Connectors & Integrations
Connectors & Integrations
What are Connectors & Integrations?
Connectors let Genspark work directly with the apps and services you already use, so it can read information and perform actions without you copying data back and forth. Connect a service from the Connectors tab in Skills, and Genspark products with connector support can use that connection, subject to your permissions and organization settings.
Quick Start
- Open the Connectors tab. In Skills, navigate to Connectors.
- Find and connect a service. Search or browse for the service and choose the intended connection method. For OAuth, sign in to the provider and review the consent screen. Arrange administrator consent if your tenant requires it. For an API Key, token, or MCP URL, prepare the required credential with the provider and enter it in the setup form.
- Check the connection. Return to the Connectors tab and confirm that the service shows as Connected. For a setup flow that offers a connection test, complete that test as well.
- Use it. Start with a read task on a resource you know you can access. If your workflow needs sending, creating, or updating, verify those permissions separately.
Summarize unread messages in my connected work Gmail account.
Find Salesforce opportunities expected to close this month.
Summarize last month's Ramp spending by department.
Connector Reference
The reference below covers 37 standard connection options, including the Google Suite and Microsoft 365 bundles. Additional connections that require allowlist access or a customer pilot are listed separately.
Availability depends on your account, organization settings, and the provider's requirements. The tasks listed are examples; available actions depend on the connection's tools and granted permissions.
Connection type describes how Genspark calls a service:
- API Call: a native integration uses the provider's API.
- MCP: Genspark uses tools exposed by an MCP server.
Authentication describes how you grant access. MCP connections can use OAuth, an API Key, an access token, or a dedicated server URL.
In the scope-options column:
- Fixed request means the connection requests a predefined permission set. Genspark does not provide individual scope checkboxes.
- Read-only policy means the connection supports narrowing requested permissions when your organization's read-only feature is enabled. See Permissions and Access for the limits.
- Provider configuration means you select resources or configure permissions in the provider's app, account, token, or server.
Communication
| Service | Connection type | Authentication | Scope options | What you can do |
|---|---|---|---|---|
| Gmail | API Call | OAuth 2.0 | Fixed request; read-only policy | Read, search, draft, send, and manage email. The current grant also includes contact reading. |
| Outlook Email | API Call | OAuth 2.0, delegated access | Fixed request; read-only policy | Read, search, send, and manage Outlook email, including authorized shared-mailbox access. |
| Slack | API Call | OAuth 2.0, user authorization | Fixed request; read-only policy | Search conversations, read channels, and send messages. |
| Microsoft Teams | API Call | OAuth 2.0, delegated access | Fixed request; read-only policy | Read chats and channels, send messages, and access team information within your permissions. |
| Google Chat | API Call | OAuth 2.0 | Fixed request; read-only policy | Read spaces and messages, and send replies. Connect Google Chat separately from Google Suite. |
| LINE Send Message | API Call | Account linking through LINE Login | Fixed identity permissions | Receive messages from the official bot on your linked LINE account. This does not authorize reading personal chat history. |
| X (Twitter) | API Call | OAuth 2.0 with PKCE | Fixed request; read-only policy | Search and publish posts, and work with permitted social actions. |
| LinkedIn Lite | API Call | Manually supplied OAuth access token | Provider configuration | Read your profile and draft or publish posts. Beta; the supplied token does not refresh automatically. |
Productivity
| Service | Connection type | Authentication | Scope options | What you can do |
|---|---|---|---|---|
| Google Suite | API Call | OAuth 2.0 | Connect services together or individually; read-only policy | Connect Gmail, Calendar, and Drive together. Docs, Sheets, and Slides file access is provided through Drive. |
| Google Calendar | API Call | OAuth 2.0 | Fixed request; read-only policy | View schedules and create or manage calendar events. |
| Google Drive | API Call | OAuth 2.0 | Fixed request; read-only policy; file authorization | Search and read files, and work with Google Docs, Sheets, and Slides files. Write access applies to files created by the app or authorized by you. |
| Google Contacts | API Call | OAuth 2.0 | Fixed read-only request | Search and view contact details. |
| Microsoft 365 | API Call | OAuth 2.0, delegated access | Connect services together or individually; read-only policy | Connect mail, calendars, files, Teams, profile, and contacts. Outlook contact access is included in this bundle. |
| Outlook Calendar | API Call | OAuth 2.0, delegated access | Fixed request; read-only policy | Find, create, and manage calendar events. |
| Microsoft OneDrive | API Call | OAuth 2.0, delegated access | Fixed request; read-only policy | Search, read, and analyze files and folders. |
| Microsoft SharePoint | API Call | OAuth 2.0, delegated access | Shared file permission set with OneDrive; read-only policy | Search sites and access pages, lists, and files. This connection does not offer per-site scope selection. |
| Box | API Call | OAuth 2.0 | App-defined permissions; read-only policy | Find files and folders, create folders, and access file information. |
| Confluence | API Call | Atlassian OAuth 2.0 | Fixed request shared with Jira; read-only policy | Search and read pages and spaces, and prepare page updates. |
| Notion | API Call | OAuth 2.0 | Provider configuration: authorize pages | Read, create, and edit pages and content authorized for the Notion integration. |
| Notion MCP | MCP | OAuth 2.1 with PKCE | Provider authorization; no Genspark scope picker | Use Notion's hosted tools within the connecting user's Notion permissions. This is separate from the native Notion connection. |
| ClickUp | MCP | OAuth 2.1 with PKCE | Provider authorization; no Genspark scope picker | Find tasks, review workload, create tasks, and update statuses. |
| monday.com | MCP | OAuth 2.1 with PKCE | Provider authorization; no Genspark scope picker | Read boards and items, create items, and update statuses. |
CRM & Sales
| Service | Connection type | Authentication | Scope options | What you can do |
|---|---|---|---|---|
| Salesforce | API Call | OAuth 2.0 | Fixed request; configure roles and object permissions in Salesforce | Read and update authorized CRM records, contacts, and opportunities; analyze the sales pipeline. |
| HubSpot | API Call | Private App Token | Provider configuration: object-level read/write scopes | Work with CRM contacts, companies, and deals. Create the token in HubSpot before connecting. |
| Pipedrive | API Call | OAuth 2.0 | Provider app configuration; no Genspark scope picker | Search and manage deals, contacts, organizations, and activities. |
| Mailchimp | API Call | OAuth 2.0 | Provider app and account permissions; no Genspark scope picker | Review audiences, campaigns, subscribers, and campaign results. |
| Affinity CRM | MCP | API Key sent as a Bearer token | Provider configuration; no OAuth scope picker | Explore relationship intelligence and CRM data through Affinity's tools. |
Developer
| Service | Connection type | Authentication | Scope options | What you can do |
|---|---|---|---|---|
| GitHub | API Call | OAuth App authorization | Fixed request; read-only policy narrows only some scopes | Search repositories and issues, and work with repository content. The repository grant still includes write access. |
| Jira | API Call | Atlassian OAuth 2.0 | Fixed request shared with Confluence; read-only policy | Search, create, and update Jira work items. |
| Linear | MCP | OAuth 2.1 with PKCE | Provider authorization; no Genspark scope picker | Find, create, and update issues, projects, and comments. |
Data
| Service | Connection type | Authentication | Scope options | What you can do |
|---|---|---|---|---|
| Airtable | MCP | OAuth 2.1 with PKCE | Provider authorization; no Genspark scope picker | Query and update records, fields, and views in authorized bases. |
HR & Recruiting
| Service | Connection type | Authentication | Scope options | What you can do |
|---|---|---|---|---|
| Greenhouse | MCP | OAuth 2.1 with PKCE | Provider-defined scope and administrator configuration | Search jobs, candidates, applications, and interview stages. Your administrator may need to enable MCP access. |
| Ashby | MCP | OAuth 2.1 with PKCE | Connecting user's provider permissions | Review candidates, jobs, applications, interviews, and feedback. Your administrator may need to enable MCP access. |
Operations & Finance
| Service | Connection type | Authentication | Scope options | What you can do |
|---|---|---|---|---|
| Stripe | MCP | OAuth 2.1 with PKCE | Provider authorization; no Genspark scope picker | Work with payment data, subscriptions, products, and customers, subject to the authorized tools and permissions. |
| PayPal | MCP | OAuth 2.1 with PKCE | Provider authorization; no Genspark scope picker | Work with invoices, orders, payments, and transactions, subject to the authorized tools and permissions. |
| Ramp | MCP | OAuth 2.1 with PKCE | Dedicated read-only scope restriction | Read spend, card, transaction, bill, and reimbursement data. Money-movement write permissions are excluded. |
| Zapier | MCP | Dedicated MCP server URL containing credentials | Configure enabled tools and app connections in Zapier | Run the actions enabled on your Zapier MCP server. Treat the connection URL as a secret. |
Community
Custom and community MCP servers are governed separately by your organization's custom MCP policy. Their tools, authentication, and resource access depend on the server operator. They are not additional standard catalog entries in the reference above. Check with your administrator before relying on a server for an enterprise workflow.
Early Access and Customer Pilots
The following connections require allowlist access or a customer pilot. They are not enabled for every production account. Once enabled, organization policies and provider requirements still apply.
| Service | Connection type | Authentication | Scope options | What you can do |
|---|---|---|---|---|
| Salesforce Sandbox | API Call | OAuth 2.0 | Fixed request; provider roles and object permissions | Test CRM workflows in a Salesforce sandbox. This authorization is separate from the production Salesforce connection. |
| Daloopa Financial Data | MCP | Provider-managed sign-in; confirm the flow during onboarding | Confirm provider permissions during the pilot | Retrieve company fundamentals, metrics, and financial statements after provider sign-in and connection validation. |
| Intercom | MCP | OAuth 2.1 with PKCE | Provider authorization; no Genspark scope picker | Find support conversations and contacts, and summarize customer feedback. |
| Amplitude | MCP | OAuth 2.1 with PKCE | Provider authorization; no Genspark scope picker | Explore funnels, retention, events, and user segments. |
| Snowflake | MCP | Programmatic Access Token (PAT) | Configure Snowflake roles and object grants | Query or search data through your Snowflake-managed MCP server. Supply the account, database, schema, MCP server, and PAT. The current connection uses PAT authentication. |
| SimilarWeb | MCP | API Key | Provider account and key permissions | Explore website traffic, keywords, and audience data available to your provider account. |
| HubSpot MCP | MCP | OAuth 2.1 with PKCE | Provider authorization; no Genspark scope picker | Use HubSpot's hosted CRM tools. Install separately from the standard native Private App Token connection. |
Permissions and Access
What can I choose during authorization?
Most OAuth connections request a predefined permission set. You can choose the provider account and, for Google and Microsoft, connect individual services instead of using a bundle.
Native Notion lets you authorize pages. For customer-managed tokens such as HubSpot's Private App Token, configure the needed permissions with the provider before entering the token in Genspark.
MCP OAuth permissions usually follow the server's authorization metadata and consent screen. Genspark does not offer individual scope checkboxes for these connections. A provider's account roles, resource sharing, and available tools can further limit access.
Important permission boundaries
- Google Suite: the bundle requests Gmail, Calendar, and Drive access. Google Chat is a separate connection. Gmail also requests contact-reading permission and, in read/write mode, Gmail settings permission.
- Google Drive:
drive.readonlypermits broader reading, whiledrive.filepermits writing files created by the app or authorized by you. Selecting files for write access does not restrict all read access to those files. - Microsoft 365: connections use the signed-in user's delegated permissions. They do not grant an administrator role. OneDrive and SharePoint request the same file permission set; this flow does not offer site-by-site scope selection.
- Notion: the native integration's authorized-page boundary and Notion MCP's user-based access are different. Review the option you connect.
- Jira and Confluence: both use the same Atlassian authorization and request permissions for both services.
- GitHub: the
reposcope includes repository write access even when the organization read-only policy narrows other scopes. - Ramp: requests are limited to the intersection of 21 allowed read-only scopes and the server's declared scopes. The connection excludes money-movement writes, bank account number access, and spendable card credentials.
Organization controls and read-only access
Enterprise administrators can allow a connector for all members, restrict it to selected teams, or disable it. These settings control who can use a connection. Provider permissions control which data and operations that connection can access.
If the read-only management feature is enabled for your organization, supported OAuth connections can request narrower permissions. Google, Microsoft, Slack, Atlassian, Box, and X support this; GitHub supports only partial narrowing. Native Notion, Salesforce, Pipedrive, Mailchimp, and supplied tokens do not automatically become provider-issued read-only credentials.
Read-only restrictions on Genspark tools and the permissions held by a provider token are separate controls. Turning on the policy does not automatically remove all permissions from previously issued tokens. Your administrator may need to arrange reauthorization, change provider permissions, or rotate credentials. Direct access through a credential-bearing CLI or sandbox requires separate assessment.
MCP connections do not have a blanket read-only guarantee. Check provider scopes, account roles, resource access, and server tools. For Zapier, also review the underlying connected apps. Ramp's dedicated scope restriction applies separately.
Managing Connections
Multiple email accounts
Gmail and Outlook Email support multiple connected accounts. Open the connector's details to view the account list, add another account, or disconnect an account using its own row.
The list identifies the default account and can show when reauthorization is needed. Other connectors do not necessarily offer the same account-list controls. If you have several mailboxes connected, specify the intended account in your request.
Disconnect an account or a service
- One Gmail or Outlook account: use that account's row to remove its mailbox connection and account-based calendar/contact access. Other mailbox accounts remain connected.
- Whole Google or Microsoft connection: the whole-connector disconnect action affects related services that share the authorization, and removes bound mailboxes from AI Inbox/GenMail. Review the affected services before confirming. Microsoft's whole-connection flow also attempts provider session revocation; if successful, other Microsoft apps may require sign-in again.
- Jira or Confluence: disconnecting either disconnects both because they share an authorization.
- MCP: disconnecting removes the MCP registration from Genspark. Provider authorization or customer-created credentials may need to be revoked separately.
Removing one Outlook account does not revoke Microsoft sessions. Removing one Gmail account attempts provider revocation only when other related connectors no longer reference that identity.
For complete offboarding, review the provider's connected-app settings and revoke or rotate customer-created tokens as needed. Disconnecting does not delete the provider account itself.
Troubleshooting
Why can't I find a connector I expected to see?
The connector may be in early access or restricted by your organization's settings. Administrators can limit which connectors are available to members or teams.
An already connected service may remain visible as blocked so you can disconnect it. A service appearing in a pilot list does not mean your account has been enabled.
Why is the connector connected but a file or action unavailable?
Connected means the connection was established; it does not guarantee access to every resource or operation.
Check the selected account, the provider's resource-sharing settings, and the required read or write permissions. For MCP, also check that the server exposes a suitable tool. Ask your administrator to review any organization restriction before reconnecting with different permissions.
Why am I being asked to reconnect?
A provider grant may expire, be revoked, or no longer include the required permissions. Reconnect the intended account when prompted.
Customer-managed keys and manually supplied tokens may need replacement; LinkedIn Lite does not currently refresh its supplied OAuth token automatically.
What should I gather before contacting support?
- The connector name and category, and whether you selected API Call or MCP.
- The exact error message, the step that failed, and the time and time zone.
- Whether you used OAuth, an API Key, a token, or a dedicated MCP URL.
- Your Genspark plan tier and any organization restriction shown.
- The relevant provider workspace or tenant, if needed to identify the connection.
Remove access tokens, API Keys, and credential-bearing URLs from screenshots and logs before sharing them with support.
FAQ
Why do I see more than one HubSpot card in the Connectors panel?
The standard native HubSpot connection uses a Private App Token that you create in HubSpot with the required CRM object permissions.
HubSpot MCP is a separate OAuth connection that requires allowlist access. Choose the connection available to your organization and approved by your administrator.
Do I need a paid subscription for any connector?
Requirements vary by provider. Some services need an eligible plan, API or MCP access enabled, or administrator consent. Greenhouse and Ashby may require an administrator to enable MCP access.
Check the provider's current requirements during setup; a visible Genspark card does not establish that your provider account is eligible.
Can LINE read my personal conversations?
The listed connection is LINE Send Message. It links your identity and lets the official bot send messages to your linked account. It does not grant access to your personal chat history.
Is every MCP connection read-only?
No. Operations depend on provider scopes, roles, and exposed tools. Ramp has a dedicated read-only scope restriction.
For other services, check the actual authorization and server configuration, including connected downstream apps for Zapier.
Was this article helpful?