks and install it if you have not already.
  2. Create a new webhook for the channel you want and copy the URL.
  3. Paste it into the Slack connector form. A test message is sent immediately to confirm.

The tool is called post_to_slack. It sends plain text and basic Slack markdown (*bold*, _italic_, `code`).

WhatsApp Business

Connects to Meta's WhatsApp Cloud API so agents can send and receive messages on your WhatsApp Business number.

  1. In Meta Business Manager, open WhatsApp → API Setup and copy the Phone Number ID.
  2. Generate a permanent system-user access token (not a temporary one).
  3. Choose a Verify Token — any string you like, e.g. my-setod-token.
  4. Fill in the connector form. The platform validates the credentials with Meta.
  5. In Meta's webhook config, set the callback URL to the one shown on the connector card and enter the same Verify Token.

The 24-hour customer service window

WhatsApp allows free-form replies only within 24 hours of the customer's last message. After that, only pre-approved template messages may be sent. The platform surfaces a clear error when the window has closed so the agent can inform the human rather than silently fail.

HubSpot

Connects to HubSpot CRM using a Private App token. Go to Settings → Integrations → Private apps, create a private app, and enable scopes: crm.objects.contacts.read/write, crm.objects.deals.read/write, crm.objects.notes.read/write. Copy the generated token and paste it into the connector form.

Tools: find_hubspot_contact, create_hubspot_contact, update_hubspot_contact, create_hubspot_deal, move_hubspot_deal, log_hubspot_note, list_hubspot_pipeline_stages.

Pipedrive

Connects to Pipedrive using your API token. Go to Settings → Personal preferences → API and copy the token.

Tools: find_pipedrive_person, create_pipedrive_person, update_pipedrive_person, create_pipedrive_deal, move_pipedrive_deal, log_pipedrive_activity, list_pipedrive_stages.

Airtable

Connects using a Personal Access Token (PAT). Create one at airtable.com/create/tokens. Required scopes: schema.bases:read, data.records:read, data.records:write. Under Access, add the specific bases you want the agent to access.

Tools: list_airtable_bases, list_airtable_records, find_airtable_record (uses Airtable formula syntax), create_airtable_record, update_airtable_record (PATCH — unmentioned fields are preserved).

Shopify

Uses a Custom App token — no OAuth, no partner account needed. In your Shopify admin, go to Settings → Apps → Develop apps, create an app, and configure these Admin API scopes: read_orders, read_customers, read_products, write_orders. After installing the app, copy the Admin API access token (starts with shpat_).

The connector also needs your store's myshopify.com domain (e.g. mystore.myshopify.com). Both fields are required.

Tools: get_shopify_order, list_shopify_orders, search_shopify_customer, list_shopify_products, get_shopify_product, add_shopify_order_note, cancel_shopify_order.

Custom App vs Public App

This connector uses the Custom App approach, which only works for connecting your own store. If you need to connect multiple different stores (SaaS scenario), you would need a Public App with OAuth — contact us.

Google Business Profile

Connects via Google OAuth with the business.manage scope. Click Connect with Google and authorise the account that is an owner or manager of your Google Business Profile location.

Requirements

Your Google account must be an owner or manager of the GBP location, and the location must be verified on Google. Unverified locations do not appear in the reviews API.

Tools: list_gbp_locations (call this first to get the location id), list_gbp_reviews, reply_to_gbp_review, delete_gbp_reply.

A typical Review Responder agent runs on a schedule (e.g. every hour), calls list_gbp_reviews to find unanswered reviews, drafts a reply, and calls reply_to_gbp_review for each. Human approval can be added before replies go live.

Calendly

Connects using a Personal Access Token (PAT). Go to calendly.com/integrations/api_webhooks and generate a new token. When creating it, enable these scopes: event_types:read, scheduled_events:read, scheduled_events:write, invitees:write, scheduling_links:write. The token is shown once — copy it immediately. Legacy tokens (created before scoped permissions) have full access without selecting scopes.

Tools: list_calendly_event_types (returns scheduling URLs too), get_calendly_availability (open slots for a date range), list_calendly_events, get_calendly_event, create_calendly_booking, cancel_calendly_event, create_scheduling_link.

Programmatic booking requires a paid plan

create_calendly_booking (booking on behalf of an invitee without a redirect) requires a Calendly Professional plan or above. On a free plan the tool returns a clear error. Use create_scheduling_link instead — it generates a single-use URL you can send in a message, and works on all plans.

Removing a connector

If an agent is using it, you will be told which agents before anything is deleted. A deleted connector takes its tools away from those agents - they keep running, but with fewer abilities, which usually means they quietly stop being useful. Detach it from the agents first if that is not what you want.

NextMCP servers →