Managed integrations

Connect Customer.io, Clay, Firecrawl, Exa, Close, Semrush, Supabase, Linear, Stripe, Resend, Sentry, Slack, HubSpot, Notion, Atlassian, Cal.com, Intercom, Apollo, Plain, Pylon, Attio, Granola, Twenty CRM, Retool, Google Drive, Gmail, Google Calendar, Salesforce, Xero, Pipedrive, Apify, Loops, and Discord with explicit credential, safety, recovery, and delivery boundaries.

Managed MCP integrations use official provider endpoints owned by Work on Repeat's server configuration. The setup is OAuth-first. Providers may offer an API-key fallback as an advanced option when OAuth is unavailable or a separately scoped credential is more appropriate; Customer.io, Clay, Supabase, Slack, HubSpot, Notion, Atlassian, Cal.com, Intercom, Apollo, Plain, Pylon, Attio, Granola, Twenty CRM, Retool, Google Drive, Gmail, Google Calendar, Salesforce, Xero, Pipedrive, and Loops are OAuth-only, and Apify's fallback is an Apify API token. Keys and tokens go only to the selected official endpoint, are encrypted at rest, are masked after setup, and are never returned by the API.

Every managed provider is independently disabled by default. An operator can enable Customer.io, Clay, Firecrawl, Exa, Close, Semrush, Supabase, Linear, Stripe, Resend, Sentry, Slack, HubSpot, Notion, Atlassian, Cal.com, Intercom, Apollo, Plain, Pylon, Attio, Granola, Twenty CRM, Retool, Google Drive, Gmail, Google Calendar, Salesforce, Xero, Pipedrive, Apify, Loops, and Discord separately for canary rollout or rollback. Disabling an integration prevents new setup and tests; it does not delete or conceal saved connections needed for recovery.

Temporary fail-closed launch state

Customer.io, Clay, Close, Semrush, Slack, HubSpot, Notion, Atlassian, Cal.com, Intercom, Apollo, Plain, Pylon, Attio, Granola, Twenty CRM, Retool, Google Drive, Gmail, Google Calendar, Salesforce, Xero, Pipedrive, Apify, Loops, every unreviewed Stripe tool, and every unreviewed Linear tool remain blocked. Stripe exposes only the reviewed stripe_api_read schema; Linear exposes only the bounded reads and create-only tools described below. Enabling a rollout flag permits connection setup; it does not make an unreviewed tool executable. Resend and Sentry expose only the exact tools already present in their reviewed manifests. Supabase exposes only its four reviewed, read-only tools under an exact project bound.

Minimum credential guidance

OAuth permissions are still subject to the provider's consent screen. For an API-key fallback, create a dedicated key with only the resources this routine needs. Customer.io, Clay, Supabase, Slack, HubSpot, Notion, Atlassian, Cal.com, Intercom, Apollo, Plain, Pylon, Attio, Granola, Twenty CRM, Retool, Google Drive, Gmail, Google Calendar, Salesforce, Xero, Pipedrive, and Loops do not expose an API-key fallback here; Apify's fallback is a dedicated Apify API token. Never reuse an owner, billing, administrator, or Work on Repeat service credential. Rotate a key immediately if it appears in a log, message, ticket, or analytics payload.

Work on Repeat also enforces a checked-in provider policy. A newly added tool is blocked, and a reviewed tool whose input schema drifts becomes unavailable until its policy is reviewed and the routine is approved again.

Provider boundaries

Customer.io

Customer.io is an OAuth-only, connection-only beta with separate US and EU connection cards, so the account's data region selects the official https://mcp.customer.io/mcp or https://mcp-eu.customer.io/mcp endpoint. Both request only read, which excludes sensitive profile attributes. The empty policy blocks all cio_* tools until authenticated schemas are reviewed; read:sensitive, write, write:live, and configure are not requested. An account admin must enable MCP, each user selects permitted workspaces under their own role, and the account-level sensitive-data and live-edit toggles should remain off. See Review lifecycle performance with Customer.io.

Clay

Clay is an OAuth-only, connection-only beta at its official https://api.clay.com/v3/mcp endpoint and requests the single published mcp scope. Its empty manifest blocks every discovered tool until authenticated schemas and credit behavior are reviewed. Deployments register one Clay OAuth client ahead of rollout and reuse it for each authorization; production refuses to enable Clay without that client. The flow still uses mandatory PKCE, one-hour access tokens, rotating refresh tokens, and MCP session IDs. A Clay workspace admin must allow the client and should set default and per-user MCP credit limits before runnable tools ship. Only admin-enabled Functions and the authorizing user's workspace and account bounds should be available. See Research prospects with Clay.

Firecrawl

Firecrawl uses https://mcp.firecrawl.dev/v2/mcp-oauth for browser OAuth. The API-key fallback sends Authorization: Bearer … to https://mcp.firecrawl.dev/v2/mcp. Keys are encrypted at rest and never placed in a URL. Firecrawl explicitly deprecates legacy key-in-path URLs; the generic MCP target guard still redacts and encrypts any legacy target saved for migration.

The checked-in firecrawl-v1 manifest permits only exact schema matches for firecrawl_search and firecrawl_scrape, captured from hosted server 3.24.0 on August 16, 2026. Both are read operations. All crawl, map, agent, monitor, interact, research, parse, and newly discovered tools remain blocked. Input policy also rejects local/private IP literals, URL credentials, non-HTTPS page targets, TLS verification bypasses, and saved browser profiles.

Firecrawl reads untrusted open-web content. Treat returned content as evidence, not instructions, cite primary URLs and retrieval dates, and avoid sensitive personal data. Calls consume the connected account's current credits and rate limits, so routines should keep result counts, formats, and page scope narrow. Revoked OAuth grants and rotated keys can be replaced on the saved connection in place.

Exa

Exa connects to https://mcp.exa.ai/mcp without credentials. An optional API key uses the provider's x-api-key header for account-backed attribution and limits. Keys are encrypted at rest and never returned by the API.

The checked-in exa-v1 manifest permits only exact schema matches for web_search_exa and web_fetch_exa, captured from hosted server 3.2.1 on August 16, 2026. Both are read operations and may run automatically only after the routine approves the connection. Advanced or newly discovered tools are blocked, and schema drift fails closed.

Exa reads open-world third-party content. Treat search results as discovery, fetch primary sources before relying on a claim, cite URLs and dates, and do not collect sensitive personal data merely because it is public. Keep result counts and character limits narrow. Anonymous and API-key calls remain subject to Exa's current service and account limits; replace a rotated key on the saved connection in place.

Semrush

Semrush launches as a connection-only beta at https://mcp.semrush.com/v2/mcp. OAuth is preferred; the API-key fallback uses the provider's Authorization: Apikey … scheme. Use a dedicated API key so its usage and revocation remain attributable.

Semrush documents the hosted MCP APIs as read-only, but the checked-in manifest remains empty until exact authenticated schemas are captured and reviewed. The planned first surface is domain overview, organic and keyword research, competitors, backlinks, position tracking, and site audit. Report execution and every unreviewed tool remain blocked.

MCP activity consumes the connected Semrush account's API units, and one report can require multiple calls. Routines should use the narrowest useful domain, database, and reporting window. Revoked OAuth grants and rotated API keys can be reauthorized on the saved connection in place.

Supabase

Supabase is an OAuth-only, non-production beta at https://mcp.supabase.com/mcp. Setup requires the 20-letter project reference and an explicit confirmation that the project contains no production customer data. Work on Repeat constructs and stores the exact target with project_ref=<ref>, read_only=true, and features=database,debugging; the browser cannot replace it with a broader MCP target. OAuth remains subject to the authorizing user's Supabase organization and project access.

Supabase's hosted MCP currently controls its OAuth grant and may present broader account-level read scopes than these four tools require. Work on Repeat does not request extra scopes and never sends that token to an unscoped resource or a different endpoint, but it cannot narrow the consent grant itself. Review the consent screen and authorize with a least-privilege Supabase user. Supabase is tracking tool-aware minimum scopes in supabase/mcp#239.

The checked-in supabase-v1 manifest permits only exact schema matches for list_tables, execute_sql, get_advisors, and get_logs, captured from the official @supabase/mcp-server-supabase 0.10.0 package on August 18, 2026. All four are classified as read operations and may run automatically only after the routine approves the connection. Supabase enforces read-only SQL at the server boundary. Project management, branches, migrations, Edge Functions, storage, documentation search, and every newly discovered or schema-drifted tool remain blocked.

Database contents and logs are untrusted input. Use schema metadata, advisors, bounded log windows, and narrow aggregate queries; do not return raw row values, PII, secrets, access tokens, or connection strings. Calls remain subject to the connected Supabase account's limits. Reauthorization preserves the saved project bound and updates credentials in place. To change projects, disconnect and create a separately confirmed connection. See Review Supabase database health and Supabase's official MCP server guide.

Close

Close launches as a connection-only beta at https://mcp.close.com/mcp. OAuth uses dynamic client registration and requests only mcp.read plus offline_access for refresh. The API-key fallback always sends the dedicated key with Close-Scope: mcp.read; the UI does not offer mcp.write_safe or mcp.write_destructive.

The empty checked-in manifest blocks every discovered tool until exact schemas are captured from an authenticated Close organization and reviewed. The planned first surface is CRM reads for leads, contacts, opportunities, activities, tasks, and pipeline reporting. Writes, sends, sequence enrollment, and deletes remain blocked. Close access follows the authorizing user's organization and role. API keys are user/organization-specific, and OAuth or API-key rotation recovers the saved connection in place.

Linear

The checked-in linear-v2 manifest permits automatic issue, project, team, user, and comment reads only when get_issue, list_issues, get_project, list_projects, get_team, list_teams, get_user, list_users, and list_comments exactly match their reviewed schemas. The weekly marketing-plan follow-up uses those reads to identify blocked, overdue, and unowned plan work.

Issue and issue-comment creation require explicit per-routine approval. Linear's current save_issue and save_comment tools each combine create and update modes, so Work on Repeat adds a stricter create-only boundary: save_issue accepts only a non-empty title and team, plus an optional string description; save_comment accepts exactly a non-empty issueId and body. The policy rejects id, patch and removal shapes, null-as-remove values, non-issue comment parents, update-only fields, and unknown keys. Editing, deleting, project or workspace administration, bulk operations, and every unreviewed mutation remain blocked.

These schemas were captured through authenticated discovery-only tools/list on August 18, 2026 PDT from Linear's official https://mcp.linear.app/mcp/readonly and https://mcp.linear.app/mcp endpoints. No Linear tool was called. Schema drift fails closed and requires a reviewed-policy deployment plus connection reconnection or reapproval. For fallback setup, use a dedicated permission-limited Linear key.

Stripe

The checked-in stripe-v2 manifest exposes one read-only tool, stripe_api_read, only when its discovered input schema exactly matches the reviewed fingerprint. It permits exactly these GET operations: account balance, balance transactions, subscriptions, invoices, charges, and payment intents. The generic wrapper rejects every other operation ID, including search and all customer, product, report, refund, and write operations. Work on Repeat blocks writes, refunds, captures, cancellations, and every operation that moves money or changes customer state, even if Stripe would accept it. Each allowed operation accepts only its reviewed pagination and filter parameters; expansion and unreviewed nested selectors are rejected.

API-key fallback accepts only a restricted rk_… key; a secret sk_… key is rejected. Grant only the six read permissions the routine needs. Schema drift or a future policy version fails closed and requires a reviewed-policy deployment plus connection reconnection or reapproval. This automatic read does not require a routine-level approval. The reviewed source is official Stripe Codex plugin cache artifact cd27e1c6198e2991c548e47f47f3cdfe5d5a1fd6.json, tool stripe_api_read, normalized as sha256:22df2c93d345ea947286d5f9769fc78447cd405228936ce0458cf0654b2be597. Revoked OAuth access moves the saved connection to reauthorization_required; reconnect or replace the restricted key in place. Customer MCP credentials are separate from Work on Repeat billing configuration.

Resend

Reviewed delivery/log, contact, segment, and broadcast reads are allowed. Resend draft construction may run after it passes the provider policy; any send operation requires explicit per-routine approval. Sending is never blindly retried after an ambiguous result. Account, API-key, domain, and webhook administration remain blocked. Scope a fallback key to the required resources and sending domain.

Sentry

Sentry launches as a read-only beta for reviewed organization/project context, issues, events, traces, and releases. Mutations, administration, membership changes, DSN or secret retrieval, and Seer/fix execution are blocked. Set an organization and, when practical, a project constraint; Work on Repeat enforces those bounds again at call time. A fallback token should have only the minimum read scopes.

Slack

Slack is an OAuth-only, connection-only beta at the official https://mcp.slack.com/mcp endpoint. Work on Repeat requests only the read-level user scopes channels:read, channels:history, users:read, and search:read.public; no chat:*, *:write, or admin scope is requested, so the connection cannot post, edit, or react even after tools are reviewed under these scopes. Slack's server does not offer dynamic client registration, so an operator must configure SLACK_MCP_OAUTH_CLIENT_ID (and secret) before enabling MANAGED_MCP_SLACK_ENABLED. Access follows the authorizing member's workspace permissions, and a workspace admin can restrict or revoke the app. The empty policy blocks every tool until authenticated schemas are reviewed. See Brief customer signals from Slack.

HubSpot

HubSpot is an OAuth-only, connection-only beta at the official https://mcp.hubspot.com endpoint. HubSpot's server does not offer dynamic client registration, so an operator must configure HUBSPOT_MCP_OAUTH_CLIENT_ID (and secret) before enabling MANAGED_MCP_HUBSPOT_ENABLED. The token authorizes one HubSpot account chosen during consent, bounded by that user's CRM permissions and the granted scopes. The empty policy blocks every tool until authenticated schemas are reviewed; the first reviewed manifest should stay read-only, with any CRM write classified separately and approval-gated. See Review HubSpot pipeline hygiene.

Notion

Notion is an OAuth-only, connection-only beta at the official https://mcp.notion.com/mcp endpoint, requesting Notion's single published default scope. Access covers only the pages and databases the authorizing person grants on Notion's consent screen, and a workspace admin can revoke the connection from Notion's side at any time. The empty policy blocks every tool — including Notion's search, fetch, and any create or update tools — until authenticated schemas are reviewed. See Review a Notion content calendar.

Atlassian

Atlassian is an OAuth-only, connection-only beta at the official https://mcp.atlassian.com/v1/mcp endpoint covering Jira and Confluence. Authorization uses Atlassian's own consent flow and follows the authorizing person's site and product permissions; Work on Repeat requests no extra scope beyond what Atlassian's server assigns during registration. The empty policy blocks every tool until authenticated schemas are reviewed; issue transitions, page edits, and deletions must remain blocked or approval-gated after review. See Review Jira delivery risk.

Cal.com

Cal.com is an OAuth-only, connection-only beta at the official https://mcp.cal.com/mcp endpoint. The token is bounded by the authorizing account's role, and the empty policy blocks every tool until authenticated schemas are reviewed. Booking creation, cancellation, and rescheduling are mutations and must remain blocked or approval-gated after review; the packaged routine needs only event-type, booking, and availability reads. See Review the Cal.com booking funnel.

Intercom

Intercom is an OAuth-only, connection-only beta at the official https://mcp.intercom.com/mcp endpoint. The token authorizes one Intercom workspace chosen during consent. Conversations routinely contain end-user personal data, so the packaged routine quotes only short anonymized excerpts and the empty policy blocks every tool — reads included — until authenticated schemas are reviewed. Replying, closing, snoozing, and reassigning are mutations and must remain blocked or approval-gated after review. See Brief Intercom conversation insights.

Apollo

Apollo is an OAuth-only, connection-only beta at the official https://mcp.apollo.io/mcp endpoint. Apollo's server advertises dynamic client registration, so no static client is configured. Work on Repeat requests read_user_profile, mixed_people_api_search, organizations_search, contacts_search, contact_read, opportunities_list, and opportunity_read — search and read scopes only; no sequence, enrichment, or email scope is requested. Access and rate limits follow the authorizing person's Apollo seat and plan. The empty policy blocks every tool until authenticated schemas are reviewed; the first reviewed manifest should stay read-only, with contact creation, enrichment, and sequence enrollment classified separately and approval-gated. See Review an Apollo prospect list.

Plain

Plain is an OAuth-only, connection-only beta at the official https://mcp.plain.com/mcp endpoint. Authorization runs through signin.auth.plain.com with dynamic client registration and requests openid plus offline_access. Plain issues rotating refresh tokens; Work on Repeat performs each rotation and stores the replacement encrypted, so the connection outlives access-token expiry without a new consent. Access follows the authorizing person's Plain workspace role. Support threads contain end-customer personal data, so the empty policy blocks every tool — reads included — until authenticated schemas are reviewed; replying, assigning, changing thread status, and creating customers must remain blocked or approval-gated. See Review the Plain support queue.

Pylon

Pylon is an OAuth-only, connection-only beta at the official https://mcp.usepylon.com/ endpoint. Authorization runs through o.auth.usepylon.com with dynamic client registration and Pylon's default scope; the token can reach only what the authorizing person can already see in Pylon. The empty policy blocks every tool until authenticated schemas are reviewed; issue replies, account field edits, and every other mutation must remain blocked or approval-gated. See Brief account health from Pylon.

Attio

Attio is an OAuth-only, connection-only beta at the official https://mcp.attio.com/mcp endpoint. Authorization runs through app.attio.com with dynamic client registration and requests openid, offline_access, and mcp. The token is bounded by the authorizing person's workspace access. The empty policy blocks every tool until authenticated schemas are reviewed; the first reviewed manifest should stay read-only across objects, records, lists, and notes, with record creation, attribute updates, and deletions classified separately and approval-gated. See Review Attio CRM hygiene.

Granola

Granola is an OAuth-only, connection-only beta at the official https://mcp.granola.ai/mcp endpoint. Authorization runs through mcp-auth.granola.ai with dynamic client registration and Granola's default scope. Each person authenticates individually — there is no workspace-wide grant — and Granola's plan and folder-sharing limits decide which meeting notes the token can reach. Notes routinely contain personal data and confidential discussion, so the empty policy blocks every tool — reads included — until authenticated schemas are reviewed, and the packaged routine reads only its configured folder and quotes short excerpts attributed to the meeting and date. See Digest voice-of-customer notes from Granola.

Twenty CRM

Twenty CRM is an OAuth-only, connection-only beta at the official https://api.twenty.com/mcp endpoint, which serves Twenty Cloud workspaces only; self-hosted Twenty instances are not covered by this card. Authorization runs through api.twenty.com with dynamic client registration and requests api and profile. Because the api scope is not split by read and write, the read-only boundary comes from Work on Repeat's tool policy rather than from the grant. The empty policy blocks every tool until authenticated schemas are reviewed; record creation, updates, and deletions must remain blocked or approval-gated. See Review the Twenty CRM pipeline.

Retool

Retool is an OAuth-only, connection-only beta at the official https://mcp.retool.com/mcp endpoint. Authorization runs through mcp.retool.com with dynamic client registration and requests only mcp:read; Retool's write and admin scopes are requested only by routines that explicitly require them, and none does today. Access follows the authorizing person's Retool organization permissions. The empty policy blocks every tool until authenticated schemas are reviewed; app, resource, and workflow reads should form the first manifest, with app edits, resource changes, and workflow runs classified separately and approval-gated. See Audit Retool operations.

Google Drive

Google Drive is an OAuth-only, connection-only beta at Google's https://drivemcp.googleapis.com/mcp/v1 endpoint, part of the Google Workspace MCP servers Developer Preview. Google offers no dynamic client registration, so an operator must create a Google Cloud OAuth client and configure GOOGLE_MCP_OAUTH_CLIENT_ID and GOOGLE_MCP_OAUTH_CLIENT_SECRET — one client shared by Google Drive, Gmail, and Google Calendar — before enabling MANAGED_MCP_GOOGLE_DRIVE_ENABLED. Work on Repeat requests only https://www.googleapis.com/auth/drive.readonly, so the grant cannot create, edit, share, or delete files even after tools are reviewed. Access follows the authorizing Google account and any Workspace admin restrictions on third-party apps. The empty policy blocks every tool until authenticated schemas are reviewed. See Digest source material from Google Drive.

Gmail

Gmail is an OAuth-only, connection-only beta at Google's https://gmailmcp.googleapis.com/mcp/v1 endpoint, also a Developer Preview and sharing the Google Cloud OAuth client above; enable it with MANAGED_MCP_GMAIL_ENABLED. Work on Repeat requests only https://www.googleapis.com/auth/gmail.readonly, so the grant cannot send, draft, label, archive, or delete mail. Google treats gmail.readonly as a restricted scope, so expect Google's app verification requirements before a production client leaves testing. Mailboxes contain personal data by definition, so the empty policy blocks every tool — reads included — until authenticated schemas are reviewed, and the packaged routine cites threads by subject and date and summarizes each ask in one line. See Review Gmail follow-ups.

Google Calendar

Google Calendar is an OAuth-only, connection-only beta at Google's https://calendarmcp.googleapis.com/mcp/v1 endpoint, also a Developer Preview and sharing the Google Cloud OAuth client; enable it with MANAGED_MCP_GOOGLE_CALENDAR_ENABLED. Work on Repeat requests only https://www.googleapis.com/auth/calendar.events.readonly and https://www.googleapis.com/auth/calendar.calendarlist.readonly, so the grant cannot create, move, or cancel events or change sharing. The empty policy blocks every tool until authenticated schemas are reviewed. See Brief meeting prep from Google Calendar.

Salesforce

Salesforce is an OAuth-only, connection-only beta at Salesforce's read-only standard hosted server, https://api.salesforce.com/platform/mcp/v1/sobject-reads; Salesforce Hosted MCP Servers have been generally available since April 2026. Authorization runs through login.salesforce.com using an External Client App with PKCE. Salesforce offers no open dynamic registration, so an operator must configure SALESFORCE_MCP_OAUTH_CLIENT_ID and SALESFORCE_MCP_OAUTH_CLIENT_SECRET before enabling MANAGED_MCP_SALESFORCE_ENABLED, and each connecting org must allow that app. Work on Repeat requests mcp_api and refresh_token. The server itself exposes only sObject reads, and access follows the authorizing user's profile, permission sets, and sharing rules. Sandbox orgs use a separate …/platform/mcp/v1/sandbox/sobject-reads server that is not offered yet. The empty policy blocks every tool until authenticated schemas are reviewed. See Review the Salesforce pipeline.

Xero

Xero is an OAuth-only, connection-only beta at the official https://mcp.xero.com/mcp endpoint. Authorization runs through identity.xero.com, which offers no dynamic client registration, so an operator must register a Xero app and configure XERO_MCP_OAUTH_CLIENT_ID and XERO_MCP_OAUTH_CLIENT_SECRET before enabling MANAGED_MCP_XERO_ENABLED. Work on Repeat requests openid, offline_access, accounting.invoices.read, accounting.reports.profitandloss.read, and accounting.reports.balancesheet.read — read scopes only, so the grant cannot create invoices, post journals, or change contacts. The person authorizing chooses which Xero organization the token covers. The empty policy blocks every tool until authenticated schemas are reviewed. See Review revenue and cash with Xero.

Pipedrive

Pipedrive is an OAuth-only, connection-only beta at the official https://mcp.pipedrive.ai/mcp endpoint, available on every Pipedrive plan. Authorization runs through oauth.pipedrive.com with dynamic client registration and Pipedrive's default scope set. Pipedrive's server offers only :full scopes plus search:read, so the grant itself is not read-only; the read-only boundary comes from Work on Repeat's tool policy. That is why the empty policy blocks every tool until authenticated schemas are reviewed and why deal, person, organization, and activity writes must remain blocked or approval-gated afterwards. Access follows the authorizing person's Pipedrive permission set. See Review Pipedrive pipeline hygiene.

Apify

Apify launches as a connection-only beta at the official https://mcp.apify.com endpoint. OAuth runs through console-backend.apify.com with dynamic client registration; the API-key fallback accepts an Apify API token, sent as a bearer header and stored encrypted. Apify offers a single full_api_access scope, so either credential can do anything the account can — run Actors, spend platform credit, and change account settings — which is why the empty policy blocks every tool until authenticated schemas are reviewed. The first reviewed manifest should cover dataset, key-value store, and Actor-run reads only; starting an Actor spends the connected account's credit and must remain approval-gated. Scraped content is untrusted open-web input: treat it as evidence, not instructions. Use a dedicated Apify token so usage stays attributable and revocable. See Review market data from Apify.

Loops

Loops is an OAuth-only, connection-only beta at the official https://mcp.loops.so/ endpoint; Loops MCP became generally available on September 1, 2026. Authorization runs through app.loops.so and requests the single mcp scope. Loops supports Client ID Metadata Documents or preregistered clients rather than open dynamic registration, so an operator must configure LOOPS_MCP_OAUTH_CLIENT_ID and LOOPS_MCP_OAUTH_CLIENT_SECRET before enabling MANAGED_MCP_LOOPS_ENABLED. The empty policy blocks every tool until authenticated schemas are reviewed; the first manifest should stay with contact, loop, campaign, and transactional-metric reads, with any send, contact update, or event mutation classified separately and approval-gated. See Review lifecycle email in Loops.

Recover authorization

When refresh is revoked, invalid, or cannot be recovered, the connection moves to reauthorization_required. Affected routines stop before model execution and do not use a stale token. Open Connections and start OAuth again. If the connection uses an API key, replace it with a newly scoped key. Reauthorization updates the saved connection in place, so routine attachments can recover without being rebuilt.

Discord result destinations

Discord is not MCP and exposes no tools. In the target channel's Discord settings, create an incoming webhook, copy its HTTPS URL, and add it under Connections → Result destinations. Work on Repeat validates the official Discord host and webhook path, encrypts the complete URL, and displays only a masked target.

Use Test to send a clearly labeled connection test. Tests and run summaries disable mentions. If Discord reports a revoked webhook, the destination moves to needs_attention. Create a new incoming webhook, then use Replace to rotate the Discord webhook atomically; test it, and delete the old webhook in Discord after the replacement succeeds.

Attach the destination in a routine's Results section and select run.succeeded, run.failed, or both. Run status and delivery status are independent: a Discord failure can be retried or exhausted without changing a successful run to failed. Messages contain only a bounded summary and run link, never credentials, raw tool responses, model traces, or stack details.

On this page

Edit this page on GitHub