Skip to main content

Connector authentication requirements

Every native connector uses an admin-level credential (an OAuth app, service account, or API token configured by a Glean admin) to crawl and index content. For most connectors, that single credential is enough.

A smaller set of connectors also support or require individual user authentication, where each end user connects their own account. This is separate from admin setup and unlocks one of the following:

  • Real-time access to content that hasn't been indexed yet (for example, OneDrive, SharePoint, Salesforce, and Notion)
  • Access to private or restricted content that the admin credential can't see on its own (for example, Affinity Opportunities and Lists, Slack private channels and DMs)
  • Identity mapping required before any results from that source appear for a user at all (for example, GitHub, Intercom, Ironclad, Miro, Tableau)

Every connector is permission-aware. Glean carries each document's source permissions over during the admin crawl, so users only ever see what they can already see in the source. The groups below show only whether users must also authenticate individually. That's separate from permission enforcement and never changes what a user is allowed to see.

note

Some sources offer both an indexed connector and a separate MCP integration with its own per-user OAuth (for example, NetSuite, Klue, and Sigma). This table shows each connector's own authentication. The MCP layer authenticates separately.

important

This page reflects the authentication model described in each connector's current setup documentation. Behavior varies between connector versions, and some connectors support more than one deployment mode (for example, indexed versus real-time access, or cloud versus Server editions), each with its own requirements. Always confirm current behavior against the linked connector documentation, and check Admin console → Platform → Connectors for your deployment's configuration.

Within each group, connectors are listed alphabetically. Click a connector name to open its setup documentation.

Connectors that require individual user authentication

Without this step, affected users see no content from the source (or only its public content). Complete the admin setup, then have each user authenticate individually.

ConnectorAdmin authenticationWhat user authentication unlocks
ClickUpOAuth app (admin registers MCP server)Live, federated access to the user's own permissioned ClickUp tasks and docs. No access without it
DocuSignOAuth app (integration key and secret)Live fetch of DocuSign document and envelope content in chat, with individual user authorization
GitHubGitHub App installed by org admin (read-only scopes)Maps the user's GitHub alias to their email. Until completed, the user sees no GitHub content, public or private
GitHub Enterprise ServerGitHub App and admin-issued classic PATMaps the user's GitHub alias to their email. Until completed, no GitHub content appears in their results
GitHub ServerGitHub App created on the instanceSyncs the user's GitHub alias. Until completed, the user can't see content in private repositories
IntercomOAuth 2.0 private app (admin-configured)Lets Glean show the user only the conversations, tickets, and draft articles their Intercom account can access. Without it, they see none of these (published Help Center articles stay visible to everyone)
IroncladOAuth app (admin-authorized, two-layer OAuth)Required for a user to see any Ironclad content at all. Results then mirror that user's real Ironclad access
MiroOAuth 2.0 app credentials (installed by a Company and Content Admin)Only boards visible to users who have completed their own OAuth authorization are crawled
TableauPersonal Access Token (admin)Each user must connect their own Personal Access Token, or they see no Tableau results

Connectors where individual user authentication is optional

Indexed search works with the admin credential alone. Individual authentication unlocks the extra access described below.

ConnectorAdmin authenticationWhat user authentication unlocks
AffinityOAuth app (central Glean OAuth app, greenlisted per workspace)Access to the user's own Opportunities and Lists (List-level permissions). Admin auth alone covers People and Companies
Confluence (Cloud)OAuth app (Forge app installed by admin)Indexing of restricted pages the user has edit access to, via a user-uploaded API token
GranolaWorkspace Enterprise API key (admin-set)Connecting a personal API key indexes the user's own private "My Notes" content
HighspotAPI client key and secret (dedicated API user)Enabling API impersonation turns on Spot-level permission enforcement. By default, all content is visible to all users
KlueAdmin API key (content:read and scim:read scopes)The separate Klue MCP integration uses per-user OAuth (via Dynamic Client Registration) for live, permission-aware access to Klue tools in Glean Assistant and Agents at query time
MondayOAuth app installed and authorized by an adminIndexes private boards, shareable boards, and public boards in closed workspaces the user can access, beyond the default public content
NetSuiteM2M OAuth 2.0 with X.509 certificate (NetSuite Administrator)The separate NetSuite MCP integration uses per-user OAuth for live, permission-aware access to NetSuite records at query time
NotionInternal integration Bearer token (Workspace Admin-created)Per-user OAuth ("Live Mode") fetches fresh, permission-aware content at query time, including private or very recent pages
OneDriveCertificate-based app-only authentication (inherited from Microsoft 365)Enables the real-time access add-on, fetching live OneDrive content scoped to the user's own permissions
SalesforceOAuth via a dedicated integration user or service account"Connect Salesforce account" enables live, permission-aware data fetching (Live Mode) and Salesforce write tools at query time
SharePointCertificate-based app permissions (Microsoft 365 parent)Enables real-time access to SharePoint content not yet indexed, scoped to the user's own permissions
SigmaAPI client credentialsEnables Sigma in Assistant for natural-language queries
SlackAdmin-authorized Slack appUnlocks private channel, DM, and group DM results for that user
SmartsheetOAuth 2.0 (admin-authorized)Indexes the user's own private Smartsheet documents

Connectors that use admin authentication only

A single admin-level credential covers indexing and permissions. Users don't authenticate individually.

ConnectorAdmin authentication
15FiveAPI token (admin-generated)
Aha!API token (personal access token)
AirtableAPI token (personal access token)
AsanaAPI token (service account or admin PAT)
Autodesk Construction CloudOAuth app (Autodesk Platform Services, admin-granted)
Azure DevOpsService account (Azure app registration or service principal with client secret)
BambooHRAPI token (admin-generated)
BitbucketOAuth consumer and API token (admin or bot account)
Bitbucket ServerAPI token (HTTP access token, admin)
BoxOAuth app (admin-authorized)
CanvaOAuth app (org-wide admin authorization)
CodaAPI token (Organization Admin service account)
Confluence Data CenterService account credentials, webhook, and plugin
CrayonAPI key (Admin or Integrator role)
DatabricksService account (M2M OAuth, service principal)
DoceboOAuth app (OAuth 2.0 or JWT Bearer, admin-authorized)
DropboxOAuth app (admin-authorized)
EgnyteOAuth app (admin-authorized, multiple admin accounts supported for throughput)
FreshdeskAPI token (admin or agent API key)
FreshserviceAPI key (Admin, Account Admin, or Workspace Admin-scoped)
GainsightMachine-to-machine OAuth client (client ID and secret)
GitLab CloudPersonal access token (admin-scoped) and webhook secret
GitLab ServerPersonal access token (admin or non-admin)
GmailService account with domain-wide delegation
Gmail (Federated)Service account with domain-wide delegation (expanded scopes)
GongOAuth 2.0 authorized by a Gong admin
Google CalendarService account with domain-wide delegation
Google ChatService account with domain-wide delegation
Google DriveService account with domain-wide delegation
Google GroupsService account with domain-wide delegation and Google Vault
Google SitesService account with domain-wide delegation and Google Vault
GreenhouseBasic Auth via Harvest API key (site admin-provisioned)
GuruUser Access Token from a Guru team admin
HubSpotPrivate app access token and client secret (super admin-created)
Jira CloudForge Crawler App installed by a Jira admin
Jira Data CenterService account (Basic Auth)
LessonlyAPI token (admin-generated)
LinearOAuth 2.0 (admin-authorized custom app)
LookerAPI3 key (client ID and secret, admin account)
LumAppsOAuth 2.0 (admin-authorized)
Microsoft 365Certificate-based app-only authentication (shared parent connector for SharePoint and OneDrive)
Microsoft Dynamics 365App registration with a client secret, added as a read-only application user
Microsoft OutlookCertificate-based app-only authentication (indexing and optional real-time access)
Microsoft TeamsAzure app registration (certificate or secret)
Microsoft Viva EngageOAuth 2.0 delegated (Verified Administrator)
OktaOAuth 2.0 Client Credentials with signed JWT (bootstrapped via temporary super admin token)
PagerDutyRead-only REST API access key (admin-generated)
PanoptoOAuth 2.0 client credentials (admin-created API client)
PerforceMCP server deployed jointly with Glean (no self-serve admin flow)
PingboardService account (client ID and secret)
ProcoreOAuth app with a Developer Managed Service Account
QuipOAuth 2.0 via Quip Admin API (dedicated service-style user)
S3IAM role (federated web identity or cross-account trust)
Salesloft Conversation IntelligenceAPI key and API password
SeismicOAuth 2.0 authorization code flow (admin-authorized)
ServiceNowDedicated service account and OAuth application
SharePoint On-PremNTLM service account and Entra App Proxy
ShortcutAPI token (workspace-level) and webhook secret
SimpplrOAuth 2.0 client credentials
Stack OverflowAdmin-configured credentials (mode-dependent)
TrelloAPI key and access token (admin)
Veeva VaultUsername and password, or OAuth 2.0 Client Credentials
WebsiteAdmin-configured site credentials
WindchillService account (Basic Auth)
WordPressHTTP Basic Auth (application password)
WorkdayOAuth 2.0 (Integration System User)
ZendeskAPI token (service account)
ZoomOAuth 2.0 app authorization (Admin or Owner)

See also