Guides

Pre-built Integrations

The catalogue of MCP integrations airlock ships with: GitHub, Linear, Notion, Google Calendar, and 50+ more.

Airlock includes 240+ pre-built integrations that let you connect AI agents to popular services without writing an OpenAPI spec. Most are MCP proxies that route tool calls to the service's own upstream MCP server; around twenty services that don't offer a suitable MCP server of their own, including several of the built-in OAuth integrations, are proxied through an airlock-hosted MCP server instead.

The categories below highlight commonly-used integrations. The complete, up-to-date list is what you see under Integrations in the Control Room.

Available Integrations

Code & Project Management

IntegrationAuth TypeDescription
GitHubBuilt-in OAuthRepository, pull request, and issue management
GitLabOAuthRepository, merge request, and CI/CD management
BitbucketBuilt-in OAuthRepository, pull request, commit, branch, and issue management
Azure DevOpsBuilt-in OAuthWork items, repositories, pull requests, pipelines, wikis, test plans, and code search (requires an Entra-backed Azure DevOps organization)
Azure DevOps (token)API KeyThe same ground as Azure DevOps: 77 tools across work items, repositories, branches, pull requests, pipelines, builds, wikis, test plans, and search, using a personal access token instead of Microsoft sign-in
LinearOAuthIssue and project tracking
RedmineAPI KeyIssues, projects, time tracking, wiki pages, and search on your self-hosted Redmine instance
AtlassianOAuthJira issues and Confluence pages
Atlassian Goals & ProjectsAPI KeyGoals and projects in Atlassian Home: search, read, post status updates, create, and archive
TodoistOAuthTask and project management
CodeRabbitAPI KeyAI code reviews, reports, and review metrics
FigmaBuilt-in OAuthDesign files and layers for design-to-code, screenshots, variables, components, styles, comments, and dev resources
MiroOAuthVisual collaboration: create and search boards, add diagrams, docs, tables, and images, and manage comments (Enterprise plan; admin must enable the MCP server)
HolmesOAuthAI QA: inspect test runs, file issues, and surface pipeline suggestions
TrelloOAuthBoards, lists, cards, and members across your organizations
Monday.comOAuthBoards, items, updates, and workspaces for work management
AirtableOAuth or API KeyRecords, comments, and schema across your bases
BreezeOAuthProject management: read projects, tasks, and boards
BuildkiteOAuthCI/CD pipelines, builds, jobs, and artifacts
CrowdinOAuthLocalization projects, files, translations, and workflows
FiberyOAuthWorkspace entities, databases, and documents
PostmanOAuthWorkspaces, collections, environments, and mocks
ProductboardOAuthProduct notes, features, releases, and feedback
RizeOAuthAI time tracking: sessions, projects, and insights
RocketlaneOAuthCustomer onboarding projects, tasks, and forms
TickTickOAuthTasks and projects
TimeCampOAuthTime tracking and project time data
WorkiomOAuthNo-code lists, records, and workflows
ShortcutOAuthStories, epics, iterations, workflows, and comments
ConvexOAuthBackend deployments: browse tables and documents and run queries
v0API KeyGenerate production-ready UI code through v0 chats
BrowserbaseAPI KeyHosted headless browser: navigate, act, observe, and extract
ChatPRDOAuthSearch and read your product documents, and draft or revise PRDs with ChatPRD's AI (Pro, Team, or Enterprise plan)
BasecampOAuthProjects, to-dos, message boards, schedules, and documents
ClickUpOAuthTasks, lists, docs, and chat across your workspace

CRM & Sales

IntegrationAuth TypeDescription
HubSpotOAuth (manual setup)CRM contacts, deals, and sales pipeline
SalesforceOAuth (manual setup)Salesforce records: SOQL queries, cross object search, object schemas, and record create, update and delete
Dynamics 365 CRMBuilt-in OAuthMicrosoft Dynamics 365 CRM (Dataverse): accounts, contacts, leads, opportunities, and other customer records
ShowpadOAuth (manual setup)Sales content and enablement
LemlistOAuthSales engagement, outreach campaigns, and sequences
Apollo.ioOAuthProspect search, contact and company enrichment, and outbound sequences
AttioOAuthCRM contacts, companies, deals, and custom objects
BrevoAPI KeyEmail marketing and CRM: transactional email and SMS, contact management, and email campaigns
FullEnrichOAuthB2B contact enrichment: verified emails and phone numbers via waterfall enrichment
HeyReachAPI KeyLinkedIn outreach automation: campaigns, leads, and sender accounts
InstantlyAPI KeyCold email outreach: campaigns, leads, email accounts, and analytics
CoresignalAPI KeyFirmographic, technographic, and employee data for B2B intelligence
SumbleAPI KeySales intelligence and B2B prospecting data
PipedriveOAuthCRM deals, contacts, leads, and activities across your pipeline
CloseOAuthCRM leads, contacts, opportunities, and activities
OutreachOAuthSales engagement: prospects, sequences, and account data
SalesloftOAuthSales engagement: accounts, people, conversations, and opportunities
Customer.ioOAuthMessaging automation: people, campaigns, and messaging data
KlaviyoOAuthMarketing automation: profiles, lists, segments, campaigns, and metrics
CompanyEnrichOAuthCompany enrichment, search, and similar-company discovery
CrustdataOAuthReal-time company and people data for B2B intelligence
DropcontactOAuthB2B email finding, verification, and contact enrichment
EnigmaOAuthU.S. business identity and financial health data
FindymailOAuthB2B email and phone finding, verification, and lists
folkOAuthCRM people, companies, groups, and custom fields
IcypeasOAuthProfessional email discovery and verification
LeadfeederOAuthWebsite visitor intelligence, leads, lists, and campaigns
LeadIQOAuthB2B prospecting: people and company search and enrichment
MixmaxOAuthSales engagement: meeting and scheduling data
RocketReachOAuthProfessional contact lookup and verification
WizaOAuthLinkedIn prospect data: verified emails and phones
HunterOAuthEmail finding and verification, people and company enrichment, leads, and campaigns
ChMeetingsOAuthChurch management: people, families, groups, events, and contributions
Jungle ScoutAPI KeyAmazon product and keyword research, sales estimates, and share of voice
AffinityOAuthRelationship intelligence CRM: people, companies, opportunities, and lists
GongOAuth (admin setup)Revenue intelligence: recorded calls, transcripts, deals, and account activity (see Gong integration setup)

Customer Support

IntegrationAuth TypeDescription
DocsBot AIOAuthDocumentation chatbots: bots, sources, and Q&A
GorgiasOAuthE-commerce helpdesk: tickets, customers, macros, and rules
PlainOAuthB2B support threads, customers, and tenants
ProductlaneOAuthCustomer feedback threads, insights, and changelogs
PylonOAuthB2B support issues, accounts, and contacts
RetentlyOAuthCX feedback, customers, campaigns, and surveys
FreshdeskAPI KeyHelpdesk: create, update, and search tickets, reply and add notes, and manage contacts and companies
ZendeskOAuthSupport tickets, users, and organizations

Marketing & Email

IntegrationAuth TypeDescription
eSputnikOAuthOmnichannel marketing: contacts, campaigns, email, SMS, and push
HandwryttenOAuthHandwritten cards: sending, contacts, orders, and balances
LinklyOAuthTracking links, retargeting, and click analytics
MailercloudOAuthEmail campaigns, contacts, and lists
MailerLiteOAuthSubscribers, groups, campaigns, and automations
MailerSendOAuthTransactional email: sending, domains, templates, and activity
PasscreatorOAuthApple/Google Wallet passes, templates, and distribution
UserlistOAuthSaaS email automation: users, companies, and campaigns
WatiOAuthWhatsApp Business messaging and contacts
WisepopsOAuthPopup campaigns and performance data
ResendOAuthTransactional email plus domains, audiences, contacts, and broadcasts
MissiveOAuthShared team inbox: conversations, drafts, contacts, and calendars
AgentMailOAuth or API KeyEmail inboxes built for agents: send, reply, and read threads
RaiselyOAuthFundraising campaigns, donations, donors, and supporter profiles
SendGridAPI KeyTransactional email: sending, dynamic templates, delivery statistics, email activity, bounce and unsubscribe lists, and marketing contacts and lists
LoopsOAuthProduct email: contacts, mailing lists, and transactional and marketing sends

Meetings & Communication

IntegrationAuth TypeDescription
SlackBuilt-in OAuthSearch messages, files, channels, and users; send messages; manage canvases; and add reactions
Google CalendarBuilt-in OAuthCalendar events and scheduling
GmailBuilt-in OAuthRead, send, and manage emails
OutlookBuilt-in OAuthRead, search, draft, and send email, and browse mail folders
Outlook CalendarBuilt-in OAuthList, create, update, and delete calendar events, and browse calendars
Microsoft TeamsBuilt-in OAuthList teams and channels, read and post channel messages, and browse and message chats
LinkedInBuilt-in OAuthPublish text, link, image and video posts to your own LinkedIn feed, comment on posts, and like them
ZoomOAuth (manual setup)Meetings, recordings, and participants
FathomOAuthMeeting recordings and transcripts
GranolaOAuthMeeting notes and action items
KrispOAuthMeeting transcripts and summaries
Wispr FlowOAuthNotetaker meetings: search them and read their notes, summaries, and briefs (read-only)
LeexiOAuthAI meeting and call intelligence: search recorded calls and read their transcripts and summaries, plus Leexi documentation
CalendlyOAuthScheduling: event types, scheduled meetings, and availability
Cal.comOAuthOpen-source scheduling: bookings, event types, and availability
FirefliesOAuthMeeting transcripts, summaries, and action items
Synthflow AIOAuthAI voice agents, phone numbers, campaigns, and call transcripts
BolnaOAuthConversational voice agents, calls, and call logs
Retell AIAPI KeyVoice agents, phone numbers, calls, and transcripts
VestaboardOAuthSplit-flap display state and the boards on your account

Infrastructure & Deployment

IntegrationAuth TypeDescription
VercelBuilt-in OAuthDeployments, projects, domains, and build logs
SupabaseOAuthDatabases, storage, and edge functions
Dagster+API KeyData orchestration: assets, pipeline runs, and job launches
AWSSigV4 (not yet supported)15,000+ AWS APIs, documentation, and guidance (coming soon)
AlchemyOAuthBlockchain data: tokens, transactions, NFTs, and on-chain queries
CloudflareOAuthWorkers, DNS, caching, security settings, and browser rendering
JumpCloudOAuthDirectory users, devices, and groups
NeonOAuthServerless Postgres: projects, branches, and SQL
SeqeraOAuthNextflow pipelines and compute environments
DNSFilterOAuthDNS security policies, blocked-domain activity, and traffic reports

Monitoring & Analytics

IntegrationAuth TypeDescription
SentryOAuthError monitoring and performance tracking
Better StackOAuth or API KeyUptime monitors, incidents, on-call, heartbeats, and status pages; logs, metrics, and dashboards; and release and error tracking
airlock GEOOAuthAirlock's GEO radar: track how AI assistants talk about your brand, with visibility summaries and question-level results
PostHogOAuth or API KeyProduct analytics and feature flags
Power BIBuilt-in OAuthBrowse your Power BI workspaces, semantic models and reports, ask questions about your data in plain language, read model schemas and report metadata, and run DAX queries under your own Power BI permissions (see Power BI tenant prerequisite)
DatadogAPI KeyLogs, metrics, alerts, and incident management
AikidoAPI KeySecurity issue tracking across code, cloud accounts, and containers
MixpanelOAuthProduct analytics: events, funnels, retention, segmentation, and insights
AmplitudeOAuthProduct analytics: events, charts, and behavioral insights
DataboxOAuthBusiness metrics, dashboards, and datasources
DataForSEOOAuthSEO data: SERPs, keywords, backlinks, and competitive intelligence
GrafanaOAuthDashboards, datasource queries, incidents, and alerts
incident.ioOAuthIncidents, alerts, schedules, and workflows
KlipfolioOAuthBusiness dashboards and metrics
MxToolboxOAuthDNS, MX, and blacklist lookups and email health checks
New RelicOAuthObservability: entities, NRQL queries, alerts, and incidents
RootlyOAuthIncidents, alerts, on-call schedules, and retrospectives
Similarweb Digital RankOAuthGlobal website rank data
tokenspend.orgAPI KeyOpen benchmark for AI adoption and token spend: org usage, spend, efficiency, and community benchmarks
UptimeRobotOAuthUptime monitors, incidents, and alerts
CoinMarketCapOAuthCryptocurrency prices, market caps, exchange data, and rankings
AlpacaAPI KeyStock, crypto, and options market data and the trading calendar
InterzoidAPI KeyData matching, standardization, verification, and enrichment

Payments

IntegrationAuth TypeDescription
StripeOAuthPayments, subscriptions, invoices, and customers
PolarOAuthProducts, pricing, checkouts, and license keys
AltovizOAuthBilling: customers, invoices, quotes, expenses, and payments
BillitOAuthE-invoicing and Peppol (read-only): invoices, credit notes and orders with payment status, customers and suppliers, Belgian company registry lookups, and Peppol receiver checks
GivebutterOAuthFundraising campaigns, contacts, transactions, and tickets
MercuryOAuthBusiness banking (read-only): accounts, transactions, cards, and statements
PayPalOAuthInvoices, orders, payments, subscriptions, and disputes
RampOAuthSpend management: cards, transactions, bills, and approvals
RazorpayOAuthOrders, payments, settlements, refunds, and payment links
WhopOAuthDigital products, memberships, and payments
OpenSeaAPI KeyNFT collections, items, listings, offers, and wallet balances

Documentation & Data

IntegrationAuth TypeDescription
Google DriveBuilt-in OAuthFiles, folders, and Docs content, plus Google Sheets: read, write, append and clear cell ranges, and manage tabs
OneDriveBuilt-in OAuthBrowse, search, read, download, upload, and manage files and folders in your OneDrive
SharePointBuilt-in OAuthFind sites, browse document libraries, search, read, upload and delete files, and manage list items
BoxOAuth (manual setup)Search, read, and manage files and folders, plus AI-powered queries across your Box content
DropboxOAuthFiles and folders in your Dropbox account
NotionOAuthPages, databases, and workspace content
Context7OAuthLibrary and framework documentation
RefOAuthAPI and library documentation
AirbyteNo authData integration documentation and guides
Google WorkspaceNo authGoogle Workspace developer documentation, APIs, and code samples
Bright DataAPI KeyWeb scraping, search, and data extraction
FirecrawlAPI KeyWeb scraping, crawling, search, and structured data extraction
ApifyOAuthWeb scraping, data extraction, and ready-made Actors from the Apify Store
RapidAPIAPI KeyThousands of APIs from the RapidAPI Hub
CogneeAPI KeyPersistent AI memory: knowledge graphs and cross-conversation context
UnblockedAPI KeyTeam context across Slack, Jira, Confluence, and GitHub
BitqueryOAuthIndexed blockchain data across 40+ networks
cloudlayer.ioOAuthPDF and image generation from templates
Conversion ToolsOAuthDocument conversion between XML, Excel, PDF, Word, CSV, and more
Data247OAuthOn-demand phone, email, address, and identity lookups
DocsAutomatorOAuthDocument generation from Google Docs templates
EODHDOAuthMarket data: EOD/intraday prices, fundamentals, news, and screeners
ExaOAuthAI web search, similar-page discovery, and content extraction
KadoaOAuthWeb data extraction workflows
KnackOAuthNo-code database records and apps
MapboxOAuthGeocoding, places, directions, styles, and datasets
MemOAuthNotes: search, read, and create
NanonetsOAuthDocument data extraction and processing workflows
NusiiOAuthProposals and clients (read access)
OpenGraph.ioOAuthOpen Graph metadata and site previews
PDF4meOAuthPDF generation, conversion, and manipulation
ScrapflyOAuthWeb scraping with JS rendering and anti-bot bypass
SliteOAuthKnowledge base docs: search, read, and write
Twelve DataOAuthReal-time and historical market data across asset classes
ZenRowsOAuthWeb scraping: structured data from dynamic sites
GristOAuthSpreadsheet-database records, schemas, downloads, and webhooks
CloudConvertOAuthConvert documents, images, audio, and video across 200+ formats
PandaDocOAuthDocuments, templates, e-signature requests, and status tracking
DocuSealNo authSemantic search over DocuSeal's documentation knowledge base
AffindaOAuthAI document extraction: resumes, invoices, and custom documents
ScrapeGraph AIOAuthAI web scraping, search, and site crawling
WebScraping.AIOAuthRendered page HTML and text plus AI field extraction
DiffbotAPI KeyURL extraction, web search, and Knowledge Graph enrichment
PiloterrAPI Key190+ ready-made scraping APIs across marketplaces and social networks
ScrapingBeeAPI KeyPage text, HTML, and screenshots plus structured retailer and search results
SERPHouseAPI KeyGoogle, Bing, and Yahoo search results across verticals
AutomAPI KeyGoogle, Bing, and Brave search-results data
DaData.ruAPI KeyRussian address standardization and company lookup
IPinfoAPI KeyIP geolocation, ASN, carrier, and VPN/proxy detection
IP2LocationAPI KeyIP geolocation with ISP, coordinates, and proxy detection
GenderizeAPI KeyPredict the likely gender behind a first name
AlgoliaOAuthSearch indices, records, index settings, and search analytics

Websites & Content

IntegrationAuth TypeDescription
Agility CMSOAuthHeadless CMS: content items, models, and containers
ContentfulOAuthEntries, content types, assets, and GraphQL content queries
MemberspotOAuthOnline courses, members, access, and community
MemberstackOAuthWebsite members and plans
SanityOAuthStructured content: documents, datasets, and releases
WebflowOAuthSites, CMS collections, pages, and publishing
WixOAuthSites, products, orders, bookings, and content
CincopaAPI KeyHosted video and image assets and media galleries

Design & Media

IntegrationAuth TypeDescription
CanvaOAuthDesigns, folders, brand templates, comments, and assets
HeyGenOAuthAI avatar video creation and asset management
ShotstackOAuthAutomated video, image, and audio rendering
TemplatedAPI KeyGenerate images and PDFs from templates

AI & Machine Learning

IntegrationAuth TypeDescription
ElevenLabsOAuthText to speech, voice design, image and video generation, and conversational AI agents
LangbaseOAuthAI pipes, memory, and agent primitives
ManusOAuthAI task automation and workflows
Mem0OAuthPersistent memory for AI agents
OpenRouterOAuthLLM models, usage, credits, and keys
ReplicateOAuthRun AI models and predictions in the cloud
AI/ML APIOAuthHosted model catalog for text, image, audio, and video generation
RoboflowOAuthComputer-vision projects, datasets, workflows, and model inference

Automation

IntegrationAuth TypeDescription
ZapierOAuthRun your connected Zapier actions across 8,000+ apps (Gmail, Slack, Google Sheets, HubSpot, and more) as MCP tools
MakeOAuthRun your Make scenarios as tools
Process StreetAPI KeyWorkflow management: launch and update workflow runs, complete tasks, approve or reject approvals, fill form fields, manage data sets and one-off tasks, and read pages
PhantomBusterAPI KeyLead generation and data extraction: launch agents and manage containers, scripts, leads, and CRM storage
Route4MeAPI KeyRoute planning and optimization, destinations, drivers, and geocoding
DetrackOAuthDelivery and job tracking, vehicles, drivers, and proof of delivery
StreamtimeOAuthCreative studio jobs, tasks, logged time, and quotes
InstacartNo authTurn recipes and ingredient lists into shoppable carts
ConveyorOAuthSecurity questionnaire automation from Trust Center content
PersonaAPI KeyIdentity verification inquiries, accounts, cases, and reports

HR & Recruiting

IntegrationAuth TypeDescription
AshbyAPI KeyCandidates, jobs, applications, interviews, and offers
GreenhouseOAuthRecruiting: candidates, jobs, applications, and interview data
Breezy HROAuthRecruiting: candidates, positions, and pipeline management
WorkableOAuthHiring: candidates, jobs, offers, and employee data
BambooHROAuthEmployees, time off, and company information

ERP

IntegrationAuth TypeDescription
Dynamics 365 Finance & OperationsBuilt-in OAuthMicrosoft Dynamics 365 finance, supply chain, and operations data (coming soon)
OdooAPI KeyOdoo ERP/CRM on Odoo 17 to 20, hosted anywhere: contacts, leads, sales orders, products, and any model across Sales, Inventory, Accounting, and Project
Odoo (native MCP)API KeyOdoo's own MCP server, for databases on Odoo Online (version 19.4 and newer): the tools your Odoo admin makes available in MCP. See Which Odoo integration to choose
PlenionAPI KeyPlenion ERP: customers, prospects, opportunities, contacts, projects, service requests, appointments, articles and stock, delivery notes, orders, and invoices, plus creating and updating those records
ApaleoOAuthHotel property management: reservations, folios, rates, and operations
StoreganiseOAuthSelf-storage bookings, units, and billing

Forms & Email Validation

IntegrationAuth TypeDescription
TallyOAuthForm creation and submission management across workspaces
ZeroBounceAPI KeyEmail validation, deliverability checks, and contact discovery
BounceBanAPI KeyEmail deliverability: validate single and bulk addresses, detect disposable and catch-all emails, and check credits
FilloutOAuthForms and submissions
JotformOAuthOnline forms and submissions
SafetyCultureOAuthInspections, audits, actions, and assets

Airlock-hosted MCP Integrations

Some services don't expose their own MCP server (or expose one airlock can't proxy), so airlock hosts one for them. These are still MCP proxies: they forward tool calls to an airlock-hosted MCP server rather than a vendor-run one. This is an implementation detail: you connect them exactly like any other integration, with whatever auth type is listed for them above (built-in OAuth ones via Connect, API-key ones by entering a key on the integration's detail page).

The airlock-hosted integrations are:

  • Built-in OAuth: Slack, Gmail, Google Calendar, Google Drive, Outlook, Outlook Calendar, OneDrive, SharePoint, Microsoft Teams, Bitbucket, Figma, LinkedIn, Vercel, Dynamics 365 CRM
  • API key / token: Aikido, Ashby, Atlassian Goals & Projects, Azure DevOps (token), BounceBan, CodeRabbit, Dagster+, Datadog, Freshdesk, Odoo, PhantomBuster, Plenion, Process Street, Redmine, SendGrid, ZeroBounce
  • Manual OAuth setup: Zoom

Authentication Types

Built-in OAuth

Integrations marked Built-in OAuth (GitHub, Bitbucket, Azure DevOps, Slack, Figma, Google Calendar, Gmail, Outlook, Outlook Calendar, Microsoft Teams, Google Drive, OneDrive, SharePoint, LinkedIn, Vercel, Dynamics 365 CRM, Power BI) have pre-configured OAuth credentials managed by airlock. Users simply click Connect and complete the authorization flow, with no setup required.

Standard OAuth

Most integrations use standard OAuth. When you add the integration, airlock handles the OAuth flow with the upstream service. Users click Connect on the integration's detail page to authorize access.

No auth

Two public documentation servers, Airbyte and Google Workspace, need no credentials at all. They work as soon as you add them; there is no Connect step.

Manual OAuth Setup

HubSpot, Showpad, and Zoom require you to create your own OAuth application in the service's developer portal first, then enter the client credentials in airlock. Salesforce works the same way, with the app created inside your own Salesforce org (see Salesforce org setup). Box is similar: each organization enables the Box MCP Server in its own Box Admin Console to generate an enterprise-specific client ID and secret. The wizard shows the redirect URI to register and links to each provider's setup guide.

API Key

Many integrations use API key or bearer token authentication, including Datadog, Firecrawl, RapidAPI, Dagster+, CodeRabbit, Aikido, ZeroBounce, PhantomBuster, BounceBan, Freshdesk, Process Street, Redmine, Plenion, SendGrid, Odoo, and Odoo (native MCP). Generate a key in the service's settings and enter it on the integration's detail page.

A few integrations ask for more than one value, and airlock combines them for you:

  • Datadog: an API key and an Application key (both from Datadog's Organization Settings → API Keys / Application Keys).
  • Odoo: your Odoo login (email) and your API key.
  • Atlassian Goals & Projects: your Atlassian account email and a classic API token.
  • Plenion: three values, because Plenion checks an installation-wide key and your own sign-in on every call: the API key for your Plenion installation, plus your Plenion login and password. A Plenion user linked to a customer only ever sees that customer's data, so whatever you can see in Plenion is what your agent can see.

Odoo (native MCP) uses one API key per member, created in Odoo under Preferences → Security → Add API Key with the MCP scope. Odoo scopes its keys: an MCP key only works with this integration, and the RPC key the other Odoo integration uses does not work here. Pick the longest duration you are allowed, because an expired key stops working without warning.

Redmine uses your personal API key from "My account" → "API access key" on your Redmine instance (the REST API must be enabled by an administrator under Administration → Settings → API).

Atlassian Goals & Projects requires a classic (unscoped) Atlassian API token created at id.atlassian.com; scoped API tokens cannot access the Goals & Projects APIs. Note that a classic token carries your full Atlassian access (including Jira and Confluence), even though this integration only exposes Goals & Projects tools.

Additional Setup

Some integrations need one extra detail when you add them, on top of credentials:

  • Showpad and Cognee ask for your workspace subdomain (for example, your-company for your-company.showpad.com).
  • Freshdesk asks for your Freshdesk domain (for example, yourcompany for yourcompany.freshdesk.com).
  • Plenion asks for your webservice URL (for example, https://yourcompany.plenion.be). Plenion is installed on its own site per customer, so ask your Plenion contact for the address if you do not know it, and note that some installations sit on a path such as https://erp.yourcompany.be/plenion. The URL must be reachable over a public HTTPS address. It is set once per server by an admin and shared by everyone who connects, while each member signs in with their own login and password, so set it to a Plenion host you trust: every connecting member's credentials are sent to whatever address is configured. If calls fail right after connecting, check this address first.
  • Redmine asks for your instance URL (for example, redmine.example.com, or tools.example.com/redmine for a subpath install). The instance must be reachable over a public HTTPS address. The instance URL is set once per server and shared by everyone who connects, while each member authenticates with their own API key, so set it to a Redmine host you trust, since every connecting member's key is sent to whatever host is configured.
  • Atlassian Goals & Projects asks for your Atlassian site (for example, yourcompany for yourcompany.atlassian.net).
  • Azure DevOps asks for your organization name (for example, contoso for dev.azure.com/contoso). The organization must be connected to Microsoft Entra ID (personal-account organizations are not supported). See Azure DevOps tenant prerequisites below.
  • Azure DevOps (token) asks for the same organization name, plus a personal access token. See Which Azure DevOps integration to choose below.
  • Dynamics 365 CRM asks for your Dataverse environment host (for example, orgname.crm.dynamics.com).
  • Salesforce asks for the address of the hosted MCP server you enabled (for example, platform/sobject-all). It is the tail of the URL Salesforce shows your administrator, and it differs between production, sandbox and My Domain orgs. See Salesforce org setup below.
  • Odoo asks for your instance host and database name.
  • Odoo (native MCP) asks for your Odoo Online database name (for example, yourcompany for yourcompany.odoo.com). Pasting the full address works too.
  • Dagster+ asks for your deployment URL.
  • RapidAPI asks for the API host of the specific API you want to call.
  • Gong needs no extra detail from you, but a Gong Tech admin must register an MCP integration before anyone can connect. See Gong integration setup below.

Airlock prompts for these when you add the integration.

Gong integration setup

Gong does not let an outside client connect until one of your own Gong Tech admins has registered an MCP integration for it. Airlock cannot do this step for you: it registers an OAuth client with Gong, which is a different thing from the integration record Gong requires.

Ask your Gong Tech admin to:

  1. Register an MCP integration in Gong.
  2. Set its type to Automatic, so any matching client can connect once a user signs in. (The alternative, Manual, has Gong issue credentials to one named client instead.)
  3. Add Airlock's callback as a Redirect URI, one URL per line: https://api.air-lock.ai/mcp-proxy/oauth/callback

Airlock shows that same callback URL on the Add Gong screen. Until the integration exists, connecting Gong fails at sign-in.

Which Odoo integration to choose

There are two Odoo tiles:

OdooOdoo (native MCP)
Odoo versions17 to 20Odoo Online 19.4 and newer
Where Odoo is hostedAnywhere: Odoo Online, Odoo.sh, or your own serverOdoo Online only
Where the tools come fromAn airlock-hosted server over Odoo's APIOdoo's own MCP server
Which tools you getA curated set, the same on every databaseWhatever your Odoo admin makes available in MCP (five read-only tools by default)
API key scopeRPCMCP

Use Odoo (the first one) when you need approvals to be precise. Its tools separate actions that reach customers, such as posting a message that notifies followers, from internal ones like logging a note, so a policy can require approval for the first and allow the second.

Use Odoo (native MCP) when your database is on Odoo Online and you want Odoo's own tools, including any your admin adds later. Those tools are generic (one Update Records tool covers every model), so a policy can gate a tool but not what it is used for. Tools your Odoo admin makes available after you first connect show up as new tools, which by default require approval until an admin reviews them.

Which Azure DevOps integration to choose

There are two Azure DevOps tiles, and they differ only in how you sign in:

Azure DevOpsAzure DevOps (token)
How you connectSign in with your Microsoft accountPaste a personal access token
Requires an Entra-backed organizationYesNo
Where the tools come fromMicrosoft's own Azure DevOps MCP serverAn airlock-hosted server over the Azure DevOps REST API
ToolsMicrosoft's set77

Use Azure DevOps (the first one) unless you can't. It is the default: Microsoft runs the server, so new capabilities appear without airlock shipping anything.

Use Azure DevOps (token) when Microsoft sign-in is not available to you, most often because your Azure DevOps organization is not backed by Microsoft Entra ID, or because an administrator cannot grant the consent the first option needs. It covers the same ground: work items (including creating and updating them), queries and WIQL, boards, iterations and capacity, repositories, branches, files and commits, pull requests with their comment threads and reviewers, pipelines and builds with their logs, wikis, test plans, and code, wiki, and work-item search.

Two capabilities of Microsoft's server the token option does not cover:

  • Listing your other Azure DevOps organizations. The token option is scoped to the single organization you name when you connect it.
  • Downloading binary attachments and build artifacts. Work-item attachments and pipeline artifacts are listed, with their download URLs, but the bytes are not returned through the integration.

Microsoft's Enterprise Live Migration tools are also absent. They are a private preview that most organizations cannot enable on either option.

One place the token option is better: ad-hoc WIQL queries. Microsoft gates wit_query_by_wiql behind an Insiders header on its own server; here query_work_items is available to everyone.

You can connect both at once; they appear as separate integrations.

Power BI tenant prerequisite

Power BI connects with Microsoft sign-in and needs no setup from you, with one exception that airlock cannot do on your behalf: a Power BI administrator must turn on the tenant setting Users can use the Power BI Model Context Protocol server endpoint (preview) in the Power BI admin portal. Until that setting is on, Microsoft refuses the requests airlock sends to the Power BI MCP server, no matter how correctly everything else is configured.

A few more things worth knowing before you connect:

  • Nobody has to hunt for an ID. Microsoft's own Power BI tools all start from a semantic model or report ID, and the server offers no way to look one up, so agents elsewhere ask you to copy it out of a Power BI web address. airlock adds three read-only tools that list your workspaces, the semantic models in a workspace and the reports in a workspace, so an agent can find the right model on its own. They read only what you can already see, and they need no extra permission.
  • You see exactly what you see in Power BI. Queries run as you, so workspace permissions and row-level security apply unchanged. Running a query against a semantic model needs at least Build permission on that model.
  • Generating a query from a plain-language question uses Copilot. That tool is powered by Copilot in Power BI and needs a Copilot license, and it consumes Copilot capacity. Reading schemas and running DAX queries do not.
  • Your tenant may want an administrator to approve airlock once. The three Power BI permissions airlock asks for can normally be approved by each user at first sign-in. If your tenant restricts who may approve applications, which is common in larger companies, an Entra administrator grants that approval once for everyone instead.

Microsoft's Power BI MCP server is in preview, so its tools and their responses can still change.

Azure DevOps tenant prerequisites

The prerequisites in this section apply to the Azure DevOps integration only. Azure DevOps (token) authenticates with a personal access token and needs none of them. Create a token in Azure DevOps under User settings → Personal access tokens, scoped to the areas you want the agent to reach, and paste it on the integration's detail page.

Azure DevOps sign-in runs through Microsoft Entra ID, so the Connect flow depends on two applications being present in your company's Entra tenant: airlock's Azure DevOps app and Microsoft's Azure DevOps MCP service. In most tenants both are set up automatically the first time a user consents. A one-time action by an Entra administrator is needed when:

  • your tenant restricts user consent to new applications (common in enterprises), or
  • Connect fails with an error about a missing service principal (for example, "the app is trying to access a service … that your organization lacks a service principal for").

In either case, an administrator with rights to grant tenant-wide admin consent (for example, a Global Administrator) can approve airlock's Azure DevOps app for the whole tenant by opening this URL and accepting the consent prompt:

https://login.microsoftonline.com/organizations/adminconsent?client_id=c79f31ab-5bae-4405-a728-3e85659584e6

If the administrator's account has access to more than one directory (for example, as a guest or delegated administrator), replace organizations in the URL with the tenant ID or a verified domain of the directory that backs your Azure DevOps organization. The organizations form applies consent in the account's home tenant, which may not be the right one.

After accepting, the browser may land on an airlock sign-in page, which the administrator can simply close (no airlock sign-in is needed for the consent). Then retry Connect in airlock.

If Connect still reports a missing service principal, or the administrator never saw a consent prompt, the administrator can create both applications directly with the Azure CLI (signed in to your tenant):

az ad sp create --id c79f31ab-5bae-4405-a728-3e85659584e6   # Airlock's Azure DevOps app
az ad sp create --id 2a72489c-aab2-4b65-b93a-a91edccf33b8   # Microsoft's Azure DevOps MCP service

Creating the applications does not by itself grant the permission: after running these commands, reopen the admin-consent URL above (or use Entra admin center → Enterprise applications → airlock's Azure DevOps app → Permissions → Grant admin consent) so the tenant-wide grant is recorded, then retry Connect.

Additionally, if your organization uses Conditional Access policies, they can block sign-ins that originate from Microsoft's remote Azure DevOps MCP service. If Connect only fails for users covered by Conditional Access, review those policies with your administrator. Microsoft documents the service's IP addresses that location-based policies may need to allow in the remote MCP server troubleshooting guide.

Salesforce org setup

Salesforce runs its own MCP servers, and airlock connects to them as the person who signs in, so every query and every write stays inside that user's field level security, object permissions and sharing rules. Two things have to happen in Salesforce first, both by an administrator, and neither can be done from airlock: the server has to be switched on, and airlock has to be registered as an app allowed to reach it.

1. Switch on the server you want. In Salesforce Setup, type MCP Servers into the Quick Find box and open MCP Servers under API Catalog. Toggle on the server your team needs and give it up to two minutes to become active. Salesforce ships several, and the SObject family splits by what an agent is allowed to do:

ServerWhat an agent can do with it
platform/sobject-allEverything below in one server: read, create, update and delete records
platform/sobject-readsRead only: SOQL queries, cross object search, object schemas, recently viewed and related records
platform/sobject-mutationsRead, create and update records, but never delete
platform/sobject-deletesRead and delete records

The choice is a real boundary, not a preference: an agent connected to platform/sobject-reads has no delete tool to call at all. airlock's own policy rules apply on top, so the other way around also works, connecting platform/sobject-all and requiring approval on the writes. Salesforce also offers Data 360, Tableau Next and Archive Connect servers; those work here too, using whatever address Salesforce lists for them.

The address depends on your org, and airlock asks for the part after https://api.salesforce.com/platform/mcp/v1/. You can paste the whole URL Salesforce shows you and airlock will trim it:

OrgAddress to enter
Productionplatform/sobject-all
Sandbox or scratchsandbox/platform/sobject-all
Production, My Domaind/your-domain/platform/sobject-all
Developer Edition, My Domaind/your-domain/develop/platform/sobject-all
Sandbox, My Domaind/your-domain--sandboxname/sandbox/platform/sobject-all

Salesforce recommends the My Domain form for every org, and requires it for an org that has turned off login through login.salesforce.com or test.salesforce.com. Your My Domain name is in Setup under My Domain. The address also decides where users sign in, so getting it right is what sends them to your own Salesforce login page rather than the shared one.

2. Register airlock as an External Client App. Salesforce does not support dynamic client registration, so each org creates the app once. From Setup, enter external client in the Quick Find box, select External Client App Manager, and click New External Client App:

  • Turn on Enable OAuth, and set Callback URL to the address airlock shows you in the connect dialog: https://api.air-lock.ai/mcp-proxy/oauth/callback
  • Add exactly two scopes: Access MCP servers (mcp_api) and Perform requests at any time (refresh_token). The second one is what lets airlock refresh access in the background instead of sending everyone back through sign in. The beta scopes (api, sfap_api, einstein_gpt_api) do not work with the generally available servers.
  • Under Security, turn on Issue JSON Web Token (JWT)-based access tokens for named users. Salesforce's MCP endpoint accepts nothing else, and answers JWT Token is required when this is off.
  • Leave Require Proof Key for Code Exchange (PKCE) Extension on. airlock always sends a PKCE challenge for Salesforce.
  • Select Require Secret for Web Server Flow. airlock stores the secret encrypted and sends it on every token exchange.
  • Open Settings > Consumer Key and Secret on the finished app to read the two values you paste into airlock.

A new External Client App can take up to 30 minutes to become usable. If the first connect fails with invalid_client_id, wait and try again before suspecting the credentials.

3. Decide who may connect. In the app's OAuth Policies you can require a permission set for pre authorization, so only the people you assign it to can connect at all. Either way, each person authenticates as themselves and inherits their own Salesforce permissions.

4. Add it in airlock. Open Integrations, choose Salesforce, enter the server address from step 1, and paste the consumer key and secret. Everyone who uses the server then connects with their own Salesforce account from the server's detail page.

Two limits worth knowing before you start:

  • Check that your edition includes hosted MCP servers. They are generally available for Enterprise Edition and above, and Salesforce also includes them in the free Developer Edition, which is a good place to try this before pointing an agent at production data.
  • A scratch org cannot create the app in Setup. Sandboxes are ordinary here: enter the sandbox address and create the External Client App in the sandbox itself. Scratch orgs are the exception, because Salesforce does not offer External Client App creation in their Setup at all. Create the app in your Dev Hub, add it to a package and install that package in the scratch org, or test against a sandbox instead.

Adding an Integration

  1. Open Integrations in the Control Room
  2. Select the integration from the catalog
  3. Follow the prompts to add it, and the integration is ready to configure
  4. Go to the integration's detail page and connect your account (OAuth flow or API key)
  5. Configure policies for the tools
  6. Copy the MCP URL and add it to your AI client

Syncing Tools

Airlock keeps each integration's tool list aligned with its upstream MCP server, both automatically and on demand.

Automatic detection. On a schedule, airlock checks your connected integrations for upstream tool changes: tools that were added, removed, or changed. When it finds any, it records a notification and applies your organization's newly discovered tools policy, set by an admin under Settings → Security:

PolicyWhat happens to a newly discovered tool
Require approval (default)The tool is visible to agents, but every call needs approval until an admin marks it reviewed
DisabledThe tool stays hidden and uncallable until an admin enables it
EnabledThe tool is available to agents immediately

The policy applies to every integration in the organization.

Where it shows up. Admins see a notification in the bell menu in the top navigation bar, with an unread count. Opening it lists each integration that changed, along with the added / removed / changed counts; clicking an entry opens that integration's Tools & Policy tab, where you review the changes, unhide tools, and re-sync. (The bell is shown to admins only.)

Manual sync. You can refresh an integration's tools yourself at any time: open its detail page, go to the Tools & Policy tab, and click Sync Tools. This is available for MCP-proxy integrations (including every pre-built one) and for airlock's own built-in surfaces. Use it whenever you want to pull the latest upstream tools immediately. Custom OpenAPI integrations have no sync button; their tools are fixed at the spec you deployed.

GitHub and Box are synced manually. Automatic detection isn't available for GitHub or Box integrations, because both services issue single-use connection tokens that airlock can't safely reuse from a background job, so it never syncs them on a schedule. After connecting either one, and whenever its tools change, refresh them yourself with Sync Tools on the integration's Tools & Policy tab.