Docs / 07 of 14
Connecting integrations
Authorize, rotate, and revoke OAuth and API-key connections for connected products. Plan caps, scopes, and the errors a workspace admin will actually see.
connected products run on nox.markets and act in systems you already use. You authorize a grant. You do not map fields. hosted products skip this page. self-hosted products do not hold your SaaS tokens on our side.
Marks of QuickBooks, HubSpot, and the rest are systems we connect to. They are not customers.
Where this lives
/dashboard/integrations is the roster of connections for the Organization. Product settings at /dashboard/products/[slug]/settings show which connections that slug needs.
Empty roster: No connections. connected products cannot act until you authorize a system on the card.
Auth types
Connectors use one authType:
authType | What you do |
|---|---|
oauth2 | Vendor consent screen. We store a scoped refresh token as a connector secret, not in application plaintext. |
api-key | You paste a key the vendor issued. Same secret handling. |
webhook | The vendor pushes events to us. You confirm the subscription in their admin. |
none | No customer grant (rare; catalog wiring only). |
Write access means we create or update objects in their tenant (a draft bill, an invoice). A Slack ping is not write access to your books.
Google is several directory slugs (gmail, google-drive, google-sheets, google-workspace) because the consent screens differ. Behind the dashboard, one provider session can be reused; adding Drive after Gmail is incremental consent, not a second Google login. Microsoft follows the same pattern (microsoft-365, microsoft-excel).
Plan caps
Counted connections with read+write:
tier | Cap |
|---|---|
starter | 2 |
growth | 8 |
scale | Unlimited |
enterprise | Unlimited |
The third write connector is a designed starter → growth trigger. A connection that is only used as read still occupies a slot if the product requested write scopes and the vendor granted them. If you need the third connector, upgrade; do not share one OAuth app across two vendors.
Connect (oauth2)
You need owner or admin. member and billing cannot connect new apps.
- Open the product card and note
integrations[]. - Open
/dashboard/integrations(or the product settings connector row). - Choose the system. Confirm sandbox vs production on the connection card before you continue. Mixing them is a common failure; the grant can look healthy while writes hit the wrong company.
- Complete the vendor consent. Grant the scopes the product lists. An admin on that system may have to approve.
- Wait for return: Waiting on {system} to return.
- Confirm a test read on the connection card (company name, mailbox, or equivalent).
Required integrations on the product must succeed before the first run. Optional ones can wait.
QuickBooks Online is per company (realmId), not per Intuit user. Switching companies in the picker creates a second connection. We do not silently retarget.
If authorization fails
Authorization was cancelled. {product} cannot act in {system} without it.
You closed the vendor dialog. Start again. The product did not get a token.
{system} did not grant the scopes {product} needs: {scopes}. An admin on that system has to approve them.
Typical on Microsoft 365, Google Workspace, and NetSuite. The person who clicked Connect was not allowed to consent. An IT admin on the vendor side has to approve the app, then retry.
A connection-healthy, write-denied state (vendor role lacks permission to create a bill) is a run error, not a broken OAuth grant. Fix the role in the vendor admin. Do not revoke and reconnect as the first move.
Revoke
Revoke connection on the integration row. Confirmation: Connection to {system} revoked. connected products that needed it cannot act.
You can also revoke in the vendor's own connected-apps screen. Either side is sufficient. Tokens we hold are then unusable; remaining copies in our secret store follow the product retention window, then are deleted.
Revoke is the off switch for connected products. Pause is the off switch inside nox.markets. Use both if you are taking the product out of the SOP.
OAuth access tokens refresh automatically. There is no separate “rotate connection” control. To rotate a pasted api-key, revoke and connect again with the new secret. Reconnect is also the path after a vendor forces app recertification.
What we hold
Scoped OAuth tokens and pasted API keys are connector_secrets. They are envelope-encrypted. They are not used to train models.
What a product reads, where it is processed, and how long run_payload is kept is on that product page, not as a single company-wide sentence. Customer data is not used to train models.
Not yet available
- Customer-managed keys for connector secrets (
enterprise, planned; see/trust). - A self-serve “test connection” API for every vendor beyond the in-app test read.
- Connecting a vendor that is not in the public directory. If the product page does not list it, we do not have it. An empty integration page is not coverage.
