> ## Documentation Index
> Fetch the complete documentation index at: https://veryfront.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Integrations API

> How service definitions, authorized connections, tools, storage, and channels provide external access.

The Integrations API connects projects and users to external services. An integration describes the service; a connection identifies an authorized account; tools perform actions through that account.

## Integrations and connections

Project configuration determines how an integration is enabled. Shared project connections and private user connections have different visibility. Access to a project does not automatically grant access to every private connection.

For example, a support agent's ticket-reading tool needs an authorized account in the ticket service. Attaching the tool to the agent does not supply that authorization. Source-defined agent capabilities belong to the [Agents API](/docs/cloud/apis/agents).

## Authentication models

The provider determines how access is established. This authorization is separate from the Veryfront credentials described in [Authentication and access](/docs/cloud/apis/identity-and-access).

| Model | Source of provider access |
| - | - |
| OAuth 2.0 | A user authorizes access on the provider's consent screen. Supported refresh flows renew tokens. |
| OAuth client credentials | Project credentials obtain machine-to-machine tokens without a user redirect. |
| API key | A project environment variable supplies a key sent in a header or query parameter. |
| Basic auth | Project environment variables supply a username and password pair. Some providers use an API key as the username. |

The [integration catalog](/docs/cloud/integration-catalog) lists the model, exact credential variables, available tools, and provider-specific setup.

## Managed and custom OAuth apps

For user-authorized OAuth, a managed app can allow connection without creating a provider app for the project. Custom OAuth credentials take precedence: project integration credentials first, then project environment variables, then the managed app.

A custom app can be needed for consent branding, provider verification, or additional scopes. A failed connection can also indicate a callback URL, scope, or permission problem; the returned error identifies what to investigate.

## Tools, storage, and channels

Tools act with the selected connection's permissions. Write tools change external state, so connection verification typically starts with a read operation. The tool reference describes the side effects and required inputs.

Connected storage operations browse and manage provider files. Importing a file creates an upload managed through the [Projects API](/docs/cloud/apis/projects); it does not automatically index that file for knowledge retrieval.

A channel binding connects a messaging platform to a project assistant. Configuration and test-message operations manage the binding, while delivery endpoints receive provider events using provider-specific authentication.

## Availability

Some integrations are enabled by default; experimental integrations require project enablement through `VERYFRONT_EXPERIMENTAL_INTEGRATIONS`. The value can be `all` or a comma-separated list of integration names.

Availability, configured credentials, and permission to execute a tool are separate checks. Review all three when a tool is missing or a call is denied.

## Get started

[Connect an integration](/docs/cloud/integrations) explains project setup and verification. [Set up Salesforce](/docs/code/guides/integrations/salesforce) covers Salesforce-specific authorization.

## API references

* [REST endpoints](/docs/cloud/rest/apis/integrations-api)
* [GraphQL queries and mutations](/docs/cloud/graphql/apis/integrations)
* [MCP tools](/docs/cloud/mcp/apis/integrations)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.