Connect an account
The three ways a connector authenticates: one-click OAuth, your own OAuth app, or a service account key.
Activating a connector makes its tools available, but a connector that reaches an outside service still needs an account to act as. That connection is what you set up here, and it is stored as a credential in a vault rather than on the agent.
How you connect depends on the connector. Each one declares its method, shown as a badge on the Connect dialog: OAuth 2.0, API Key, or Service account.
Open the Connect dialog
- Open Settings, then Vaults under Agent.
- Open the vault the credential should live in.
- In the Credentials section, click Add credential and pick a connector.
The dialog is titled Connect followed by the connector's name. Reaching it from outside a vault adds a vault picker at the top, so you always know where the credential is being stored. Only active connectors that need credentials can be added.
One-click OAuth
The default for an OAuth connector, and the shortest path. Under How do you want to connect?, leave One-click (use the app we manage) selected and click Connect with the connector. You are sent to the provider, you grant access, and you land back in Spark with the connection made.
There is nothing to register and no secret to handle. Spark's own registered application asks for the access, and the dialog lists the Requested scopes before you go so you can see what you are granting.
Bring your own OAuth app
Choose this when your organization requires the connection to run through its own registered application, for example so the grant appears under your own tenant's audit trail.
- Select Bring your own OAuth app.
- Copy the redirect URI shown under the fields, and register it in your provider's OAuth app. The dialog shows the exact URI for that connector, so copy it from there rather than constructing it.
- Paste the Client ID and Client Secret from your app.
- Click Connect with the connector and grant access at the provider as usual.
Service account
Some connectors authenticate with a key rather than with a user. The Google Cloud connectors work this way: BigQuery, Cloud Storage, Cloud Logging, Cloud Run, Cloud SQL and Firestore.
- Create a service account with the access the connector needs, and download its JSON key.
- In the Connect dialog, paste the full JSON key into the field.
- Click Save.
There is no authorization round trip, so the connection is live as soon as it saves. The key grants whatever the service account can do, so scope the service account itself rather than relying on Spark to narrow it.
API key
The simplest case, unchanged: paste the key into the field the connector asks for and click Save. Some connectors ask for more than one value, for example a key and an account identifier; the dialog shows a field per value.
Tokens are refreshed for you
An OAuth connection does not need re-authorizing per agent. Spark holds the connection centrally and hands out a fresh token whenever an agent runs, so one connection works for every agent bound to that vault, and an expired token is renewed without anyone being sent back to the provider.
A connection lives in the vault, not on the agent. Store it in your Personal vault when it should act as you alone, and in a Shared vault when several teammates or agents should act through the same account. See Vaults.