Skip to content

Connections: credentials for external services

Settings → Security, section “Credentials”

A connection is a securely stored access to an external service: an API key, a username with password, or an OAuth sign-in (for example Microsoft or Google). Once stored, the AI can use the service for you in every chat, for example through connected skills or skill templates.

You don’t have to create connections manually; they appear where you need them:

  • When activating a template (the standard way): If you pick a template under Settings → System integrations (for example Microsoft 365 or DHL Tracking), the credentials dialog or the provider sign-in opens right away.
  • In the chat: When the AI needs credentials for a task, it shows a secure input field right in the chat. Whatever you enter there is stored encrypted and never appears in the chat history.
  • Via OAuth: For services like Microsoft 365 or Google Workspace you sign in with the provider directly in a popup. Your password never reaches 9brains.
  • Through an assignment: An administrator can assign a service to you. The connection then appears under “Action required” and you connect with your own credentials.

Security principle: write once, never read back

Section titled “Security principle: write once, never read back”

Stored credentials cannot be displayed again by anyone, not even by yourself or by administrators. There are only two actions: replace them with new values or delete them. They are used exclusively and automatically when the AI calls the respective service, and only for exactly that service.

Under Settings → Security you find the “Credentials” section. The list is organized in three groups:

  • Action required: Connections that still need something from you, for example assigned services you have not connected yet, or connections without stored values.
  • My connections: All connections you own.
  • Shared with me: Connections others have shared with you. You can use and test them, but not change them.

As long as something sits in “Action required”, the Security menu item in the settings shows a small counter badge. It disappears as soon as you have taken care of the open items.

Every connection shows its current state:

StatusMeaning
Connected (green)The last test succeeded; access is proven to work
OAuth activeThe provider sign-in is in place and renewed automatically
Unverified (grey)Credentials are stored but not yet tested successfully
Error (red)The last test failed; the service no longer accepts the credentials
No credentialsNo values have been stored yet

All connections with stored credentials are also re-checked automatically every day. If a service stops accepting the values (for example after a key rotation on the provider side), the status flips to “Error” on its own, without you having to test.

Click a connection to open the detail view. It is organized in three areas: Credentials, Access and Activity.

  • Test: Checks with the stored credentials whether access to the service works. The result appears immediately and updates the status.
  • Set credentials / Re-enter: Opens the secure input field to store the values for the first time or to renew them (for example after a key rotation).
  • Reconnect (OAuth only): Restarts the provider sign-in, for example when the connection has expired or you want to use a different account.
  • Activity: Shows the connection’s recent events; the full audit log lists when it was created, used, tested or changed. The credentials themselves never appear there.
  • Delete: Removes the connection and the stored credentials permanently. Skills using this connection stop working until new credentials are stored.

For OAuth services (for example Microsoft 365) there is nothing to type in: the sign-in runs through the provider and is renewed automatically. The connection shows which account it is connected with. You can also connect several accounts of the same provider, for example your personal mailbox and a team mailbox; the displayed account keeps them apart. Every time you connect, the provider asks which account the connection is for, even when you are already signed in there in the same browser. For a second mailbox, pick “Use another account” in that prompt and sign in with the account you want.

If you hold a single account with a provider, it applies to all of your connections to that provider, across workspaces too. As soon as a second account joins, every connection carries only its own: which one is meant is never guessed. If a connection reads “No account connected”, nobody has completed a sign-in for it yet. Use Reconnect to catch up; until then it stays unused, and agents are not offered it either.

Some connections cover an entire provider, others cover exactly one of its services. If you have connected both Google Workspace and Google Ads, for example, Google Ads uses the connection made specifically for it, not the general one. That way every request reaches the account it was meant for.

Your own OAuth app: For services without a preconfigured sign-in (for example banks or company-owned OAuth apps), you store the client ID and optionally the client secret of your own OAuth app in the detail view. You must register the redirect URI shown there in the service’s OAuth app, otherwise the sign-in fails. Like all credentials, the client secret cannot be viewed again after saving.

By default a connection is personal: nobody but you can use the credentials. You change that deliberately in the Access area of the detail view:

  • “Share connection”: Pick groups or people. They then use your stored credentials, a common team access. For the recipients the connection appears under “Shared with me”.
  • Granting agents access: to let an agent use your credentials, add it here, in the same picker. From then on it works with them like a colleague with a keyring of their own, in chat exactly as in runs on a schedule or via webhook, and for everyone who may use the agent.

When you open the picker it immediately shows the existing groups, people and agents, grouped by kind. You only need to type if you want to narrow the list down; anyone who already has access is greyed out and marked “Already granted”.

If you pick an agent, you are asked straight away, before the selection even becomes a chip. The question names who is allowed to use this agent and points out that the agent also works without you, including on a schedule. The agent only gets the access once you agree, and the agreement is recorded together with its time and the audience. Details under Contributing an account.

You can only pass on your own credentials. A connection somebody else shared with you cannot be handed to an agent.

A highlighted agent chip with a “Confirm” button is left over from an earlier version: the agent does not use the access. Use “Confirm” to supply the agreement, or remove the entry.

Important: Sharing always means others work with your credentials. If each person should use their own credentials, an assignment by an administrator is the right way.

Next to every name in the access list you see what that person or group may do. There are two levels:

  • Use: the connection can be used, nothing more. The recipient can neither view nor change it. This is the default, and it is what sharing has always meant.
  • Administer: on top of that, the recipient may edit the connection, replace the credentials, share it with further people and delete it. A tool entry attached to this connection can be managed by them as well.

You change the level right on the chip and save with “Save access”. It can be taken back at any time.

Administer exists for the case where somebody sets a connection up on behalf of another person and then wants to hand it over completely, without making that person an administrator of the entire workspace. Pick the level deliberately: whoever may administer can replace the credentials, and therefore also decide where they travel.

Administrators can assign a service to you. Only the description of what to connect is distributed, never anyone else’s credentials. After signing in, a prompt reminds you of open assignments, and they appear in the “Credentials” section under “Action required”. With “Connect now” you store your own credentials or sign in with the provider. After that, the service is ready for you.

Administrators find the workspace-wide overview under Settings → Administration → Credentials, split into two areas.

All connections in the workspace with owner, service, status, sharing and last use. The key figures at the top of the page (total connections, shared, without credentials, unused for a while) double as filters, complemented by search plus status and sharing filters.

Even administrators never see the stored values; what is managed are properties, sharing and lifecycle. Connections can be revoked here (deleted permanently, including credentials), for example when an employee leaves the company.

Assignments: one service, own credentials per person

Section titled “Assignments: one service, own credentials per person”

With an assignment you roll out a service to your team without handing out credentials:

  1. In the “Assignments” tab, click “New assignment” and pick the service
  2. Pick the groups or people who should use it
  3. Each assigned person is reminded after signing in and connects with their own credentials

You see the progress per assignment (for example “3 / 8 connected”). An assignment can be withdrawn; credentials users have already stored are kept.