Connectors
Connectors is where you connect your own accounts, such as Outlook, Slack or Salesforce, so Nexus tools and AI teams can act in them. On the page it is titled My Connectors.
The subtitle reads: "Store personal credentials for GitHub, Slack, Notion, HuggingFace, AWS and the other integrations your admin has enabled. Credentials are encrypted at rest and only you can see them."
How it works
- These are your accounts. Another person cannot see them or use them unless you lend them to an Agent Force team (see below).
- Your administrator decides which connectors appear. Only enabled ones are listed. Turning one off also stops tools and queued actions that use it.
- Some connectors also need your administrator to set up the platform's own app under Admin → OAuth Providers before anyone can connect.
- This page is for personal accounts. Systems set up once for the whole organization are shown only on an Agent Force team's Resources tab, tagged Org-wide.
- AI provider keys are on a different page: AI Model Keys.
Open the page
Click Settings → Connectors in the Nexus sidebar (/nexus/settings/connectors). Everyone who is signed in can see it. Opening just /nexus/settings also lands here.
With nothing enabled you see an amber box: "No connectors are available yet. Your platform admin hasn't enabled any integrations. Ask them to turn connectors on under Admin → Platform Config → Connectors." While loading it says "Loading connectors…".
A connector card
Each card shows a letter badge, the connector's name and short ID (such as hubspot), a one-line description, and a button on the right.
Status
- One OAuth account: "Connected ✓".
- Several OAuth accounts: "N accounts connected".
- Several pasted keys: "N credentials saved".
- Nothing connected shows no status word.
The button depends on how the connector connects
| How it connects | Button |
|---|---|
| Sign in with the provider (OAuth) | Connect or Connect another |
| Sign in, after choosing a setting first (for example a Salesforce login host) | Connect, which opens a short form |
| Company password grant (SAP Concur) | Connect, which opens a special dialog |
| Paste a key, or SFTP and SQL connections | Add or Add another |
| Not supported yet | A grey tag Not connectable here yet |
A card can hold several connections, one row each. Each row shows who it is: "Connected as (person)", "Connected to (tenant or site)" or "No account recorded — reconnect it to show which account this is", plus a name you gave it.
Row labels and chips
| Label | Meaning |
|---|---|
| Default | Used by your own chats and by any AI team member not pinned to a specific connection |
| Format checked (green) | "This secret decrypts and has the format this connector requires. It has NOT been tried against the vendor — a revoked or wrong-account credential would still show this." |
| Needs reconnecting (amber) | The sign-in needs to be redone |
| Format not checked (amber) | A pasted key that has not been checked yet |
| Some permissions not in the last-issued token (amber) | Hover to see which. It clears by itself within about an hour once an admin grants them |
Row actions
| Action | What it does |
|---|---|
| Name it / Rename | Gives the connection a name. An empty name clears it ("Name cleared.") |
| Make default | Appears only when you have more than one. Asks "Make (account) the default?". Toast "Default connection updated." |
| Edit | For SFTP and SQL connections |
| Check format | For pasted keys. Toast "Connector verified." It never contacts the vendor |
| Reconnect | For sign-in connectors. Redo the sign-in |
| Disconnect (trash) | For sign-in connectors. "Disconnect this (name) connection?" then Disconnect. Toast "Connection disconnected." |
| Remove (trash) | For pasted keys. "Remove this (name) connection?" then Remove. Any AI team member pointed at it stops working. Toast "Connection removed." |
| Test connection | For SFTP, SQL and some others (see below) |
Connect an account
Sign in with the provider
Click Connect
You are taken to the provider's own sign-in and consent screen.
Screenshot placeholderScreenshot to add: A connector card with the Connect button and the provider's consent screen. Approve
Sign in and approve. You return to the page with a toast: "Connected to (provider) successfully."
Connect another (optional)
Click Connect another and sign in with a different account. This adds a new connection and does not replace the first. Reconnecting an existing one uses Reconnect instead.
If it fails you see "OAuth error: (reason)". Some failures show as plain text in the browser tab instead, such as "Provider '…' is not configured. A platform admin must enter the client_id and client_secret…" or "Invalid or expired OAuth state. Please start the connect flow again." Start again from the Connectors page.
A red banner on a card means your last attempt did not finish, for example an abandoned sign-in after more than 10 minutes.
Sign in with a setting first
For connectors that need a choice up front, Connect opens a dialog titled "Connect (name)" with a field or two. Choose a value (a red * means required) and click Continue.
SAP Concur (company connect)
An amber box warns "Read this before you paste anything." The single-use request token is used up the moment it is sent, so fetch it last.
- Paste the token into the password box.
- Click Connect ("Exchanging…").
- On success a toast says "(name) is connected for this company." and the dialog shows the values read back. Click Done.
- If it fails, the box clears: "The value you sent is now used up. Fetch another … and put it in the empty box below…". The button becomes "Connect with a new token". "This dialog has already handed that exact string to (name). It is dead; paste a freshly generated one."
Paste a key
Click Add
A dialog opens titled "Add (name) credential".
Fill in the details
Paste the secret ("Paste secret") and any other fields shown, such as a site. Optionally add a Label ("e.g. personal github").
Save
Click Save ("Saving…"). A toast says "(name) credential saved." If the connector refuses the format, the reason appears in a red box.
To change a key later, use Replace a saved key… (title "Replace (name) credential"; the placeholder reads "(Replaces ****…)").
SFTP and SQL connections
These use a form instead of a single secret.
- SFTP: host, port (22 by default), username, root folder (required), and password or private key.
- SQL: engine, host, port, database, username, password, TLS mode, and an optional schema allowlist. Or tick Use a connection string instead ("It is stored encrypted and never shown again"). You cannot switch this on an existing connection.
- Saved secrets show "••• saved — leave blank to keep".
Use a read-only login unless you need changes. Every write still waits for your approval.
Test connection
Test connection (SFTP, SQL and some others, such as an Outlook app) checks the connection and shows each step: for example Network policy, TCP connect, Host key, Authentication, Root directory, TLS, Login, Read-only SELECT, Sign-in to the tenant, Graph permissions and Mailbox access. It reads "Connection works" or "Connection failed", with "Last test: ok · 5 minutes ago". It is limited to 10 per minute. If the login can write you see "This login can write. Use a read-only login unless you need changes; every write still waits for your approval."
SFTP host keys are trusted the first time you connect (Host key trusted). If the server's key changes you see Host key changed — connection blocked and a link to review it. Confirm with Trust the new key, entering the fingerprint you verified.
Teams you lend your connectors to
Near the top of the page. An Agent Force team normally runs on its owner's accounts. If you are on someone else's team, you can lend it yours, so a member can send from your mailbox.
"Turning this on lets the team sign in as any account you have connected — all of them, not a chosen few. Anyone who can see the team, not only its owner, will see which accounts those are, including a personal address if you have connected one. Only you can switch it on, and only you can switch it off."
Lending is all or nothing: you cannot lend a single account.
Find the team
Every team you are on but do not own is listed, whether or not it has asked. Nobody has to ask first.
Turn it on
Use the switch Share my connectors with (team), or Allow if the team has asked. Confirm "Share your connectors with "(team)"?" with Share my connectors. A toast says "(team) can now sign in as your connected accounts."
Turn it off any time
Flip the switch off and confirm Stop sharing. Members pointed at your accounts stop working at once and the owner is told. Or click Decline on a request ("You declined. (team) cannot use your accounts.").
Each row shows a state: "Asked on (date)", "Sharing since (date)", "You declined on (date)", "You stopped sharing on (date)" or "You are on this team and are not sharing anything with it". If you are on no one's team: "Nothing of yours is shared with anyone's team."
Team owners can only ask, from their Resources tab. They cannot switch it on for you. A lent account is never the default.
TAO bot
Lets you chat with your TAO assistant by direct message in Slack or Microsoft Teams. An administrator installs the bot once for the workspace. "There is no on/off switch here: not using the bot is the opt-out."
- Each channel shows Linked or Not linked.
- Slack: Link your TAO account if not linked. A linked one shows "Linked by you" or "Auto-linked" and Unlink (confirm "Unlink Slack?").
- Teams: connect Microsoft Teams above, or sign in with single sign-on, then message the bot. It links automatically the first time.
- Default project for (channel) bot chats: "Personal (default)" or one of your organization's projects. Toast "Default project for bot chats updated."
Which connectors you may see
The list is whatever your administrator enabled. Typically it includes:
| Area | Examples |
|---|---|
| Microsoft | Outlook and calendar, Teams, OneDrive, Excel, SharePoint, Entra, Planner and To Do, OneNote, Power Platform |
| Gmail, Drive and Calendar on one connection | |
| CRM and e-signature | HubSpot, Salesforce, Dynamics 365 Sales, Zoho, DocuSign, Adobe Sign |
| Finance, ERP and HR | Dynamics 365, Coupa, SAP Concur, SAP Ariba, Oracle, QuickBooks, Stripe, Avalara, Vertex, ADP |
| Developer and IT | Jira, GitHub, ServiceNow, Azure DevOps, Zendesk, Snowflake, Databricks |
| Messaging and automation | Slack (connects as you), UiPath |
| Network connections | SFTP, SQL databases (PostgreSQL, SQL Server, Oracle, MySQL) |
How connectors are used
- Chat: tools appear only for providers you have connected. Otherwise tool lists say "Available — connect (provider) to enable N tools". See Chat.
- Agent Force: a team's members act as the owner by default. See Knowledge: Resources.
- Approvals: changes through a connector wait for approval in Manual mode. See Approvals.