Integrations
Give Agents controlled access to external tools through Agent Secrets, Shared Credentials, scoped OAuth access, and Runtime-materialized Skills.
- For
- Organization administrators and Agent operators
Tool Integration credential boundaries
This section covers tool Integrations an Agent uses during Runtime execution. It does not cover Slack, Microsoft Teams, Telegram, or Discord message transport.
- Agent Secrets are encrypted, Agent-owned credentials for tool Integrations.
- Shared Credentials are encrypted, Organization-owned tool credentials that permitted Agents may attach.
- Communication Connection credentials belong to an Agent-subordinate Connection, are validated by a Platform Plugin, and never become Runtime Integration secrets.
- Application deployment secrets are a separate operational credential class.
According to the provider, Runtime materialization can supply environment, configuration, aai-cli profiles, gog setup, and eligible bundled Skills.
Slack tool access: a Slack Agent Secret lets a Runtime Skill perform Slack tool operations. Slack Communication Connection credentials let Communications receive and send Agent messages. Configuring one does not configure the other.
Recommended
Connect Integrations and Credentials Safely
Configure tool Integrations with Agent Secrets, Shared Credentials, OAuth access, exact Skill requirements, and least-privilege Runtime materialization.
GuideAvailable documentation
Connect Integrations and Credentials Safely
Configure tool Integrations with Agent Secrets, Shared Credentials, OAuth access, exact Skill requirements, and least-privilege Runtime materialization.
Manage Agent credentials
Add, replace, validate, attach, and remove the encrypted Agent Secrets and Shared Credentials used by Runtime tool Integrations.
Use shared credentials
Use Organization-owned Shared Credentials for eligible manual-entry tool providers; they are not Communication Connection credentials.
Connect Google Workspace
Use one service-scoped OAuth credential for selected Gmail, Calendar, Drive, and Sheets access.
Connect GitHub
Configure GitHub tool-provider credentials with least-privilege repository access and Runtime-materialized profiles and Skills.
Connect Jira
Configure Jira Cloud tool-provider credentials with scoped access and the minimum required project permissions.
Connect Confluence
Configure Confluence Cloud tool-provider credentials with scoped access to selected spaces.
Connect Bitbucket
Configure Bitbucket Cloud tool-provider credentials with repository profiles, the isolated aai-bitbucket Skill, and aai-cli commands.
Connect Zoho
Configure Zoho Mail tool-provider OAuth credentials with the isolated aai-zoho-mail Skill and aai-cli email commands.
Connect SharePoint
Connect Microsoft SharePoint to an Agent Barn Agent via the Microsoft Teams app registration using delegated OAuth PKCE public client flows.
Connect Pipedrive
Configure Pipedrive tool-provider credentials with an optional company domain, generated profile, isolated Skill, and aai-cli CRM commands.
Connect Firecrawl
Use the platform Firecrawl capability or a per-Agent override for Runtime web search and page fetching.
Looking for communication platforms?
To receive and send messages through Slack, Microsoft Teams, Telegram, or Discord, add a Communication Connection. Platform settings, provider credentials, access policies, health, and Delivery state are managed separately from tool Integrations.