DocumentationConnected accounts
Docs/Extend

Connected accounts

Let an operator use their own account in an external service without sharing one organization-wide token.

Choose the connection scope

ScopeUse it forCredential behavior
Per operatorServices where actions should carry the person's identity.Each operator grants and revokes their own OAuth token.
DeploymentA service account intended for shared automation.An administrator stores one restricted deployment credential.

Connect an account

  1. Install and configure the plugin that owns the connection.
  2. Open Connected accounts in settings.
  3. Choose the provider and complete its authorization screen.
  4. Confirm the granted scopes and run a read-only test.

The worker injects the appropriate operator or deployment token for the invocation. The token is not shared with another operator and is not placed into the conversation.

Revoke and review

Revoke access in OpenNeko and, when required by the provider, in the provider's own account settings. Review connections after role changes, offboarding, plugin upgrades, and security incidents.