Connector authentication requirements
Every native connector uses an admin-level credential (an OAuth app, service account, or API token configured by a Glean admin) to crawl and index content. For most connectors, that single credential is enough.
A smaller set of connectors also support or require individual user authentication, where each end user connects their own account. This is separate from admin setup and unlocks one of the following:
- Real-time access to content that hasn't been indexed yet (for example, OneDrive, SharePoint, Salesforce, and Notion)
- Access to private or restricted content that the admin credential can't see on its own (for example, Affinity Opportunities and Lists, Slack private channels and DMs)
- Identity mapping required before any results from that source appear for a user at all (for example, GitHub, Intercom, Ironclad, Miro, Tableau)
Every connector is permission-aware. Glean carries each document's source permissions over during the admin crawl, so users only ever see what they can already see in the source. The groups below show only whether users must also authenticate individually. That's separate from permission enforcement and never changes what a user is allowed to see.
Some sources offer both an indexed connector and a separate MCP integration with its own per-user OAuth (for example, NetSuite, Klue, and Sigma). This table shows each connector's own authentication. The MCP layer authenticates separately.
This page reflects the authentication model described in each connector's current setup documentation. Behavior varies between connector versions, and some connectors support more than one deployment mode (for example, indexed versus real-time access, or cloud versus Server editions), each with its own requirements. Always confirm current behavior against the linked connector documentation, and check Admin console → Platform → Connectors for your deployment's configuration.
Within each group, connectors are listed alphabetically. Click a connector name to open its setup documentation.
Connectors that require individual user authentication
Without this step, affected users see no content from the source (or only its public content). Complete the admin setup, then have each user authenticate individually.
| Connector | Admin authentication | What user authentication unlocks |
|---|---|---|
| ClickUp | OAuth app (admin registers MCP server) | Live, federated access to the user's own permissioned ClickUp tasks and docs. No access without it |
| DocuSign | OAuth app (integration key and secret) | Live fetch of DocuSign document and envelope content in chat, with individual user authorization |
| GitHub | GitHub App installed by org admin (read-only scopes) | Maps the user's GitHub alias to their email. Until completed, the user sees no GitHub content, public or private |
| GitHub Enterprise Server | GitHub App and admin-issued classic PAT | Maps the user's GitHub alias to their email. Until completed, no GitHub content appears in their results |
| GitHub Server | GitHub App created on the instance | Syncs the user's GitHub alias. Until completed, the user can't see content in private repositories |
| Intercom | OAuth 2.0 private app (admin-configured) | Lets Glean show the user only the conversations, tickets, and draft articles their Intercom account can access. Without it, they see none of these (published Help Center articles stay visible to everyone) |
| Ironclad | OAuth app (admin-authorized, two-layer OAuth) | Required for a user to see any Ironclad content at all. Results then mirror that user's real Ironclad access |
| Miro | OAuth 2.0 app credentials (installed by a Company and Content Admin) | Only boards visible to users who have completed their own OAuth authorization are crawled |
| Tableau | Personal Access Token (admin) | Each user must connect their own Personal Access Token, or they see no Tableau results |
Connectors where individual user authentication is optional
Indexed search works with the admin credential alone. Individual authentication unlocks the extra access described below.
| Connector | Admin authentication | What user authentication unlocks |
|---|---|---|
| Affinity | OAuth app (central Glean OAuth app, greenlisted per workspace) | Access to the user's own Opportunities and Lists (List-level permissions). Admin auth alone covers People and Companies |
| Confluence (Cloud) | OAuth app (Forge app installed by admin) | Indexing of restricted pages the user has edit access to, via a user-uploaded API token |
| Granola | Workspace Enterprise API key (admin-set) | Connecting a personal API key indexes the user's own private "My Notes" content |
| Highspot | API client key and secret (dedicated API user) | Enabling API impersonation turns on Spot-level permission enforcement. By default, all content is visible to all users |
| Klue | Admin API key (content:read and scim:read scopes) | The separate Klue MCP integration uses per-user OAuth (via Dynamic Client Registration) for live, permission-aware access to Klue tools in Glean Assistant and Agents at query time |
| Monday | OAuth app installed and authorized by an admin | Indexes private boards, shareable boards, and public boards in closed workspaces the user can access, beyond the default public content |
| NetSuite | M2M OAuth 2.0 with X.509 certificate (NetSuite Administrator) | The separate NetSuite MCP integration uses per-user OAuth for live, permission-aware access to NetSuite records at query time |
| Notion | Internal integration Bearer token (Workspace Admin-created) | Per-user OAuth ("Live Mode") fetches fresh, permission-aware content at query time, including private or very recent pages |
| OneDrive | Certificate-based app-only authentication (inherited from Microsoft 365) | Enables the real-time access add-on, fetching live OneDrive content scoped to the user's own permissions |
| Salesforce | OAuth via a dedicated integration user or service account | "Connect Salesforce account" enables live, permission-aware data fetching (Live Mode) and Salesforce write tools at query time |
| SharePoint | Certificate-based app permissions (Microsoft 365 parent) | Enables real-time access to SharePoint content not yet indexed, scoped to the user's own permissions |
| Sigma | API client credentials | Enables Sigma in Assistant for natural-language queries |
| Slack | Admin-authorized Slack app | Unlocks private channel, DM, and group DM results for that user |
| Smartsheet | OAuth 2.0 (admin-authorized) | Indexes the user's own private Smartsheet documents |
Connectors that use admin authentication only
A single admin-level credential covers indexing and permissions. Users don't authenticate individually.
| Connector | Admin authentication |
|---|---|
| 15Five | API token (admin-generated) |
| Aha! | API token (personal access token) |
| Airtable | API token (personal access token) |
| Asana | API token (service account or admin PAT) |
| Autodesk Construction Cloud | OAuth app (Autodesk Platform Services, admin-granted) |
| Azure DevOps | Service account (Azure app registration or service principal with client secret) |
| BambooHR | API token (admin-generated) |
| Bitbucket | OAuth consumer and API token (admin or bot account) |
| Bitbucket Server | API token (HTTP access token, admin) |
| Box | OAuth app (admin-authorized) |
| Canva | OAuth app (org-wide admin authorization) |
| Coda | API token (Organization Admin service account) |
| Confluence Data Center | Service account credentials, webhook, and plugin |
| Crayon | API key (Admin or Integrator role) |
| Databricks | Service account (M2M OAuth, service principal) |
| Docebo | OAuth app (OAuth 2.0 or JWT Bearer, admin-authorized) |
| Dropbox | OAuth app (admin-authorized) |
| Egnyte | OAuth app (admin-authorized, multiple admin accounts supported for throughput) |
| Freshdesk | API token (admin or agent API key) |
| Freshservice | API key (Admin, Account Admin, or Workspace Admin-scoped) |
| Gainsight | Machine-to-machine OAuth client (client ID and secret) |
| GitLab Cloud | Personal access token (admin-scoped) and webhook secret |
| GitLab Server | Personal access token (admin or non-admin) |
| Gmail | Service account with domain-wide delegation |
| Gmail (Federated) | Service account with domain-wide delegation (expanded scopes) |
| Gong | OAuth 2.0 authorized by a Gong admin |
| Google Calendar | Service account with domain-wide delegation |
| Google Chat | Service account with domain-wide delegation |
| Google Drive | Service account with domain-wide delegation |
| Google Groups | Service account with domain-wide delegation and Google Vault |
| Google Sites | Service account with domain-wide delegation and Google Vault |
| Greenhouse | Basic Auth via Harvest API key (site admin-provisioned) |
| Guru | User Access Token from a Guru team admin |
| HubSpot | Private app access token and client secret (super admin-created) |
| Jira Cloud | Forge Crawler App installed by a Jira admin |
| Jira Data Center | Service account (Basic Auth) |
| Lessonly | API token (admin-generated) |
| Linear | OAuth 2.0 (admin-authorized custom app) |
| Looker | API3 key (client ID and secret, admin account) |
| LumApps | OAuth 2.0 (admin-authorized) |
| Microsoft 365 | Certificate-based app-only authentication (shared parent connector for SharePoint and OneDrive) |
| Microsoft Dynamics 365 | App registration with a client secret, added as a read-only application user |
| Microsoft Outlook | Certificate-based app-only authentication (indexing and optional real-time access) |
| Microsoft Teams | Azure app registration (certificate or secret) |
| Microsoft Viva Engage | OAuth 2.0 delegated (Verified Administrator) |
| Okta | OAuth 2.0 Client Credentials with signed JWT (bootstrapped via temporary super admin token) |
| PagerDuty | Read-only REST API access key (admin-generated) |
| Panopto | OAuth 2.0 client credentials (admin-created API client) |
| Perforce | MCP server deployed jointly with Glean (no self-serve admin flow) |
| Pingboard | Service account (client ID and secret) |
| Procore | OAuth app with a Developer Managed Service Account |
| Quip | OAuth 2.0 via Quip Admin API (dedicated service-style user) |
| S3 | IAM role (federated web identity or cross-account trust) |
| Salesloft Conversation Intelligence | API key and API password |
| Seismic | OAuth 2.0 authorization code flow (admin-authorized) |
| ServiceNow | Dedicated service account and OAuth application |
| SharePoint On-Prem | NTLM service account and Entra App Proxy |
| Shortcut | API token (workspace-level) and webhook secret |
| Simpplr | OAuth 2.0 client credentials |
| Stack Overflow | Admin-configured credentials (mode-dependent) |
| Trello | API key and access token (admin) |
| Veeva Vault | Username and password, or OAuth 2.0 Client Credentials |
| Website | Admin-configured site credentials |
| Windchill | Service account (Basic Auth) |
| WordPress | HTTP Basic Auth (application password) |
| Workday | OAuth 2.0 (Integration System User) |
| Zendesk | API token (service account) |
| Zoom | OAuth 2.0 app authorization (Admin or Owner) |
See also
- About connectors — how Glean's data access modes (indexed, live, and hybrid) relate to authentication
- Crawl and index connectors — how connectors crawl and refresh content
- Manage connectors — monitor connector status and health after setup