Your agent does the setup
When an agent reaches a task that needs access it doesn’t have, it asks for exactly what it needs, right then. You approve, and it carries on.1
The agent needs access
It hits a task requiring a service it isn’t connected to.
2
You approve
A connect card appears in the conversation. One click signs you in or accepts the key.
3
The agent continues
With access in place, it finishes the job, using the credential securely through the proxy.
The agent never sees your secrets
When you connect a service, the credential is stored securely and injected at the network layer: a proxy attaches it to the agent’s outbound requests on the wire. The agent acts on your behalf, but the raw token never appears in its prompts, its logs, or its memory. You grant real access without handing the model your keys.Ways to connect
Most of the time the agent prompts you and you approve. To set something up yourself:Connect a service
One-click authorization for supported services, with tokens refreshed automatically.
Supported integrations
See the services your agent can connect to today.
API keys & secrets
Give the agent a key for a service, stored securely.
GitHub
Give your agent its own GitHub identity to read and write code.
Permissioning
How credentials are scoped and injected without ever leaking.
Connect your first service
Walk through the authorization flow.