Airlock includes 240+ pre-built integrations that let you connect AI agents to popular services without writing an OpenAPI spec. Most are MCP proxies that route tool calls to the service's own upstream MCP server; around twenty services that don't offer a suitable MCP server of their own — including several of the built-in OAuth integrations — are proxied through an airlock-hosted MCP server instead.
The categories below highlight commonly-used integrations. The complete, up-to-date list is what you see under Integrations in the Control Room.
Available Integrations
Code & Project Management
| Integration | Auth Type | Description |
|---|---|---|
| GitHub | Built-in OAuth | Repository, pull request, and issue management |
| GitLab | OAuth | Repository, merge request, and CI/CD management |
| Bitbucket | Built-in OAuth | Repository, pull request, commit, branch, and issue management |
| Azure DevOps | Built-in OAuth | Work items, repositories, pull requests, pipelines, wikis, test plans, and code search (requires an Entra-backed Azure DevOps organization) |
| Azure DevOps (token) | API Key | The same ground as Azure DevOps — 77 tools across work items, repositories, branches, pull requests, pipelines, builds, wikis, test plans, and search — using a personal access token instead of Microsoft sign-in |
| Linear | OAuth | Issue and project tracking |
| Redmine | API Key | Issues, projects, time tracking, wiki pages, and search on your self-hosted Redmine instance |
| Atlassian | OAuth | Jira issues and Confluence pages |
| Atlassian Goals & Projects | API Key | Goals and projects in Atlassian Home — search, read, post status updates, create, and archive |
| Todoist | OAuth | Task and project management |
| CodeRabbit | API Key | AI code reviews, reports, and review metrics |
| Figma | Built-in OAuth | Design files and layers for design-to-code, screenshots, variables, components, styles, comments, and dev resources |
| Miro | OAuth | Visual collaboration — create and search boards, add diagrams, docs, tables, and images, and manage comments (Enterprise plan; admin must enable the MCP server) |
| Holmes | OAuth | AI QA — inspect test runs, file issues, and surface pipeline suggestions |
| Trello | OAuth | Boards, lists, cards, and members across your organizations |
| Monday.com | OAuth | Boards, items, updates, and workspaces for work management |
| Airtable | OAuth or API Key | Records, comments, and schema across your bases |
| Breeze | OAuth | Project management — read projects, tasks, and boards |
| Buildkite | OAuth | CI/CD pipelines, builds, jobs, and artifacts |
| Crowdin | OAuth | Localization projects, files, translations, and workflows |
| Fibery | OAuth | Workspace entities, databases, and documents |
| Postman | OAuth | Workspaces, collections, environments, and mocks |
| Productboard | OAuth | Product notes, features, releases, and feedback |
| Rize | OAuth | AI time tracking — sessions, projects, and insights |
| Rocketlane | OAuth | Customer onboarding projects, tasks, and forms |
| TickTick | OAuth | Tasks and projects |
| TimeCamp | OAuth | Time tracking and project time data |
| Workiom | OAuth | No-code lists, records, and workflows |
| Shortcut | OAuth | Stories, epics, iterations, workflows, and comments |
| Convex | OAuth | Backend deployments — browse tables and documents and run queries |
| v0 | API Key | Generate production-ready UI code through v0 chats |
| Browserbase | API Key | Hosted headless browser — navigate, act, observe, and extract |
CRM & Sales
| Integration | Auth Type | Description |
|---|---|---|
| HubSpot | OAuth (manual setup) | CRM contacts, deals, and sales pipeline |
| Dynamics 365 CRM | Built-in OAuth | Microsoft Dynamics 365 CRM (Dataverse) — accounts, contacts, leads, opportunities, and other customer records |
| Showpad | OAuth (manual setup) | Sales content and enablement |
| Lemlist | OAuth | Sales engagement, outreach campaigns, and sequences |
| Apollo.io | OAuth | Prospect search, contact and company enrichment, and outbound sequences |
| Attio | OAuth | CRM contacts, companies, deals, and custom objects |
| Brevo | OAuth or API Key | Email marketing and CRM — transactional email and SMS, contact management, and email campaigns |
| FullEnrich | OAuth | B2B contact enrichment — verified emails and phone numbers via waterfall enrichment |
| HeyReach | API Key | LinkedIn outreach automation — campaigns, leads, and sender accounts |
| Instantly | API Key | Cold email outreach — campaigns, leads, email accounts, and analytics |
| Coresignal | API Key | Firmographic, technographic, and employee data for B2B intelligence |
| Sumble | API Key | Sales intelligence and B2B prospecting data |
| Pipedrive | OAuth | CRM deals, contacts, leads, and activities across your pipeline |
| Close | OAuth | CRM leads, contacts, opportunities, and activities |
| Outreach | OAuth | Sales engagement — prospects, sequences, and account data |
| Salesloft | OAuth | Sales engagement — accounts, people, conversations, and opportunities |
| Customer.io | OAuth | Messaging automation — people, campaigns, and messaging data |
| Klaviyo | OAuth | Marketing automation — profiles, lists, segments, campaigns, and metrics |
| CompanyEnrich | OAuth | Company enrichment, search, and similar-company discovery |
| Crustdata | OAuth | Real-time company and people data for B2B intelligence |
| Dropcontact | OAuth | B2B email finding, verification, and contact enrichment |
| Enigma | OAuth | U.S. business identity and financial health data |
| Findymail | OAuth | B2B email and phone finding, verification, and lists |
| folk | OAuth | CRM people, companies, groups, and custom fields |
| Icypeas | OAuth | Professional email discovery and verification |
| Leadfeeder | OAuth | Website visitor intelligence, leads, lists, and campaigns |
| LeadIQ | OAuth | B2B prospecting — people and company search and enrichment |
| Mixmax | OAuth | Sales engagement — meeting and scheduling data |
| RocketReach | OAuth | Professional contact lookup and verification |
| Wiza | OAuth | LinkedIn prospect data — verified emails and phones |
| Hunter | OAuth | Email finding and verification, people and company enrichment, leads, and campaigns |
| ChMeetings | OAuth | Church management — people, families, groups, events, and contributions |
| Jungle Scout | API Key | Amazon product and keyword research, sales estimates, and share of voice |
Customer Support
| Integration | Auth Type | Description |
|---|---|---|
| DocsBot AI | OAuth | Documentation chatbots — bots, sources, and Q&A |
| Gorgias | OAuth | E-commerce helpdesk — tickets, customers, macros, and rules |
| Plain | OAuth | B2B support threads, customers, and tenants |
| Productlane | OAuth | Customer feedback threads, insights, and changelogs |
| Pylon | OAuth | B2B support issues, accounts, and contacts |
| Retently | OAuth | CX feedback, customers, campaigns, and surveys |
| Freshdesk | API Key | Helpdesk — create, update, and search tickets, reply and add notes, and manage contacts and companies |
Marketing & Email
| Integration | Auth Type | Description |
|---|---|---|
| eSputnik | OAuth | Omnichannel marketing — contacts, campaigns, email, SMS, and push |
| Handwrytten | OAuth | Handwritten cards — sending, contacts, orders, and balances |
| Linkly | OAuth | Tracking links, retargeting, and click analytics |
| Mailercloud | OAuth | Email campaigns, contacts, and lists |
| MailerLite | OAuth | Subscribers, groups, campaigns, and automations |
| MailerSend | OAuth | Transactional email — sending, domains, templates, and activity |
| Passcreator | OAuth | Apple/Google Wallet passes, templates, and distribution |
| Userlist | OAuth | SaaS email automation — users, companies, and campaigns |
| Wati | OAuth | WhatsApp Business messaging and contacts |
| Wisepops | OAuth | Popup campaigns and performance data |
| Resend | OAuth | Transactional email plus domains, audiences, contacts, and broadcasts |
| Missive | OAuth | Shared team inbox — conversations, drafts, contacts, and calendars |
| AgentMail | OAuth | Email inboxes built for agents — send, reply, and read threads |
| Raisely | OAuth | Fundraising campaigns, donations, donors, and supporter profiles |
Meetings & Communication
| Integration | Auth Type | Description |
|---|---|---|
| Slack | Built-in OAuth | Search messages, files, channels, and users; send messages; manage canvases; and add reactions |
| Google Calendar | Built-in OAuth | Calendar events and scheduling |
| Gmail | Built-in OAuth | Read, send, and manage emails |
| Outlook | Built-in OAuth | Read, search, draft, and send email, and browse mail folders |
| Outlook Calendar | Built-in OAuth | List, create, update, and delete calendar events, and browse calendars |
| Microsoft Teams | Built-in OAuth | List teams and channels, read and post channel messages, and browse and message chats |
| Zoom | OAuth (manual setup) | Meetings, recordings, and participants |
| Fathom | OAuth | Meeting recordings and transcripts |
| Granola | OAuth | Meeting notes and action items |
| Krisp | OAuth | Meeting transcripts and summaries |
| Wispr Flow | OAuth | Notetaker meetings — search them and read their notes, summaries, and briefs (read-only) |
| Leexi | OAuth | AI meeting and call intelligence — search recorded calls and read their transcripts and summaries, plus Leexi documentation |
| Calendly | OAuth | Scheduling — event types, scheduled meetings, and availability |
| Cal.com | OAuth | Open-source scheduling — bookings, event types, and availability |
| Fireflies | OAuth | Meeting transcripts, summaries, and action items |
| Synthflow AI | OAuth | AI voice agents, phone numbers, campaigns, and call transcripts |
| Bolna | OAuth | Conversational voice agents, calls, and call logs |
| Retell AI | API Key | Voice agents, phone numbers, calls, and transcripts |
| Vestaboard | OAuth | Split-flap display state and the boards on your account |
Infrastructure & Deployment
| Integration | Auth Type | Description |
|---|---|---|
| Vercel | Built-in OAuth | Deployments, projects, domains, and build logs |
| Supabase | OAuth | Databases, storage, and edge functions |
| Dagster+ | API Key | Data orchestration — assets, pipeline runs, and job launches |
| AWS | SigV4 (not yet supported) | 15,000+ AWS APIs, documentation, and guidance (coming soon) |
| Alchemy | OAuth | Blockchain data — tokens, transactions, NFTs, and on-chain queries |
| Cloudflare | OAuth | Workers, DNS, caching, security settings, and browser rendering |
| JumpCloud | OAuth | Directory users, devices, and groups |
| Neon | OAuth | Serverless Postgres — projects, branches, and SQL |
| Seqera | OAuth | Nextflow pipelines and compute environments |
| DNSFilter | OAuth | DNS security policies, blocked-domain activity, and traffic reports |
Monitoring & Analytics
| Integration | Auth Type | Description |
|---|---|---|
| Sentry | OAuth | Error monitoring and performance tracking |
| Better Stack | OAuth or API Key | Uptime monitors, incidents, on-call, heartbeats, and status pages; logs, metrics, and dashboards; and release and error tracking |
| airlock GEO | OAuth | Airlock's GEO radar — track how AI assistants talk about your brand, with visibility summaries and question-level results |
| PostHog | OAuth or API Key | Product analytics and feature flags |
| Datadog | API Key | Logs, metrics, alerts, and incident management |
| Aikido | API Key | Security issue tracking across code, cloud accounts, and containers |
| Mixpanel | OAuth | Product analytics — events, funnels, retention, segmentation, and insights |
| Amplitude | OAuth | Product analytics — events, charts, and behavioral insights |
| Databox | OAuth | Business metrics, dashboards, and datasources |
| DataForSEO | OAuth | SEO data — SERPs, keywords, backlinks, and competitive intelligence |
| Grafana | OAuth | Dashboards, datasource queries, incidents, and alerts |
| incident.io | OAuth | Incidents, alerts, schedules, and workflows |
| Klipfolio | OAuth | Business dashboards and metrics |
| MxToolbox | OAuth | DNS, MX, and blacklist lookups and email health checks |
| New Relic | OAuth | Observability — entities, NRQL queries, alerts, and incidents |
| Rootly | OAuth | Incidents, alerts, on-call schedules, and retrospectives |
| Similarweb Digital Rank | OAuth | Global website rank data |
| tokenspend.org | API Key | Open benchmark for AI adoption and token spend — org usage, spend, efficiency, and community benchmarks |
| UptimeRobot | OAuth | Uptime monitors, incidents, and alerts |
| CoinMarketCap | OAuth | Cryptocurrency prices, market caps, exchange data, and rankings |
| Alpaca | API Key | Stock, crypto, and options market data and the trading calendar |
| Interzoid | API Key | Data matching, standardization, verification, and enrichment |
Payments
| Integration | Auth Type | Description |
|---|---|---|
| Stripe | OAuth | Payments, subscriptions, invoices, and customers |
| Polar | OAuth | Products, pricing, checkouts, and license keys |
| Altoviz | OAuth | Billing — customers, invoices, quotes, expenses, and payments |
| Givebutter | OAuth | Fundraising campaigns, contacts, transactions, and tickets |
| Mercury | OAuth | Business banking (read-only) — accounts, transactions, cards, and statements |
| PayPal | OAuth | Invoices, orders, payments, subscriptions, and disputes |
| Ramp | OAuth | Spend management — cards, transactions, bills, and approvals |
| Razorpay | OAuth | Orders, payments, settlements, refunds, and payment links |
| Whop | OAuth | Digital products, memberships, and payments |
| OpenSea | API Key | NFT collections, items, listings, offers, and wallet balances |
Documentation & Data
| Integration | Auth Type | Description |
|---|---|---|
| Google Drive | Built-in OAuth | Files, folders, and Docs/Sheets content |
| OneDrive | Built-in OAuth | Browse, search, read, download, upload, and manage files and folders in your OneDrive |
| Box | OAuth (manual setup) | Search, read, and manage files and folders, plus AI-powered queries across your Box content |
| Dropbox | OAuth | Files and folders in your Dropbox account |
| Notion | OAuth | Pages, databases, and workspace content |
| Context7 | OAuth | Library and framework documentation |
| Ref | OAuth | API and library documentation |
| Airbyte | No auth | Data integration documentation and guides |
| Google Workspace | No auth | Google Workspace developer documentation, APIs, and code samples |
| Bright Data | API Key | Web scraping, search, and data extraction |
| Firecrawl | API Key | Web scraping, crawling, search, and structured data extraction |
| Apify | OAuth | Web scraping, data extraction, and ready-made Actors from the Apify Store |
| RapidAPI | API Key | Thousands of APIs from the RapidAPI Hub |
| Cognee | API Key | Persistent AI memory — knowledge graphs and cross-conversation context |
| Unblocked | API Key | Team context across Slack, Jira, Confluence, and GitHub |
| Bitquery | OAuth | Indexed blockchain data across 40+ networks |
| cloudlayer.io | OAuth | PDF and image generation from templates |
| Conversion Tools | OAuth | Document conversion between XML, Excel, PDF, Word, CSV, and more |
| Data247 | OAuth | On-demand phone, email, address, and identity lookups |
| DocsAutomator | OAuth | Document generation from Google Docs templates |
| EODHD | OAuth | Market data — EOD/intraday prices, fundamentals, news, and screeners |
| Exa | OAuth | AI web search, similar-page discovery, and content extraction |
| Kadoa | OAuth | Web data extraction workflows |
| Knack | OAuth | No-code database records and apps |
| Mapbox | OAuth | Geocoding, places, directions, styles, and datasets |
| Mem | OAuth | Notes — search, read, and create |
| Nanonets | OAuth | Document data extraction and processing workflows |
| Nusii | OAuth | Proposals and clients (read access) |
| OpenGraph.io | OAuth | Open Graph metadata and site previews |
| PDF4me | OAuth | PDF generation, conversion, and manipulation |
| Scrapfly | OAuth | Web scraping with JS rendering and anti-bot bypass |
| Slite | OAuth | Knowledge base docs — search, read, and write |
| Twelve Data | OAuth | Real-time and historical market data across asset classes |
| ZenRows | OAuth | Web scraping — structured data from dynamic sites |
| Grist | OAuth | Spreadsheet-database records, schemas, downloads, and webhooks |
| CloudConvert | OAuth | Convert documents, images, audio, and video across 200+ formats |
| PandaDoc | OAuth | Documents, templates, e-signature requests, and status tracking |
| DocuSeal | No auth | Semantic search over DocuSeal's documentation knowledge base |
| Affinda | OAuth | AI document extraction — resumes, invoices, and custom documents |
| ScrapeGraph AI | OAuth | AI web scraping, search, and site crawling |
| WebScraping.AI | OAuth | Rendered page HTML and text plus AI field extraction |
| Diffbot | API Key | URL extraction, web search, and Knowledge Graph enrichment |
| Piloterr | API Key | 190+ ready-made scraping APIs across marketplaces and social networks |
| ScrapingBee | API Key | Page text, HTML, and screenshots plus structured retailer and search results |
| SERPHouse | API Key | Google, Bing, and Yahoo search results across verticals |
| Autom | API Key | Google, Bing, and Brave search-results data |
| DaData.ru | API Key | Russian address standardization and company lookup |
| IPinfo | API Key | IP geolocation, ASN, carrier, and VPN/proxy detection |
| IP2Location | API Key | IP geolocation with ISP, coordinates, and proxy detection |
| Genderize | API Key | Predict the likely gender behind a first name |
Websites & Content
| Integration | Auth Type | Description |
|---|---|---|
| Agility CMS | OAuth | Headless CMS — content items, models, and containers |
| Contentful | OAuth | Entries, content types, assets, and GraphQL content queries |
| Memberspot | OAuth | Online courses, members, access, and community |
| Memberstack | OAuth | Website members and plans |
| Sanity | OAuth | Structured content — documents, datasets, and releases |
| Webflow | OAuth | Sites, CMS collections, pages, and publishing |
| Wix | OAuth | Sites, products, orders, bookings, and content |
| Cincopa | API Key | Hosted video and image assets and media galleries |
Design & Media
| Integration | Auth Type | Description |
|---|---|---|
| Canva | OAuth | Designs, folders, brand templates, comments, and assets |
| HeyGen | OAuth | AI avatar video creation and asset management |
| Shotstack | OAuth | Automated video, image, and audio rendering |
| Templated | API Key | Generate images and PDFs from templates |
AI & Machine Learning
| Integration | Auth Type | Description |
|---|---|---|
| Langbase | OAuth | AI pipes, memory, and agent primitives |
| Manus | OAuth | AI task automation and workflows |
| Mem0 | OAuth | Persistent memory for AI agents |
| OpenRouter | OAuth | LLM models, usage, credits, and keys |
| Replicate | OAuth | Run AI models and predictions in the cloud |
| AI/ML API | OAuth | Hosted model catalog for text, image, audio, and video generation |
| Roboflow | OAuth | Computer-vision projects, datasets, workflows, and model inference |
Automation
| Integration | Auth Type | Description |
|---|---|---|
| Zapier | OAuth | Run your connected Zapier actions across 8,000+ apps (Gmail, Slack, Google Sheets, HubSpot, and more) as MCP tools |
| Make | OAuth | Run your Make scenarios as tools |
| Process Street | API Key | Workflow management — launch and update workflow runs, complete tasks, approve or reject approvals, fill form fields, manage data sets and one-off tasks, and read pages |
| PhantomBuster | API Key | Lead generation and data extraction — launch agents and manage containers, scripts, leads, and CRM storage |
| Route4Me | API Key | Route planning and optimization, destinations, drivers, and geocoding |
| Detrack | OAuth | Delivery and job tracking, vehicles, drivers, and proof of delivery |
| Streamtime | OAuth | Creative studio jobs, tasks, logged time, and quotes |
| Instacart | No auth | Turn recipes and ingredient lists into shoppable carts |
| Conveyor | OAuth | Security questionnaire automation from Trust Center content |
| Persona | API Key | Identity verification inquiries, accounts, cases, and reports |
HR & Recruiting
| Integration | Auth Type | Description |
|---|---|---|
| Ashby | API Key | Candidates, jobs, applications, interviews, and offers |
| Greenhouse | OAuth | Recruiting — candidates, jobs, applications, and interview data |
| Breezy HR | OAuth | Recruiting — candidates, positions, and pipeline management |
| Workable | OAuth | Hiring — candidates, jobs, offers, and employee data |
ERP
| Integration | Auth Type | Description |
|---|---|---|
| Dynamics 365 Finance & Operations | Built-in OAuth | Microsoft Dynamics 365 finance, supply chain, and operations data (coming soon) |
| Odoo | API Key | Odoo ERP/CRM — contacts, leads, sales orders, products, and any model across Sales, Inventory, Accounting, and Project |
| Apaleo | OAuth | Hotel property management — reservations, folios, rates, and operations |
| Storeganise | OAuth | Self-storage bookings, units, and billing |
Forms & Email Validation
| Integration | Auth Type | Description |
|---|---|---|
| Tally | OAuth | Form creation and submission management across workspaces |
| ZeroBounce | API Key | Email validation, deliverability checks, and contact discovery |
| BounceBan | API Key | Email deliverability — validate single and bulk addresses, detect disposable and catch-all emails, and check credits |
| Fillout | OAuth | Forms and submissions |
| Jotform | OAuth | Online forms and submissions |
| SafetyCulture | OAuth | Inspections, audits, actions, and assets |
Airlock-hosted MCP Integrations
Some services don't expose their own MCP server (or expose one airlock can't proxy), so airlock hosts one for them. These are still MCP proxies — they forward tool calls to an airlock-hosted MCP server rather than a vendor-run one. This is an implementation detail: you connect them exactly like any other integration, with whatever auth type is listed for them above (built-in OAuth ones via Connect, API-key ones by entering a key on the integration's detail page).
The airlock-hosted integrations are:
- Built-in OAuth: Slack, Gmail, Google Calendar, Google Drive, Outlook, Outlook Calendar, OneDrive, Microsoft Teams, Bitbucket, Figma, Vercel, Dynamics 365 CRM
- API key / token: Aikido, Ashby, Atlassian Goals & Projects, Azure DevOps (token), BounceBan, CodeRabbit, Dagster+, Datadog, Freshdesk, Odoo, PhantomBuster, Process Street, Redmine, ZeroBounce
- Manual OAuth setup: Zoom
Authentication Types
Built-in OAuth
Integrations marked Built-in OAuth (GitHub, Bitbucket, Azure DevOps, Slack, Figma, Google Calendar, Gmail, Outlook, Outlook Calendar, Microsoft Teams, Google Drive, OneDrive, Vercel, Dynamics 365 CRM) have pre-configured OAuth credentials managed by airlock. Users simply click Connect and complete the authorization flow — no setup required.
Standard OAuth
Most integrations use standard OAuth. When you add the integration, airlock handles the OAuth flow with the upstream service. Users click Connect on the integration's detail page to authorize access.
No auth
A few public documentation servers — Airbyte and Google Workspace — need no credentials at all. They work as soon as you add them; there is no Connect step.
Manual OAuth Setup
HubSpot, Showpad, and Zoom require you to create your own OAuth application in the service's developer portal first, then enter the client credentials in airlock. Box is similar — each organization enables the Box MCP Server in its own Box Admin Console to generate an enterprise-specific client ID and secret. The wizard shows the redirect URI to register and links to each provider's setup guide.
API Key
Many integrations — including Datadog, Firecrawl, RapidAPI, Dagster+, CodeRabbit, Aikido, ZeroBounce, PhantomBuster, BounceBan, Freshdesk, Process Street, Redmine, and Odoo — use API key or bearer token authentication. Generate a key in the service's settings and enter it on the integration's detail page.
A few integrations ask for two values instead of one, and airlock combines them for you:
- Datadog — an API key and an Application key (both from Datadog's Organization Settings → API Keys / Application Keys).
- Odoo — your Odoo login (email) and your API key.
- Atlassian Goals & Projects — your Atlassian account email and a classic API token.
Redmine uses your personal API key from "My account" → "API access key" on your Redmine instance (the REST API must be enabled by an administrator under Administration → Settings → API).
Atlassian Goals & Projects requires a classic (unscoped) Atlassian API token created at id.atlassian.com — scoped API tokens cannot access the Goals & Projects APIs. Note that a classic token carries your full Atlassian access (including Jira and Confluence), even though this integration only exposes Goals & Projects tools.
Additional Setup
Some integrations need one extra detail when you add them, on top of credentials:
- Showpad and Cognee ask for your workspace subdomain (for example,
your-companyforyour-company.showpad.com). - Freshdesk asks for your Freshdesk domain (for example,
yourcompanyforyourcompany.freshdesk.com). - Redmine asks for your instance URL (for example,
redmine.example.com, ortools.example.com/redminefor a subpath install). The instance must be reachable over a public HTTPS address. The instance URL is set once per server and shared by everyone who connects, while each member authenticates with their own API key — so set it to a Redmine host you trust, since every connecting member's key is sent to whatever host is configured. - Atlassian Goals & Projects asks for your Atlassian site (for example,
yourcompanyforyourcompany.atlassian.net). - Azure DevOps asks for your organization name (for example,
contosofordev.azure.com/contoso). The organization must be connected to Microsoft Entra ID (personal-account organizations are not supported) — see Azure DevOps tenant prerequisites below. - Azure DevOps (token) asks for the same organization name, plus a personal access token — see Which Azure DevOps integration to choose below.
- Dynamics 365 CRM asks for your Dataverse environment host (for example,
orgname.crm.dynamics.com). - Odoo asks for your instance host and database name.
- Dagster+ asks for your deployment URL.
- RapidAPI asks for the API host of the specific API you want to call.
Airlock prompts for these when you add the integration.
Which Azure DevOps integration to choose
There are two Azure DevOps tiles, and they differ only in how you sign in:
| Azure DevOps | Azure DevOps (token) | |
|---|---|---|
| How you connect | Sign in with your Microsoft account | Paste a personal access token |
| Requires an Entra-backed organization | Yes | No |
| Where the tools come from | Microsoft's own Azure DevOps MCP server | An airlock-hosted server over the Azure DevOps REST API |
| Tools | Microsoft's set | 77 |
Use Azure DevOps (the first one) unless you can't. It is the default: Microsoft runs the server, so new capabilities appear without airlock shipping anything.
Use Azure DevOps (token) when Microsoft sign-in is not available to you — most often because your Azure DevOps organization is not backed by Microsoft Entra ID, or because an administrator cannot grant the consent the first option needs. It covers the same ground: work items (including creating and updating them), queries and WIQL, boards, iterations and capacity, repositories, branches, files and commits, pull requests with their comment threads and reviewers, pipelines and builds with their logs, wikis, test plans, and code, wiki, and work-item search.
Two capabilities of Microsoft's server the token option does not cover:
- Listing your other Azure DevOps organizations. The token option is scoped to the single organization you name when you connect it.
- Downloading binary attachments and build artifacts. Work-item attachments and pipeline artifacts are listed, with their download URLs, but the bytes are not returned through the integration.
Microsoft's Enterprise Live Migration tools are also absent — they are a private preview that most organizations cannot enable on either option.
One place the token option is better: ad-hoc WIQL queries. Microsoft gates
wit_query_by_wiql behind an Insiders header on its own server; here
query_work_items is available to everyone.
You can connect both at once — they appear as separate integrations.
Azure DevOps tenant prerequisites
The prerequisites in this section apply to the Azure DevOps integration only. Azure DevOps (token) authenticates with a personal access token and needs none of them — create a token in Azure DevOps under User settings → Personal access tokens, scoped to the areas you want the agent to reach, and paste it on the integration's detail page.
Azure DevOps sign-in runs through Microsoft Entra ID, so the Connect flow depends on two applications being present in your company's Entra tenant: airlock's Azure DevOps app and Microsoft's Azure DevOps MCP service. In most tenants both are set up automatically the first time a user consents. A one-time action by an Entra administrator is needed when:
- your tenant restricts user consent to new applications (common in enterprises), or
- Connect fails with an error about a missing service principal (for example, "the app is trying to access a service … that your organization lacks a service principal for").
In either case, an administrator with rights to grant tenant-wide admin consent (for example, a Global Administrator) can approve airlock's Azure DevOps app for the whole tenant by opening this URL and accepting the consent prompt:
https://login.microsoftonline.com/organizations/adminconsent?client_id=c79f31ab-5bae-4405-a728-3e85659584e6If the administrator's account has access to more than one directory (for example, as a guest or delegated administrator), replace organizations in the URL with the tenant ID or a verified domain of the directory that backs your Azure DevOps organization — the organizations form applies consent in the account's home tenant, which may not be the right one.
After accepting, the browser may land on an airlock sign-in page — the administrator can simply close it (no airlock sign-in is needed for the consent). Then retry Connect in airlock.
If Connect still reports a missing service principal — or the administrator never saw a consent prompt — the administrator can create both applications directly with the Azure CLI (signed in to your tenant):
az ad sp create --id c79f31ab-5bae-4405-a728-3e85659584e6 # Airlock's Azure DevOps app
az ad sp create --id 2a72489c-aab2-4b65-b93a-a91edccf33b8 # Microsoft's Azure DevOps MCP serviceCreating the applications does not by itself grant the permission: after running these commands, reopen the admin-consent URL above (or use Entra admin center → Enterprise applications → airlock's Azure DevOps app → Permissions → Grant admin consent) so the tenant-wide grant is recorded, then retry Connect.
Additionally, if your organization uses Conditional Access policies, they can block sign-ins that originate from Microsoft's remote Azure DevOps MCP service. If Connect only fails for users covered by Conditional Access, review those policies with your administrator — Microsoft documents the service's IP addresses that location-based policies may need to allow in the remote MCP server troubleshooting guide.
Adding an Integration
- Open Integrations in the Control Room
- Select the integration from the catalog
- Follow the prompts to add it — the integration is ready to configure
- Go to the integration's detail page and connect your account (OAuth flow or API key)
- Configure policies for the tools
- Copy the MCP URL and add it to your AI client
Syncing Tools
Airlock keeps each integration's tool list aligned with its upstream MCP server, both automatically and on demand.
Automatic detection. On a schedule, airlock checks your connected integrations for upstream tool changes — tools that were added, removed, or changed. When it finds any, it records a notification and applies your organization's newly discovered tools policy, set by an admin under Settings → Security:
| Policy | What happens to a newly discovered tool |
|---|---|
| Require approval (default) | The tool is visible to agents, but every call needs approval until an admin marks it reviewed |
| Disabled | The tool stays hidden and uncallable until an admin enables it |
| Enabled | The tool is available to agents immediately |
The policy applies to every integration in the organization.
Where it shows up. Admins see a notification in the bell menu in the top navigation bar, with an unread count. Opening it lists each integration that changed, along with the added / removed / changed counts; clicking an entry opens that integration's Tools & Policy tab, where you review the changes, unhide tools, and re-sync. (The bell is shown to admins only.)
Manual sync. You can refresh an integration's tools yourself at any time: open its detail page, go to the Tools & Policy tab, and click Sync Tools. This is available for MCP-proxy integrations (including every pre-built one) and for airlock's own built-in surfaces — use it whenever you want to pull the latest upstream tools immediately. Custom OpenAPI integrations have no sync button; their tools are fixed at the spec you deployed.
GitHub and Box are synced manually. Automatic detection isn't available for GitHub or Box integrations — both services issue single-use connection tokens that airlock can't safely reuse from a background job, so it never syncs them on a schedule. After connecting either one, and whenever its tools change, refresh them yourself with Sync Tools on the integration's Tools & Policy tab.