Guides

Pre-built Integrations

The catalogue of MCP integrations airlock ships with — GitHub, Linear, Notion, Google Calendar, and 50+ more.

Airlock includes 240+ pre-built integrations that let you connect AI agents to popular services without writing an OpenAPI spec. Most are MCP proxies that route tool calls to the service's own upstream MCP server; around twenty services that don't offer a suitable MCP server of their own — including several of the built-in OAuth integrations — are proxied through an airlock-hosted MCP server instead.

The categories below highlight commonly-used integrations. The complete, up-to-date list is what you see under Integrations in the Control Room.

Available Integrations

Code & Project Management

IntegrationAuth TypeDescription
GitHubBuilt-in OAuthRepository, pull request, and issue management
GitLabOAuthRepository, merge request, and CI/CD management
BitbucketBuilt-in OAuthRepository, pull request, commit, branch, and issue management
Azure DevOpsBuilt-in OAuthWork items, repositories, pull requests, pipelines, wikis, test plans, and code search (requires an Entra-backed Azure DevOps organization)
Azure DevOps (token)API KeyThe same ground as Azure DevOps — 77 tools across work items, repositories, branches, pull requests, pipelines, builds, wikis, test plans, and search — using a personal access token instead of Microsoft sign-in
LinearOAuthIssue and project tracking
RedmineAPI KeyIssues, projects, time tracking, wiki pages, and search on your self-hosted Redmine instance
AtlassianOAuthJira issues and Confluence pages
Atlassian Goals & ProjectsAPI KeyGoals and projects in Atlassian Home — search, read, post status updates, create, and archive
TodoistOAuthTask and project management
CodeRabbitAPI KeyAI code reviews, reports, and review metrics
FigmaBuilt-in OAuthDesign files and layers for design-to-code, screenshots, variables, components, styles, comments, and dev resources
MiroOAuthVisual collaboration — create and search boards, add diagrams, docs, tables, and images, and manage comments (Enterprise plan; admin must enable the MCP server)
HolmesOAuthAI QA — inspect test runs, file issues, and surface pipeline suggestions
TrelloOAuthBoards, lists, cards, and members across your organizations
Monday.comOAuthBoards, items, updates, and workspaces for work management
AirtableOAuth or API KeyRecords, comments, and schema across your bases
BreezeOAuthProject management — read projects, tasks, and boards
BuildkiteOAuthCI/CD pipelines, builds, jobs, and artifacts
CrowdinOAuthLocalization projects, files, translations, and workflows
FiberyOAuthWorkspace entities, databases, and documents
PostmanOAuthWorkspaces, collections, environments, and mocks
ProductboardOAuthProduct notes, features, releases, and feedback
RizeOAuthAI time tracking — sessions, projects, and insights
RocketlaneOAuthCustomer onboarding projects, tasks, and forms
TickTickOAuthTasks and projects
TimeCampOAuthTime tracking and project time data
WorkiomOAuthNo-code lists, records, and workflows
ShortcutOAuthStories, epics, iterations, workflows, and comments
ConvexOAuthBackend deployments — browse tables and documents and run queries
v0API KeyGenerate production-ready UI code through v0 chats
BrowserbaseAPI KeyHosted headless browser — navigate, act, observe, and extract

CRM & Sales

IntegrationAuth TypeDescription
HubSpotOAuth (manual setup)CRM contacts, deals, and sales pipeline
Dynamics 365 CRMBuilt-in OAuthMicrosoft Dynamics 365 CRM (Dataverse) — accounts, contacts, leads, opportunities, and other customer records
ShowpadOAuth (manual setup)Sales content and enablement
LemlistOAuthSales engagement, outreach campaigns, and sequences
Apollo.ioOAuthProspect search, contact and company enrichment, and outbound sequences
AttioOAuthCRM contacts, companies, deals, and custom objects
BrevoOAuth or API KeyEmail marketing and CRM — transactional email and SMS, contact management, and email campaigns
FullEnrichOAuthB2B contact enrichment — verified emails and phone numbers via waterfall enrichment
HeyReachAPI KeyLinkedIn outreach automation — campaigns, leads, and sender accounts
InstantlyAPI KeyCold email outreach — campaigns, leads, email accounts, and analytics
CoresignalAPI KeyFirmographic, technographic, and employee data for B2B intelligence
SumbleAPI KeySales intelligence and B2B prospecting data
PipedriveOAuthCRM deals, contacts, leads, and activities across your pipeline
CloseOAuthCRM leads, contacts, opportunities, and activities
OutreachOAuthSales engagement — prospects, sequences, and account data
SalesloftOAuthSales engagement — accounts, people, conversations, and opportunities
Customer.ioOAuthMessaging automation — people, campaigns, and messaging data
KlaviyoOAuthMarketing automation — profiles, lists, segments, campaigns, and metrics
CompanyEnrichOAuthCompany enrichment, search, and similar-company discovery
CrustdataOAuthReal-time company and people data for B2B intelligence
DropcontactOAuthB2B email finding, verification, and contact enrichment
EnigmaOAuthU.S. business identity and financial health data
FindymailOAuthB2B email and phone finding, verification, and lists
folkOAuthCRM people, companies, groups, and custom fields
IcypeasOAuthProfessional email discovery and verification
LeadfeederOAuthWebsite visitor intelligence, leads, lists, and campaigns
LeadIQOAuthB2B prospecting — people and company search and enrichment
MixmaxOAuthSales engagement — meeting and scheduling data
RocketReachOAuthProfessional contact lookup and verification
WizaOAuthLinkedIn prospect data — verified emails and phones
HunterOAuthEmail finding and verification, people and company enrichment, leads, and campaigns
ChMeetingsOAuthChurch management — people, families, groups, events, and contributions
Jungle ScoutAPI KeyAmazon product and keyword research, sales estimates, and share of voice

Customer Support

IntegrationAuth TypeDescription
DocsBot AIOAuthDocumentation chatbots — bots, sources, and Q&A
GorgiasOAuthE-commerce helpdesk — tickets, customers, macros, and rules
PlainOAuthB2B support threads, customers, and tenants
ProductlaneOAuthCustomer feedback threads, insights, and changelogs
PylonOAuthB2B support issues, accounts, and contacts
RetentlyOAuthCX feedback, customers, campaigns, and surveys
FreshdeskAPI KeyHelpdesk — create, update, and search tickets, reply and add notes, and manage contacts and companies

Marketing & Email

IntegrationAuth TypeDescription
eSputnikOAuthOmnichannel marketing — contacts, campaigns, email, SMS, and push
HandwryttenOAuthHandwritten cards — sending, contacts, orders, and balances
LinklyOAuthTracking links, retargeting, and click analytics
MailercloudOAuthEmail campaigns, contacts, and lists
MailerLiteOAuthSubscribers, groups, campaigns, and automations
MailerSendOAuthTransactional email — sending, domains, templates, and activity
PasscreatorOAuthApple/Google Wallet passes, templates, and distribution
UserlistOAuthSaaS email automation — users, companies, and campaigns
WatiOAuthWhatsApp Business messaging and contacts
WisepopsOAuthPopup campaigns and performance data
ResendOAuthTransactional email plus domains, audiences, contacts, and broadcasts
MissiveOAuthShared team inbox — conversations, drafts, contacts, and calendars
AgentMailOAuthEmail inboxes built for agents — send, reply, and read threads
RaiselyOAuthFundraising campaigns, donations, donors, and supporter profiles

Meetings & Communication

IntegrationAuth TypeDescription
SlackBuilt-in OAuthSearch messages, files, channels, and users; send messages; manage canvases; and add reactions
Google CalendarBuilt-in OAuthCalendar events and scheduling
GmailBuilt-in OAuthRead, send, and manage emails
OutlookBuilt-in OAuthRead, search, draft, and send email, and browse mail folders
Outlook CalendarBuilt-in OAuthList, create, update, and delete calendar events, and browse calendars
Microsoft TeamsBuilt-in OAuthList teams and channels, read and post channel messages, and browse and message chats
ZoomOAuth (manual setup)Meetings, recordings, and participants
FathomOAuthMeeting recordings and transcripts
GranolaOAuthMeeting notes and action items
KrispOAuthMeeting transcripts and summaries
Wispr FlowOAuthNotetaker meetings — search them and read their notes, summaries, and briefs (read-only)
LeexiOAuthAI meeting and call intelligence — search recorded calls and read their transcripts and summaries, plus Leexi documentation
CalendlyOAuthScheduling — event types, scheduled meetings, and availability
Cal.comOAuthOpen-source scheduling — bookings, event types, and availability
FirefliesOAuthMeeting transcripts, summaries, and action items
Synthflow AIOAuthAI voice agents, phone numbers, campaigns, and call transcripts
BolnaOAuthConversational voice agents, calls, and call logs
Retell AIAPI KeyVoice agents, phone numbers, calls, and transcripts
VestaboardOAuthSplit-flap display state and the boards on your account

Infrastructure & Deployment

IntegrationAuth TypeDescription
VercelBuilt-in OAuthDeployments, projects, domains, and build logs
SupabaseOAuthDatabases, storage, and edge functions
Dagster+API KeyData orchestration — assets, pipeline runs, and job launches
AWSSigV4 (not yet supported)15,000+ AWS APIs, documentation, and guidance (coming soon)
AlchemyOAuthBlockchain data — tokens, transactions, NFTs, and on-chain queries
CloudflareOAuthWorkers, DNS, caching, security settings, and browser rendering
JumpCloudOAuthDirectory users, devices, and groups
NeonOAuthServerless Postgres — projects, branches, and SQL
SeqeraOAuthNextflow pipelines and compute environments
DNSFilterOAuthDNS security policies, blocked-domain activity, and traffic reports

Monitoring & Analytics

IntegrationAuth TypeDescription
SentryOAuthError monitoring and performance tracking
Better StackOAuth or API KeyUptime monitors, incidents, on-call, heartbeats, and status pages; logs, metrics, and dashboards; and release and error tracking
airlock GEOOAuthAirlock's GEO radar — track how AI assistants talk about your brand, with visibility summaries and question-level results
PostHogOAuth or API KeyProduct analytics and feature flags
DatadogAPI KeyLogs, metrics, alerts, and incident management
AikidoAPI KeySecurity issue tracking across code, cloud accounts, and containers
MixpanelOAuthProduct analytics — events, funnels, retention, segmentation, and insights
AmplitudeOAuthProduct analytics — events, charts, and behavioral insights
DataboxOAuthBusiness metrics, dashboards, and datasources
DataForSEOOAuthSEO data — SERPs, keywords, backlinks, and competitive intelligence
GrafanaOAuthDashboards, datasource queries, incidents, and alerts
incident.ioOAuthIncidents, alerts, schedules, and workflows
KlipfolioOAuthBusiness dashboards and metrics
MxToolboxOAuthDNS, MX, and blacklist lookups and email health checks
New RelicOAuthObservability — entities, NRQL queries, alerts, and incidents
RootlyOAuthIncidents, alerts, on-call schedules, and retrospectives
Similarweb Digital RankOAuthGlobal website rank data
tokenspend.orgAPI KeyOpen benchmark for AI adoption and token spend — org usage, spend, efficiency, and community benchmarks
UptimeRobotOAuthUptime monitors, incidents, and alerts
CoinMarketCapOAuthCryptocurrency prices, market caps, exchange data, and rankings
AlpacaAPI KeyStock, crypto, and options market data and the trading calendar
InterzoidAPI KeyData matching, standardization, verification, and enrichment

Payments

IntegrationAuth TypeDescription
StripeOAuthPayments, subscriptions, invoices, and customers
PolarOAuthProducts, pricing, checkouts, and license keys
AltovizOAuthBilling — customers, invoices, quotes, expenses, and payments
GivebutterOAuthFundraising campaigns, contacts, transactions, and tickets
MercuryOAuthBusiness banking (read-only) — accounts, transactions, cards, and statements
PayPalOAuthInvoices, orders, payments, subscriptions, and disputes
RampOAuthSpend management — cards, transactions, bills, and approvals
RazorpayOAuthOrders, payments, settlements, refunds, and payment links
WhopOAuthDigital products, memberships, and payments
OpenSeaAPI KeyNFT collections, items, listings, offers, and wallet balances

Documentation & Data

IntegrationAuth TypeDescription
Google DriveBuilt-in OAuthFiles, folders, and Docs/Sheets content
OneDriveBuilt-in OAuthBrowse, search, read, download, upload, and manage files and folders in your OneDrive
BoxOAuth (manual setup)Search, read, and manage files and folders, plus AI-powered queries across your Box content
DropboxOAuthFiles and folders in your Dropbox account
NotionOAuthPages, databases, and workspace content
Context7OAuthLibrary and framework documentation
RefOAuthAPI and library documentation
AirbyteNo authData integration documentation and guides
Google WorkspaceNo authGoogle Workspace developer documentation, APIs, and code samples
Bright DataAPI KeyWeb scraping, search, and data extraction
FirecrawlAPI KeyWeb scraping, crawling, search, and structured data extraction
ApifyOAuthWeb scraping, data extraction, and ready-made Actors from the Apify Store
RapidAPIAPI KeyThousands of APIs from the RapidAPI Hub
CogneeAPI KeyPersistent AI memory — knowledge graphs and cross-conversation context
UnblockedAPI KeyTeam context across Slack, Jira, Confluence, and GitHub
BitqueryOAuthIndexed blockchain data across 40+ networks
cloudlayer.ioOAuthPDF and image generation from templates
Conversion ToolsOAuthDocument conversion between XML, Excel, PDF, Word, CSV, and more
Data247OAuthOn-demand phone, email, address, and identity lookups
DocsAutomatorOAuthDocument generation from Google Docs templates
EODHDOAuthMarket data — EOD/intraday prices, fundamentals, news, and screeners
ExaOAuthAI web search, similar-page discovery, and content extraction
KadoaOAuthWeb data extraction workflows
KnackOAuthNo-code database records and apps
MapboxOAuthGeocoding, places, directions, styles, and datasets
MemOAuthNotes — search, read, and create
NanonetsOAuthDocument data extraction and processing workflows
NusiiOAuthProposals and clients (read access)
OpenGraph.ioOAuthOpen Graph metadata and site previews
PDF4meOAuthPDF generation, conversion, and manipulation
ScrapflyOAuthWeb scraping with JS rendering and anti-bot bypass
SliteOAuthKnowledge base docs — search, read, and write
Twelve DataOAuthReal-time and historical market data across asset classes
ZenRowsOAuthWeb scraping — structured data from dynamic sites
GristOAuthSpreadsheet-database records, schemas, downloads, and webhooks
CloudConvertOAuthConvert documents, images, audio, and video across 200+ formats
PandaDocOAuthDocuments, templates, e-signature requests, and status tracking
DocuSealNo authSemantic search over DocuSeal's documentation knowledge base
AffindaOAuthAI document extraction — resumes, invoices, and custom documents
ScrapeGraph AIOAuthAI web scraping, search, and site crawling
WebScraping.AIOAuthRendered page HTML and text plus AI field extraction
DiffbotAPI KeyURL extraction, web search, and Knowledge Graph enrichment
PiloterrAPI Key190+ ready-made scraping APIs across marketplaces and social networks
ScrapingBeeAPI KeyPage text, HTML, and screenshots plus structured retailer and search results
SERPHouseAPI KeyGoogle, Bing, and Yahoo search results across verticals
AutomAPI KeyGoogle, Bing, and Brave search-results data
DaData.ruAPI KeyRussian address standardization and company lookup
IPinfoAPI KeyIP geolocation, ASN, carrier, and VPN/proxy detection
IP2LocationAPI KeyIP geolocation with ISP, coordinates, and proxy detection
GenderizeAPI KeyPredict the likely gender behind a first name

Websites & Content

IntegrationAuth TypeDescription
Agility CMSOAuthHeadless CMS — content items, models, and containers
ContentfulOAuthEntries, content types, assets, and GraphQL content queries
MemberspotOAuthOnline courses, members, access, and community
MemberstackOAuthWebsite members and plans
SanityOAuthStructured content — documents, datasets, and releases
WebflowOAuthSites, CMS collections, pages, and publishing
WixOAuthSites, products, orders, bookings, and content
CincopaAPI KeyHosted video and image assets and media galleries

Design & Media

IntegrationAuth TypeDescription
CanvaOAuthDesigns, folders, brand templates, comments, and assets
HeyGenOAuthAI avatar video creation and asset management
ShotstackOAuthAutomated video, image, and audio rendering
TemplatedAPI KeyGenerate images and PDFs from templates

AI & Machine Learning

IntegrationAuth TypeDescription
LangbaseOAuthAI pipes, memory, and agent primitives
ManusOAuthAI task automation and workflows
Mem0OAuthPersistent memory for AI agents
OpenRouterOAuthLLM models, usage, credits, and keys
ReplicateOAuthRun AI models and predictions in the cloud
AI/ML APIOAuthHosted model catalog for text, image, audio, and video generation
RoboflowOAuthComputer-vision projects, datasets, workflows, and model inference

Automation

IntegrationAuth TypeDescription
ZapierOAuthRun your connected Zapier actions across 8,000+ apps (Gmail, Slack, Google Sheets, HubSpot, and more) as MCP tools
MakeOAuthRun your Make scenarios as tools
Process StreetAPI KeyWorkflow management — launch and update workflow runs, complete tasks, approve or reject approvals, fill form fields, manage data sets and one-off tasks, and read pages
PhantomBusterAPI KeyLead generation and data extraction — launch agents and manage containers, scripts, leads, and CRM storage
Route4MeAPI KeyRoute planning and optimization, destinations, drivers, and geocoding
DetrackOAuthDelivery and job tracking, vehicles, drivers, and proof of delivery
StreamtimeOAuthCreative studio jobs, tasks, logged time, and quotes
InstacartNo authTurn recipes and ingredient lists into shoppable carts
ConveyorOAuthSecurity questionnaire automation from Trust Center content
PersonaAPI KeyIdentity verification inquiries, accounts, cases, and reports

HR & Recruiting

IntegrationAuth TypeDescription
AshbyAPI KeyCandidates, jobs, applications, interviews, and offers
GreenhouseOAuthRecruiting — candidates, jobs, applications, and interview data
Breezy HROAuthRecruiting — candidates, positions, and pipeline management
WorkableOAuthHiring — candidates, jobs, offers, and employee data

ERP

IntegrationAuth TypeDescription
Dynamics 365 Finance & OperationsBuilt-in OAuthMicrosoft Dynamics 365 finance, supply chain, and operations data (coming soon)
OdooAPI KeyOdoo ERP/CRM — contacts, leads, sales orders, products, and any model across Sales, Inventory, Accounting, and Project
ApaleoOAuthHotel property management — reservations, folios, rates, and operations
StoreganiseOAuthSelf-storage bookings, units, and billing

Forms & Email Validation

IntegrationAuth TypeDescription
TallyOAuthForm creation and submission management across workspaces
ZeroBounceAPI KeyEmail validation, deliverability checks, and contact discovery
BounceBanAPI KeyEmail deliverability — validate single and bulk addresses, detect disposable and catch-all emails, and check credits
FilloutOAuthForms and submissions
JotformOAuthOnline forms and submissions
SafetyCultureOAuthInspections, audits, actions, and assets

Airlock-hosted MCP Integrations

Some services don't expose their own MCP server (or expose one airlock can't proxy), so airlock hosts one for them. These are still MCP proxies — they forward tool calls to an airlock-hosted MCP server rather than a vendor-run one. This is an implementation detail: you connect them exactly like any other integration, with whatever auth type is listed for them above (built-in OAuth ones via Connect, API-key ones by entering a key on the integration's detail page).

The airlock-hosted integrations are:

  • Built-in OAuth: Slack, Gmail, Google Calendar, Google Drive, Outlook, Outlook Calendar, OneDrive, Microsoft Teams, Bitbucket, Figma, Vercel, Dynamics 365 CRM
  • API key / token: Aikido, Ashby, Atlassian Goals & Projects, Azure DevOps (token), BounceBan, CodeRabbit, Dagster+, Datadog, Freshdesk, Odoo, PhantomBuster, Process Street, Redmine, ZeroBounce
  • Manual OAuth setup: Zoom

Authentication Types

Built-in OAuth

Integrations marked Built-in OAuth (GitHub, Bitbucket, Azure DevOps, Slack, Figma, Google Calendar, Gmail, Outlook, Outlook Calendar, Microsoft Teams, Google Drive, OneDrive, Vercel, Dynamics 365 CRM) have pre-configured OAuth credentials managed by airlock. Users simply click Connect and complete the authorization flow — no setup required.

Standard OAuth

Most integrations use standard OAuth. When you add the integration, airlock handles the OAuth flow with the upstream service. Users click Connect on the integration's detail page to authorize access.

No auth

A few public documentation servers — Airbyte and Google Workspace — need no credentials at all. They work as soon as you add them; there is no Connect step.

Manual OAuth Setup

HubSpot, Showpad, and Zoom require you to create your own OAuth application in the service's developer portal first, then enter the client credentials in airlock. Box is similar — each organization enables the Box MCP Server in its own Box Admin Console to generate an enterprise-specific client ID and secret. The wizard shows the redirect URI to register and links to each provider's setup guide.

API Key

Many integrations — including Datadog, Firecrawl, RapidAPI, Dagster+, CodeRabbit, Aikido, ZeroBounce, PhantomBuster, BounceBan, Freshdesk, Process Street, Redmine, and Odoo — use API key or bearer token authentication. Generate a key in the service's settings and enter it on the integration's detail page.

A few integrations ask for two values instead of one, and airlock combines them for you:

  • Datadog — an API key and an Application key (both from Datadog's Organization Settings → API Keys / Application Keys).
  • Odoo — your Odoo login (email) and your API key.
  • Atlassian Goals & Projects — your Atlassian account email and a classic API token.

Redmine uses your personal API key from "My account" → "API access key" on your Redmine instance (the REST API must be enabled by an administrator under Administration → Settings → API).

Atlassian Goals & Projects requires a classic (unscoped) Atlassian API token created at id.atlassian.com — scoped API tokens cannot access the Goals & Projects APIs. Note that a classic token carries your full Atlassian access (including Jira and Confluence), even though this integration only exposes Goals & Projects tools.

Additional Setup

Some integrations need one extra detail when you add them, on top of credentials:

  • Showpad and Cognee ask for your workspace subdomain (for example, your-company for your-company.showpad.com).
  • Freshdesk asks for your Freshdesk domain (for example, yourcompany for yourcompany.freshdesk.com).
  • Redmine asks for your instance URL (for example, redmine.example.com, or tools.example.com/redmine for a subpath install). The instance must be reachable over a public HTTPS address. The instance URL is set once per server and shared by everyone who connects, while each member authenticates with their own API key — so set it to a Redmine host you trust, since every connecting member's key is sent to whatever host is configured.
  • Atlassian Goals & Projects asks for your Atlassian site (for example, yourcompany for yourcompany.atlassian.net).
  • Azure DevOps asks for your organization name (for example, contoso for dev.azure.com/contoso). The organization must be connected to Microsoft Entra ID (personal-account organizations are not supported) — see Azure DevOps tenant prerequisites below.
  • Azure DevOps (token) asks for the same organization name, plus a personal access token — see Which Azure DevOps integration to choose below.
  • Dynamics 365 CRM asks for your Dataverse environment host (for example, orgname.crm.dynamics.com).
  • Odoo asks for your instance host and database name.
  • Dagster+ asks for your deployment URL.
  • RapidAPI asks for the API host of the specific API you want to call.

Airlock prompts for these when you add the integration.

Which Azure DevOps integration to choose

There are two Azure DevOps tiles, and they differ only in how you sign in:

Azure DevOpsAzure DevOps (token)
How you connectSign in with your Microsoft accountPaste a personal access token
Requires an Entra-backed organizationYesNo
Where the tools come fromMicrosoft's own Azure DevOps MCP serverAn airlock-hosted server over the Azure DevOps REST API
ToolsMicrosoft's set77

Use Azure DevOps (the first one) unless you can't. It is the default: Microsoft runs the server, so new capabilities appear without airlock shipping anything.

Use Azure DevOps (token) when Microsoft sign-in is not available to you — most often because your Azure DevOps organization is not backed by Microsoft Entra ID, or because an administrator cannot grant the consent the first option needs. It covers the same ground: work items (including creating and updating them), queries and WIQL, boards, iterations and capacity, repositories, branches, files and commits, pull requests with their comment threads and reviewers, pipelines and builds with their logs, wikis, test plans, and code, wiki, and work-item search.

Two capabilities of Microsoft's server the token option does not cover:

  • Listing your other Azure DevOps organizations. The token option is scoped to the single organization you name when you connect it.
  • Downloading binary attachments and build artifacts. Work-item attachments and pipeline artifacts are listed, with their download URLs, but the bytes are not returned through the integration.

Microsoft's Enterprise Live Migration tools are also absent — they are a private preview that most organizations cannot enable on either option.

One place the token option is better: ad-hoc WIQL queries. Microsoft gates wit_query_by_wiql behind an Insiders header on its own server; here query_work_items is available to everyone.

You can connect both at once — they appear as separate integrations.

Azure DevOps tenant prerequisites

The prerequisites in this section apply to the Azure DevOps integration only. Azure DevOps (token) authenticates with a personal access token and needs none of them — create a token in Azure DevOps under User settings → Personal access tokens, scoped to the areas you want the agent to reach, and paste it on the integration's detail page.

Azure DevOps sign-in runs through Microsoft Entra ID, so the Connect flow depends on two applications being present in your company's Entra tenant: airlock's Azure DevOps app and Microsoft's Azure DevOps MCP service. In most tenants both are set up automatically the first time a user consents. A one-time action by an Entra administrator is needed when:

  • your tenant restricts user consent to new applications (common in enterprises), or
  • Connect fails with an error about a missing service principal (for example, "the app is trying to access a service … that your organization lacks a service principal for").

In either case, an administrator with rights to grant tenant-wide admin consent (for example, a Global Administrator) can approve airlock's Azure DevOps app for the whole tenant by opening this URL and accepting the consent prompt:

https://login.microsoftonline.com/organizations/adminconsent?client_id=c79f31ab-5bae-4405-a728-3e85659584e6

If the administrator's account has access to more than one directory (for example, as a guest or delegated administrator), replace organizations in the URL with the tenant ID or a verified domain of the directory that backs your Azure DevOps organization — the organizations form applies consent in the account's home tenant, which may not be the right one.

After accepting, the browser may land on an airlock sign-in page — the administrator can simply close it (no airlock sign-in is needed for the consent). Then retry Connect in airlock.

If Connect still reports a missing service principal — or the administrator never saw a consent prompt — the administrator can create both applications directly with the Azure CLI (signed in to your tenant):

az ad sp create --id c79f31ab-5bae-4405-a728-3e85659584e6   # Airlock's Azure DevOps app
az ad sp create --id 2a72489c-aab2-4b65-b93a-a91edccf33b8   # Microsoft's Azure DevOps MCP service

Creating the applications does not by itself grant the permission: after running these commands, reopen the admin-consent URL above (or use Entra admin center → Enterprise applications → airlock's Azure DevOps app → Permissions → Grant admin consent) so the tenant-wide grant is recorded, then retry Connect.

Additionally, if your organization uses Conditional Access policies, they can block sign-ins that originate from Microsoft's remote Azure DevOps MCP service. If Connect only fails for users covered by Conditional Access, review those policies with your administrator — Microsoft documents the service's IP addresses that location-based policies may need to allow in the remote MCP server troubleshooting guide.

Adding an Integration

  1. Open Integrations in the Control Room
  2. Select the integration from the catalog
  3. Follow the prompts to add it — the integration is ready to configure
  4. Go to the integration's detail page and connect your account (OAuth flow or API key)
  5. Configure policies for the tools
  6. Copy the MCP URL and add it to your AI client

Syncing Tools

Airlock keeps each integration's tool list aligned with its upstream MCP server, both automatically and on demand.

Automatic detection. On a schedule, airlock checks your connected integrations for upstream tool changes — tools that were added, removed, or changed. When it finds any, it records a notification and applies your organization's newly discovered tools policy, set by an admin under Settings → Security:

PolicyWhat happens to a newly discovered tool
Require approval (default)The tool is visible to agents, but every call needs approval until an admin marks it reviewed
DisabledThe tool stays hidden and uncallable until an admin enables it
EnabledThe tool is available to agents immediately

The policy applies to every integration in the organization.

Where it shows up. Admins see a notification in the bell menu in the top navigation bar, with an unread count. Opening it lists each integration that changed, along with the added / removed / changed counts; clicking an entry opens that integration's Tools & Policy tab, where you review the changes, unhide tools, and re-sync. (The bell is shown to admins only.)

Manual sync. You can refresh an integration's tools yourself at any time: open its detail page, go to the Tools & Policy tab, and click Sync Tools. This is available for MCP-proxy integrations (including every pre-built one) and for airlock's own built-in surfaces — use it whenever you want to pull the latest upstream tools immediately. Custom OpenAPI integrations have no sync button; their tools are fixed at the spec you deployed.

GitHub and Box are synced manually. Automatic detection isn't available for GitHub or Box integrations — both services issue single-use connection tokens that airlock can't safely reuse from a background job, so it never syncs them on a schedule. After connecting either one, and whenever its tools change, refresh them yourself with Sync Tools on the integration's Tools & Policy tab.