powered by

How integrations work

Integrations let your workflows call Slack, Google Calendar, GitHub, OpenAI and more, using OAuth or API-key connections Anythink stores encrypted for you.

An integration lets your project call an external service — post a Slack message, create a Google Calendar event, read a GitHub repository, generate text with Claude — without writing the HTTP calls or storing tokens yourself. Anythink defines each provider; you connect your project to it and call it from a workflow's Integration step.

This page explains the model. To connect your first integration, see Post to Slack when a record is created.

Definitions and connections

Part What it is
Definition A provider: Slack, GitHub, Google Calendar. Anythink maintains these — each has an auth type, the OAuth scopes it requests and its operations.
Connection Your project's link to a definition: a name plus encrypted credentials. A project can hold several connections to the same provider.
Operation One thing a provider can do, such as Slack's send-message or Google Calendar's create-event, with a fixed set of inputs.

See what's available under Settings › Integrations in the Anythink dashboard, or with anythink integrations list and anythink integrations connections list. Integration providers and operations reference lists every provider and operation.

Project connections and user connections

A connection belongs either to the whole project or to one user:

  • Project connection (the default): shared by every workflow. Use it for a team Slack workspace or a shared booking calendar.
  • User connection: one user links their own account, and only jobs that user triggers can pick it up. Use it when a workflow should act as the person who triggered it.

The dashboard creates project connections. Create user connections with the CLI's --user-connection flag or is_user_connection: true on the API — see Let each user connect their own account.

Choosing a connection in a workflow step

Each Integration step has a Credential Source that decides which connection it uses:

Credential Source (dashboard) Value Uses
System (shared connection) system An enabled project connection for the provider.
Current User (first connection) current_user An enabled connection visible to the user who triggered the job: their own user connection or a project connection.
Specific Connection (by ID) connection The connection with the given ID, which can be a template such as {{ $anythink.trigger.data.connection_id }}. If no connection has that ID, the step falls back to current_user.
Entity Field entity_field Credentials from a template that resolves to a stored credentials object, such as a secret field on the triggering record.

When more than one connection matches system or current_user, Anythink doesn't guarantee which one it picks. Keep one enabled connection per provider for those sources, or use Specific Connection (by ID).

OAuth and API-key providers

Each definition has one auth type:

  • OAuth2: Slack, Google Calendar, GitHub, LinkedIn and Twitter / X. You register an OAuth app with the provider, save its client ID and secret in your project, then approve access in the browser. Anythink exchanges the authorisation code for an access token and, where the provider issues one, a refresh token.
  • API key: Claude AI, OpenAI and Grok. You paste the key once and Anythink stores it encrypted.

The OAuth app belongs to your project, so the consent screen shows your app's name, and you control its scopes and redirect URLs. See Connect Slack to send messages from workflows and Connect Google Calendar to create events from workflows for the setup per provider.

Note: Google, GitHub, LinkedIn and Apple can also be used for social sign-in — letting your users log in with that provider. That's configured on the Social Sign-In tab and uses a different callback URL from integration connections. Most providers allow one callback URL per OAuth app, so use a separate OAuth app for each purpose. Google allows several redirect URIs on one OAuth client.

How credentials are handled

Connection credentials — access tokens, refresh tokens and API keys — are encrypted at rest and decrypted only on Anythink's servers when a step needs them. The dashboard, the CLI and the API return a connection's ID, name, provider, owner, enabled flag and timestamps, never its credentials.

When an OAuth access token has expired and the connection has a refresh token, the Integration step refreshes it before calling the provider and saves the new token.

Parent providers

Google Calendar has Google as its parent provider. If Google Calendar has no OAuth credentials of its own, it uses the Google credentials saved for your project — so a project that already has Google sign-in set up can connect Google Calendar without registering another app. Google Calendar is currently the only Google service available as an integration.

Turning things off

  • Disable a connection to stop workflows picking it up without deleting its credentials: anythink integrations disable <connection-id>. Re-enable it with anythink integrations enable <connection-id>.
  • Disconnect to delete the connection and its credentials: Disconnect in the dashboard or anythink integrations disconnect <connection-id>.

See Rotate, pause or disconnect an integration for the full procedure.

Where connections are used

  • The Integration workflow step calls one operation with a connection chosen by its credential source. See Step types for its parameters and output.
  • The AI sidebar's bring-your-own-key mode uses the project's claude, openai or grok connection instead of Anythink's shared AI quota.

Limits

Limit Detail
User connections One per user, per provider, per project. Connecting the same provider again as the same user fails; disconnect the old one first.
Connections per provider in the dashboard The dashboard shows and manages one connection per provider. Add more project connections with the CLI or API.
Connection choice system and current_user pick any matching enabled connection, in no guaranteed order.
GitHub results List operations return one page of up to 100 results. There's no page input; narrow the range with since and until where the operation has them.
Connection test anythink integrations test confirms the connection exists. It doesn't call the provider — run the workflow to check the credentials work.
Callback URLs Most OAuth providers allow one callback URL per app, so social sign-in and integration connections for the same provider need separate apps.

Next steps

Post to Slack when a record is created Integration providers and operations reference Step types