Auth boundary
OAuth, signed webhooks, SAML/SCIM, PAT, and BYOK keys stay credential-gated. This page lists names and scopes, not secret values.
Public setup guidance for connector auth, scopes, mapping, sync behavior, webhooks, verification, troubleshooting, and rollback. Runtime connection health lives in Settings -> Integrations.
OAuth, signed webhooks, SAML/SCIM, PAT, and BYOK keys stay credential-gated. This page lists names and scopes, not secret values.
Use Settings -> Integrations to view connected, disconnected, disabled, preview, retry, and sync-log state.
Docs and analytics must not contain provider account ids, OAuth codes, token prefixes, webhook URLs, or provider payload bodies.
Every connector should be tested first in sandbox mode with scope review, callback validation, sync proof, and rollback rehearsal.
The hub can show local sync evidence rows, recent/stale posture, and blocked Gmail polling without returning provider objects, payloads, or live upstream responses.
Runtime health can show connected or ready after configuration is complete.
The adapter is production-shaped, but deployment configuration is required.
The setup, mapping, and health contract are visible before broad provider proof.
Atlas has an admission/control-plane contract; sandbox or live proof is still gated.
Messaging
Developer
Calendar
Workspace suite
Calendar
Work management
Collaboration
Meetings
Work management
Developer
Knowledge
Knowledge
CRM
CRM
E-signature
E-signature
E-signature
E-signature
AI
Identity
Platform
Storage
Storage
Storage
Billing
Growth Suite
Business ops
Messaging command and notification routing.
Workspace, Gmail, and Calendar setup paths.
Mailbox authorization, history, and disconnect readiness.
Calendar source, push, and write-back proof gates.
Teams, Outlook, Calendar, and OneDrive readiness.
Teams collaboration under the Microsoft Graph setup path.
Meeting connector setup and webhook proof contract.
CRM object sync and Growth Suite provider admission.
CRM timeline, pipeline, and workflow setup readiness.
Work-management issue mapping and signed webhook setup.
Team mapping, status, connect, disconnect, and sync-now contract.
Repository installation, webhook, PR, and issue evidence.
Merge request and project event proof gates.
Workspace knowledge and database mapping readiness.
Knowledge base indexing and permission mapping readiness.
Storage OAuth, file metadata, and webhook setup.
Enterprise storage mapping and event proof gates.
Microsoft storage and Graph change notification setup.
Billing event destination, signature, and replay setup.
Envelope status, Connect callbacks, and audit proof gates.
Agreement routing and PDF/e-sign provider admission.
E-signature workflow and callback setup readiness.
Contract template, signing, and document workflow readiness.
AI provider activation via concrete no-key setup group.
Provider setup: OpenAI
AI provider activation via concrete no-key setup group.
Provider setup: Gemini
AI provider activation via concrete no-key setup group.
Provider setup: Anthropic
Messaging
Events, slash commands, notifications, reminders, and Slack action routing.
Runtime status remains in Settings -> Integrations.
SLACK_CLIENT_IDSLACK_CLIENT_SECRETSLACK_SIGNING_SECRETSLACK_TOKEN_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profilecommandschat:writechannels:readusers:read.emailDeveloper
Repository installation, webhook ingestion, task links, and PR/issue evidence.
Runtime status remains in Settings -> Integrations.
GITHUB_APP_IDGITHUB_APP_PRIVATE_KEYGITHUB_APP_WEBHOOK_SECRETGITHUB_APP_CLIENT_IDGITHUB_APP_CLIENT_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileissuespull_requestsmetadatawebhooksPer-user OAuth, mailbox status, disconnect, token refresh, and safe callback handling.
Runtime status remains in Settings -> Integrations.
GMAIL_CLIENT_IDGMAIL_CLIENT_SECRETGMAIL_REDIRECT_URIGMAIL_TOKEN_SECRETGMAIL_PUBSUB_TOPIC_NAMEOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileopenidemailprofilehttps://www.googleapis.com/auth/gmail.readonlyhttps://www.googleapis.com/auth/gmail.modifyCalendar
Calendar OAuth, external event reads, planning overlays, and morning briefing context.
Runtime status remains in Settings -> Integrations.
GOOGLE_OAUTH_CLIENT_IDGOOGLE_OAUTH_CLIENT_SECRETCALENDAR_TOKEN_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profilecalendar.readonlyopenidemailprofileWorkspace suite
Workspace-wide Gmail, Calendar, Drive, Docs, and admin-domain mapping setup for enterprise collaboration.
Runtime status remains in Settings -> Integrations.
GOOGLE_WORKSPACE_CLIENT_IDGOOGLE_WORKSPACE_CLIENT_SECRETGOOGLE_WORKSPACE_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileopenidemailprofilehttps://www.googleapis.com/auth/gmail.readonlyhttps://www.googleapis.com/auth/calendar.readonlyhttps://www.googleapis.com/auth/drive.metadata.readonlyCalendar
Outlook calendar reads through Microsoft Graph for planning and availability.
Runtime status remains in Settings -> Integrations.
MICROSOFT_OAUTH_CLIENT_IDMICROSOFT_OAUTH_CLIENT_SECRETCALENDAR_TOKEN_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileUser.ReadCalendars.Readoffline_accessWork management
OAuth-backed Linear GraphQL issue and team operations through the shared connector store.
Runtime status remains in Settings -> Integrations.
LINEAR_CLIENT_IDLINEAR_CLIENT_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profilereadwriteCollaboration
Microsoft Graph OAuth, Outlook mail, and Teams read/write operations.
Runtime status remains in Settings -> Integrations.
MICROSOFT_OAUTH_CLIENT_IDMICROSOFT_OAUTH_CLIENT_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileoffline_accessUser.ReadMail.ReadMail.SendTeam.ReadBasic.AllChannel.ReadBasic.AllChannelMessage.Read.AllChannelMessage.SendChatMessage.SendMeetings
Meeting, webinar, recording, and event-subscription setup tracked through the connector hub.
Runtime status remains in Settings -> Integrations.
ZOOM_CLIENT_IDZOOM_CLIENT_SECRETZOOM_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profilemeeting:readwebinar:readrecording:readuser:readWork management
Issue, project, sprint, and status mapping setup for work intake and delivery evidence.
Runtime status remains in Settings -> Integrations.
JIRA_CLIENT_IDJIRA_CLIENT_SECRETJIRA_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileread:jira-workwrite:jira-workread:jira-useroffline_accessDeveloper
Group, project, merge request, issue, and pipeline evidence setup for engineering workflows.
Runtime status remains in Settings -> Integrations.
GITLAB_CLIENT_IDGITLAB_CLIENT_SECRETGITLAB_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileapiread_userread_repositoryKnowledge
Workspace pages, databases, owners, and knowledge references prepared for project context.
Runtime status remains in Settings -> Integrations.
NOTION_CLIENT_IDNOTION_CLIENT_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileread_contentupdate_contentread_userKnowledge
Space, page, comment, and knowledge-base mapping setup for project and customer evidence.
Runtime status remains in Settings -> Integrations.
ATLASSIAN_CLIENT_IDATLASSIAN_CLIENT_SECRETATLASSIAN_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileread:confluence-content.allwrite:confluence-contentread:meCRM
Connected-app, CRM object, account/contact/opportunity, sharing, and webhook proof gates for Growth Suite sync.
Runtime status remains in Settings -> Integrations.
SALESFORCE_CLIENT_IDSALESFORCE_CLIENT_SECRETSALESFORCE_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileapirefresh_tokenoffline_accesswebCRM
HubSpot app scopes, CRM objects, deal pipeline, timeline, and webhook proof gates for Growth Suite sync.
Runtime status remains in Settings -> Integrations.
HUBSPOT_CLIENT_IDHUBSPOT_CLIENT_SECRETHUBSPOT_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profilecrm.objects.contacts.readcrm.objects.companies.readcrm.objects.deals.readE-signature
DocuSign JWT/OAuth setup, envelope status, Connect callbacks, signing evidence, and audit proof gates.
Runtime status remains in Settings -> Integrations.
DOCUSIGN_INTEGRATION_KEYDOCUSIGN_USER_IDDOCUSIGN_PRIVATE_KEYDOCUSIGN_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profilesignatureimpersonationE-signature
Adobe Acrobat Sign OAuth, agreement events, embedded signing, and webhook proof gates.
Runtime status remains in Settings -> Integrations.
ADOBE_ACROBAT_SIGN_CLIENT_IDADOBE_ACROBAT_SIGN_CLIENT_SECRETADOBE_ACROBAT_SIGN_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileagreement_readagreement_writeuser_readE-signature
Dropbox Sign embedded signing, callback sequencing, signature requests, and audit proof gates.
Runtime status remains in Settings -> Integrations.
DROPBOX_SIGN_CLIENT_IDDROPBOX_SIGN_API_KEYDROPBOX_SIGN_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profilesignature_requestaccounttemplateE-signature
PandaDoc document send, embedded signing session, template, and webhook proof gates.
Runtime status remains in Settings -> Integrations.
PANDADOC_CLIENT_IDPANDADOC_API_KEYPANDADOC_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profiledocuments:readdocuments:writetemplates:readAI
Provider mode, BYOK key posture, fallback chain, model catalog, cost, and latency tracking.
Runtime status remains in Settings -> Integrations.
OPENAI_API_KEYANTHROPIC_API_KEYGEMINI_API_KEYAZURE_OPENAI_API_KEYAZURE_OPENAI_ENDPOINTAZURE_OPENAI_API_VERSIONOLLAMA_BASE_URLAI_PROVIDER_KEY_ENCRYPTION_SECRETATLAS_AI_PROVIDER_PROOF_FILEATLAS_AI_PROVIDER_PROOF_HMAC_SECRETProvider routing mode, fallback order, usage ledger retention, and credentialed replay proofmodel inferenceusage telemetryfallback routingIdentity
Enterprise SAML login, SCIM provisioning, deprovisioning, and audit evidence.
Runtime identity setup and SCIM health/activity live in Settings -> Security.
IdP Entity ID, SSO URL, x509 certificate, optional SP private keyAtlas ACS URL and metadata URL copied into the providerSCIM base URL, one-time bearer token, token rotation owner, and pilot user groupAttribute mapping for userName, name.givenName, name.familyName, externalId, and activeOptional JSON provider-log export for transient preview of operation and failure bucketsidentitygroupsusersprovisioningPlatform
Outbound events, HMAC signatures, retries, delivery logs, and scoped API tokens.
Runtime status remains in Settings -> Integrations.
Subscription name and allowed event typesReceiver endpoint URL entered in Settings -> WebhooksOne-time generated per-subscription signing secretRetry policy, replay workflow, owner approval, and rollback notesevents:readwebhooks:writetokens:manageStorage
Dropbox OAuth, folder mapping, artifact storage, webhook, and permission proof setup.
Runtime status remains in Settings -> Integrations.
DROPBOX_CLIENT_IDDROPBOX_CLIENT_SECRETDROPBOX_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profilefiles.metadata.readfiles.content.readsharing.readStorage
Box OAuth, enterprise app authorization, folder mapping, and webhook proof setup.
Runtime status remains in Settings -> Integrations.
BOX_CLIENT_IDBOX_CLIENT_SECRETBOX_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileroot_readwritemanage_webhookStorage
OneDrive and SharePoint file metadata, permission mapping, and Microsoft Graph change notification setup.
Runtime status remains in Settings -> Integrations.
MICROSOFT_OAUTH_CLIENT_IDMICROSOFT_OAUTH_CLIENT_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profileFiles.Read.AllSites.Read.Alloffline_accessBilling
Stripe customer, subscription, invoice, charge, event destination, signature, and replay setup.
Runtime status remains in Settings -> Integrations.
STRIPE_SECRET_KEYSTRIPE_WEBHOOK_SECRETOAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profilecustomerssubscriptionsinvoiceswebhooksGrowth Suite
Provider admission, sandbox/live proof boundaries, signing, CRM, PDF, and audit readiness.
Runtime status remains in Settings -> Integrations.
GROWTH_SUITE_*DOCUSIGN_*ADOBE_*DROPBOX_SIGN_*PANDADOC_*OAuth redirect URI or provider callback URLWebhook signing secret or provider event secret when the connector supports eventsSandbox/live mode, tenant scope, owner approval, and field mapping profilecrm objectssigning envelopesPDF serviceswebhooksBusiness ops
Storage and billing connectors are tracked in the setup backlog with credential gates.
Runtime status remains in Settings -> Integrations.
Dropbox: DROPBOX_CLIENT_ID, DROPBOX_CLIENT_SECRET, DROPBOX_WEBHOOK_SECRETBox: BOX_CLIENT_ID, BOX_CLIENT_SECRET, BOX_WEBHOOK_SECRETOneDrive: MICROSOFT_OAUTH_CLIENT_ID, MICROSOFT_OAUTH_CLIENT_SECRETStripe: STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRETProvider-specific OAuth redirect URI or callback URLProvider webhook signing secret, event destination, or Graph subscription evidenceSandbox/live mode, tenant scope, owner approval, and field mapping profilefilesbillingwebhooks