Integration catalog

This page lists the public catalog services that can be added to exe.dev. It is generated from the same descriptors and visibility rules used by the catalog browse and add flows, so staged previews and names owned by built-in integration types are omitted.

Use the handle exactly as the service query parameter in a connect link:

https://exe.dev/integrations/add?service=<handle>&attach=vm:<vm>&for=<duration>&source=shelley

The link only pre-fills the add dialog. The user reviews it and supplies or authorizes credentials on exe.dev; credentials never belong in the URL.

Service Handle Connection Description
Airtable airtable API credential Spreadsheet-database for structured records, bases, and views.
Algolia algolia API credential Hosted search-as-a-service with instant, typo-tolerant queries.
Alpha Vantage (market data) alphavantage API credential Stock, forex, and crypto market data API.
Amplitude amplitude API credential Product analytics for user behavior and funnels.
Anthropic anthropic API credential Claude large language models (chat, tools, vision).
Argo CD argocd API credential GitOps continuous delivery for Kubernetes.
Asana asana API credential Work and project management for teams.
AssemblyAI assemblyai API credential Speech-to-text transcription and audio intelligence.
atcr.io (AT Protocol container registry) atcr API credential AT Protocol container registry: mint short-lived scoped pull tokens (Tangled/Knot).
Attio attio API credential Modern, data-driven CRM.
Axiom axiom API credential Log management and event analytics at scale.
511 SF Bay (transit & traffic) bay511 API credential San Francisco Bay Area transit and traffic open data.
Better Stack betterstack API credential Uptime monitoring, incident management, and logs.
Bitbucket Cloud bitbucket API credential Git repository hosting: repos, pull requests, and pipelines.
Brave Search API brave API credential Independent web search API with its own index.
Buildkite buildkite API credential CI/CD pipelines that run on your own infrastructure.
Cal.com calcom API credential Open-source scheduling and booking (Calendly alternative).
Calendly calendly API credential Automated meeting scheduling and booking links.
Cerebras cerebras API credential Ultra-fast LLM inference on wafer-scale hardware.
CircleCI circleci API credential Continuous integration and delivery pipelines.
Clerk clerk API credential Drop-in user authentication and management.
ClickHouse Cloud clickhouse API credential Columnar SQL database for real-time analytics.
ClickUp clickup API credential All-in-one project management and docs.
Cloudflare cloudflare API credential CDN, DNS, and edge network management.
CockroachDB Cloud cockroachdb API credential Manage CockroachDB Cloud clusters via the Cloud API.
Cohere cohere API credential Enterprise LLMs for chat, embeddings, and rerank.
CoinGecko coingecko API credential Cryptocurrency prices and market data.
Confluence Cloud confluence API credential Team wiki and documentation (Atlassian).
Convex convex API credential Reactive backend-as-a-service: database, functions, and scheduling.
crates.io cratesio API credential The Rust package registry.
Datadog datadog API credential Infrastructure and application monitoring.
Deepgram deepgram API credential Real-time and batch speech-to-text.
DeepSeek deepseek API credential Open-weight LLMs (chat and reasoning), OpenAI-compatible.
DigitalOcean digitalocean API credential Cloud VMs, databases, and managed infrastructure.
Docker Hub dockerhub API credential Container image registry and repository management.
Doppler doppler API credential Secrets management and environment configuration.
Dynatrace dynatrace API credential Full-stack observability and APM.
EasyPost easypost API credential Multi-carrier shipping, tracking, and labels.
ElevenLabs elevenlabs API credential AI text-to-speech and voice generation.
Etherscan etherscan API credential Ethereum blockchain explorer and on-chain data.
Exa exa API credential Neural web search built for AI agents.
Fastly fastly API credential Edge CDN and real-time content delivery.
Fastmail fastmail API credential Full email, contacts, and calendar access over JMAP.
Figma figma API credential Collaborative interface design: files, comments, components, and dev resources.
Finnhub finnhub API credential Real-time stock, forex, and financial data.
Firecrawl firecrawl API credential Turn websites into clean, LLM-ready markdown.
Fireworks AI fireworks API credential Fast hosted inference for open LLMs, OpenAI-compatible.
Fly.io flyio API credential Deploy app containers close to users, globally.
Forgejo forgejo API credential Self-hostable Git forge (Gitea fork); Codeberg.org is the flagship public instance.
Freshdesk freshdesk API credential Customer support ticketing and helpdesk.
Front front API credential Shared inbox and customer communication hub.
Google Artifact Registry gar API credential Google Artifact Registry: docker push/pull through the integration, no SA key on the VM.
Google Gemini gemini API credential Google's Gemini multimodal large language models.
GitHub Container Registry (ghcr.io) ghcr API credential GitHub Container Registry: mint registry tokens at ghcr.io's OCI token realm.
Ghost (Content API) ghost API credential Publishing platform and newsletter CMS.
GitGuardian gitguardian API credential Secrets detection and code security scanning.
GitLab gitlab API credential Git hosting, CI/CD, and DevOps platform.
Google Maps Platform googlemaps API credential Geocoding, directions, places, and maps data.
Google Service Account (JWT-bearer token mint) googlesa API credential Mint Google API access tokens from a service-account key (Sheets, Drive, GCS, ...).
Google Sheets (read) googlesheets API credential Read link-shared Google Sheets data.
Grafana grafana API credential Dashboards and visualization for metrics and logs.
Groq groq API credential Very-low-latency LLM inference, OpenAI-compatible.
HashiCorp Vault hashicorpvault API credential Secrets management and encryption as a service.
Have I Been Pwned haveibeenpwned API credential Check emails and passwords against known breaches.
Heroku heroku API credential Managed platform-as-a-service app hosting.
Hetzner Cloud hetzner API credential Budget cloud servers and infrastructure.
Home Assistant homeassistant API credential Control and observe a Home Assistant instance: states, services, automations.
Honeycomb honeycomb API credential Observability for distributed systems and tracing.
HubSpot hubspot API credential CRM, marketing, and sales platform.
HubSpot hubspotapi API credential HubSpot CRM objects, contacts, and deals API.
Hugging Face huggingface API credential Model, dataset, and inference hub for ML.
Infisical infisical API credential Open-source secrets management.
InfluxDB Cloud influxdb API credential Time-series database for metrics and events.
Intercom intercom API credential Customer messaging and support platform.
Jenkins jenkins API credential Self-hosted automation and CI server.
Jina AI jina API credential Embeddings, rerank, and a web reader for AI.
Jira Cloud jira API credential Issue tracking and agile project management (Atlassian).
Keycloak (OAuth2 token mint) keycloak API credential Open-source identity and OAuth2/OIDC provider.
Last.fm lastfm API credential Music scrobbling, listening history, and metadata.
LaunchDarkly launchdarkly API credential Feature flags and progressive delivery.
Lemon Squeezy lemonsqueezy API credential Payments and subscriptions for digital products.
Linear linear API credential Issue tracking and planning for software teams.
Linode (Akamai) linode API credential Akamai's cloud compute and hosting.
Grafana Loki loki API credential Grafana's log aggregation system.
Mailgun mailgun API credential Transactional and bulk email delivery.
Mattermost mattermost API credential Self-hosted team chat and collaboration.
Meilisearch meilisearch API credential Fast, typo-tolerant open-source search engine.
Mistral mistral API credential Open-weight and frontier LLMs, OpenAI-compatible.
Mixpanel mixpanel API credential Product analytics and user event tracking.
monday.com monday API credential Work OS: boards, items, and workflows via a GraphQL API.
Neon neon API credential Serverless PostgreSQL with branching.
Netlify netlify API credential Deploy and host web front-ends and functions.
Netlify netlifyapi API credential Netlify site, deploy, and DNS management API.
New Relic newrelic API credential Application performance monitoring and observability.
NewsAPI.org newsapi API credential Headlines and articles from news sources worldwide.
Notion notion API credential Connected workspace for notes, docs, and databases.
npm registry npm API credential The JavaScript/Node package registry.
Okta okta API credential Enterprise identity and single sign-on.
OMDb (movie database) omdb API credential Movie and TV metadata from IMDb.
1Password Connect (self-hosted) onepassword API credential Secrets vault via a self-hosted 1Password Connect server.
OneSignal onesignal API credential Push notifications and customer messaging.
OpenAI openai API credential GPT models, embeddings, images, and audio.
OpenAI Ads (ChatGPT) openai-ads API credential Create and manage ChatGPT ad campaigns and pull performance insights.
OpenRouter openrouter API credential One API gateway to many LLM providers.
OpenWeather openweather API credential Current weather and forecasts worldwide.
Opsgenie opsgenie API credential On-call scheduling and alert routing (Atlassian).
Paddle paddle API credential Merchant-of-record billing for software.
PagerDuty pagerduty API credential Incident response and on-call management.
Perplexity perplexity API credential Answer engine with live web search (Sonar models).
Pinecone pinecone API credential Managed vector database for semantic search.
Pipedrive pipedrive API credential Sales-focused CRM and pipeline management.
PlanetScale planetscale API credential Serverless MySQL platform built on Vitess.
Polygon.io polygon API credential Real-time and historical stock and crypto data.
PostHog posthog API credential Open-source product analytics and session replay.
PostHog (query API) posthogapi API credential PostHog query and events API (HogQL).
Postmark postmark API credential Fast, reliable transactional email.
Pushover pushover API credential Simple push notifications to your devices.
PyPI (upload) pypi API credential The Python package index (uploads).
Qdrant Cloud qdrant API credential Vector database for similarity search.
Red Hat Quay (quay.io) quay API credential Red Hat Quay container registry: mint short-lived scoped registry JWTs.
Railway railway API credential Deploy apps and databases with minimal config.
Reddit Ads reddit-ads Credential mint Reddit Ads API: manage and report on Reddit advertising campaigns.
Render render API credential Managed cloud hosting for apps and databases.
Replicate replicate API credential Run and host open ML models via API.
Resend resend API credential Developer-first transactional email.
Scaleway scaleway API credential European cloud compute and storage.
SendGrid sendgrid API credential Transactional and marketing email (Twilio).
Sentry sentry API credential Error tracking and performance monitoring.
SerpApi (Google search results) serpapi API credential Scrape Google and other search-engine results.
Shippo shippo API credential Multi-carrier shipping labels and tracking.
Shodan shodan API credential Search engine for internet-connected devices.
Shopify (Admin API) shopify API credential E-commerce store and order management.
Shortcut shortcut API credential Issue tracking and project planning for dev teams.
Snowflake snowflake API credential Run SQL against your Snowflake warehouse over the SQL REST API.
Snyk snyk API credential Developer security scanning for code and deps.
Square square API credential Payments, point-of-sale, and commerce.
Statsig statsig API credential Feature flags and experimentation.
Stripe stripe API credential Online payments and billing.
Supabase supabase API credential Postgres backend with auth, storage, and APIs.
Tailscale tailscale API credential Manage a tailnet: devices, keys, DNS, and ACLs via the Tailscale API.
Tavily tavily API credential Web search API built for LLMs and agents.
Telegram Bot API telegram API credential Send messages and read updates as a Telegram bot.
Telnyx telnyx API credential Programmable voice, SMS, and connectivity.
TMDB (movies) tmdb API credential Movie and TV database (TMDB).
Todoist todoist API credential Task management and to-do lists.
Together AI togetherai API credential Open-source LLM inference, fine-tuning, and embeddings API.
Trello trello API credential Kanban boards, lists, and cards.
Turso turso API credential SQLite-compatible edge database platform (libSQL) — Platform API.
Twilio twilio API credential Programmable SMS, voice, and messaging.
Twitch twitch Credential mint Twitch Helix API: streams, channels, games, clips and EventSub subscriptions.
Typesense typesense API credential Open-source, typo-tolerant search engine.
Upstash Redis upstash API credential Serverless Redis and data over HTTP.
UptimeRobot uptimerobot API credential Website and endpoint uptime monitoring.
urlscan.io urlscan API credential Scan and analyse websites: submit URLs, search scans, fetch verdicts.
Vercel vercel API credential Deploy and host front-end apps and functions.
VirusTotal virustotal API credential File, URL, and domain threat analysis.
Voyage AI (embeddings) voyage API credential High-quality text embeddings and rerank.
Vultr vultr API credential Cloud compute, storage, and bare metal.
Weaviate Cloud weaviate API credential Open-source vector database.
Webflow webflow API credential Visual website builder and CMS.
Wolfram|Alpha wolframalpha API credential Computational knowledge and answers engine.
WordPress wordpress API credential Manage posts, pages, media, and users on a WordPress site via the REST API.
WorkOS workos API credential Enterprise SSO, SCIM, and directory sync.
xAI (Grok) xai API credential Grok large language models from xAI.
YouTube Data API (read) youtube API credential YouTube video, channel, and search data (read).
Zendesk zendesk API credential Customer support ticketing and helpdesk.
Zulip zulip API credential Threaded team chat (Zulip Cloud or self-hosted).

Service notes

Operational caveats carried by the descriptors themselves (the same notes the catalog add flow surfaces), keyed by handle. Only services with notes appear.

  • algolia — Proxies the -dsn host only; SDK retry strategies that rotate to -1/-2/-3.algolianet.com hosts bypass the proxy — pin SDK hosts to the proxy URL.
  • alphavantage — Free tier: 25 requests/day. Errors arrive as HTTP 200 with an error JSON body. CAVEAT: the API appears to serve data for ANY well-formed key, so verify only proves the key is not missing or throttled — it cannot distinguish a valid key from a wrong one.
  • amplitude — Basic auth: API key + secret key.
  • anthropic — Custom x-api-key header plus a fixed anthropic-version header. SSE streaming supported.
  • argocd — Self-hosted: pass --base-url for your Argo CD server.
  • assemblyai — Raw key in Authorization header (no scheme).
  • atcr — Token mint: GET the realm with your chosen scope; the proxy injects your handle + app password and atcr's JWT comes back to you. The JWT lives ~45 SECONDS — use it as 'Authorization: Bearer ' against https://atcr.io/v2/... immediately and re-mint on 401. The app password never touches the VM. Consume it with curl/skopeo/crane (docker's static 'registrytoken' config field works but a ~45s TTL makes it impractical). Full details: https://exe.dev/docs/integrations-oci-registries
  • attio — Bearer key.
  • axiom — Bearer API token.
  • bay511 — Rate limit: 60 requests/hour per token. format=json is injected (the API defaults to XML).
  • betterstack — Bearer token (Uptime API).
  • bitbucket — App passwords are GONE (removed 2026-07-28); the credential is an Atlassian API token, and the Basic username must be the ACCOUNT EMAIL — the old Bitbucket username 401s with a valid token on the REST API (git-over-HTTPS confusingly still wants the username, but that never rides this proxy). Tokens carry scopes chosen at creation; /2.0/user needs account:read.
  • brave — Custom X-Subscription-Token header.
  • calcom — API v2 (v1 decommissioned, HTTP 410). Bearer API key (cal_... / cal_live_...). Some v2 endpoints additionally require a cal-api-version header (e.g. bookings wants cal-api-version: 2024-08-13); /v2/me does not.
  • calendly — Bearer PAT.
  • cerebras — OpenAI-compatible, very fast inference.
  • circleci — v2 API under /api/v2; some legacy step-output flows still need /api/v1.1 (same host, same token).
  • clerk — Single global hostname, plain REST.
  • clickhouse — Basic auth over the HTTP interface; pass --base-url for your host:port.
  • cloudflare — Use scoped API tokens (per-zone, per-permission), not the legacy X-Auth-Key global key.
  • cockroachdb — This is the CockroachDB Cloud MANAGEMENT API (cluster lifecycle: create/list/scale/delete clusters) — it does NOT run SQL. There is no public SQL-over-HTTP endpoint for Cloud; connect to the database itself over the Postgres wire protocol directly. The secret key belongs to a service account and inherits its role/permissions. Rate limited to 10 req/s.
  • cohere — Bearer key; v2 chat API.
  • coingecko — Custom x-cg-demo-api-key header (Pro uses x-cg-pro-api-key + api.coingecko.com/api/v3/pro). Verify uses /ping, which DOES authenticate (401 on a bad key); most data endpoints like /simple/price serve anonymously and would return 200 for any garbage key.
  • confluence — The same site/email/token also works for the jira service.
  • convex — Deployment-scoped: proxies https://.convex.cloud; the deploy key grants admin on this ONE deployment (Convex auth scheme, not Bearer). Do not use POST /api/query as a health check — it 200s unauthenticated requests with an in-body error. HTTP actions are served from .convex.site (not proxied here). Streaming export/import endpoints 403 (StreamingExportNotEnabled) without a paid Convex plan even with a valid key. The npx convex CLI also talks to the convex.dev control plane, so CLI deploys aren't covered — use the HTTP API.
  • cratesio — Raw token in Authorization header (no scheme). crates.io's API data-access policy (https://crates.io/data-access) rejects generic user agents with HTTP 403 regardless of the credential, so the descriptor sends an identifying User-Agent. CAVEAT: crates.io cannot be made to authenticate the verify probe. Every authenticated GET either requires a cookie session (AuthCheck::only_cookie — /api/v1/me answers 403 'this action can only be performed on the crates.io website' to ALL tokens) or enforces token endpoint-scopes, so no single GET accepts every valid token; verify is a liveness probe only and cannot distinguish a valid token from a wrong one. Revisit if crates.io ever adds a token-introspection GET.
  • datadog — Defaults to the US1 site; EU and other regional accounts must set --base-url (e.g. https://api.datadoghq.eu).
  • deepgram — Custom 'Token ' Authorization scheme.
  • deepseek — OpenAI-compatible; /v1 alias also works.
  • digitalocean — Spaces (S3-compatible) uses separate keys and SigV4 hosts; this covers the REST API only.
  • dockerhub — Hub management API. PAT directly as Bearer (no login dance).
  • doppler — Read-only per-config scoping available on service tokens. The verify path needs a real project+config: a service token is scoped to one config, and personal tokens must name one. project/config are declared non-secret fields so RenderVerify templates them in (the old descriptor hardcoded YOUR_PROJECT and could never verify).
  • dynatrace — Custom 'Api-Token ' scheme. Templated env host; or --base-url for Managed.
  • easypost — Basic auth: API key as username, empty password.
  • elevenlabs — Billing is character-based; TTS responses are audio bytes — save to a file.
  • etherscan — V2 API is multi-chain via chainid parameter. Errors arrive as HTTP 200 with status=0 in the body.
  • exa — The /contents endpoint doubles as a scraper; pass livecrawl for freshness.
  • fastly — Custom Fastly-Key header.
  • fastmail — JMAP, not REST: everything after the session is POST /jmap/api/ with batched methodCalls, and every call needs the accountId from GET /jmap/session (under primaryAccounts). Token scopes are chosen at creation (read-only vs read-write); a read-only token still passes verify. New tokens are shown once, prefixed fmu1-.
  • figma — PATs are scoped at creation and a missing scope 403s with 'Invalid scope(s)' naming the scope required — fix the token's scopes, not the token. Tokens expire (90-day default in the UI); invalid or expired tokens get 403, not 401. Rate limits are per seat/plan/endpoint tier and harsh on free Starter files (file content can be as low as 6 req/month); 429 carries Retry-After.
  • finnhub — API token as query param.
  • firecrawl — Scrape is synchronous; crawl is submit-then-poll. Credits are billed per page.
  • fireworks — OpenAI-compatible under /inference/v1.
  • flyio — Machines API only; org/certs/IP management lives on the legacy GraphQL API at api.fly.io (same token, not proxied here).
  • forgejo — Defaults to Codeberg.org; self-hosted: pass --base-url https://git.mycorp.example. API is Gitea-compatible under /api/v1, and Gitea instances accept the same shape. Tokens are scoped — verify needs read:user, and a valid token without it gets 403 (fix the scope, not the token).
  • freshdesk — Basic auth: API key as username, any password. Templated per-account host.
  • front — Bearer token.
  • gar — Full-surface registry proxy: use the integration hostname AS the registry (docker pull/push /PROJECT/REPO/IMAGE — no docker login; push needs roles/artifactregistry.writer on the SA). The proxy injects _json_key + your SA key only at the token realm (/v2/token) and rewrites the auth challenge so stock docker/podman/skopeo/crane mint through the integration automatically. Regions: the default target is us-docker.pkg.dev; for other regions pass --base-url (europe-docker.pkg.dev, asia-docker.pkg.dev, or a regional host like us-central1-docker.pkg.dev / europe-west1-docker.pkg.dev). GAR also accepts oauth2accesstoken: at the realm; this integration uses the durable _json_key form so it never expires server-side. Blob downloads redirect to a pre-signed /artifacts-downloads/ URL (self-authorizing, no credential needed) which the gate admits alongside /v2/. Full details: https://exe.dev/docs/integrations-oci-registries
  • gemini — Google is migrating Gemini API keys: new AI Studio keys are auth keys (AQ....), and standard keys (AIza...) are being phased out during 2026. Both forms work here; credentials are injected as a request header server-side.
  • ghcr — Full-surface registry proxy: use the integration hostname AS the registry (docker pull /owner/image — no docker login). The proxy injects your PAT only at the token realm (/token) and rewrites the auth challenge so stock docker/podman/skopeo/crane mint through the integration automatically. CAUTION: ghcr's minted token is your PAT base64-encoded, NOT a short-lived JWT — it passes through to the client, so scope the PAT tightly (read:packages only, expiring). Full details: https://exe.dev/docs/integrations-oci-registries
  • ghost — Content API key as query param; pass --base-url for your blog. (Admin API is JWT — separate.)
  • gitguardian — Custom 'Token ' scheme.
  • gitlab — Self-hosted: pass --base-url https://gitlab.mycorp.example. Prefer project/group access tokens for scoping.
  • googlemaps — Billing account required on the Google Cloud project (generous free monthly credit). Restrict the key server-side.
  • googlesa — Token mint: POST /token with an EMPTY body; the proxy signs the JWT assertion server-side and returns a ~1h access token. Use it directly against the Google API (those calls do NOT ride this integration) and re-mint on 401 — the private key never touches the VM. Share the target resource with the client_email; --subject enables domain-wide delegation. Full details: https://exe.dev/docs/integrations-token-mint
  • googlesheets — API-key query param; reads link-shared sheets only (no OAuth).
  • grafana — Stack Grafana API only; Grafana Cloud metrics/logs ingest uses separate per-signal hosts with basic auth.
  • groq — OpenAI-compatible API under /openai/v1; also serves fast Whisper transcription at /openai/v1/audio/transcriptions.
  • hashicorpvault — Self-hosted: pass --base-url for your Vault address. X-Vault-Token custom header.
  • haveibeenpwned — Custom hibp-api-key header.
  • heroku — Bearer token + fixed Accept version header.
  • hetzner — Cloud API only; Hetzner DNS and Robot (dedicated) use different hosts and auth. Tokens are per-project, read-only or read-write.
  • homeassistant — Self-hosted: pass --base-url for your instance (often http://:8123; HTTPS only if you've set it up). Long-lived tokens last 10 years but die if the creating user is deleted. /api/ requires auth and 401s wrong tokens, so verify genuinely authenticates. If HA sits behind its own reverse proxy, trusted_proxies must include the caller or HA 400s valid requests.
  • honeycomb — Targets the US instance (EU teams use api.eu1.honeycomb.io); Query Data API is plan-gated.
  • hubspotapi — Private app token as Bearer.
  • huggingface — Large file downloads via //resolve/... also work through the proxy.
  • infisical — Bearer token; --base-url for self-hosted. Verify uses GET /api/v1/workspace: it authenticates the token (403 on a bad token, 200 on a good one) WITHOUT requiring a workspaceId/environment. The old verify hit /api/v3/secrets/raw, which 400s ('You must provide projectSlug or workspaceId') for every caller — it was untestable.
  • influxdb — Custom 'Token ' scheme; pass --base-url for your region host.
  • intercom — Requires an explicit Accept: application/json; without it Intercom answers 406 media_type_not_acceptable (curl hides this by defaulting to /, Go's client sends no Accept at all).
  • jenkins — Self-hosted: pass --base-url. Basic auth = username + API token.
  • jina — Bearer key; embeddings, rerank, reader. Verify posts a 1-token embeddings call (Jina has no GET liveness endpoint): a bad key 401s, a good key 200s.
  • jira — Jira Server/Data Center uses different auth (PATs with Bearer); this descriptor targets Jira Cloud. The same site/email/token also works for the confluence service.
  • keycloak — Token mint: POST the realm's token endpoint (path-gated to /realms/); a short-lived bearer token comes back. Use it directly against your API and re-mint on 401 — the client secret never touches the VM. Point --base-url at your Keycloak install. Full details: https://exe.dev/docs/integrations-token-mint
  • lastfm — Read-only methods only: write/scrobble methods need OAuth-style session signing, not supported here.
  • launchdarkly — Raw token in Authorization header (no scheme).
  • lemonsqueezy — Bearer key + JSON:API Accept header.
  • linear — GraphQL API: access scoping is delegated to the token's permissions
  • linode — Bearer PAT.
  • loki — Self-hosted: pass --base-url. Basic auth. CAVEAT: upstream Loki ships no auth layer (it expects an authenticating proxy in front), so whether this credential authenticates is a property of YOUR deployment, not of Loki — verify only proves the endpoint answered, and a multi-tenant Loki wants X-Scope-OrgID and can 401 even a valid Basic credential.
  • mailgun — Basic auth: username 'api', password = key. EU: --base-url https://api.eu.mailgun.net.
  • mattermost — Self-hosted: pass --base-url. Bearer PAT.
  • meilisearch — Bearer key; pass --base-url for your instance.
  • mistral — OpenAI-ish shape.
  • mixpanel — Basic auth with a service account.
  • monday — GraphQL-only API (POST /v2); the token goes bare in the Authorization header (linear-style, no Bearer). Complexity budget: each account gets a per-minute complexity allowance and heavy queries return a COMPLEXITY_BUDGET_EXHAUSTED error with a retry_in_seconds hint — page with limit/page rather than fetching whole boards.
  • neon — Management API (Bearer). SQL-over-HTTP is a separate per-endpoint host.
  • netlifyapi — Bearer PAT.
  • newrelic — Api-Key custom header (User key).
  • newsapi — Custom X-Api-Key header.
  • notion — Pages must be explicitly shared with the integration in Notion before the API can see them.
  • npm — Bearer token as used by .npmrc _authToken. Plain REST, no token dance.
  • okta — Custom 'SSWS ' scheme. Templated org host; or --base-url for custom domains.
  • omdb — Errors arrive as HTTP 200 with Response:"False" in the body.
  • onepassword — Self-hosted Connect server ONLY: pass --base-url for your deployment. 1password.com accounts and service-account tokens (ops_...) do not work here — the hosted product has no Connect REST API.
  • onesignal — Custom 'Key ' Authorization scheme.
  • openai — The OpenAI-compatible shape is the industry lingua franca; many providers below mirror it.
  • openai-ads — Advertiser API (beta): key comes from the OpenAI Ads Manager Settings tab, NOT platform.openai.com. Each key is scoped to a single ad account; the account must pass OpenAI's advertiser verification before campaigns deliver. Docs have Markdown twins: append .md to any page URL, index at developers.openai.com/ads/llms.txt.
  • openrouter — OpenAI-compatible API under /api/v1; point OpenAI SDKs at the proxy host with /api/v1 as the base path.
  • openweather — New keys can take ~10 minutes to activate. Free tier: 60 calls/minute.
  • opsgenie — Custom 'GenieKey ' Authorization scheme.
  • paddle — Bearer key. Sandbox: --base-url https://sandbox-api.paddle.com.
  • perplexity — OpenAI-ish chat/completions with sonar models.
  • pinecone — Control plane only: per-index data-plane hosts (from /indexes) are NOT proxied; upsert/query traffic cannot go through this integration.
  • pipedrive — API token as query param; templated per-company host.
  • planetscale — Authorization header is 'token_id:token' (no scheme).
  • polygon — Bearer key (also accepts ?apiKey=).
  • posthog — Defaults to US Cloud; EU Cloud or self-hosted instances must set --base-url (e.g. https://eu.posthog.com).
  • posthogapi — Personal API key Bearer. Use --base-url for EU (eu.posthog.com) or self-hosted.
  • postmark — Custom X-Postmark-Server-Token header.
  • pushover — App token as param; message also needs a user key.
  • pypi — Basic auth with the literal username 'token' and the API token as password.
  • qdrant — Custom api-key header. Templated per-cluster host; or --base-url.
  • quay — Full-surface registry proxy: use the integration hostname AS the registry (docker pull /org/repo — no docker login). The proxy injects your robot credentials only at the token realm (/v2/auth) and rewrites the auth challenge so stock docker/podman/skopeo/crane mint through the integration automatically; your image traffic and minted tokens pass through untouched (blobs come from quay's CDN directly). Self-hosted Quay: pass --base-url. Full details: https://exe.dev/docs/integrations-oci-registries
  • railway — Bearer token; GraphQL API. Verification works with both account and workspace tokens (the { projects } query answers for either). Project tokens still cannot verify — they authenticate via the Project-Access-Token header (not Authorization: Bearer), so they will always be rejected.
  • reddit-ads — Token mint: POST /api/v1/access_token (any body is ignored); the proxy runs the refresh-token grant server-side and a ~1h access_token comes back. Use it as 'Authorization: Bearer ' on /api/v3/... and re-mint on 401 — the refresh token and client secret never reach the VM. Scopes: adsread (reporting/reads), adsedit (campaign writes), adsconversions (conversion uploads). Getting the refresh token + full details: https://exe.dev/docs/integrations-token-mint
  • render — Bearer key.
  • replicate — Poll predictions instead of webhooks; output URLs (replicate.delivery) are presigned and expire — download promptly.
  • resend — Bearer key. Resend mints two key classes: full_access and sending_access (send-only, optionally domain-restricted). Verification calls GET /domains, which only a full-access key can answer — a valid sending-access key gets 401 restricted_api_key there, so add it with --skip-verify; it still sends fine (POST /emails). Every management endpoint 401s for sending keys, so no side-effect-free verify path exists for them today.
  • scaleway — Custom X-Auth-Token header.
  • sendgrid — Bearer key.
  • sentry — EU-region orgs use https://de.sentry.io and self-hosted installs their own host: pass --base-url
  • shippo — Custom 'ShippoToken ' scheme.
  • shopify — Custom app token self-minted per store. Templated per-store hostname.
  • snowflake — The PROGRAMMATIC_ACCESS_TOKEN token-type header is mandatory (this descriptor injects it); without it Snowflake assumes the bearer is an OAuth token and rejects PATs confusingly. A 401 on a fresh token usually means the user needs a network policy, not that the token is bad. Most statements need a warehouse (in the body or as user default); SELECT 1 runs warehouse-less.
  • snyk — Custom 'token ' scheme.
  • square — Bearer token + fixed Square-Version header. Sandbox: --base-url https://connect.squareupsandbox.com.
  • statsig — Custom STATSIG-API-KEY header.
  • stripe — Use restricted keys (rk_) to scope access. Event-driven flows: poll /v1/events instead of webhooks.
  • supabase — The key rides both the apikey header and Bearer. service_role/secret keys bypass RLS — prefer anon/publishable unless you need that. Per-project host (your project ref is the X in X.supabase.co). Verify uses GET /auth/v1/health, which the project's API gateway key-auths for every key role.
  • tailscale — The '-' tailnet path segment means "the token's own tailnet", so no tailnet name field is needed. API access tokens (tskey-api-...) expire at most 90 days after creation — a verify that starts failing on a previously-good credential usually means the token aged out, not that access was revoked. Auth keys (tskey-auth-...) enroll devices and will NOT work here.
  • tavily — Results are pre-chunked for RAG; free monthly credit tier.
  • telegram — The bot token is a path segment: exe.dev injects it server-side, so write paths WITHOUT the token. Method calls use /bot/ — write /getMe, /sendMessage, etc. File downloads use /file/bot/<FILE_PATH> — keep the /file/ prefix and write the file_path exactly as getFile returned it (e.g. /file/photos/file_1.jpg). Add the bot to a chat and use getUpdates to discover chat_id.
  • telnyx — Bearer key.
  • tmdb — v4 read access token as Bearer.
  • todoist — Unified API v1 (Sync v9 and REST v2 decommissioned, HTTP 410). List endpoints are paginated: {"results": [...], "next_cursor": ...}.
  • togetherai — OpenAI-compatible API surface (/v1/chat/completions, /v1/embeddings), so OpenAI SDKs work by pointing base_url at the integration hostname. Model names are namespaced (org/model); list /v1/models for current serverless availability.
  • trello — Auth rides in query parameters (key= and token=), injected by the proxy — write paths WITHOUT them. Both halves are needed: the API key identifies the Power-Up, the token grants a user's access to it. POST endpoints take arguments as query params too, not JSON bodies.
  • turso — Control plane only — DB queries go to https://-.turso.io with a separate DB token; mint a short-lived one via this API (see usage) so the durable platform token never leaves the proxy. libsql:// URLs use WebSocket; prefer the https:// URL form for Hrana-over-HTTP.
  • twilio — Basic auth: Account SID as username, Auth Token as password.
  • twitch — Token mint: POST /oauth2/token (any body is ignored); the proxy runs the client-credentials grant server-side and an app access token comes back. Use it as 'Authorization: Bearer ' on /helix/... through this integration (the proxy adds the required Client-Id header) and re-mint on 401. App tokens carry no user scopes — user-context endpoints need a user token this shape does not mint. Full details: https://exe.dev/docs/integrations-token-mint
  • typesense — Custom X-TYPESENSE-API-KEY header; pass --base-url for your node.
  • upstash — Any Redis command as path segments. Templated per-db hostname.
  • uptimerobot — API key as POST/query param; format=json injected. POST-only API; the key rides the query params, so the verify body only forces a POST. UptimeRobot answers HTTP 200 even for a bad key ({"stat":"fail"}), hence the body assertion — and it ECHOES the submitted api_key in that envelope, so the response body must never be logged or quoted.
  • urlscan — Scan submissions default to PUBLIC visibility — set visibility (unlisted/private) explicitly to avoid publishing the URLs you scan. Result fetch is asynchronous: poll /api/v1/result/{uuid}/ until it stops 404ing. Search serves unauthenticated traffic at a lower rate limit, so a passing search proves nothing about the key; verify uses /user/quotas/, which rejects wrong keys.
  • vercel — Team resources need ?teamId=... on each request; endpoints are versioned per-path (v6/v9/v13).
  • virustotal — Custom x-apikey header.
  • voyage — Bearer key; embeddings + rerank.
  • vultr — Bearer API key.
  • weaviate — Bearer key; pass --base-url for your cluster endpoint.
  • webflow — Bearer token.
  • wolframalpha — AppID as query param.
  • wordpress — Self-hosted: pass --base-url for your site. The credential is an APPLICATION password (Users > Profile > Application Passwords), not the login password; WordPress displays it with spaces — pasting either form works. A 404 on EVERY /wp-json path usually means plain permalinks: set a permalink structure or use ?rest_route=/wp/v2/... A 403 with rest_disabled/rest_login_required means a security plugin, not a bad credential.
  • workos — Bearer key.
  • xai — Both OpenAI- and Anthropic-compatible endpoint shapes.
  • youtube — API-key auth is read-only; uploads/comments need OAuth (not supported here). Default quota 10k units/day; a search costs 100 units.
  • zulip — Zulip Cloud or self-hosted: pass --base-url with your realm (https://.zulipchat.com). Basic auth = bot-email + API key from the bot's settings.

Databases

Database (wire-protocol) integrations hold the endpoint and credentials server-side and broker a TLS connection, so the password never lands on the VM. Their handles carry the db: prefix — that is the only form the add flow accepts — and the same connect-link shape applies (service=db:neon). Database integrations are still rolling out; if the Databases section is missing from your account's catalog page, they are not enabled for you yet.

Service Handle Protocol Description
CockroachDB Cloud (SQL access) db:cockroachdb-sql postgres Run SQL against a CockroachDB Cloud cluster over Postgres-wire.
Neon (Serverless Postgres) db:neon postgres Serverless Postgres with branching. Broker holds the role password.
PostgreSQL (generic) db:postgres postgres Any PostgreSQL endpoint — RDS, Aurora, Timescale, or self-hosted.
Supabase (Postgres) db:supabase postgres The Postgres database behind a Supabase project, direct or pooled.

Database notes

  • db:cockroachdb-sql — SQL query access (the other half of the cockroachdb management integration). Most clusters need NO routing id: modern dedicated hosts route by hostname, so leave 'cluster' empty. Only the shared free-tier hosts require it. TLS is pinned to verify-full and validates against public roots (CockroachDB Cloud uses Let's Encrypt), so no root.crt download is needed despite what older docs say.
  • db:neon — Neon requires TLS; sslmode is pinned to verify-full on the backend leg. Use a role scoped to what the agent needs.
  • db:postgres — Generic Postgres-wire endpoint. The broker holds the credentials; VMs connect over TLS with no password. Prefer a least-privilege database user.
  • db:supabase — Database is fixed to 'postgres'. Use the session pooler (port 5432) or transaction pooler (port 6543) host with user postgres.; the direct db..supabase.co host is IPv6-only. sslmode pinned verify-full. The vendor CA (Supabase Root 2021 CA) is pinned in the descriptor: Supabase signs server certs with its own CA, so verify-full needs it and system roots never suffice.