Skip to main content
To do real work, an agent needs access to your tools: your GitHub, your Google account, an API, an internal system. You don’t have to set any of it up in advance. Your agent connects the services it needs, when it needs them. You approve with one click.

Your agent does the setup

When an agent reaches a task that needs access it doesn’t have, it asks for exactly what it needs, right then. You approve, and it carries on.
1

The agent needs access

It hits a task requiring a service it isn’t connected to.
2

You approve

A connect card appears in the conversation. One click signs you in or accepts the key.
3

The agent continues

With access in place, it finishes the job, using the credential securely through the proxy.

The agent never sees your secrets

When you connect a service, the credential is stored securely and injected at the network layer: a proxy attaches it to the agent’s outbound requests on the wire. The agent acts on your behalf, but the raw token never appears in its prompts, its logs, or its memory. You grant real access without handing the model your keys.

Ways to connect

Most of the time the agent prompts you and you approve. To set something up yourself:

Connect a service

One-click authorization for supported services, with tokens refreshed automatically.

Supported integrations

See the services your agent can connect to today.

API keys & secrets

Give the agent a key for a service, stored securely.

GitHub

Give your agent its own GitHub identity to read and write code.

Permissioning

How credentials are scoped and injected without ever leaking.

Connect your first service

Walk through the authorization flow.