ConnectorsYour apps and services, connected to agents
Give agents the tools your team uses
Each person connects their own accounts, admins register internal services, and you decide which tools every agent may call.
Connect your accounts
Manage connectorsConnect the tools your agents can use on your behalf. CLI tools like GitHub and AWS are connected in Settings → Connectors.
Apps
Connect your accounts
Connect the tools your agents can use on your behalf. CLI tools like GitHub and AWS are connected in Settings → Connectors.
Apps
Connect with your own account
Each person signs in to their own Slack, Google Workspace, Salesforce or GitHub, and agents act with that account.
Connect your accounts
Manage connectorsConnect the tools your agents can use on your behalf. CLI tools like GitHub and AWS are connected in Settings → Connectors.
Apps
Register the services you run
An admin describes an internal HTTP or MCP service once, with its sign-in and its tools.
Register Connector
Define a connector with its tools. Form and YAML edit the same manifest.
- 1Connector
- 2Access
- 3Authentication
- 4Tools
Choose the tools each agent calls
Mark any tool Available or Blocked for a person or an agent, and the block is enforced on every call.
Salesforce
ConnectedConnect the apps you already use
One directory holds every app your deployment offers. Each person connects their own account, so an agent reaches only what that person can.
Connect your accounts
Manage connectorsConnect the tools your agents can use on your behalf. CLI tools like GitHub and AWS are connected in Settings → Connectors.
Apps
Connect your accounts
Connect the tools your agents can use on your behalf. CLI tools like GitHub and AWS are connected in Settings → Connectors.
Apps
Register your own services
Turn an internal API or MCP server into a connector your agents can call, without writing an integration.
Register Connector
Define a connector with its tools. Form and YAML edit the same manifest.
- 1Connector
- 2Access
- 3Authentication
- 4Tools
Register Connector
Define a connector with its tools. Form and YAML edit the same manifest.
- 1
- 2Access
- 3
- 4
Decide what every agent may call
A connector's Tools tab lists each tool it offers, for one person or one agent at a time.
Salesforce
ConnectedSalesforce
ConnectedSecure by default
No standing secret is placed in a sandbox, and every connection an agent makes crosses a checkpoint outside it.
Secrets
New secretKeys your agents and applets can use to call third-party APIs. Encrypted on save, sent only to the hosts you allow, never shown again.
- FactSet API (production)Organization · Bearer · api.factset.com
- Visibility
- Organization · Any applet in the org can be bound to it
- Auth
- Bearer
Allowed hostsThe key may only ever be sent to these hosts, a bare public hostname, e.g. api.stripe.com.api.factset.comAny hostLet the key be sent to any public host, instead of pinning it to a specific list. - Bloomberg data licenceOrganization · Header · api.bloomberg.com, dlws.bloomberg.com
- Weather APIWorkspace · Bearer · Any public host
Secrets
New secretKeys your agents and applets can use to call third-party APIs. Encrypted on save, sent only to the hosts you allow, never shown again.
- FactSet API (production)Organization · Bearer · api.factset.com
- Visibility
- Organization · Any applet in the org can be bound to it
- Auth
- Bearer
Allowed hostsThe key may only ever be sent to these hosts, a bare public hostname, e.g. api.stripe.com.api.factset.com - Bloomberg data licenceOrganization · Header · api.bloomberg.com, dlws.bloomberg.com
- Weather APIWorkspace · Bearer · Any public host
Connect once, use it everywhere
An account you connect works from the web, the phone apps, the desktop app and the terminal, with the same permissions on each.
Connect your accounts
Manage connectorsConnect the tools your agents can use on your behalf. CLI tools like GitHub and AWS are connected in Settings → Connectors.
Apps
Connect your accounts
Connect the tools your agents can use on your behalf. CLI tools like GitHub and AWS are connected in Settings → Connectors.
Apps
Work across the Context platform
Connectors feed every product that runs an agent, from the task composer to the API.
- UnifyConnectors, Slack channels and search across your files, as one layer your agents read from.
- API and MCPCall Context from your own code, or reach Context from the AI tools you already use.
- Audit logAgent actions, the decisions on them and every outbound connection, with who asked and for whom.
- Secure VMThe sandbox each task runs in, where connector calls leave through one checkpoint.
Home
- q3-portfolio-review.pptx1h ago
- q3-valuation-bridge.xlsx2h ago
- q3-portfolio-updates.docx3h ago
- lp-letter.pptx5h ago
Home
- q3-portfolio-review.pptx1h ago
- q3-valuation-bridge.xlsx2h ago
- q3-portfolio-updates.docx3h ago
- lp-letter.pptx5h ago
Deploy in your environment
Run connectors inside your own deployment, where they can reach internal services over a private network.
- Inside your deploymentConnector calls run on your own Kubernetes cluster, on Amazon EKS or Azure AKS.
- Private network routesRoute a connector to an internal service over a private network instead of the internet.
- Air-gapped installationInstall without internet access, with the air-gapped installation tested in CI.
- Your identity providerSign people in with SAML or OIDC and provision them with SCIM.
Context runs in production at Qualcomm. Read the case study
- Amazon EKS
- Azure AKS
- Air-gapped
Connectors are included in every Context workspace, including the Free plan.
- Free$0Includes Connectors
- Plus$20Per person per month
- EnterpriseCustomEnterprise deployments run in your own cloud.Talk to us about a plan
Questions
Whose account does an agent use?
The account of the person it works for. Each person connects their own accounts, so an agent reaches only what that person can.
Can we connect an internal service?
Yes. An admin registers it as an HTTP or MCP connector, with a form or as YAML, and chooses whether the organization, specific workspaces or only they can use it.
Which sign-in methods does a custom connector support?
No auth, a bearer token, an API key header, an HMAC-SHA256 signature or OAuth 2, with presets for Microsoft Entra, Google, Okta and any OIDC provider.
Can we stop an agent from calling one tool?
Yes. On the connector's Tools tab, mark the tool Blocked for that agent or person. The call is refused, and the tool is left out of what the agent is given.
What happens when a service changes its tools?
A banner on the connector's Tools tab says how many tools changed since you last accepted the tool set, and the Changed filter lists each new, changed or removed tool. Accept current tools records the reviewed set.
Do agents ever see our API keys?
No. Credentials are added at the edge outside the sandbox after an authorization check, and each stored secret is pinned to the hosts it may be sent to.



