Why we build these ourselves
The agent is good at working out access to a service on its own. For most of the web, that is exactly what you want, and it is what the Bot detection page walks you through. But a handful of services show up in almost every customer’s work. Rebuilding access to those from scratch in every workspace wastes your time and gives you a slightly different result each time. So we build those in house and call them first-party integrations. You connect once, we maintain it, and it works the same way in every workspace you own.The vault
Connecting a service puts its credentials in a vault that we run, not in your workspace. Here is what that means in practice.- The agent never holds your long-lived credential. It stays encrypted in our database and never reaches your workspace.
- The agent asks for access at run time. When a run needs to touch your mail, it requests a short-lived token, uses it, and lets it expire. It does not keep a copy.
- Some credentials never leave at all. Where a service has no such thing as a short-lived token, the agent does not get one. It asks us to do the lookup and gets back only the answer. That is how 1Password works, and it is why your password vault key stays here.
- We refresh it for you. Tokens expire on the provider’s schedule. We renew them behind the scenes, so your automation does not break one morning because a token aged out.
- You can pull the plug. Disconnect a service under Integrations and every automation loses access right away.
What we support
Live now. Forward mail to an address we give you.
Live now. Gmail and Google Docs.
1Password
Live now. Sign in to sites with no API.
Outlook
Coming soon.
Slack
Coming soon.
Notion
Coming soon.