Integration catalog
Services available through exe.dev catalog integrations
This page lists the public catalog services that can be added to exe.dev.
It is generated from the same descriptors and visibility rules used by the
catalog browse and add flows, so staged previews and names owned by built-in
integration types are omitted.
Use the **handle** exactly as the <code>service</code> query parameter in a connect link:
~~~
https://exe.dev/integrations/add?service=<handle>&attach=vm:<vm>&for=<duration>&source=shelley
~~~
The link only pre-fills the add dialog. The user reviews it and supplies or
authorizes credentials on exe.dev; credentials never belong in the URL.
| Service | Handle | Connection | Description |
|---|---|---|---|
| [Airtable](/integrations/add?service=airtable) | `airtable` | API credential | Spreadsheet-database for structured records, bases, and views. |
| [Algolia](/integrations/add?service=algolia) | `algolia` | API credential | Hosted search-as-a-service with instant, typo-tolerant queries. |
| [Alpha Vantage (market data)](/integrations/add?service=alphavantage) | `alphavantage` | API credential | Stock, forex, and crypto market data API. |
| [Amplitude](/integrations/add?service=amplitude) | `amplitude` | API credential | Product analytics for user behavior and funnels. |
| [Anthropic](/integrations/add?service=anthropic) | `anthropic` | API credential | Claude large language models (chat, tools, vision). |
| [Argo CD](/integrations/add?service=argocd) | `argocd` | API credential | GitOps continuous delivery for Kubernetes. |
| [Asana](/integrations/add?service=asana) | `asana` | API credential | Work and project management for teams. |
| [AssemblyAI](/integrations/add?service=assemblyai) | `assemblyai` | API credential | Speech-to-text transcription and audio intelligence. |
| [atcr.io (AT Protocol container registry)](/integrations/add?service=atcr) | `atcr` | API credential | AT Protocol container registry: mint short-lived scoped pull tokens (Tangled/Knot). |
| [Attio](/integrations/add?service=attio) | `attio` | API credential | Modern, data-driven CRM. |
| [Axiom](/integrations/add?service=axiom) | `axiom` | API credential | Log management and event analytics at scale. |
| [511 SF Bay (transit & traffic)](/integrations/add?service=bay511) | `bay511` | API credential | San Francisco Bay Area transit and traffic open data. |
| [Better Stack](/integrations/add?service=betterstack) | `betterstack` | API credential | Uptime monitoring, incident management, and logs. |
| [Bitbucket Cloud](/integrations/add?service=bitbucket) | `bitbucket` | API credential | Git repository hosting: repos, pull requests, and pipelines. |
| [Brave Search API](/integrations/add?service=brave) | `brave` | API credential | Independent web search API with its own index. |
| [Buildkite](/integrations/add?service=buildkite) | `buildkite` | API credential | CI/CD pipelines that run on your own infrastructure. |
| [Cal.com](/integrations/add?service=calcom) | `calcom` | API credential | Open-source scheduling and booking (Calendly alternative). |
| [Calendly](/integrations/add?service=calendly) | `calendly` | API credential | Automated meeting scheduling and booking links. |
| [Cerebras](/integrations/add?service=cerebras) | `cerebras` | API credential | Ultra-fast LLM inference on wafer-scale hardware. |
| [CircleCI](/integrations/add?service=circleci) | `circleci` | API credential | Continuous integration and delivery pipelines. |
| [Clerk](/integrations/add?service=clerk) | `clerk` | API credential | Drop-in user authentication and management. |
| [ClickHouse Cloud](/integrations/add?service=clickhouse) | `clickhouse` | API credential | Columnar SQL database for real-time analytics. |
| [ClickUp](/integrations/add?service=clickup) | `clickup` | API credential | All-in-one project management and docs. |
| [Cloudflare](/integrations/add?service=cloudflare) | `cloudflare` | API credential | CDN, DNS, and edge network management. |
| [CockroachDB Cloud](/integrations/add?service=cockroachdb) | `cockroachdb` | API credential | Manage CockroachDB Cloud clusters via the Cloud API. |
| [Cohere](/integrations/add?service=cohere) | `cohere` | API credential | Enterprise LLMs for chat, embeddings, and rerank. |
| [CoinGecko](/integrations/add?service=coingecko) | `coingecko` | API credential | Cryptocurrency prices and market data. |
| [Confluence Cloud](/integrations/add?service=confluence) | `confluence` | API credential | Team wiki and documentation (Atlassian). |
| [Convex](/integrations/add?service=convex) | `convex` | API credential | Reactive backend-as-a-service: database, functions, and scheduling. |
| [crates.io](/integrations/add?service=cratesio) | `cratesio` | API credential | The Rust package registry. |
| [Datadog](/integrations/add?service=datadog) | `datadog` | API credential | Infrastructure and application monitoring. |
| [Deepgram](/integrations/add?service=deepgram) | `deepgram` | API credential | Real-time and batch speech-to-text. |
| [DeepSeek](/integrations/add?service=deepseek) | `deepseek` | API credential | Open-weight LLMs (chat and reasoning), OpenAI-compatible. |
| [DigitalOcean](/integrations/add?service=digitalocean) | `digitalocean` | API credential | Cloud VMs, databases, and managed infrastructure. |
| [Docker Hub](/integrations/add?service=dockerhub) | `dockerhub` | API credential | Container image registry and repository management. |
| [Doppler](/integrations/add?service=doppler) | `doppler` | API credential | Secrets management and environment configuration. |
| [Dynatrace](/integrations/add?service=dynatrace) | `dynatrace` | API credential | Full-stack observability and APM. |
| [EasyPost](/integrations/add?service=easypost) | `easypost` | API credential | Multi-carrier shipping, tracking, and labels. |
| [ElevenLabs](/integrations/add?service=elevenlabs) | `elevenlabs` | API credential | AI text-to-speech and voice generation. |
| [Etherscan](/integrations/add?service=etherscan) | `etherscan` | API credential | Ethereum blockchain explorer and on-chain data. |
| [Exa](/integrations/add?service=exa) | `exa` | API credential | Neural web search built for AI agents. |
| [Fastly](/integrations/add?service=fastly) | `fastly` | API credential | Edge CDN and real-time content delivery. |
| [Fastmail](/integrations/add?service=fastmail) | `fastmail` | API credential | Full email, contacts, and calendar access over JMAP. |
| [Figma](/integrations/add?service=figma) | `figma` | API credential | Collaborative interface design: files, comments, components, and dev resources. |
| [Finnhub](/integrations/add?service=finnhub) | `finnhub` | API credential | Real-time stock, forex, and financial data. |
| [Firecrawl](/integrations/add?service=firecrawl) | `firecrawl` | API credential | Turn websites into clean, LLM-ready markdown. |
| [Fireworks AI](/integrations/add?service=fireworks) | `fireworks` | API credential | Fast hosted inference for open LLMs, OpenAI-compatible. |
| [Fly.io](/integrations/add?service=flyio) | `flyio` | API credential | Deploy app containers close to users, globally. |
| [Forgejo](/integrations/add?service=forgejo) | `forgejo` | API credential | Self-hostable Git forge (Gitea fork); Codeberg.org is the flagship public instance. |
| [Freshdesk](/integrations/add?service=freshdesk) | `freshdesk` | API credential | Customer support ticketing and helpdesk. |
| [Front](/integrations/add?service=front) | `front` | API credential | Shared inbox and customer communication hub. |
| [Google Artifact Registry](/integrations/add?service=gar) | `gar` | API credential | Google Artifact Registry: docker push/pull through the integration, no SA key on the VM. |
| [Google Gemini](/integrations/add?service=gemini) | `gemini` | API credential | Google's Gemini multimodal large language models. |
| [GitHub Container Registry (ghcr.io)](/integrations/add?service=ghcr) | `ghcr` | API credential | GitHub Container Registry: mint registry tokens at ghcr.io's OCI token realm. |
| [Ghost (Content API)](/integrations/add?service=ghost) | `ghost` | API credential | Publishing platform and newsletter CMS. |
| [GitGuardian](/integrations/add?service=gitguardian) | `gitguardian` | API credential | Secrets detection and code security scanning. |
| [GitLab](/integrations/add?service=gitlab) | `gitlab` | API credential | Git hosting, CI/CD, and DevOps platform. |
| [Google Maps Platform](/integrations/add?service=googlemaps) | `googlemaps` | API credential | Geocoding, directions, places, and maps data. |
| [Google Service Account (JWT-bearer token mint)](/integrations/add?service=googlesa) | `googlesa` | API credential | Mint Google API access tokens from a service-account key (Sheets, Drive, GCS, ...). |
| [Google Sheets (read)](/integrations/add?service=googlesheets) | `googlesheets` | API credential | Read link-shared Google Sheets data. |
| [Grafana](/integrations/add?service=grafana) | `grafana` | API credential | Dashboards and visualization for metrics and logs. |
| [Groq](/integrations/add?service=groq) | `groq` | API credential | Very-low-latency LLM inference, OpenAI-compatible. |
| [HashiCorp Vault](/integrations/add?service=hashicorpvault) | `hashicorpvault` | API credential | Secrets management and encryption as a service. |
| [Have I Been Pwned](/integrations/add?service=haveibeenpwned) | `haveibeenpwned` | API credential | Check emails and passwords against known breaches. |
| [Heroku](/integrations/add?service=heroku) | `heroku` | API credential | Managed platform-as-a-service app hosting. |
| [Hetzner Cloud](/integrations/add?service=hetzner) | `hetzner` | API credential | Budget cloud servers and infrastructure. |
| [Home Assistant](/integrations/add?service=homeassistant) | `homeassistant` | API credential | Control and observe a Home Assistant instance: states, services, automations. |
| [Honeycomb](/integrations/add?service=honeycomb) | `honeycomb` | API credential | Observability for distributed systems and tracing. |
| [HubSpot](/integrations/add?service=hubspot) | `hubspot` | API credential | CRM, marketing, and sales platform. |
| [HubSpot](/integrations/add?service=hubspotapi) | `hubspotapi` | API credential | HubSpot CRM objects, contacts, and deals API. |
| [Hugging Face](/integrations/add?service=huggingface) | `huggingface` | API credential | Model, dataset, and inference hub for ML. |
| [Infisical](/integrations/add?service=infisical) | `infisical` | API credential | Open-source secrets management. |
| [InfluxDB Cloud](/integrations/add?service=influxdb) | `influxdb` | API credential | Time-series database for metrics and events. |
| [Intercom](/integrations/add?service=intercom) | `intercom` | API credential | Customer messaging and support platform. |
| [Jenkins](/integrations/add?service=jenkins) | `jenkins` | API credential | Self-hosted automation and CI server. |
| [Jina AI](/integrations/add?service=jina) | `jina` | API credential | Embeddings, rerank, and a web reader for AI. |
| [Jira Cloud](/integrations/add?service=jira) | `jira` | API credential | Issue tracking and agile project management (Atlassian). |
| [Keycloak (OAuth2 token mint)](/integrations/add?service=keycloak) | `keycloak` | API credential | Open-source identity and OAuth2/OIDC provider. |
| [Last.fm](/integrations/add?service=lastfm) | `lastfm` | API credential | Music scrobbling, listening history, and metadata. |
| [LaunchDarkly](/integrations/add?service=launchdarkly) | `launchdarkly` | API credential | Feature flags and progressive delivery. |
| [Lemon Squeezy](/integrations/add?service=lemonsqueezy) | `lemonsqueezy` | API credential | Payments and subscriptions for digital products. |
| [Linear](/integrations/add?service=linear) | `linear` | API credential | Issue tracking and planning for software teams. |
| [Linode (Akamai)](/integrations/add?service=linode) | `linode` | API credential | Akamai's cloud compute and hosting. |
| [Grafana Loki](/integrations/add?service=loki) | `loki` | API credential | Grafana's log aggregation system. |
| [Mailgun](/integrations/add?service=mailgun) | `mailgun` | API credential | Transactional and bulk email delivery. |
| [Mattermost](/integrations/add?service=mattermost) | `mattermost` | API credential | Self-hosted team chat and collaboration. |
| [Meilisearch](/integrations/add?service=meilisearch) | `meilisearch` | API credential | Fast, typo-tolerant open-source search engine. |
| [Mistral](/integrations/add?service=mistral) | `mistral` | API credential | Open-weight and frontier LLMs, OpenAI-compatible. |
| [Mixpanel](/integrations/add?service=mixpanel) | `mixpanel` | API credential | Product analytics and user event tracking. |
| [monday.com](/integrations/add?service=monday) | `monday` | API credential | Work OS: boards, items, and workflows via a GraphQL API. |
| [Neon](/integrations/add?service=neon) | `neon` | API credential | Serverless PostgreSQL with branching. |
| [Netlify](/integrations/add?service=netlify) | `netlify` | API credential | Deploy and host web front-ends and functions. |
| [Netlify](/integrations/add?service=netlifyapi) | `netlifyapi` | API credential | Netlify site, deploy, and DNS management API. |
| [New Relic](/integrations/add?service=newrelic) | `newrelic` | API credential | Application performance monitoring and observability. |
| [NewsAPI.org](/integrations/add?service=newsapi) | `newsapi` | API credential | Headlines and articles from news sources worldwide. |
| [Notion](/integrations/add?service=notion) | `notion` | API credential | Connected workspace for notes, docs, and databases. |
| [npm registry](/integrations/add?service=npm) | `npm` | API credential | The JavaScript/Node package registry. |
| [Okta](/integrations/add?service=okta) | `okta` | API credential | Enterprise identity and single sign-on. |
| [OMDb (movie database)](/integrations/add?service=omdb) | `omdb` | API credential | Movie and TV metadata from IMDb. |
| [1Password Connect (self-hosted)](/integrations/add?service=onepassword) | `onepassword` | API credential | Secrets vault via a self-hosted 1Password Connect server. |
| [OneSignal](/integrations/add?service=onesignal) | `onesignal` | API credential | Push notifications and customer messaging. |
| [OpenAI](/integrations/add?service=openai) | `openai` | API credential | GPT models, embeddings, images, and audio. |
| [OpenAI Ads (ChatGPT)](/integrations/add?service=openai-ads) | `openai-ads` | API credential | Create and manage ChatGPT ad campaigns and pull performance insights. |
| [OpenRouter](/integrations/add?service=openrouter) | `openrouter` | API credential | One API gateway to many LLM providers. |
| [OpenWeather](/integrations/add?service=openweather) | `openweather` | API credential | Current weather and forecasts worldwide. |
| [Opsgenie](/integrations/add?service=opsgenie) | `opsgenie` | API credential | On-call scheduling and alert routing (Atlassian). |
| [Paddle](/integrations/add?service=paddle) | `paddle` | API credential | Merchant-of-record billing for software. |
| [PagerDuty](/integrations/add?service=pagerduty) | `pagerduty` | API credential | Incident response and on-call management. |
| [Perplexity](/integrations/add?service=perplexity) | `perplexity` | API credential | Answer engine with live web search (Sonar models). |
| [Pinecone](/integrations/add?service=pinecone) | `pinecone` | API credential | Managed vector database for semantic search. |
| [Pipedrive](/integrations/add?service=pipedrive) | `pipedrive` | API credential | Sales-focused CRM and pipeline management. |
| [PlanetScale](/integrations/add?service=planetscale) | `planetscale` | API credential | Serverless MySQL platform built on Vitess. |
| [Polygon.io](/integrations/add?service=polygon) | `polygon` | API credential | Real-time and historical stock and crypto data. |
| [PostHog](/integrations/add?service=posthog) | `posthog` | API credential | Open-source product analytics and session replay. |
| [PostHog (query API)](/integrations/add?service=posthogapi) | `posthogapi` | API credential | PostHog query and events API (HogQL). |
| [Postmark](/integrations/add?service=postmark) | `postmark` | API credential | Fast, reliable transactional email. |
| [Pushover](/integrations/add?service=pushover) | `pushover` | API credential | Simple push notifications to your devices. |
| [PyPI (upload)](/integrations/add?service=pypi) | `pypi` | API credential | The Python package index (uploads). |
| [Qdrant Cloud](/integrations/add?service=qdrant) | `qdrant` | API credential | Vector database for similarity search. |
| [Red Hat Quay (quay.io)](/integrations/add?service=quay) | `quay` | API credential | Red Hat Quay container registry: mint short-lived scoped registry JWTs. |
| [Railway](/integrations/add?service=railway) | `railway` | API credential | Deploy apps and databases with minimal config. |
| [Reddit Ads](/integrations/add?service=reddit-ads) | `reddit-ads` | Credential mint | Reddit Ads API: manage and report on Reddit advertising campaigns. |
| [Render](/integrations/add?service=render) | `render` | API credential | Managed cloud hosting for apps and databases. |
| [Replicate](/integrations/add?service=replicate) | `replicate` | API credential | Run and host open ML models via API. |
| [Resend](/integrations/add?service=resend) | `resend` | API credential | Developer-first transactional email. |
| [Scaleway](/integrations/add?service=scaleway) | `scaleway` | API credential | European cloud compute and storage. |
| [SendGrid](/integrations/add?service=sendgrid) | `sendgrid` | API credential | Transactional and marketing email (Twilio). |
| [Sentry](/integrations/add?service=sentry) | `sentry` | API credential | Error tracking and performance monitoring. |
| [SerpApi (Google search results)](/integrations/add?service=serpapi) | `serpapi` | API credential | Scrape Google and other search-engine results. |
| [Shippo](/integrations/add?service=shippo) | `shippo` | API credential | Multi-carrier shipping labels and tracking. |
| [Shodan](/integrations/add?service=shodan) | `shodan` | API credential | Search engine for internet-connected devices. |
| [Shopify (Admin API)](/integrations/add?service=shopify) | `shopify` | API credential | E-commerce store and order management. |
| [Shortcut](/integrations/add?service=shortcut) | `shortcut` | API credential | Issue tracking and project planning for dev teams. |
| [Snowflake](/integrations/add?service=snowflake) | `snowflake` | API credential | Run SQL against your Snowflake warehouse over the SQL REST API. |
| [Snyk](/integrations/add?service=snyk) | `snyk` | API credential | Developer security scanning for code and deps. |
| [Square](/integrations/add?service=square) | `square` | API credential | Payments, point-of-sale, and commerce. |
| [Statsig](/integrations/add?service=statsig) | `statsig` | API credential | Feature flags and experimentation. |
| [Stripe](/integrations/add?service=stripe) | `stripe` | API credential | Online payments and billing. |
| [Supabase](/integrations/add?service=supabase) | `supabase` | API credential | Postgres backend with auth, storage, and APIs. |
| [Tailscale](/integrations/add?service=tailscale) | `tailscale` | API credential | Manage a tailnet: devices, keys, DNS, and ACLs via the Tailscale API. |
| [Tavily](/integrations/add?service=tavily) | `tavily` | API credential | Web search API built for LLMs and agents. |
| [Telegram Bot API](/integrations/add?service=telegram) | `telegram` | API credential | Send messages and read updates as a Telegram bot. |
| [Telnyx](/integrations/add?service=telnyx) | `telnyx` | API credential | Programmable voice, SMS, and connectivity. |
| [TMDB (movies)](/integrations/add?service=tmdb) | `tmdb` | API credential | Movie and TV database (TMDB). |
| [Todoist](/integrations/add?service=todoist) | `todoist` | API credential | Task management and to-do lists. |
| [Together AI](/integrations/add?service=togetherai) | `togetherai` | API credential | Open-source LLM inference, fine-tuning, and embeddings API. |
| [Trello](/integrations/add?service=trello) | `trello` | API credential | Kanban boards, lists, and cards. |
| [Turso](/integrations/add?service=turso) | `turso` | API credential | SQLite-compatible edge database platform (libSQL) — Platform API. |
| [Twilio](/integrations/add?service=twilio) | `twilio` | API credential | Programmable SMS, voice, and messaging. |
| [Twitch](/integrations/add?service=twitch) | `twitch` | Credential mint | Twitch Helix API: streams, channels, games, clips and EventSub subscriptions. |
| [Typesense](/integrations/add?service=typesense) | `typesense` | API credential | Open-source, typo-tolerant search engine. |
| [Upstash Redis](/integrations/add?service=upstash) | `upstash` | API credential | Serverless Redis and data over HTTP. |
| [UptimeRobot](/integrations/add?service=uptimerobot) | `uptimerobot` | API credential | Website and endpoint uptime monitoring. |
| [urlscan.io](/integrations/add?service=urlscan) | `urlscan` | API credential | Scan and analyse websites: submit URLs, search scans, fetch verdicts. |
| [Vercel](/integrations/add?service=vercel) | `vercel` | API credential | Deploy and host front-end apps and functions. |
| [VirusTotal](/integrations/add?service=virustotal) | `virustotal` | API credential | File, URL, and domain threat analysis. |
| [Voyage AI (embeddings)](/integrations/add?service=voyage) | `voyage` | API credential | High-quality text embeddings and rerank. |
| [Vultr](/integrations/add?service=vultr) | `vultr` | API credential | Cloud compute, storage, and bare metal. |
| [Weaviate Cloud](/integrations/add?service=weaviate) | `weaviate` | API credential | Open-source vector database. |
| [Webflow](/integrations/add?service=webflow) | `webflow` | API credential | Visual website builder and CMS. |
| [Wolfram\|Alpha](/integrations/add?service=wolframalpha) | `wolframalpha` | API credential | Computational knowledge and answers engine. |
| [WordPress](/integrations/add?service=wordpress) | `wordpress` | API credential | Manage posts, pages, media, and users on a WordPress site via the REST API. |
| [WorkOS](/integrations/add?service=workos) | `workos` | API credential | Enterprise SSO, SCIM, and directory sync. |
| [xAI (Grok)](/integrations/add?service=xai) | `xai` | API credential | Grok large language models from xAI. |
| [YouTube Data API (read)](/integrations/add?service=youtube) | `youtube` | API credential | YouTube video, channel, and search data (read). |
| [Zendesk](/integrations/add?service=zendesk) | `zendesk` | API credential | Customer support ticketing and helpdesk. |
| [Zulip](/integrations/add?service=zulip) | `zulip` | API credential | Threaded team chat (Zulip Cloud or self-hosted). |
## Service notes
Operational caveats carried by the descriptors themselves (the same notes the
catalog add flow surfaces), keyed by handle. Only services with notes appear.
- `algolia` — Proxies the -dsn host only; SDK retry strategies that rotate to <app>-1/-2/-3.algolianet.com hosts bypass the proxy — pin SDK hosts to the proxy URL.
- `alphavantage` — Free tier: 25 requests/day. Errors arrive as HTTP 200 with an error JSON body. CAVEAT: the API appears to serve data for ANY well-formed key, so verify only proves the key is not missing or throttled — it cannot distinguish a valid key from a wrong one.
- `amplitude` — Basic auth: API key + secret key.
- `anthropic` — Custom x-api-key header plus a fixed anthropic-version header. SSE streaming supported.
- `argocd` — Self-hosted: pass --base-url for your Argo CD server.
- `assemblyai` — Raw key in Authorization header (no scheme).
- `atcr` — Token mint: GET the realm with your chosen scope; the proxy injects your handle + app password and atcr's JWT comes back to you. The JWT lives ~45 SECONDS — use it as 'Authorization: Bearer <token>' against https://atcr.io/v2/... immediately and re-mint on 401. The app password never touches the VM. Consume it with curl/skopeo/crane (docker's static 'registrytoken' config field works but a ~45s TTL makes it impractical). Full details: https://exe.dev/docs/integrations-oci-registries
- `attio` — Bearer key.
- `axiom` — Bearer API token.
- `bay511` — Rate limit: 60 requests/hour per token. format=json is injected (the API defaults to XML).
- `betterstack` — Bearer token (Uptime API).
- `bitbucket` — App passwords are GONE (removed 2026-07-28); the credential is an Atlassian API token, and the Basic username must be the ACCOUNT EMAIL — the old Bitbucket username 401s with a valid token on the REST API (git-over-HTTPS confusingly still wants the username, but that never rides this proxy). Tokens carry scopes chosen at creation; /2.0/user needs account:read.
- `brave` — Custom X-Subscription-Token header.
- `calcom` — API v2 (v1 decommissioned, HTTP 410). Bearer API key (cal_... / cal_live_...). Some v2 endpoints additionally require a cal-api-version header (e.g. bookings wants cal-api-version: 2024-08-13); /v2/me does not.
- `calendly` — Bearer PAT.
- `cerebras` — OpenAI-compatible, very fast inference.
- `circleci` — v2 API under /api/v2; some legacy step-output flows still need /api/v1.1 (same host, same token).
- `clerk` — Single global hostname, plain REST.
- `clickhouse` — Basic auth over the HTTP interface; pass --base-url for your host:port.
- `cloudflare` — Use scoped API tokens (per-zone, per-permission), not the legacy X-Auth-Key global key.
- `cockroachdb` — This is the CockroachDB Cloud MANAGEMENT API (cluster lifecycle: create/list/scale/delete clusters) — it does NOT run SQL. There is no public SQL-over-HTTP endpoint for Cloud; connect to the database itself over the Postgres wire protocol directly. The secret key belongs to a service account and inherits its role/permissions. Rate limited to 10 req/s.
- `cohere` — Bearer key; v2 chat API.
- `coingecko` — Custom x-cg-demo-api-key header (Pro uses x-cg-pro-api-key + api.coingecko.com/api/v3/pro). Verify uses /ping, which DOES authenticate (401 on a bad key); most data endpoints like /simple/price serve anonymously and would return 200 for any garbage key.
- `confluence` — The same site/email/token also works for the jira service.
- `convex` — Deployment-scoped: proxies https://<deployment>.convex.cloud; the deploy key grants admin on this ONE deployment (Convex auth scheme, not Bearer). Do not use POST /api/query as a health check — it 200s unauthenticated requests with an in-body error. HTTP actions are served from <deployment>.convex.site (not proxied here). Streaming export/import endpoints 403 (StreamingExportNotEnabled) without a paid Convex plan even with a valid key. The npx convex CLI also talks to the convex.dev control plane, so CLI deploys aren't covered — use the HTTP API.
- `cratesio` — Raw token in Authorization header (no scheme). crates.io's API data-access policy (https://crates.io/data-access) rejects generic user agents with HTTP 403 regardless of the credential, so the descriptor sends an identifying User-Agent. CAVEAT: crates.io cannot be made to authenticate the verify probe. Every authenticated GET either requires a cookie session (AuthCheck::only_cookie — /api/v1/me answers 403 'this action can only be performed on the crates.io website' to ALL tokens) or enforces token endpoint-scopes, so no single GET accepts every valid token; verify is a liveness probe only and cannot distinguish a valid token from a wrong one. Revisit if crates.io ever adds a token-introspection GET.
- `datadog` — Defaults to the US1 site; EU and other regional accounts must set --base-url (e.g. https://api.datadoghq.eu).
- `deepgram` — Custom 'Token <key>' Authorization scheme.
- `deepseek` — OpenAI-compatible; /v1 alias also works.
- `digitalocean` — Spaces (S3-compatible) uses separate keys and SigV4 hosts; this covers the REST API only.
- `dockerhub` — Hub management API. PAT directly as Bearer (no login dance).
- `doppler` — Read-only per-config scoping available on service tokens. The verify path needs a real project+config: a service token is scoped to one config, and personal tokens must name one. project/config are declared non-secret fields so RenderVerify templates them in (the old descriptor hardcoded YOUR_PROJECT and could never verify).
- `dynatrace` — Custom 'Api-Token <token>' scheme. Templated env host; or --base-url for Managed.
- `easypost` — Basic auth: API key as username, empty password.
- `elevenlabs` — Billing is character-based; TTS responses are audio bytes — save to a file.
- `etherscan` — V2 API is multi-chain via chainid parameter. Errors arrive as HTTP 200 with status=0 in the body.
- `exa` — The /contents endpoint doubles as a scraper; pass livecrawl for freshness.
- `fastly` — Custom Fastly-Key header.
- `fastmail` — JMAP, not REST: everything after the session is POST /jmap/api/ with batched methodCalls, and every call needs the accountId from GET /jmap/session (under primaryAccounts). Token scopes are chosen at creation (read-only vs read-write); a read-only token still passes verify. New tokens are shown once, prefixed fmu1-.
- `figma` — PATs are scoped at creation and a missing scope 403s with 'Invalid scope(s)' naming the scope required — fix the token's scopes, not the token. Tokens expire (90-day default in the UI); invalid or expired tokens get 403, not 401. Rate limits are per seat/plan/endpoint tier and harsh on free Starter files (file content can be as low as 6 req/month); 429 carries Retry-After.
- `finnhub` — API token as query param.
- `firecrawl` — Scrape is synchronous; crawl is submit-then-poll. Credits are billed per page.
- `fireworks` — OpenAI-compatible under /inference/v1.
- `flyio` — Machines API only; org/certs/IP management lives on the legacy GraphQL API at api.fly.io (same token, not proxied here).
- `forgejo` — Defaults to Codeberg.org; self-hosted: pass --base-url https://git.mycorp.example. API is Gitea-compatible under /api/v1, and Gitea instances accept the same shape. Tokens are scoped — verify needs read:user, and a valid token without it gets 403 (fix the scope, not the token).
- `freshdesk` — Basic auth: API key as username, any password. Templated per-account host.
- `front` — Bearer token.
- `gar` — Full-surface registry proxy: use the integration hostname AS the registry (docker pull/push <host>/PROJECT/REPO/IMAGE — no docker login; push needs roles/artifactregistry.writer on the SA). The proxy injects _json_key + your SA key only at the token realm (/v2/token) and rewrites the auth challenge so stock docker/podman/skopeo/crane mint through the integration automatically. Regions: the default target is us-docker.pkg.dev; for other regions pass --base-url (europe-docker.pkg.dev, asia-docker.pkg.dev, or a regional host like us-central1-docker.pkg.dev / europe-west1-docker.pkg.dev). GAR also accepts oauth2accesstoken:<access token> at the realm; this integration uses the durable _json_key form so it never expires server-side. Blob downloads redirect to a pre-signed /artifacts-downloads/ URL (self-authorizing, no credential needed) which the gate admits alongside /v2/. Full details: https://exe.dev/docs/integrations-oci-registries
- `gemini` — Google is migrating Gemini API keys: new AI Studio keys are auth keys (AQ....), and standard keys (AIza...) are being phased out during 2026. Both forms work here; credentials are injected as a request header server-side.
- `ghcr` — Full-surface registry proxy: use the integration hostname AS the registry (docker pull <host>/owner/image — no docker login). The proxy injects your PAT only at the token realm (/token) and rewrites the auth challenge so stock docker/podman/skopeo/crane mint through the integration automatically. CAUTION: ghcr's minted token is your PAT base64-encoded, NOT a short-lived JWT — it passes through to the client, so scope the PAT tightly (read:packages only, expiring). Full details: https://exe.dev/docs/integrations-oci-registries
- `ghost` — Content API key as query param; pass --base-url for your blog. (Admin API is JWT — separate.)
- `gitguardian` — Custom 'Token <token>' scheme.
- `gitlab` — Self-hosted: pass --base-url https://gitlab.mycorp.example. Prefer project/group access tokens for scoping.
- `googlemaps` — Billing account required on the Google Cloud project (generous free monthly credit). Restrict the key server-side.
- `googlesa` — Token mint: POST /token with an EMPTY body; the proxy signs the JWT assertion server-side and returns a ~1h access token. Use it directly against the Google API (those calls do NOT ride this integration) and re-mint on 401 — the private key never touches the VM. Share the target resource with the client_email; --subject enables domain-wide delegation. Full details: https://exe.dev/docs/integrations-token-mint
- `googlesheets` — API-key query param; reads link-shared sheets only (no OAuth).
- `grafana` — Stack Grafana API only; Grafana Cloud metrics/logs ingest uses separate per-signal hosts with basic auth.
- `groq` — OpenAI-compatible API under /openai/v1; also serves fast Whisper transcription at /openai/v1/audio/transcriptions.
- `hashicorpvault` — Self-hosted: pass --base-url for your Vault address. X-Vault-Token custom header.
- `haveibeenpwned` — Custom hibp-api-key header.
- `heroku` — Bearer token + fixed Accept version header.
- `hetzner` — Cloud API only; Hetzner DNS and Robot (dedicated) use different hosts and auth. Tokens are per-project, read-only or read-write.
- `homeassistant` — Self-hosted: pass --base-url for your instance (often http://<host>:8123; HTTPS only if you've set it up). Long-lived tokens last 10 years but die if the creating user is deleted. /api/ requires auth and 401s wrong tokens, so verify genuinely authenticates. If HA sits behind its own reverse proxy, trusted_proxies must include the caller or HA 400s valid requests.
- `honeycomb` — Targets the US instance (EU teams use api.eu1.honeycomb.io); Query Data API is plan-gated.
- `hubspotapi` — Private app token as Bearer.
- `huggingface` — Large file downloads via /<repo>/resolve/... also work through the proxy.
- `infisical` — Bearer token; --base-url for self-hosted. Verify uses GET /api/v1/workspace: it authenticates the token (403 on a bad token, 200 on a good one) WITHOUT requiring a workspaceId/environment. The old verify hit /api/v3/secrets/raw, which 400s ('You must provide projectSlug or workspaceId') for every caller — it was untestable.
- `influxdb` — Custom 'Token <token>' scheme; pass --base-url for your region host.
- `intercom` — Requires an explicit `Accept: application/json`; without it Intercom answers 406 media_type_not_acceptable (curl hides this by defaulting to */*, Go's client sends no Accept at all).
- `jenkins` — Self-hosted: pass --base-url. Basic auth = username + API token.
- `jina` — Bearer key; embeddings, rerank, reader. Verify posts a 1-token embeddings call (Jina has no GET liveness endpoint): a bad key 401s, a good key 200s.
- `jira` — Jira Server/Data Center uses different auth (PATs with Bearer); this descriptor targets Jira Cloud. The same site/email/token also works for the confluence service.
- `keycloak` — Token mint: POST the realm's token endpoint (path-gated to /realms/); a short-lived bearer token comes back. Use it directly against your API and re-mint on 401 — the client secret never touches the VM. Point --base-url at your Keycloak install. Full details: https://exe.dev/docs/integrations-token-mint
- `lastfm` — Read-only methods only: write/scrobble methods need OAuth-style session signing, not supported here.
- `launchdarkly` — Raw token in Authorization header (no scheme).
- `lemonsqueezy` — Bearer key + JSON:API Accept header.
- `linear` — GraphQL API: access scoping is delegated to the token's permissions
- `linode` — Bearer PAT.
- `loki` — Self-hosted: pass --base-url. Basic auth. CAVEAT: upstream Loki ships no auth layer (it expects an authenticating proxy in front), so whether this credential authenticates is a property of YOUR deployment, not of Loki — verify only proves the endpoint answered, and a multi-tenant Loki wants X-Scope-OrgID and can 401 even a valid Basic credential.
- `mailgun` — Basic auth: username 'api', password = key. EU: --base-url https://api.eu.mailgun.net.
- `mattermost` — Self-hosted: pass --base-url. Bearer PAT.
- `meilisearch` — Bearer key; pass --base-url for your instance.
- `mistral` — OpenAI-ish shape.
- `mixpanel` — Basic auth with a service account.
- `monday` — GraphQL-only API (POST /v2); the token goes bare in the Authorization header (linear-style, no Bearer). Complexity budget: each account gets a per-minute complexity allowance and heavy queries return a COMPLEXITY_BUDGET_EXHAUSTED error with a retry_in_seconds hint — page with limit/page rather than fetching whole boards.
- `neon` — Management API (Bearer). SQL-over-HTTP is a separate per-endpoint host.
- `netlifyapi` — Bearer PAT.
- `newrelic` — Api-Key custom header (User key).
- `newsapi` — Custom X-Api-Key header.
- `notion` — Pages must be explicitly shared with the integration in Notion before the API can see them.
- `npm` — Bearer token as used by .npmrc _authToken. Plain REST, no token dance.
- `okta` — Custom 'SSWS <token>' scheme. Templated org host; or --base-url for custom domains.
- `omdb` — Errors arrive as HTTP 200 with Response:"False" in the body.
- `onepassword` — Self-hosted Connect server ONLY: pass --base-url for your deployment. 1password.com accounts and service-account tokens (ops_...) do not work here — the hosted product has no Connect REST API.
- `onesignal` — Custom 'Key <key>' Authorization scheme.
- `openai` — The OpenAI-compatible shape is the industry lingua franca; many providers below mirror it.
- `openai-ads` — Advertiser API (beta): key comes from the OpenAI Ads Manager Settings tab, NOT platform.openai.com. Each key is scoped to a single ad account; the account must pass OpenAI's advertiser verification before campaigns deliver. Docs have Markdown twins: append .md to any page URL, index at developers.openai.com/ads/llms.txt.
- `openrouter` — OpenAI-compatible API under /api/v1; point OpenAI SDKs at the proxy host with /api/v1 as the base path.
- `openweather` — New keys can take ~10 minutes to activate. Free tier: 60 calls/minute.
- `opsgenie` — Custom 'GenieKey <key>' Authorization scheme.
- `paddle` — Bearer key. Sandbox: --base-url https://sandbox-api.paddle.com.
- `perplexity` — OpenAI-ish chat/completions with sonar models.
- `pinecone` — Control plane only: per-index data-plane hosts (from /indexes) are NOT proxied; upsert/query traffic cannot go through this integration.
- `pipedrive` — API token as query param; templated per-company host.
- `planetscale` — Authorization header is 'token_id:token' (no scheme).
- `polygon` — Bearer key (also accepts ?apiKey=).
- `posthog` — Defaults to US Cloud; EU Cloud or self-hosted instances must set --base-url (e.g. https://eu.posthog.com).
- `posthogapi` — Personal API key Bearer. Use --base-url for EU (eu.posthog.com) or self-hosted.
- `postmark` — Custom X-Postmark-Server-Token header.
- `pushover` — App token as param; message also needs a user key.
- `pypi` — Basic auth with the literal username '__token__' and the API token as password.
- `qdrant` — Custom api-key header. Templated per-cluster host; or --base-url.
- `quay` — Full-surface registry proxy: use the integration hostname AS the registry (docker pull <host>/org/repo — no docker login). The proxy injects your robot credentials only at the token realm (/v2/auth) and rewrites the auth challenge so stock docker/podman/skopeo/crane mint through the integration automatically; your image traffic and minted tokens pass through untouched (blobs come from quay's CDN directly). Self-hosted Quay: pass --base-url. Full details: https://exe.dev/docs/integrations-oci-registries
- `railway` — Bearer token; GraphQL API. Verification works with both account and workspace tokens (the { projects } query answers for either). Project tokens still cannot verify — they authenticate via the Project-Access-Token header (not Authorization: Bearer), so they will always be rejected.
- `reddit-ads` — Token mint: POST /api/v1/access_token (any body is ignored); the proxy runs the refresh-token grant server-side and a ~1h access_token comes back. Use it as 'Authorization: Bearer <token>' on /api/v3/... and re-mint on 401 — the refresh token and client secret never reach the VM. Scopes: adsread (reporting/reads), adsedit (campaign writes), adsconversions (conversion uploads). Getting the refresh token + full details: https://exe.dev/docs/integrations-token-mint
- `render` — Bearer key.
- `replicate` — Poll predictions instead of webhooks; output URLs (replicate.delivery) are presigned and expire — download promptly.
- `resend` — Bearer key. Resend mints two key classes: full_access and sending_access (send-only, optionally domain-restricted). Verification calls GET /domains, which only a full-access key can answer — a valid sending-access key gets 401 restricted_api_key there, so add it with --skip-verify; it still sends fine (POST /emails). Every management endpoint 401s for sending keys, so no side-effect-free verify path exists for them today.
- `scaleway` — Custom X-Auth-Token header.
- `sendgrid` — Bearer key.
- `sentry` — EU-region orgs use https://de.sentry.io and self-hosted installs their own host: pass --base-url
- `shippo` — Custom 'ShippoToken <token>' scheme.
- `shopify` — Custom app token self-minted per store. Templated per-store hostname.
- `snowflake` — The PROGRAMMATIC_ACCESS_TOKEN token-type header is mandatory (this descriptor injects it); without it Snowflake assumes the bearer is an OAuth token and rejects PATs confusingly. A 401 on a fresh token usually means the user needs a network policy, not that the token is bad. Most statements need a warehouse (in the body or as user default); SELECT 1 runs warehouse-less.
- `snyk` — Custom 'token <token>' scheme.
- `square` — Bearer token + fixed Square-Version header. Sandbox: --base-url https://connect.squareupsandbox.com.
- `statsig` — Custom STATSIG-API-KEY header.
- `stripe` — Use restricted keys (rk_) to scope access. Event-driven flows: poll /v1/events instead of webhooks.
- `supabase` — The key rides both the apikey header and Bearer. service_role/secret keys bypass RLS — prefer anon/publishable unless you need that. Per-project host (your project ref is the X in X.supabase.co). Verify uses GET /auth/v1/health, which the project's API gateway key-auths for every key role.
- `tailscale` — The '-' tailnet path segment means "the token's own tailnet", so no tailnet name field is needed. API access tokens (tskey-api-...) expire at most 90 days after creation — a verify that starts failing on a previously-good credential usually means the token aged out, not that access was revoked. Auth keys (tskey-auth-...) enroll devices and will NOT work here.
- `tavily` — Results are pre-chunked for RAG; free monthly credit tier.
- `telegram` — The bot token is a path segment: exe.dev injects it server-side, so write paths WITHOUT the token. Method calls use /bot<token>/<METHOD> — write /getMe, /sendMessage, etc. File downloads use /file/bot<token>/<FILE_PATH> — keep the /file/ prefix and write the file_path exactly as getFile returned it (e.g. /file/photos/file_1.jpg). Add the bot to a chat and use getUpdates to discover chat_id.
- `telnyx` — Bearer key.
- `tmdb` — v4 read access token as Bearer.
- `todoist` — Unified API v1 (Sync v9 and REST v2 decommissioned, HTTP 410). List endpoints are paginated: {"results": [...], "next_cursor": ...}.
- `togetherai` — OpenAI-compatible API surface (/v1/chat/completions, /v1/embeddings), so OpenAI SDKs work by pointing base_url at the integration hostname. Model names are namespaced (org/model); list /v1/models for current serverless availability.
- `trello` — Auth rides in query parameters (key= and token=), injected by the proxy — write paths WITHOUT them. Both halves are needed: the API key identifies the Power-Up, the token grants a user's access to it. POST endpoints take arguments as query params too, not JSON bodies.
- `turso` — Control plane only — DB queries go to https://<db>-<org>.turso.io with a separate DB token; mint a short-lived one via this API (see usage) so the durable platform token never leaves the proxy. libsql:// URLs use WebSocket; prefer the https:// URL form for Hrana-over-HTTP.
- `twilio` — Basic auth: Account SID as username, Auth Token as password.
- `twitch` — Token mint: POST /oauth2/token (any body is ignored); the proxy runs the client-credentials grant server-side and an app access token comes back. Use it as 'Authorization: Bearer <token>' on /helix/... through this integration (the proxy adds the required Client-Id header) and re-mint on 401. App tokens carry no user scopes — user-context endpoints need a user token this shape does not mint. Full details: https://exe.dev/docs/integrations-token-mint
- `typesense` — Custom X-TYPESENSE-API-KEY header; pass --base-url for your node.
- `upstash` — Any Redis command as path segments. Templated per-db hostname.
- `uptimerobot` — API key as POST/query param; format=json injected. POST-only API; the key rides the query params, so the verify body only forces a POST. UptimeRobot answers HTTP 200 even for a bad key ({"stat":"fail"}), hence the body assertion — and it ECHOES the submitted api_key in that envelope, so the response body must never be logged or quoted.
- `urlscan` — Scan submissions default to PUBLIC visibility — set visibility (unlisted/private) explicitly to avoid publishing the URLs you scan. Result fetch is asynchronous: poll /api/v1/result/{uuid}/ until it stops 404ing. Search serves unauthenticated traffic at a lower rate limit, so a passing search proves nothing about the key; verify uses /user/quotas/, which rejects wrong keys.
- `vercel` — Team resources need ?teamId=... on each request; endpoints are versioned per-path (v6/v9/v13).
- `virustotal` — Custom x-apikey header.
- `voyage` — Bearer key; embeddings + rerank.
- `vultr` — Bearer API key.
- `weaviate` — Bearer key; pass --base-url for your cluster endpoint.
- `webflow` — Bearer token.
- `wolframalpha` — AppID as query param.
- `wordpress` — Self-hosted: pass --base-url for your site. The credential is an APPLICATION password (Users > Profile > Application Passwords), not the login password; WordPress displays it with spaces — pasting either form works. A 404 on EVERY /wp-json path usually means plain permalinks: set a permalink structure or use ?rest_route=/wp/v2/... A 403 with rest_disabled/rest_login_required means a security plugin, not a bad credential.
- `workos` — Bearer key.
- `xai` — Both OpenAI- and Anthropic-compatible endpoint shapes.
- `youtube` — API-key auth is read-only; uploads/comments need OAuth (not supported here). Default quota 10k units/day; a search costs 100 units.
- `zulip` — Zulip Cloud or self-hosted: pass --base-url with your realm (https://<org>.zulipchat.com). Basic auth = bot-email + API key from the bot's settings.
## Databases
Database (wire-protocol) integrations hold the endpoint and credentials
server-side and broker a TLS connection, so the password never lands on the
VM. Their handles carry the `db:` prefix — that is the only form
the add flow accepts — and the same connect-link shape applies
(`service=db:neon`). Database integrations are still rolling out; if
the Databases section is missing from your account's catalog page, they are
not enabled for you yet.
| Service | Handle | Protocol | Description |
|---|---|---|---|
| [CockroachDB Cloud (SQL access)](/integrations/add?service=db:cockroachdb-sql) | `db:cockroachdb-sql` | postgres | Run SQL against a CockroachDB Cloud cluster over Postgres-wire. |
| [Neon (Serverless Postgres)](/integrations/add?service=db:neon) | `db:neon` | postgres | Serverless Postgres with branching. Broker holds the role password. |
| [PostgreSQL (generic)](/integrations/add?service=db:postgres) | `db:postgres` | postgres | Any PostgreSQL endpoint — RDS, Aurora, Timescale, or self-hosted. |
| [Supabase (Postgres)](/integrations/add?service=db:supabase) | `db:supabase` | postgres | The Postgres database behind a Supabase project, direct or pooled. |
### Database notes
- `db:cockroachdb-sql` — SQL query access (the other half of the cockroachdb management integration). Most clusters need NO routing id: modern dedicated hosts route by hostname, so leave 'cluster' empty. Only the shared free-tier hosts require it. TLS is pinned to verify-full and validates against public roots (CockroachDB Cloud uses Let's Encrypt), so no root.crt download is needed despite what older docs say.
- `db:neon` — Neon requires TLS; sslmode is pinned to verify-full on the backend leg. Use a role scoped to what the agent needs.
- `db:postgres` — Generic Postgres-wire endpoint. The broker holds the credentials; VMs connect over TLS with no password. Prefer a least-privilege database user.
- `db:supabase` — Database is fixed to 'postgres'. Use the session pooler (port 5432) or transaction pooler (port 6543) host with user postgres.<ref>; the direct db.<ref>.supabase.co host is IPv6-only. sslmode pinned verify-full. The vendor CA (Supabase Root 2021 CA) is pinned in the descriptor: Supabase signs server certs with its own CA, so verify-full needs it and system roots never suffice.