Connecting integrations
Open Integrations in the right-hand panel. Each connection is scoped to the selected brand: connecting HubSpot in Brand A does not connect it in Brand B.
OAuth flow — most integrations use OAuth. Click Connect, a popup opens, you authorize the Magister app in the provider's UI, and control returns here. The token is stored server-side.
API key flow — a few integrations (Ahrefs, Instantly, parts of PostHog, etc.) use API keys instead. You'll be prompted to paste a key. Keys are encrypted at rest before being stored.
Where credentials live — OAuth tokens and API keys are stored in the gateway, encrypted, and only decrypted when the agent makes a request to that provider on your behalf. They're never stored in the chat transcript.
When it becomes ready — Connect can use a completed integration immediately from the connected assistant. Hosted Agent sessions normally refresh capabilities on a later turn; if the current session still does not see it, start a new chat.
Disconnecting — click Disconnect on any connected service. This revokes Magister's access (as much as the provider's API allows) and deletes the token from our storage. The agent won't be able to call that provider anymore until you reconnect.
Allowed-service policy — brand admins and organization managers control which integrations are enabled for the brand. Disabled cards remain visible so existing connections can be understood and managed, but a new connection cannot start until the policy allows it. See Roles.