Support

CellCog Connectors Guide

Connectors let your agents attach files from Google Drive, receive work from Linear and coding agents, and act inside 1,500+ apps through connected tools, keys, and your own MCP servers.


What Are Connectors?

Connectors come in three classes, each with its own page under Connectors:

  • Platforms: attach files from services you already use (Google Drive)
  • Delegate (its own app since October 2026, MCP / API in the left sidebar): bring CellCog into the agents and tools your team works in (Claude, Cursor, Claude Code, Codex, OpenClaw, Hermes, Muse, Linear, and other agents)
  • Tools: let agents act on your behalf in external apps, including the Keys page for raw credentials, the MCP servers page for your own tool servers, and the Logins page for website passwords your AI employees' cloud browsers fill in

Important: connecting a service does not by itself give agents access in a chat. You turn tools on per chat (or per AI employee) with the Tools chip in the editor, and actions above your approval threshold wait for your approval.


Accessing Connectors

Open Connectors from the sidebar, or go to cellcog.ai/connectors. The hub shows the three classes, a search box for the tools catalog, and Your connections, a list of everything you have connected with a Manage link on each.


Platforms

Google Drive

Connect Google Drive to attach files without downloading them first.

Connecting:

  1. Go to Connectors, then Platforms, then Google Drive (cellcog.ai/connectors/platforms/google-drive)
  2. Click Connect
  3. Authorize with Google

Using Google Drive:

  • Browse and attach files from any Drive folder when uploading to a project's context
  • Docs are converted to Markdown and Slides to PDF automatically
  • Access is read-only: CellCog only sees the files you pick in the file picker

Disconnecting: click Disconnect on the Google Drive page.


Delegate

Delegate lets you bring CellCog into the agents and platforms your team already uses. Instead of coming to CellCog, CellCog comes to you: assign a task from within Linear, Cursor, Claude Code, or OpenClaw, and results flow back where you were.

Delegation Platforms

table
PlatformHow it works
OpenClawGenerate an API key, hand it to your OpenClaw agent, and it delegates through the CellCog Python SDK and ClawHub skills
LinearAssign an issue to @CellCog or @-mention it in a comment; the agent session streams back into the issue
CursorInstall the CellCog plugin; /cellcog and the skill commands appear in the command menu
Claude CodeInstall the CellCog plugin; slash commands light up CellCog inline
Other AgentsCustom scripts, direct HTTP callers, or any agent framework that can make API requests, with the same API key

Open MCP / API in the left sidebar and pick your agent to see every way it connects. Each platform also has its own page there, with setup steps, connection status, and the number of tasks delegated so far:


Tools

Tools let agents perform actions in external services during chats. The catalog covers 1,500+ apps with 20,000+ tools: Gmail, Slack, Linear, Jira, Notion, HubSpot, Salesforce, Shopify, Stripe, Figma, Canva, Google Analytics, and many more.

Connecting a Tool

  1. Go to Connectors, then Tools (cellcog.ai/connectors/tools)
  2. Search or browse for the service
  3. Click Connect
  4. Complete the OAuth authorization, or fill in the credential form for services that use an API key

Each tool's page shows what agents can do with it before you authorize. Some tools are built in and need no connection at all; they are ready in any chat where Tools is enabled.

Using Tools in Chats

The Tools chip in the editor has three states:

  • All: every connected tool and every key you have stored is available in this chat
  • Choose: pick specific providers for this chat. A provider bundles its connector and any keys captured for it, so choosing one service enables both its actions and its credentials
  • Off: no tool calls and no keys in this chat

The chip shows what is active (all of your connections, or how many you picked). You can also search the catalog and connect a new service from inside the chip. The selection is saved with the chat.

AI employees hold their own Tools selection, set when you hire them and editable afterwards, so each employee works with only the providers its role needs.

Approvals

Every tool call is classified before it runs: safe (reading non-private data), moderate (reading private data such as full email content or payment history), or dangerous (anything that changes data or acts on your behalf, such as sending an email or posting publicly). On the Tools page, Auto-approve tool calls up to sets your account-wide level: None, Safe, Moderate, or Dangerous. Calls above the level pause and wait for your approval in the chat. Tools from your own MCP servers are always treated as at least moderate.

For the full approval model, including per-chat overrides, see the Approvals and Safety Guide.

Connection Expiry and Reconnecting

If a service revokes or expires its authorization, the tool's page shows that the connection has expired and offers Reconnect. Agents get a clear message instead of failing silently. When a service adds capabilities that need new permissions, the connection keeps working and the page recommends a reconnect to enable them.

Disconnecting a Tool

  1. Go to Connectors, then Tools, and open the service
  2. Click Disconnect and confirm

Disconnecting removes the connection and its credentials from your account. Agents lose that service immediately.


Triggers

Many connected tools can also raise events, such as a new email in Gmail, a new calendar invite, a new GitHub issue or a failed Stripe payment. A trigger turns one of those events into a wake for an AI employee. Your employees find triggers alongside tools and may set up the ones their job clearly needs; for anything less clear they send you a trigger link (cellcog.ai/connectors/triggers/...) that opens as a card with an Enable button. If the tool is not connected yet, the card asks you to connect it first. Opening a link never enables anything by itself. Each employee's triggers are listed and managed in the Wake app on its Employee Computer. Triggers need a standing AI employee to wake; regular chats do not use them. When no app event fits, an employee can build a watcher: a scheduled check that reads your connected tools the way the employee would, and wakes it only when something worth acting on shows up. Watchers only read; see the AI Employees Guide for details.

Keys (raw API credentials)

Some services are not in the tools catalog, or an agent's scripts need a raw credential directly. The Keys page at Connectors, then Tools, then Keys (cellcog.ai/connectors/keys) is the home for these.

How Keys Work

  • Add keys for a service: enter the service name, then one or more rows of key type and key value (a service that needs several values, such as a key ID plus a private key, is one service with several rows). An optional description helps you remember what a key is for
  • Your agents see each key as an environment variable named SERVICE_KEYTYPE; the page previews the exact name as you type
  • Values are stored encrypted and never shown again. To rotate a key, add it again with the same name, or use Rotate on its row
  • Keys are injected into the agent's workspace environment only in chats where Tools is enabled (with Choose, only the keys of the providers you picked). They live in the agent's environment, never on your machine. Keys added mid-conversation are available immediately; removing a key revokes access just as fast
  • Keys are account-level: every agent working for you sees the same keychain, subject to each chat's or employee's Tools selection
  • Connecting an API-key-based tool from the catalog saves that credential as a key automatically, so one paste covers both actions and scripts. Disconnecting a tool removes its credentials from your account

Your Connections on the Keys Page

Each row shows the service, the variable names your agents see, where the key came from ("Added when you connected X" or "Added by you"), and two capability marks: Actions (agents can call the service's tools directly) and Scripts (agents can use the key in code they run for you). If a key you added matches a service in the catalog, Enable actions turns on direct tool calls using that same key.

Keys vs Tools

Tools are connections you authorize with a click; agents call their actions directly. Keys are credentials you paste; agents' own scripts read them from the environment. If a service is not in the catalog, add its credential on the Keys page.


MCP Servers (bring your own tools)

Beyond the tools catalog and Keys, you can plug in any remote MCP server: your company's internal tools, a self-hosted service, or any vendor that exposes an MCP endpoint. MCP (Model Context Protocol) is the open standard AI platforms use to connect to tool servers.

Adding a Server

Go to Connectors, then Tools, then MCP servers (cellcog.ai/connectors/mcps). Enter a Name, the Server URL (a public https MCP endpoint), and pick the Authentication:

  • None: the server needs no credential
  • API key: paste the key and choose how it is sent (as an Authorization Bearer header or an X-API-Key header)
  • Sign in (OAuth): for OAuth-protected servers such as Linear, Notion, Sentry, and similar. After you add the server, its sign-in opens in a popup; complete it and the server connects. The server must support OAuth dynamic client registration. A Discovery URL is optional and only needed when the server's sign-in lives on another host

Click Add server. CellCog connects, discovers the server's tools, and lists them on the server's card. Tools are kept in sync daily; use the refresh button on the card to re-discover them anytime.

Using MCP Tools

The server's tools work like catalog tools: your agents find them in tool search and call them in any chat where Tools is enabled, behind your approval threshold. Calls to your own MCP servers are always treated as at least moderate risk, since a third-party server's tools are not vetted by CellCog. Your MCP servers are private to your account.

Server Status

Each card shows a status: Connected, Connecting…, Sync failed (the URL is unreachable, not a valid MCP endpoint, or exposes too many tools), or Key rejected (the API key was refused). OAuth servers show Sign in required, Finishing sign-in…, or Sign-in failed; whenever an OAuth server is not connected, its card carries a Sign in button, so reconnecting after an expired sign-in is one click. Any card also has Disable (keep the server but hide its tools), Rename, Change URL or auth (replace), and Remove.

Good to Know

  • A server's URL and auth mode cannot be edited in place. Change URL or auth (replace) removes the server and pre-fills the form so you can re-add it; you re-enter the key or sign in again
  • Credentials and sign-ins are held encrypted by our tools provider, never stored by CellCog, and never visible to agents
  • You can register up to 10 servers; a server exposing more than 500 tools cannot be synced
  • Removing a server deletes its registration and its stored credential or sign-in; agents lose its tools immediately

MCP Servers vs Tools vs Keys

Tools are the built-in catalog with one-click connect. Keys are raw credentials your agents' scripts read from the environment. MCP servers are your own tool servers, discovered and called like catalog tools. If a service is not in the catalog: use Keys when you have an API key and the agent can script against the service's API; use MCP servers when the service (or your team) exposes an MCP endpoint, so agents get schema-validated tools instead of raw scripting.


Logins (saved website passwords)

The Logins page at Connectors, then Logins (cellcog.ai/connectors/logins) keeps website usernames and passwords for your AI employees' cloud browsers, so an employee can log in to a site by itself.

Adding a Login

  1. Click Add login
  2. Enter the site (for example example.com), the username, and the password, or generate a new one
  3. Optionally add the site's 2FA setup key. With it, CellCog holds both your password and your second factor for that account, and the employee can enter the current code
  4. Choose which employees may use it. A login assigned to no one is used by no one

An employee that needs a login can send you a link that opens this form with the site already filled in.

How Employees Use Logins

  • The employee fills the password (and the 2FA code) straight into the site's page inside its cloud browser. It never sees the value: not in its scripts, its results, or its messages
  • A login is only filled on its own site or that site's subdomains
  • Passwords an employee creates, for a new account or a password reset, are saved here automatically, marked with the employee's name
  • Each row shows when the login was last used

Revealing a Password

Click Reveal and confirm it is you by signing in again. You see the password, and the current 2FA code if the login has a 2FA key. You can reveal up to 10 times an hour.

Logins vs Keys

Keys are credentials your agents' scripts read from their workspace environment. Logins are website passwords that are only ever entered into a web page by the employee's cloud browser, and never shown to agents.


Privacy and Security

Credentials

  • OAuth tools never share your password with CellCog; you authorize specific permissions and can revoke them anytime
  • API keys you paste (for catalog tools, the Keys page, or MCP servers) are stored encrypted and never shown again
  • Agents see tool names and schemas; they never see your keys' values, except as environment variables inside their own workspace when Tools is enabled

Revoking Access

  1. Disconnect in CellCog under Connectors
  2. For OAuth services, also revoke in the service's own settings (for example, Google: myaccount.google.com, Security, Third-party apps)

What Agents Can Do

  • Agents act only in chats where Tools is enabled, within that chat's selection
  • Every call carries a summary and a classification; anything above your auto-approve level waits for you
  • Tool calls and their results are visible in the chat

Frequently Asked Questions

Do I need to connect tools for every chat?

No. Connect once, then decide per chat with the Tools chip: All, Choose, or Off.

Can agents access my services without permission?

No. Tools must be enabled in the chat, and calls above your approval level wait for you.

What if I disconnect a tool mid-chat?

The agent loses access immediately. Ongoing operations may fail.

Are my credentials stored by CellCog?

OAuth tokens and the credentials for catalog tools and MCP servers are held encrypted by our tools provider. Keys you add on the Keys page are stored encrypted and never shown again. Saved logins are stored encrypted, and only you can reveal one, after signing in again.

Can my AI employees see the passwords I save in Logins?

No. An employee's cloud browser enters a saved password straight into the site's page. The value never appears in the employee's scripts, results, or messages.

Can I see what actions agents take?

Yes. Tool calls, their summaries, and their results appear in the chat.

What happens if a tool connection expires?

The tool's page shows the connection as expired and offers Reconnect. Agents are told the connection needs reconnecting instead of failing silently.

Do my AI employees use the same tools as my chats?

They draw from the same connections and keys, but each employee has its own Tools selection, so you can limit an employee to the providers its role needs.

Can I connect tools for two different companies in one account?

Connections and keys belong to you, not to an organization, so the tools you connect are available to your chats and AI employees in every organization you belong to.


Troubleshooting

Connection Failed

  1. Try disconnecting and reconnecting
  2. For credential-based tools, verify the values you entered
  3. Check the service's status page and your permissions in the service
  4. Contact support if the problem persists

Tool Not Appearing in a Chat

  1. Check the Tools chip: it must be All, or Choose with that provider picked
  2. Open the tool's page under Connectors, then Tools, and confirm it shows Connected rather than expired
  3. For MCP servers, confirm the card shows Connected and is not disabled

MCP Server Shows Sync Failed or Key Rejected

  1. Confirm the URL is a public https MCP endpoint
  2. Confirm the credential is current, or click Sign in for OAuth servers
  3. Click the refresh button on the card

Related Guides