Skip to main content
A Connection is a Workspace-scoped, nonsecret handle to one external account or provider capability. The Agent can use the account through a governed call path without receiving its credential.

Connect and assign access

  1. Use Connect Center to choose a qualified offering and start a ConnectionSession
  2. Let the account owner complete the trusted handoff
  3. Observe completion, review the tools, and assign access explicitly
A completed connection is not an access grant. Connected calls still require PermissionAssignments, ActionPolicy evaluation, any required ActionApproval, and a live authority and revocation check at the trusted effect boundary. See permissions and governance. ConnectionSession completion is asynchronous. Use the ConnectionSession operations or Connect Center controller to observe the handoff. Connection resource webhooks report creation, revocation, and refresh failure; they do not replace observing the ConnectionSession. The provider-account guide walks through the integration.

Keep accounts and secrets separate

Vaults and Credentials explain secret custody. A ConnectionVault groups Connections and compiles member access into ordinary PermissionAssignments; its row grants no runtime authority. Read the integration details for native and runtime-backed custody, reconnect, concurrency, role restrictions, and revocation. Check capability status for the deployment and Workspace before depending on an execution path.