You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: apps/docs/content/docs/platform/connected-accounts.mdx
+13-5Lines changed: 13 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -57,7 +57,7 @@ For Search-enabled organizations, open **Settings → Integrations → People**.
57
57
58
58
Invitees can contribute accounts without joining your organization. The invitation grants access to their connection form; it does not grant access to your workspaces or workflows.
59
59
60
-
Use the invitation email in workflow lookups. For example, if you invite `alex@example.com`, **Find Organization Account** with that email and **Gmail** finds Alex's active Gmail contribution.
60
+
Use the invitation email in workflow lookups. For example, if you invite `alex@example.com`, **Find Credential Group Account** with that email and **Gmail** finds Alex's active Gmail contribution.
61
61
62
62
#### How the email is associated with a Sim user
63
63
@@ -83,17 +83,25 @@ Removing a workspace stops subsequent use of the pool. It does not recall provid
83
83
84
84
Use the **Credential** block's organization operations in an allowed workspace:
85
85
86
-
-**Find Organization Account** selects an OAuth account by invitation email and provider.
87
-
-**List Organization Accounts** returns a page of OAuth accounts, optionally filtered by email and providers.
88
-
-**Find Organization MCP Connection** selects a person's managed MCP connection by invitation email and MCP provider.
89
-
-**List Organization MCP Connections** returns a page of managed MCP connections, optionally filtered by email and provider.
86
+
-**Find Credential Group Account** selects an OAuth account by invitation email and provider.
87
+
-**List Credential Group Accounts** returns a page of OAuth accounts, optionally filtered by email and providers.
88
+
-**Find Credential Group MCP Connection** selects a person's managed MCP connection by invitation email and MCP provider.
89
+
-**List Credential Group MCP Connections** returns a page of managed MCP connections, optionally filtered by email and provider.
90
90
91
91
The organization is determined by the workflow's workspace. You do not enter a credential group ID or organization ID in the block.
92
92
93
93
The outputs are account references, without tokens. Use an OAuth `credentialId` in the corresponding integration block's credential field. For managed MCP, `credentialId` identifies the person's connection; `mcpServerId` identifies shared configuration and cannot select that person's authorization by itself.
94
94
95
95
See the [Credential block reference](/workflows/blocks/credential#organization-accounts) for inputs, outputs, pagination, and connection-event triggers.
96
96
97
+
## Named API keys
98
+
99
+
In the Credential Group's **Integrations** tab, select **Add API key**. Enter a name and an optional description explaining where invitees can get the key. The administrator defines the request; each invited person enters their own secret value in the connection form. A name such as `EXA_API_KEY` is permitted but does not create an environment variable.
100
+
101
+
Allow **API keys** for the workspaces that should use these contributions. In a workflow, **List Credential Group API Keys** returns submitted key IDs and metadata. Pass a selected ID into **Get Credential Group API Key**, then reference its `apiKey` output directly in the downstream block. See the [named API key example](/workflows/blocks/credential#named-api-keys).
102
+
103
+
People can replace or disconnect their key from their connection form. Renaming a request preserves the submissions and IDs. Removing a request deletes every submitted key for that request. Names and connection status are visible in management views; saved values are not returned to those views.
104
+
97
105
## Reconnect or stop sharing
98
106
99
107
People can open **Settings → Account → Connected accounts** to view accounts they contributed, including contributions to organizations they have not joined. **Reconnect** starts authorization again. **Disconnect** stops the organization from using that account in subsequent calls.
The **Credential block**passes account references to downstream blocks without exposing tokens. **Select Credential** and **List Credentials** use workspace OAuth credentials. When [organization connected accounts](/platform/connected-accounts) is enabled and shared with the workflow's workspace, the organization operations find or list contributed OAuth accounts and managed MCP connections.
17
+
The **Credential block**selects accounts and API keys for downstream blocks. **Select Credential** and **List Credentials** use workspace OAuth credentials. When [organization connected accounts](/platform/connected-accounts) is enabled and shared with the workflow's workspace, the Credential Group operations find or list contributed OAuth accounts, managed MCP connections, and named API keys.
18
18
19
19
<BlockPreviewtype="credential" />
20
20
21
21
<Callout>
22
-
The Credential block outputs credential **ID references**, not secrets. Downstream blocks receive the ID and resolve the actual OAuth token securely during their own execution.
22
+
OAuth and MCP operations return credential **ID references**. **List Credential Group API Keys** returns metadata and IDs. **Get Credential Group API Key** returns a usable `apiKey` value and registers it with secret provenance before releasing the output.
23
23
</Callout>
24
24
25
25
## Configuration
@@ -30,10 +30,12 @@ The **Credential block** passes account references to downstream blocks without
30
30
|---|---|
31
31
|**Select Credential**| Pick one OAuth credential and output its reference — use this to wire a single credential into downstream blocks |
32
32
|**List Credentials**| Return all OAuth credentials in the workspace as an array — use this with a ForEach loop |
33
-
|**Find Organization Account**| Find exactly one active OAuth contribution by invitation email and provider |
34
-
|**List Organization Accounts**| Return a page of active OAuth contributions, optionally filtered by email and providers |
35
-
|**Find Organization MCP Connection**| Find exactly one active managed MCP connection by invitation email and MCP provider |
36
-
|**List Organization MCP Connections**| Return a page of active managed MCP connections, optionally filtered by email and provider |
33
+
|**Find Credential Group Account**| Find exactly one active OAuth contribution by invitation email and provider |
34
+
|**List Credential Group Accounts**| Return a page of active OAuth contributions, optionally filtered by email and providers |
35
+
|**Find Credential Group MCP Connection**| Find exactly one active managed MCP connection by invitation email and MCP provider |
36
+
|**List Credential Group MCP Connections**| Return a page of active managed MCP connections, optionally filtered by email and provider |
37
+
|**List Credential Group API Keys**| Return submitted key IDs and metadata, optionally filtered by key name and invitation email |
38
+
|**Get Credential Group API Key**| Resolve the submitted key selected by an explicit credential ID |
37
39
38
40
### Credential (Select operation)
39
41
@@ -85,7 +87,7 @@ Every authorized workflow in an allowed workspace can discover active contributi
85
87
86
88
### Discover accounts by provider
87
89
88
-
1. Choose **List Organization Accounts**.
90
+
1. Choose **List Credential Group Accounts**.
89
91
2. Select a provider such as **Gmail** in **Providers**. Leave it empty to list all allowed providers.
90
92
3. Leave **Email** blank. You do not need to know an account's email to discover it.
91
93
4. Read **emails** for the provider account addresses, or **credentials** for the corresponding account references.
@@ -97,10 +99,12 @@ Multiple accounts are returned separately, including accounts contributed by the
|**List Credential Group API Keys**| — | Key name, Email, Limit, Cursor |
107
+
|**Get Credential Group API Key**| API Key Credential ID | — |
104
108
105
109
For list operations, **Limit** accepts 1–100 and defaults to 100. **Cursor** accepts the previous page's `nextCursor`.
106
110
@@ -110,17 +114,17 @@ Find operations fail unless there is exactly one active matching connection. Lis
110
114
111
115
### OAuth outputs
112
116
113
-
**Find Organization Account** returns `credentialId`, `displayName`, `providerId`, and the invitation `email`. Pass `credentialId` into the corresponding integration block's credential field in advanced mode.
117
+
**Find Credential Group Account** returns `credentialId`, `displayName`, `providerId`, and the invitation `email`. Pass `credentialId` into the corresponding integration block's credential field in advanced mode.
114
118
115
-
**List Organization Accounts** returns these account references in `credentials`, with an additional `accountEmail` field containing the email verified by the OAuth provider. The existing `email` field remains the person's invitation address, which can differ from their provider account address. An optional **Email** input continues to filter by that exact invitation address.
119
+
**List Credential Group Accounts** returns these account references in `credentials`, with an additional `accountEmail` field containing the email verified by the OAuth provider. The existing `email` field remains the person's invitation address, which can differ from their provider account address. An optional **Email** input continues to filter by that exact invitation address.
116
120
117
121
The list also returns `emails`, `count`, `hasMore`, and `nextCursor`. `emails` contains the provider account addresses on this page in the same order as `credentials`; it preserves separate accounts even when addresses repeat. `count` is the number of accounts returned on this page. Feed `credentials` into a ForEach loop and use `<loop.currentItem.credentialId>` inside the loop. To process additional pages, pass `nextCursor` into another call with the same filters while `hasMore` is true; the block does not fetch all pages automatically.
118
122
119
-
For example, name a Credential block **account**, choose **Find Organization Account**, set **Email** to `alex@example.com`, and select **Gmail**. Reference `<account.credentialId>` in a Gmail block to act using Alex's contribution.
123
+
For example, name a Credential block **account**, choose **Find Credential Group Account**, set **Email** to `alex@example.com`, and select **Gmail**. Reference `<account.credentialId>` in a Gmail block to act using Alex's contribution.
120
124
121
125
### Managed MCP outputs
122
126
123
-
**Find Organization MCP Connection** returns:
127
+
**Find Credential Group MCP Connection** returns:
124
128
125
129
| Output | Type | Description |
126
130
| --- | --- | --- |
@@ -131,12 +135,27 @@ For example, name a Credential block **account**, choose **Find Organization Acc
131
135
|`mcpServerName`|`string`| Configured MCP server name |
132
136
|`toolNames`|`json`| Tool names available to this connection |
133
137
134
-
**List Organization MCP Connections** returns these objects in `mcpConnections`, plus `count`, `hasMore`, and `nextCursor`. Pagination works the same way as for organization OAuth accounts; `nextCursor` is `null` on the last page.
138
+
**List Credential Group MCP Connections** returns these objects in `mcpConnections`, plus `count`, `hasMore`, and `nextCursor`. Pagination works the same way as for organization OAuth accounts; `nextCursor` is `null` on the last page.
135
139
136
140
<Callout>
137
141
For a managed MCP account, use the returned **`credentialId`** to select the person's connection in the MCP Tool block. **`mcpServerId`** identifies the shared provider configuration; it does not identify a person's authorization. No OAuth token or client secret is returned by the Credential block.
138
142
</Callout>
139
143
144
+
### Named API keys
145
+
146
+
An organization admin defines each key request with a name and an optional description. Each invited person supplies their own value. Names such as `Exa API key` and `EXA_API_KEY` are both accepted; the name is a label, not an environment variable. Renaming a request preserves its IDs and existing submissions.
147
+
148
+
1. Use **List Credential Group API Keys**, optionally filtering by **Key name** and **Email**. Names match case-insensitively; an unknown name fails instead of listing unrelated keys.
149
+
2. Select a returned `credentialId`, or iterate over `apiKeys` with a ForEach loop.
150
+
3. In another Credential block named **GetKey**, choose **Get Credential Group API Key**. Set **API Key Credential ID** to the selected ID, such as `<loop.currentItem.credentialId>`.
151
+
4. Use `<GetKey.apiKey>` in an integration's API-key field, or `Bearer <GetKey.apiKey>` in an HTTP Authorization header. No environment variable needs to be created.
152
+
153
+
The list returns `apiKeys`, `count`, `hasMore`, and `nextCursor`. Each entry contains `credentialId`, `optionId`, `name`, and the invitation `email`; it contains no key value. Retrieval returns those fields plus `apiKey`. Workspace access, group status, and the contributor's current connection are checked again on retrieval. The executing user is used for authorization, not to select a key automatically.
154
+
155
+
API key values are encrypted at rest and registered with secret provenance at retrieval. Retrieval fails if provenance cannot be registered. Values must be 8–4096 characters without surrounding whitespace. Removing a key request removes all submissions for that request; workflows using their IDs then fail.
156
+
157
+
The previous **Find/List Organization Account** and **Find/List Organization MCP Connection** labels now say **Credential Group**. Their stored operation IDs and existing output fields are unchanged.
158
+
140
159
## Connection-event triggers
141
160
142
161
Switch the Credential block to trigger mode to start a workflow when an account connects or a connection form is submitted. Select an **Event** and deploy the workflow in an allowed workspace.
@@ -147,7 +166,7 @@ Switch the Credential block to trigger mode to start a workflow when an account
147
166
|**Credential Reconnected**| A person reconnects an existing contribution |
148
167
|**Account Connections Submitted**| A person submits the connection form |
149
168
150
-
Events include `event`, `timestamp`, `email`, `enrollmentId`, `enrollmentStatus`, `credentialGroupId`, and `credentialGroupName`. Added and reconnected events also include account details such as `credentialId`, `provider`, and `displayName`; `mcpServerId` identifies shared configuration for an MCP connection and is `null` for an OAuth account.
169
+
Events include `event`, `timestamp`, `email`, `enrollmentId`, `enrollmentStatus`, `credentialGroupId`, and `credentialGroupName`. Adding or replacing an API key also emits the corresponding event with `provider: "api_key"` and metadata only. Added and reconnected events include account details such as `credentialId`, `provider`, and `displayName`; `mcpServerId` identifies shared configuration for an MCP connection and is `null` for an OAuth account.
151
170
152
171
Each deployed workflow that selects the event in an allowed workspace can receive it. Removing workspace access stops subsequent event delivery. Legacy **Credential Group** blocks must be replaced with the Credential block; they are not automatically converted.
0 commit comments