Skip to content
Data

Integrations

LiveContext ships a catalog of 1000+ third-party integrations, plus native nodes for email, SSH, SFTP, and SQL databases. This page shows how to connect an account once, use it in workflows and agents, keep it healthy, and add an API that is not in the catalog.

How integrations work

An integration (Slack, GitHub, Google Drive, and so on) is a collection of tools. Each tool is exactly one operation on one endpoint of the provider's API, such as “send a message” or “create an issue”. Every tool declares its HTTP method, its typed parameters, and the fields it returns.

The same tools serve two places. In a workflow, you add a tool as a step. In an agent, you put tools in its scope and the agent decides when to call them (see Agents). Either way, the tool runs with the account you connected for that integration.

The catalog holds more than 1,000 integrations. On LiveContext Cloud it is maintained for you. A self-hosted install keeps its copy up to date on its own, see Catalog updates on a self-hosted install.

Before you begin

Three Settings pages are involved. Open Settings from the sidebar, then:

Settings pages used by integrations
Settings pageWhat you do there
Credentials & VariablesConnect accounts, see their status, reconnect, rename, pick a default, and manage your custom OAuth connections.
Custom APIsRegister an API that is not in the catalog.
Platform KeysAdministrators only. Holds the OAuth apps and keys the whole install uses. On a self-hosted install, this is where the Standard connection gets its OAuth client.

Connect an account

You connect a service once, and every tool from that integration reuses the connection. The connection is called a credential.

  1. Open the list of integrations
    Go to Settings > Credentials & Variables, then open the Available Integrations tab. Search by name, or filter by authentication type. An integration you already connected carries an Added badge.
  2. Pick the integration
    Click its row. The Configure dialog opens. To set up several at once, tick their boxes and click Connect (with the count, such as Connect (3)): the dialog walks you through each one in turn.
  3. Choose how to authenticate
    Some integrations accept more than one method (for example Airtable takes OAuth2 or a bearer token, and Apollo.io an API key or OAuth2). In that case the dialog shows a picker so you choose one. Optionally set a Credential Namethat tells accounts apart, such as “Gmail (work account)”.
  4. Finish the connection
    For OAuth2, click Connect: you sign in on the provider's page and grant access, then return to LiveContext. For an API key, a bearer token, or a username and password, paste the values and click Save.
  5. Check the result
    The credential now appears on the My Credentials tab with its status. For OAuth2 credentials, a badge shows how many scopes the provider granted; hover it to see them.

You can also connect from where you need the account. In the workflow builder, an integration step without an account offers Configure Credential. In chat, when the assistant needs a service you have not connected, it shows a Connection Required card with a Connect button.

Several accounts for one service

You can hold more than one credential per integration, for example two Slack workspaces. One of them is the default: use Set as default on the My Credentials tab to change it. A tool that runs without a specific account uses the default.

A workflow step can use another account instead. In the step's inspector, pick it under Account used by this step. To choose the account at run time, turn on the toggle next to it and write an Account expression that resolves to the name (or id) of one of your credentials for that integration, for example from a table row or a split item. One workflow can then serve several accounts.

Personal and team credentials

A credential belongs to the workspace you are in when you create it. In your personal workspace it is yours alone. In an organization, all members can view, use, edit, and delete the organization's credentials. Switch workspace to see the other set. See Organizations & roles.

Authentication types

Credential authentication types
TypeWhat you provide
OAuth2Nothing to paste: you sign in on the provider and LiveContext stores the tokens it returns.
API keyA single key or token.
Bearer tokenA token sent in the Authorization header.
Basic authA username and password.
CustomSeveral fields defined by the integration (for example host, port, username, password).
NoneNothing: the endpoints are public.

Credential status and reconnecting

The My Credentials tab shows the state of each credential. You can filter it by status.

Credential statuses
StatusMeaningWhat to do
ActiveThe credential works.Nothing.
Expiring soonIt still works, but the token is close to expiry.Nothing in most cases: OAuth2 refreshes itself. Reconnect if it stays in this state.
Reconnect requiredThe provider revoked the token or it expired for good, so the stored tokens were removed.Click Reconnect next to the badge and sign in again. Hover the badge to see the reason.
Connection errorA configuration problem on the platform side, such as an invalid client secret on the OAuth app.Reconnecting alone does not help. Contact your administrator or support.

OAuth2 credentials refresh their tokens in the background, so tools keep working without you. API keys, bearer tokens, and passwords never refresh: if you rotate one at the provider, update the credential yourself. Most credentials can be renamed with the pencil icon next to their name; only the display name changes.

OAuth connections: Standard and Custom OAuth

For an OAuth2 integration, the Configure dialog offers a Connection mode with two choices.

  • Standard uses the OAuth app that LiveContext already registered with the provider. It is one click, and it can only request the permissions (scopes) that app is approved for.
  • Custom OAuthuses an OAuth app that you create in the provider's developer console. You enter its Client ID and Client Secret, and the connection can request every scope the integration supports, including scopes the Standard app cannot request. The link Need a custom OAuth app? switches to this mode, and How to get my Client ID & Secret? explains the setup.

A few integrations (Google Classroom, for example) exist only as Custom OAuth. For those, the dialog opens directly on the custom form with the notice This integration requires your own OAuth client.

The OAuth apps you registered are listed under Your custom OAuth connections on the credentials page. Deleting one disconnects only the accounts that app authorized; the dialog tells you how many first. Your Standard connections are not affected.

Providers that require PKCE (for example Airtable, Dropbox, GitLab, Microsoft Outlook and Teams, Twitter/X, and Zoom) get it automatically, so there is nothing to configure. LiveContext records the scopes the provider actually granted, not only the ones it asked for, so unticking an optional scope on the consent screen is reflected accurately.

Integrations in the workflow builder

In the builder, click Add node. Third-party apps are grouped under the Integrations category (plug icon): pick an integration, then one of its tools. The Application triggers shortcuts add ready-made starting points such as New Gmail email or Slack event.

The step's inspector shows the credential it will use, with Select a credential, Add new credential, and Manage all credentials. For some services, an administrator also provides a shared platform account: the step then offers a Credential source of My credential or Platform. With Platform you need no setup of your own, and the step bills a per-call markup that the inspector displays.

Reference a tool's result downstream like any other node output:

Referencing a tool result
ExpressionWhat it returns
{{mcp:send_message.output.ts}}The id Slack returned for the message.
{{mcp:create_issue.output.url}}The URL of the issue you just opened.

The same reference works in decision conditions, split items, and anywhere else an expression is accepted. See Expressions & variables.

Email, SSH, SFTP, and database nodes

Five protocols are native workflow nodes rather than catalog integrations. Each reads its own credential type, which you create on the same Available Integrations tab.

Protocol nodes and their credentials
NodeCredential to createWhat the credential holds
Send EmailSMTP EmailHost, port, username, password or API key, sender address and name, TLS.
Email InboxIMAP EmailThe mailbox server and login used to read and act on messages.
SSHSSHHost, port, username, and a password or a private key.
SFTPSFTPHost, port, username, and a password or a private key. Separate from SSH, so a file-transfer account does not need shell access.
DatabaseDatabase (SQL)Database type (PostgreSQL or MySQL), host, port, database name, username, password, SSL.

Send Email and Email Inbox use your default SMTP or IMAP credential automatically. The chat assistant reads and sends mail with the same two credentials, so you connect a mailbox once for both.

SSH, SFTP, and Database use a credential only when you select it on the node. They also accept the connection details typed directly into the node, but then the host and the password are stored in the workflow itself. Prefer a credential. See Node referencefor each node's parameters.

Register a custom API

If a service is not in the catalog, register it yourself. Its endpoints become tools you can add to workflows and give to agents, exactly like catalog tools.

  1. Open the form
    Go to Settings > Custom APIs and click Register API. To let the assistant fill everything in from a short description, click Register with AI instead.
  2. Describe the API
    Enter the API Name, a Description, the Base URL, and a Category. Optionally upload an Icon (an image under 2 MB). Advanced Settings holds the API Version, a Documentation URL, and rate limits in Requests/second and Requests/day.
  3. Choose the authentication
    Set Authentication Type to None, Bearer Token, API Key, Basic Auth, or OAuth2. For OAuth2, also enter the provider's Authorization URL, Token URL, and scopes: the form refuses OAuth2 without both URLs.
  4. Add the endpoints
    Click Add Endpoint once per operation. Give each a Tool Name, a Path, a Method (GET, POST, PUT, PATCH, or DELETE), and a Description. Add its Parameters, each with a Location of query, path, body, or header. Pick an Execution Mode: sync (the default), async_poll, upload, or streaming.
  5. Declare the output
    Fill in Output Schema (JSON): the fields the endpoint returns, each with a key, a type, and a description. It is required. Allowed types are string, number, boolean, datetime, object, array, and fileRef.
  6. Connect an account
    Registering defines the API; it does not connect it. If the API needs authentication, connect it from Credentials & Variables like any other integration. For OAuth2, you create your own app at the provider and enter its client id and secret when you connect.
Custom API rules
TopicBehavior
Who sees itIn your personal workspace, only you. In an organization workspace, the API belongs to the organization: members can update and delete it.
Duplicate namesRegistering a name that already exists is refused. Edit the existing API instead.
Updates change tool idsSaving an edit re-creates the API and all its tools under new ids. Workflow steps that used the old tools must be pointed at the new ones. Your stored credential is kept.
DeletingDeleting the API also removes your stored credential for it.
Address checkThe base URL is only format-checked when you register. Requests to private or internal addresses are blocked each time a tool runs.
PKCEThe form has no PKCE option.

Sending files to a tool

Some tools upload a file, for example sending a photo through Telegram or uploading a video to YouTube. You do not handle the encoding: the integration defines how the file is sent, whether as a part of a multipart form or, for Google media uploads, as a metadata part plus the file in one multipart/related request.

Pass a file reference to the tool's file parameter, such as the output of a Download File node ({{core:download_file.output.file}}) or a file a user uploaded. LiveContext fetches the bytes from your storage and attaches them. See Files & storage.

Catalog updates on a self-hosted install

A self-hosted install starts with the catalog bundled in its image, then checks LiveContext Cloud about every 15 minutes for a newer, signed version of the integrations catalog and applies it. This does not require a cloud link, and it never touches your custom APIs or your stored credentials.

Administrators can see the sync state in Settings > Cloud > Bundles > Integrations catalog, with the last fetch, the last applied version, and a Sync now button. See Self-hosting.

Let external MCP clients use LiveContext

LiveContext is also an MCP server. An external client such as Claude Code, Cursor, or Claude Desktop can connect to it with an API key and use the same tools as the in-app assistant, including searching and calling catalog integrations. A key can be limited to some of those tools. LiveContext does not connect to external MCP servers as a source of tools. See MCP server.

Troubleshooting

A step needs a permission the account does not have

When a tool needs an OAuth scope your credential was not granted, the step inspector (and the approval card in chat) shows Additional permissions needed for the integration, before anything runs. Click Reconnect (Standard) to sign in again and grant it. If the provider restricts that scope, reconnecting cannot grant it: click Use a custom OAuth connection and connect with your own OAuth app.

A tool that used to work now fails

Open Credentials & Variables and check the status. A Reconnect required badge means the provider revoked the token (a password change, the app removed from your account, a withdrawn scope): click Reconnect. If reconnecting keeps failing within a few hours, the provider may not have approved the OAuth app for every permission; contact support. A Connection error badge needs an administrator.

An API key stopped working

Keys do not refresh. If you rotated or revoked the key at the provider, open the credential and enter the new one.

A custom API step cannot find its tool

Editing a custom API gives its tools new ids. Re-select the tool in each workflow step that used it.

Related pages