Choose the connection scope
| Scope | Use it for | Credential behavior |
|---|---|---|
| Per operator | Services where actions should carry the person's identity. | Each operator grants and revokes their own OAuth token. |
| Deployment | A service account intended for shared automation. | An administrator stores one restricted deployment credential. |
Connect an account
- Install and configure the plugin that owns the connection.
- Open Connected accounts in settings.
- Choose the provider and complete its authorization screen.
- Confirm the granted scopes and run a read-only test.
The worker injects the appropriate operator or deployment token for the invocation. The token is not shared with another operator and is not placed into the conversation.
Revoke and review
Revoke access in OpenNeko and, when required by the provider, in the provider's own account settings. Review connections after role changes, offboarding, plugin upgrades, and security incidents.