conn_ plus 16 characters. For the steps, see Connect an outside service.
An MCP server is a separate object, managed with the mcp CLI group. An MCP server can point at a connection with --connection-id. Signing in to an MCP server by OAuth also makes a connection. Its integration.id is mcp-server:<id> and its auth kind is mcp_oauth. See Add an MCP server.
States
Create returns the existing connection when one with the same service, owner and account label is already
active.
Auth kinds
Setup status
Create and reauthorize return aconnection_setup_result. Its status is connected or human_required.
Fields
The connection, fromGET /api/v1/connections/:id:
string
required
Always
connection.string
required
Connection id,
conn_ prefix.object
required
The service it signs in to.
object
required
Who owns it.
string
required
Your label for the account. May be empty.
string
required
pending, active, expired or revoked.string[]
required
Scopes the provider granted. May be empty.
string
Last runtime use, ISO 8601. Null when never used.
string
required
ISO 8601.
string
required
ISO 8601.
object
required
Auth facts. Never the secret values.
string[]
required
mcp, native or both.object
required
How the token reaches a run.
local is device_injection and cloud is network_broker.GET /api/v1/connections returns rows without auth, availableSurfaces and runtimeDelivery. The list envelope has hasMore, nextCursor, returnedCount and totalCount.
CLI
API
You see connections you own and connections linked to the workspace. Others return
404. ownerType is required, but the server does not use it. An agent can list, get and revoke.
Errors
These codes arrive in anerror object with code, message and details. That object has no type or requestId.
See API errors for the shared codes.
Limits
- A pending sign-in lasts 10 minutes. After that, start it again.
- The OAuth callback takes 10 requests per minute from one IP address.
- A list page holds 1 to 100 connections, 25 by default.
qon the list is at most 200 characters.
Connect an outside service
Sign in to a service from the dashboard or CLI.
Add an MCP server
Add a server by URL or command, the separate
mcp object.Secret
Store keys that are not tied to a catalog service.
Run
The runs that use a connection’s token.