Integrations

Connect external services without exposing private credentials.

Updated 2026-07-30 · Relevant product surface

Credentials stay private

Provider keys are accepted only through protected server paths and should be encrypted at rest. Never place service-role keys, database passwords, webhook secrets, or private keys in browser-visible variables.

Truthful states

An integration may be connected, not configured, unavailable, unsupported, or require external setup. Provider presence does not prove an authenticated request succeeded.