# Connectors

Connect apps, MCP servers and APIs to a goal, choose who connects, and decide what each tool may do.

Canonical page: https://app.auto-lab.ai/docs/connect/connectors

A connector lets the goal's agent work in an outside app or service: read a Gmail inbox, update a CRM, call your own API. You connect it once, and the agent uses its tools as it works. Auto Lab keeps the account's credentials and makes each call on the agent's behalf.

## Where connectors live

Open **Brain › Connectors**. The same page is at **Settings › Connectors**. It has four tabs.

| Tab | What it shows |
|---|---|
| **Discovery** | The app catalogue, grouped by category |
| **All** | The same catalogue as one list |
| **Connected** | The connectors this goal already has |
| **Channels** | Slack, Teams, iMessage and email. See [Channels](/docs/connect/channels) |

Adding or changing a connector needs permission to manage the goal's connectors. Without it the page is read-only.

If your deployment has no app catalogue, **Discovery** and **All** do not appear, and an empty **Connected** tab says "Connector discovery isn't set up on this deployment". You can still add a custom connector and connect channels.

## Connect an app from the catalogue

### Pick the app
In **Brain › Connectors › Discovery**, search for the app or open a category, then select the app.

### Choose who connects
Under **Authorization owner**, choose **Project** so everyone in the goal shares one connection, or **User** so each person connects their own account. This choice is fixed once the connector exists. See [Shared or personal connections](#shared-or-personal-connections).

### Add the connector
Select **Add connector**. Auto Lab adds it to the goal manifest.

### Sign in to the app
For a shared connection, select **Connect now**. A window opens on the app's own sign-in page. Approve access there. For a personal connection, each person connects their own account in **Personal settings › Connectors**.

## Connect during setup or from Chat

You rarely need to open the Connectors page first.

- **During setup.** The **Works with** part of the goal brief lists the tools you named. A catalogue app shows **Connect**, a public website shows **Ready**, and a site behind a login shows **Sign in**. Apps connected here are shared with the goal. While you set up, the agent only reads from connected apps. Nothing is written before you launch.
- **In Chat.** When the agent needs an app that is not connected, it posts a **Connect {app}** card. **Connect** opens the connection page in a new tab. Once the app is connected, the thread carries on with what you asked.
- **Without permission.** If you cannot manage connectors, the setup card says **Ask an admin to connect {app}**. When the goal already has that connector, **Copy link** gives you a connect link to send them.

A connect link opens without signing in to Auto Lab, so the person who owns the account can use it. Anyone who has the link can connect an account to the goal, so share it like a password. It lasts seven days by default.

## Connect an MCP server or your own API

Select **New › Add a custom connector**. Choose the **Provider**: **OpenAPI**, **Postman**, **GraphQL**, **MCP** or **HTTP**. Give the address of the spec, the server or the API. Under **Auth**, **Auto-detect** reads the sign-in method from the source. You can also pick one yourself, such as **Bearer**, **API key** or **OAuth 2.0**.

After you add the connector, open it and select **Add credential**.

- **An API key or token.** Use the **Static credential** tab and paste the value. Auto Lab encrypts it and attaches it to every call.
- **An MCP server that uses OAuth.** Use the **OAuth 2.0** tab. Auto Lab reads the server's sign-in settings first. If it shows **One-click OAuth 2.1 available**, select the connect button and approve at the provider. There is no client ID to create. If it says **This server needs a pre-registered OAuth app**, create an app at the provider, register the redirect address below, and paste its client ID.

```text
https://api.auto-lab.ai/v1/connectors/oauth2/callback
```

**New › Create in chat** is the other route: an agent sets the connector up for you and opens a change request to review.

## Shared or personal connections

| | Shared (**Project**) | Personal (**User**) |
|---|---|---|
| Whose account | One account for the whole goal | Each person's own account |
| Who connects it | Someone who manages connectors | Each person, for themselves |
| Good for | A team inbox, a shared CRM, a company data source | Your own calendar or mailbox, where the agent should act as you |

People connect their personal accounts in **Personal settings › Connectors**. Pick the organization and the goal, then use **Connect account** under **Your connections**. You can also select **Add my own** on the connector's **Accounts** tab. Each person's credentials stay with their own Auto Lab account. A connect link from Chat only works for shared connections.

## Choose which agents can use a connector

An agent can only call a connector its agent settings allow. Open **Brain › Agents**, select the agent, and set **Connectors** to **All**, **Pick** or **None**. With **Pick**, you can also mark a connector **Required**. A session for that agent then does not start until the connector has a usable connection.

## Set what each tool may do

Open the connector and select the **Tools** tab. Every tool has four settings.

| Setting | What happens |
|---|---|
| **Default** | The tool follows the goal's delegation setting and your **Global rules** |
| **Allow** | The tool runs without asking |
| **Ask** | The call waits for your approval |
| **Block** | The tool never runs |

**Set all** changes a whole group at once. Under **Advanced**, **Ask before every use** makes every tool of this connector ask, reads included. Use it for mail, files or anything where reading is itself sensitive. **Pattern rules** cover many tools with one pattern, such as `delete_*`.

**Global rules**, next to the tabs on the Connectors page, apply to every connector and are checked first. A tool decided by a global rule is locked on the **Tools** tab.

The **Delegation** dial on the Overview sets what **Default** means. Setup asks the same question under **On its own**.

| Delegation | Tools left on **Default** |
|---|---|
| **Ask first** (setup: **Asks before acting**) | Every connector call waits for approval, reads included. This overrides the tool settings |
| **Within policy** (setup: **Acts within your rules**) | Your rules decide. With no rule, reads run and writes and deletes wait for approval |
| **Act freely** (setup: **Acts on its own**) | Reads and writes run. Connectors set to **Ask before every use** still ask |

A call that waits appears as an approval card in Chat and on the Overview under **Needs you**. See [Approvals and autonomy](/docs/goals/approvals).

## When a call is refused

When the agent cannot make a call, it tells you in one line and offers another way. The usual reasons:

| Reason | What to do |
|---|---|
| The agent's settings do not include this connector | Add it under **Brain › Agents** |
| No account is connected | Connect one, or ask someone who can |
| A tool setting or a global rule blocks the tool | Change the rule if the agent should use it |
| You denied the approval | Nothing. The call did not run |

## Where credentials live

A connector's credentials stay on Auto Lab's servers, encrypted. When the agent calls a tool, Auto Lab attaches the credential and makes the call. The credential never enters the agent's machine, and the agent never sees it. Keys the agent's own code needs work differently. See [Secrets](/docs/connect/secrets).

## Remove a connector

Open the connector, select the **Settings** tab, then **Remove connector**. Its saved connections, agent assignments and tool rules are deleted too, and this cannot be undone. To switch a connector between shared and personal, remove it and add it again.
