How does a connector authenticate?

Through OAuth on a hosted consent page or an API key you enter there. Connections are per agent or per user, and tokens never enter the sandbox.

When you connect a system, you either approve an OAuth consent screen or paste an API key on a hosted page; either way the secret is stored by the connector service, not typed into a prompt. A connection belongs to the agent or the person who made it, so an agent acting for you uses your access and nothing broader.

At run time the sandbox calls the connector through the Context server, which brokers the credential per action. The sandbox never sees the token, and the destination system's own permissions still apply to every call.

Written for it and security, developers. Last reviewed 2026-09-15.

Still need an answer?

Tell us what you were looking for and we reply within one business day.

Contact the team →

Running a security review?

Documents, controls, and the request form live in the Trust Center.

Open the Trust Center →

Something to report?

Security findings go straight to the people who fix them.

security@context.ai