Connected apps feeding into a team of OpenFactory agents

App Integrations

Connected apps, with the boundary made explicit

See what is configured now, what remains a workflow pattern, where managed credentials live, and which approvals stay with the account owner.

Production currently exposes managed connections for Gmail, GitHub, Vercel, Facebook, Instagram, LinkedIn, Reddit, and YouTube. Slack, Notion, and Linear pages on this site document planned workflow patterns; those three are not current connection choices as of August 12, 2026.

Connect once, then your agents act

Connecting creates an account-scoped tool boundary, not blanket approval for every action. The current flow sends you through a managed provider authorization, stores an encrypted account reference in OpenFactory, and lets you assign exact active accounts to agent roles. Provider scopes, upstream audit history, model data flow, and human approval remain part of the operating design.

Current catalog and planned patterns

How it works

  1. Inspect the live catalog. Availability is determined by the configured apps shown in the console, not by the existence of a marketing page.
  2. Connect narrowly. Use a dedicated or least-privileged provider account, inspect scopes, and assign the exact connection only to the role that needs it.
  3. Gate and verify actions. Prefer drafts and reversible calls first. Require approval for consequential writes, then inspect provider-native history and test revocation.

Managed-provider and self-hosting boundary

Today, Composio Cloud conducts the managed OAuth flow and stores provider tokens; OpenFactory stores encrypted connected-account references and mints scoped tool sessions. A self-hosted OpenFactory control plane does not, by itself, make that credential path local. Disconnect in OpenFactory and revoke the grant at the upstream provider when ending access or responding to an incident.

Frequently asked questions

What does connecting an app actually do?

A managed connection authorizes provider tools for a specific account. OpenFactory stores an encrypted reference to the connected account, then exposes account-scoped tools to permitted agent roles. Available actions and data access depend on the provider's current tool and OAuth scopes.

Whose account do the agents act in?

Actions use the connected provider account, but attribution varies by provider and action. Confirm the actor shown in provider-native audit history before relying on it for accountability.

Can I limit what an agent is allowed to do?

You can select accounts for agent roles and disconnect them. Those controls do not replace provider-side least-privilege scopes or per-action approval. Start with read or draft workflows and require review for sending, publishing, deletion, financial, access, or deployment actions.

Where does my data live?

The current managed-integration path uses Composio Cloud for OAuth and provider-token storage; OpenFactory stores encrypted connected-account references. Requested app data can pass through the provider, Composio, OpenFactory, and the configured model path. Self-hosting the OpenFactory control plane alone does not remove those external processors.

How do I connect an app?

Open the console and use only an app shown in its current connection catalog. Review the provider scopes, connect the least-privileged test account first, assign that exact account to an agent role, exercise a reversible action, inspect provider audit history, and define approval and revocation steps before broader use.

Build the image instead of hand-assembling it

Use OpenFactory to turn the same requirements into a bootable, testable Linux system.

Open console