Skip to main content
A connection is your signed-in link to an outside service, such as Linear, Notion or HubSpot. You sign in once. Pinework stores the token, and your agents use the service’s tools in their runs. The service’s catalog entry decides how you sign in. Most use OAuth in a popup. Some ask for an API key. A few need no sign-in at all.

Before you start

  • You need a Pinework account and a workspace. An agent cannot create a connection. Only a signed-in person can.
  • Have an account at the outside service. For an API key service, create the key there first.
  • For the CLI tab, install the pinework CLI and run pinework login.
To connect GitHub for repos and pull requests, follow Connect GitHub instead.

Connect the service

1

Open the MCP Servers tab

In the sidebar, click Customize. Then click the MCP Servers tab.
2

Pick the service

Click Add MCP server. In the Add an MCP server dialog, type in Search the marketplace. Each row shows how it signs in: OAuth, API key, Optional API key or No sign-in.Click the service. A dialog titled Connect and the service’s name opens.
3

Sign in

Click Connect followed by the service’s name.For an OAuth service, a popup opens at the service’s sign-in page. The dialog says Waiting for you to approve access in the popup.... Approve access in the popup.For an API key service, the dialog shows one field per value the service needs. Paste the values and click Save and connect.For an optional key service, pick Connect (free) or Connect with API key.
4

Check the result

A toast says Connected to <service>. The service appears in the MCP Servers list. A service already in the list shows Added in the marketplace.

How your agents use it without the token

Pinework keeps the token or key in its own store. How the token reaches the service depends on where the run happens.
  • In a cloud run, Pinework adds the token to requests bound for that service as they leave the sandbox. The agent never reads the token. A service Pinework cannot handle this way is left out of cloud runs.
  • On your own device, Pinework hands the token to the service’s tool settings when the run starts. The token is on your machine for that run.
Pinework refreshes an OAuth token when the service allows it. See Cloud and device for where runs happen.
A connection belongs to the person who signed in. Only agents you created, and agents they created, use your connection. An agent another person created runs without this service’s tools.

Reconnect or remove a connection

A connection row shows a state when it needs you. Setup incomplete means a sign-in started and never finished. Revoked means access was withdrawn. Pinework leaves a connection out of runs until it is active again.
Click the row to open it. The dialog shows Source, Sign-in, State and Added.
  • To sign in again, click Finish setup. It shows on any connection that is not active. The sign-in dialog opens again.
  • The row of such a connection also has a Reconnect button. It opens the same sign-in dialog.
  • To stop using the service, click Remove. Pinework revokes the connection.

Troubleshooting

The popup did not open. Your browser blocked it. Click Re-open authorization window in the dialog. Authorization window was closed before completing. Try again. You closed the popup before you approved access. Click Try again. That API key didn't work. Double-check it and try again. The service refused the key. Click Try again and paste a fresh key. An agent’s run has no tools from the service. Check that the connection is active. Then check that you created the agent.

Next

Add an MCP server

Add a server that is not in the marketplace.

Secrets

How Pinework stores keys and passwords for your agents.

Cloud and device

Where runs happen and what each place can reach.

Connect GitHub

Give agents your repos and pull requests.