Documentation

connectors

connect a service you already use and your agent can work inside it: read your notes, your books, your mail, your calendar, and act in them only after you approve the exact action. every connector starts read-only, and nothing it writes leaves without your yes.

a connector is an account you hand your agent a key to, on your terms. this page is the list, the rules, and the state of each one today.

which services?

| service | what your agent can read | state today | |---|---|---| | Notion | your pages, databases and docs | live | | QuickBooks | invoices, bills, payments and financial reports | coming: the rail is built and being proven | | Gmail | your mail, for context and triage | coming | | GitHub | repos, issues and pull requests | coming | | Slack | channels and threads | coming | | Google Calendar | your schedule | coming | | Stripe | customers, charges and payouts | coming |

a service appears as a door on your dashboard only when its rail actually exists on our side; the list is derived from what is configured, never typed by hand, so a door is never drawn over nothing.

how do i connect one?

from instaclaw.io/dashboard/connectors, choose the service and sign in on that service's own page. you authorise your agent there; we never see your password. what comes back is a token scoped to what you allowed, held on our side, encrypted. disconnect from the same place and the token is gone.

what can it do once connected?

read, first and by default. every connector starts read-only: your agent can look things up, summarise, cross-reference, and answer questions from what is in the account. that is where most of the value is, and it is safe by construction.

writing is a separate door. sending a message, creating a record, paying an invoice, deleting anything: each of those waits for your approval of that exact action, asked in the channel you use, and the approval is good for that one action for a few minutes and then expires. this is not a setting you can turn off, because a prompt injected from a web page is a real thing and a human tap on the exact action is the only defence that holds. the irreversible kinds, mail, payments, deletions and transfers, ask more sternly.

what can a connector never reach?

anything but the connected service's own API. a Notion connector can speak to Notion and to nothing else; it cannot be turned into a door to your other accounts.

what is switched on today?

Notion is live to read. QuickBooks is built and waiting on its own proof before it opens. the rest are listed and coming. writes are not switched on for any connector yet: every connector is read-only today, and the write door opens service by service, each with the approval described above, and this page changes for each one the day it does.

what next

  • your logins: the other two ways your agent acts inside your accounts
  • skills: the skills that use connected accounts
  • command center: where connected accounts show up as doors

Reading this as a machine? Get the raw markdown.