# Unified.to Documentation > Unified.to provides a single API to integrate multiple B2B SaaS platforms. One API to rule CRM, ATS, HRIS, Accounting, Commerce, Messaging, Storage, Ticketing, and 37 categories in total. For the complete documentation in a single file, see: https://docs.unified.to/llms-full.txt ## Build with a coding agent - [Agent Quick Start Skill](https://docs.unified.to/skills/unified-quickstart/SKILL.md): read this first to add Unified.to integrations to an app; the per-category skills are listed under Agent Skills below - [Install the skills and Core MCP server](https://docs.unified.to/skills/install.md): Claude Code plugin (`/plugin marketplace add https://docs.unified.to/.claude-plugin/marketplace.json`), `npx skills add https://docs.unified.to` for other agents, and MCP configs for Codex, Cursor, and VS Code - [Core MCP server](https://docs.unified.to/mcp/core.md): lets a coding agent search these docs, check integration support, manage connections and webhooks, and read API-call logs ## Getting Started - [Unified.to Documentation](https://docs.unified.to/index.md) - [Get started with Unified.to](https://docs.unified.to/quick-start.md) ## Concepts - [Unified.to Architecture](https://docs.unified.to/concepts/architecture.md) - [Integration Authorization](https://docs.unified.to/concepts/embedded-components.md) - [Sandbox / Synthetic Data environment](https://docs.unified.to/concepts/sandbox.md) - [sandboxes](https://docs.unified.to/concepts/sandboxes.md) - [Understanding scopes](https://docs.unified.to/concepts/scopes.md) - [Virtual Webhooks](https://docs.unified.to/concepts/virtual_webhooks.md) - [What is a Unified API?](https://docs.unified.to/concepts/what-is-a-unified-api.md) ## Guides - [Advertising Report Metrics by Integration](https://docs.unified.to/guides/advertising_report_metrics_by_integration.md) - [ATS to Vector DB: How to Power Talent Intelligence with Real-Time Data](https://docs.unified.to/guides/ats_to_vector_db_how_to_power_talent_intelligence_with_real_time_data.md) - [Building AI applications with Unified and Langbase](https://docs.unified.to/guides/building_ai_applications_with_unified_and_langbase.md) - [Concur & Concur (Company) — Connection Guide](https://docs.unified.to/guides/concur_and_concur_company_connection_guide.md) - [Configure Greenhouse Native Candidate Webhooks](https://docs.unified.to/guides/configure_greenhouse_native_candidate_webhooks.md) - [Connect Amazon Seller Central to Unified.to](https://docs.unified.to/guides/connect_amazon_seller_central_to_unified.md) - [Connecting BambooHR via OAuth 2](https://docs.unified.to/guides/connecting_bamboohr_via_oauth_2.md) - [Connecting Google Workspace Integrations with a Service Account](https://docs.unified.to/guides/connecting_google_workspace_integrations_with_a_service_account.md) - [Correct WelcomeKit Scopes for Jungle Integration](https://docs.unified.to/guides/correct_welcomekit_scopes_for_jungle_integration.md) - [Creating Ads using the Unified Ads API](https://docs.unified.to/guides/creating_ads_using_the_unified_ads_api.md) - [Creating Walmart Items via Unified](https://docs.unified.to/guides/creating_walmart_items_via_unified.md) - [End-Users, Integrations, and Connections](https://docs.unified.to/guides/end_users_integrations_and_connections.md) - [Enriching Unified Objects with Custom Metadata](https://docs.unified.to/guides/enriching_unified_objects_with_custom_metadata.md) - [Enterprise-managed authorization (EMA) with a static key](https://docs.unified.to/guides/enterprise_managed_authorization_ema_with_a_static_key.md) - [Enterprise-managed authorization (EMA) with a workspace secret](https://docs.unified.to/guides/enterprise_managed_authorization_ema_with_a_workspace_secret.md) - [Enterprise-managed authorization (EMA) with Microsoft Entra ID](https://docs.unified.to/guides/enterprise_managed_authorization_ema_with_microsoft_entra_id.md) - [Extended observability — pushing API logs to ClickHouse](https://docs.unified.to/guides/extended_observability_pushing_api_logs_to_clickhouse.md) - [Extended observability — pushing API logs to Grafana / Loki](https://docs.unified.to/guides/extended_observability_pushing_api_logs_to_grafana_loki.md) - [Extended Observability - Pushing API Logs to your Datadog Instance](https://docs.unified.to/guides/extended_observability_pushing_api_logs_to_your_datadog_instance.md) - [Facebook Messenger Webhook Setup](https://docs.unified.to/guides/facebook_messenger_webhook_setup.md) - [Fireflies Integration Guide](https://docs.unified.to/guides/fireflies_integration_guide.md) - [Getting started with Workable](https://docs.unified.to/guides/getting_started_with_workable.md) - [Handling Delegated vs. Application Scopes in Microsoft Integrations](https://docs.unified.to/guides/handling_delegated_vs_application_scopes_in_microsoft_integrations.md) - [HiBob & Unified: connection and time off guide](https://docs.unified.to/guides/hibob_and_unified_connection_and_time_off_guide.md) - [How long are logs retained](https://docs.unified.to/guides/how_long_are_logs_retained.md) - [How to access employees and users](https://docs.unified.to/guides/how_to_access_employees_and_users.md) - [How to add API support for the Create Activity in Crelate](https://docs.unified.to/guides/how_to_add_api_support_for_the_create_activity_in_crelate.md) - [How to Associate a Connection ID with Your End-User](https://docs.unified.to/guides/how_to_associate_a_connection_id_with_your_end_user.md) - [How to build a Candidate Assessment product with Unified.to](https://docs.unified.to/guides/how_to_build_a_candidate_assessment_product_with_unified.md) - [How to build a candidate sourcing or job board app with Unified.to](https://docs.unified.to/guides/how_to_build_a_candidate_sourcing_or_job_board_app_with_unified.md) - [How to build a Discord support bot with Unified.to and Langbase](https://docs.unified.to/guides/how_to_build_a_discord_support_bot_with_unified_and_langbase.md) - [How to Build a Fintech Application with Unified's Payments API](https://docs.unified.to/guides/how_to_build_a_fintech_application_with_unified_payments_api.md) - [How to Build an E-Commerce Product Integration with Unified](https://docs.unified.to/guides/how_to_build_an_e_commerce_product_integration_with_unified.md) - [How to build an invoicing system with Unified.to](https://docs.unified.to/guides/how_to_build_an_invoicing_system_with_unified.md) - [How to build Enterprise Search using RAG](https://docs.unified.to/guides/how_to_build_enterprise_search_using_rag.md) - [How to configure Bullhorn Redirect URI for creating a connection](https://docs.unified.to/guides/how_to_configure_bullhorn_redirect_uri_for_creating_a_connection.md) - [How to configure webhooks in HubSpot](https://docs.unified.to/guides/how_to_configure_webhooks_in_hubspot.md) - [How to configure webhooks in Thrive Learning](https://docs.unified.to/guides/how_to_configure_webhooks_in_thrive_learning.md) - [How to configure webhooks in Toast for Unified](https://docs.unified.to/guides/how_to_configure_webhooks_in_toast_for_unified.md) - [How to Connect Anthropic to Real-Time SaaS Data with Unified.to MCP Server](https://docs.unified.to/guides/how_to_connect_anthropic_to_real_time_saas_data_with_unified_mcp_server.md) - [How to Connect Cohere to Real-Time SaaS Data with Unified.to MCP Server](https://docs.unified.to/guides/how_to_connect_cohere_to_real_time_saas_data_with_unified_mcp_server.md) - [How to Connect Google Gemini to Real-Time SaaS Data with Unified.to MCP Server](https://docs.unified.to/guides/how_to_connect_google_gemini_to_real_time_saas_data_with_unified_mcp_server.md) - [How to Connect LLMs to Real-Time SaaS Data with Unified.to MCP Server](https://docs.unified.to/guides/how_to_connect_llms_to_real_time_saas_data_with_unified_mcp_server.md) - [How to Connect OpenAI to Real-Time SaaS Data with Unified.to MCP Server](https://docs.unified.to/guides/how_to_connect_openai_to_real_time_saas_data_with_unified_mcp_server.md) - [How to Connect Zoom and Zoom Phone](https://docs.unified.to/guides/how_to_connect_zoom_and_zoom_phone.md) - [How to create a Connection In Microsoft Teams](https://docs.unified.to/guides/how_to_create_a_connection_in_microsoft_teams.md) - [How to create a token-based connection in Highlevel](https://docs.unified.to/guides/how_to_create_a_token_based_connection_in_highlevel.md) - [How to Create a Unified.to Connection to HighLevel](https://docs.unified.to/guides/how_to_create_a_unified_connection_to_highlevel.md) - [How to Create a Xero Connection in Unified.to](https://docs.unified.to/guides/how_to_create_a_xero_connection_in_unified.md) - [How to create and configure webhooks](https://docs.unified.to/guides/how_to_create_and_configure_webhooks.md) - [How to create Connection with Hubspot](https://docs.unified.to/guides/how_to_create_connection_with_hubspot.md) - [How to customize portal URLs for Stripe and GoCardless](https://docs.unified.to/guides/how_to_customize_portal_urls_for_stripe_and_gocardless.md) - [How to filter webhook events](https://docs.unified.to/guides/how_to_filter_webhook_events.md) - [How-to Get a Private Support Channel for Your Unified Integration](https://docs.unified.to/guides/how_to_get_a_private_support_channel_for_your_unified_integration.md) - [How to get your 8x8 Connect API Key and Account ID: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_8x8_connect_api_key_and_account_id_step_by_step_guide.md) - [How to get your ADP Workforce Now Oauth2 client ID, Oauth2 client secret, Oauth2 PEM certificate and Oauth2 private key: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_adp_workforce_now_oauth2_client_id_oauth2_client_secret_oauth2_pem_certificate_and_oauth2_private_key_step_by_step_guide.md) - [How to get your Amazon S3 AWS Region, AWS S3 Key and AWS S3 Secret: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_amazon_s3_aws_region_aws_s3_key_and_aws_s3_secret_step_by_step_guide.md) - [How to get your Ashby API Key: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_ashby_api_key_step_by_step_guide.md) - [How to get your Brex API token: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_brex_api_token_step_by_step_guide.md) - [How to get your Bullhorn OAuth2 Client ID, OAuth2 Client Secret, API Username and API Password: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_bullhorn_oauth2_client_id_oauth2_client_secret_api_username_and_api_password_step_by_step_guide.md) - [How to get your Ceridian Dayforce Username, Password and Client Namespace: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_ceridian_dayforce_username_password_and_client_namespace_step_by_step_guide.md) - [How to get your Crelate API key: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_crelate_api_key_step_by_step_guide.md) - [How to get your Dashlane API Key: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_dashlane_api_key_step_by_step_guide.md) - [How to get your Deel Access Token: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_deel_access_token_step_by_step_guide.md) - [How to get your Dialpad API Key: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_dialpad_api_key_step_by_step_guide.md) - [How to get your Discord OAuth 2 credentials and bot token](https://docs.unified.to/guides/how_to_get_your_discord_oauth_2_credentials_and_bot_token.md) - [How to get your ELMO client ID and client secret: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_elmo_client_id_and_client_secret_step_by_step_guide.md) - [How to get your Gainsight Client ID, Client Secret and Gainsight API Domain: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_gainsight_client_id_client_secret_and_gainsight_api_domain_step_by_step_guide.md) - [How to get your Greenhouse API Key and Job board token: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_greenhouse_api_key_and_job_board_token_step_by_step_guide.md) - [How to get your Helpscout API Key: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_helpscout_api_key_step_by_step_guide.md) - [How to get your HiBob Service User ID and Service User Token: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_hibob_service_user_id_and_service_user_token_step_by_step_guide.md) - [How to get your HighLevel API Key and Location ID: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_highlevel_api_key_and_location_id_step_by_step_guide.md) - [How to get your HubSpot developer key and OAuth 2 credentials (Legacy Apps)](https://docs.unified.to/guides/how_to_get_your_hubspot_developer_key_and_oauth_2_credentials_legacy_apps.md) - [How to get your Humaans API Key: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_humaans_api_key_step_by_step_guide.md) - [How to get your iCIMS API Username, API Password and Customer ID: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_icims_api_username_api_password_and_customer_id_step_by_step_guide.md) - [How to get your JobDiva Client ID, Username/email and Password: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_jobdiva_client_id_username_email_and_password_step_by_step_guide.md) - [How to get your Jobvite API Key, API Key Secret and Email: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_jobvite_api_key_api_key_secret_and_email_step_by_step_guide.md) - [How to get your Lever API Key: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_lever_api_key_step_by_step_guide.md) - [How to get your Loxo Agency slug, API Key and Agency ID: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_loxo_agency_slug_api_key_and_agency_id_step_by_step_guide.md) - [How to get your Microsoft Active Directory / Entra ID Client ID, Client Secret and Tenant ID: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_microsoft_active_directory_entra_id_client_id_client_secret_and_tenant_id_step_by_step_guide.md) - [How to get your Microsoft Azure AD OAuth 2 credentials](https://docs.unified.to/guides/how_to_get_your_microsoft_azure_ad_oauth_2_credentials.md) - [How to get your OAuth 2 credentials for Gmail](https://docs.unified.to/guides/how_to_get_your_oauth_2_credentials_for_gmail.md) - [How to get your OAuth 2 credentials for Microsoft Dynamics 365](https://docs.unified.to/guides/how_to_get_your_oauth_2_credentials_for_microsoft_dynamics_365.md) - [How to get your OAuth 2 credentials in PipeDrive](https://docs.unified.to/guides/how_to_get_your_oauth_2_credentials_in_pipedrive.md) - [How to get your OpenAI API Key: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_openai_api_key_step_by_step_guide.md) - [How to get your Paycom SID/Username and Token/Password: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_paycom_sid_username_and_token_password_step_by_step_guide.md) - [How to get your PCRecruiter Username, Password, Database ID, App Key and App ID: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_pcrecruiter_username_password_database_id_app_key_and_app_id_step_by_step_guide.md) - [How to get your SAP SuccessFactors (OpenID Connect) Username, Password, Client ID, Client Secret, Dependency Name, IAS Host and API URL: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_sap_successfactors_openid_connect_username_password_client_id_client_secret_dependency_name_ias_host_and_api_url_step_by_step_guide.md) - [How to get your SAP SuccessFactors Username, Company ID, Password and API URL: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_sap_successfactors_username_company_id_password_and_api_url_step_by_step_guide.md) - [How to get your Shopify Admin API access token and Store ID: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_shopify_admin_api_access_token_and_store_id_step_by_step_guide.md) - [How to get your Wayfair Client ID, Client Secret and Vendor Encrypted Key: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_wayfair_client_id_client_secret_and_vendor_encrypted_key_step_by_step_guide.md) - [How to get your Workable API Token and Subdomain: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_workable_api_token_and_subdomain_step_by_step_guide.md) - [How to get your yotpo APP Key / Store ID and Secret Key: Step-by-step guide](https://docs.unified.to/guides/how_to_get_your_yotpo_app_key_store_id_and_secret_key_step_by_step_guide.md) - [How to Handle Attachments in Invoice, Bill and Credit Memo](https://docs.unified.to/guides/how_to_handle_attachments_in_invoice_bill_and_credit_memo.md) - [How to migrate or import your integrations into Unified.to](https://docs.unified.to/guides/how_to_migrate_or_import_your_integrations_into_unified.md) - [How to obtain your GitHub OAuth2 credentials](https://docs.unified.to/guides/how_to_obtain_your_github_oauth2_credentials.md) - [How to Power Claude with Live Customer Data Using Unified MCP](https://docs.unified.to/guides/how_to_power_claude_with_live_customer_data_using_unified_mcp.md) - [How to register a Google developer app and get OAuth 2 credentials](https://docs.unified.to/guides/how_to_register_a_google_developer_app_and_get_oauth_2_credentials.md) - [How to register a Salesforce developer app and get OAuth 2 credentials](https://docs.unified.to/guides/how_to_register_a_salesforce_developer_app_and_get_oauth_2_credentials.md) - [How to register a Slack developer account and get OAuth 2 credentials](https://docs.unified.to/guides/how_to_register_a_slack_developer_account_and_get_oauth_2_credentials.md) - [How to Register a Workday Developer App and Get OAUTH2 Credentials](https://docs.unified.to/guides/how_to_register_a_workday_developer_app_and_get_oauth2_credentials.md) - [How to Register a Workday Developer App and Get OAUTH2/ SOAP Credentials](https://docs.unified.to/guides/how_to_register_a_workday_developer_app_and_get_oauth2_soap_credentials.md) - [How to Register a ZendeskSell Developer App and Get OAUTH2 Credentials](https://docs.unified.to/guides/how_to_register_a_zendesksell_developer_app_and_get_oauth2_credentials.md) - [How to Register a Zoho Developer App and Get OAUTH2 Credentials](https://docs.unified.to/guides/how_to_register_a_zoho_developer_app_and_get_oauth2_credentials.md) - [How to Register an ADP Developer App and Get OAUTH2 Credentials](https://docs.unified.to/guides/how_to_register_an_adp_developer_app_and_get_oauth2_credentials.md) - [How to Register an Atlassian Developer App and Get OAUTH2 Credentials](https://docs.unified.to/guides/how_to_register_an_atlassian_developer_app_and_get_oauth2_credentials.md) - [How to Register your Facebook OAuth2 Application](https://docs.unified.to/guides/how_to_register_your_facebook_oauth2_application.md) - [How to Register your Google Ads OAuth2 Application](https://docs.unified.to/guides/how_to_register_your_google_ads_oauth2_application.md) - [How to Register your MetaAds OAuth2 application](https://docs.unified.to/guides/how_to_register_your_metaads_oauth2_application.md) - [How To Request & Write Raw Integration Data](https://docs.unified.to/guides/how_to_request_and_write_raw_integration_data.md) - [How to Retrieve Microsoft Dynamics 365 Business Central Credentials](https://docs.unified.to/guides/how_to_retrieve_microsoft_dynamics_365_business_central_credentials.md) - [How to set up a custom API URL with a CNAME](https://docs.unified.to/guides/how_to_set_up_a_custom_api_url_with_a_cname.md) - [How to Set Up a Microsoft Teams Bot with Unified](https://docs.unified.to/guides/how_to_set_up_a_microsoft_teams_bot_with_unified.md) - [How to set up and configure Notion](https://docs.unified.to/guides/how_to_set_up_and_configure_notion.md) - [How to set up Google Business Profile API access and get OAuth 2 credentials](https://docs.unified.to/guides/how_to_set_up_google_business_profile_api_access_and_get_oauth_2_credentials.md) - [How to Set Up LinkedIn Webhooks with Unified](https://docs.unified.to/guides/how_to_set_up_linkedin_webhooks_with_unified.md) - [How to set up native webhooks for QuickBooks Online with Unified](https://docs.unified.to/guides/how_to_set_up_native_webhooks_for_quickbooks_online_with_unified.md) - [How to set up Slack webhooks using event subscriptions](https://docs.unified.to/guides/how_to_set_up_slack_webhooks_using_event_subscriptions.md) - [How to set up Telegram (bot) with Unified.to](https://docs.unified.to/guides/how_to_set_up_telegram_bot_with_unified.md) - [How to set up your scopes in HubSpot](https://docs.unified.to/guides/how_to_set_up_your_scopes_in_hubspot.md) - [How to setup a Freshbooks developer app](https://docs.unified.to/guides/how_to_setup_a_freshbooks_developer_app.md) - [How to setup a TikTok Shop application](https://docs.unified.to/guides/how_to_setup_a_tiktok_shop_application.md) - [How to Setup AWS Assume Role for AWS Secret Manager](https://docs.unified.to/guides/how_to_setup_aws_assume_role_for_aws_secret_manager.md) - [How to setup Oracle JD Edwards](https://docs.unified.to/guides/how_to_setup_oracle_jd_edwards.md) - [How to Setup Quickbooks Desktop](https://docs.unified.to/guides/how_to_setup_quickbooks_desktop.md) - [How to setup Sage 100 with Unified.to](https://docs.unified.to/guides/how_to_setup_sage_100_with_unified.md) - [How to troubleshoot unhealthy connections](https://docs.unified.to/guides/how_to_troubleshoot_unhealthy_connections.md) - [How to troubleshoot unhealthy webhooks](https://docs.unified.to/guides/how_to_troubleshoot_unhealthy_webhooks.md) - [How to use SCIM with the Unified API](https://docs.unified.to/guides/how_to_use_scim_with_the_unified_api.md) - [How to use the Passthrough API](https://docs.unified.to/guides/how_to_use_the_passthrough_api.md) - [How to Use Unified.to's Generative AI API with OpenAI and Claude](https://docs.unified.to/guides/how_to_use_unified_generative_ai_api_with_openai_and_claude.md) - [How to use User Provisioning and Verification with Unified](https://docs.unified.to/guides/how_to_use_user_provisioning_and_verification_with_unified.md) - [How virtual webhook retry and recovery works](https://docs.unified.to/guides/how_virtual_webhook_retry_and_recovery_works.md) - [Integration set-up guide for Lever](https://docs.unified.to/guides/integration_set_up_guide_for_lever.md) - [Managing custom validation rules in Salesforce](https://docs.unified.to/guides/managing_custom_validation_rules_in_salesforce.md) - [Multi-Region Sync](https://docs.unified.to/guides/multi_region_sync.md) - [NetSuite Authentication Setup for Unified](https://docs.unified.to/guides/netsuite_authentication_setup_for_unified.md) - [Notice of Deprecation of Fields and Objects (Nov 2025)](https://docs.unified.to/guides/notice_of_deprecation_of_fields_and_objects_nov_2025.md) - [Oracle HCM / Taleo OAuth Credentials Guide](https://docs.unified.to/guides/oracle_hcm_taleo_oauth_credentials_guide.md) - [Retrieval-Augmented Generation (RAG)](https://docs.unified.to/guides/retrieval_augmented_generation_rag.md) - [SalesForce (External Client Apps) on Multiple Organizations](https://docs.unified.to/guides/salesforce_external_client_apps_on_multiple_organizations.md) - [SAML Single-Sign-On](https://docs.unified.to/guides/saml_single_sign_on.md) - [Scaling MCP Tools with Anthropic's (& OpenAI's) Defer Loading](https://docs.unified.to/guides/scaling_mcp_tools_with_anthropic_and_openai_defer_loading.md) - [Set Environments for your Unified.to Workspace](https://docs.unified.to/guides/set_environments_for_your_unified_workspace.md) - [Setting up a Slack Bot Connection with Unified.to](https://docs.unified.to/guides/setting_up_a_slack_bot_connection_with_unified.md) - [Setting up OAuth 2 Credentials for Greenhouse's APIs](https://docs.unified.to/guides/setting_up_oauth_2_credentials_for_greenhouse_apis.md) - [Trello Connection Guide in Unified](https://docs.unified.to/guides/trello_connection_guide_in_unified.md) - [Understanding OAuth2 Authorization flows](https://docs.unified.to/guides/understanding_oauth2_authorization_flows.md) - [Understanding Response Time Headers in the Unified API](https://docs.unified.to/guides/understanding_response_time_headers_in_the_unified_api.md) - [Unified Assessment API: Embed Assessments Inside ATS Platforms](https://docs.unified.to/guides/unified_assessment_api_embed_assessments_inside_ats_platforms.md) - [Unified's MCP Server](https://docs.unified.to/guides/unified_mcp_server.md) - [Unified MCP Server with LangChain and LangGraph](https://docs.unified.to/guides/unified_mcp_server_with_langchain_and_langgraph.md) - [Unlock real-time data with virtual webhooks](https://docs.unified.to/guides/unlock_real_time_data_with_virtual_webhooks.md) - [Use Unified to sign in your users into your application](https://docs.unified.to/guides/use_unified_to_sign_in_your_users_into_your_application.md) - [Workable: Creating candidates and attaching them to jobs](https://docs.unified.to/guides/workable_creating_candidates_and_attaching_them_to_jobs.md) - [Workday vs Workday Legacy — Why Unified.to Supports Both](https://docs.unified.to/guides/workday_vs_workday_legacy_why_unified_supports_both.md) - [Working with hierarchical tree data in Storage, Messaging, and KMS APIs](https://docs.unified.to/guides/working_with_hierarchical_tree_data_in_storage_messaging_and_kms_apis.md) ## Agent Skills - [apollo-oauth-app](https://docs.unified.to/skills/apollo-oauth-app/SKILL.md): Establishes which Apollo.io credential a connector actually needs and obtains it — the OAuth 2.0 client registered in-product and approved by Apollo (the model Apollo intends for platforms acting on behalf of other organizations), or per-customer API keys with their master-vs-scoped split — with the four-redirect-URL cap, the locked-in scope set, the hash-routed authorize URL, the plan and credit gates, rate limits and a safe credential handoff. Use when asked to get Apollo OAuth credentials, register an Apollo app, create or rotate an Apollo API key, write an Apollo admin runbook for customers, or fix an Apollo auth error like a 403 on one endpoint, "Missing required parameter: client_id", a 401 after 30 days, a refresh that works once, or credits draining on a sync. For any other vendor's developer portal, use that vendor's skill instead. - [asana-oauth-app](https://docs.unified.to/skills/asana-oauth-app/SKILL.md): Creates or signs in to an Asana account and registers an app in the Asana developer console to obtain OAuth2 client ID and client secret — with redirect URLs, the granular-scopes-vs-Full-permissions decision, workspace distribution settings, token behaviour and a safe credential handoff. Use when asked to get Asana OAuth credentials, create an Asana app, pick Asana OAuth scopes, rotate an Asana client secret, request an Asana developer sandbox, or fix an Asana authorization error like `forbidden_scopes`, `invalid_scope`, or "This app is not available to your Asana workspace or organization". For any other vendor's developer portal, use that vendor's skill instead. - [atlassian-cloud-oauth](https://docs.unified.to/skills/atlassian-cloud-oauth/SKILL.md): The shared Atlassian Developer Console / OAuth 2.0 (3LO) mechanics behind every Atlassian Cloud product registration — creating the app and enabling 3LO, the single callback URL per app, account-level vs resource-level grants, the classic and granular scope families, `offline_access`, rotating refresh tokens, the cloudid indirection and `/ex/{product}/{cloudid}/...` addressing, scope changes forcing re-consent, distribution and Marketplace approval. Read this first when registering any Atlassian Cloud OAuth app; the product skills (Atlassian Jira, Atlassian Confluence) build on it and cover only what their product adds. Use directly when the task is a plain Atlassian 3LO app with no particular product named. Covers Atlassian **Cloud** only — Data Center / Server uses a different auth model entirely. - [atlassian-confluence-oauth-app](https://docs.unified.to/skills/atlassian-confluence-oauth-app/SKILL.md): The Confluence Cloud layer on top of the shared `atlassian-cloud-oauth` skill — the Confluence scope family and why a v2-era app ends up granular rather than classic, the v1/v2 REST split and what still only exists in v1, space/page/blogpost/attachment/comment addressing through `/ex/confluence/{cloudid}`, the space- and page-level permission model that makes a valid token see an empty wiki, data security policy app access rules, and Confluence's rate-limit budget. Use when asked to get Confluence OAuth credentials, register or scope a Confluence Cloud 3LO app, choose between `read:confluence-content.all` and `read:page:confluence`, or explain why a connected Confluence returns no pages. Read `atlassian-cloud-oauth` first for the console, callback, cloudid and refresh-token mechanics; use the Atlassian Jira skill for Jira, and note that Confluence Data Center is a different auth model entirely. - [atlassian-jira-oauth-app](https://docs.unified.to/skills/atlassian-jira-oauth-app/SKILL.md): The Jira Cloud layer on top of the shared `atlassian-cloud-oauth` skill — the Jira classic scope set and its granular counterparts, the split between the Jira platform, Jira Software, Jira Service Management, Confluence and Assets APIs, `/ex/jira/{cloudid}/rest/api/3/...` addressing, and the 3LO limitations that are Jira's alone. Use when asked to get Jira OAuth credentials, create a Jira Cloud app or 3LO integration, scope a Jira connector, or fix a Jira OAuth error like a 401 on `/ex/jira/...` or a scope mismatch on an endpoint you are entitled to call. Read `atlassian-cloud-oauth` first for the developer console, the single callback URL, the cloudid indirection and rotating refresh tokens. Covers Jira Cloud only — Jira Data Center/Server uses a different auth model entirely, and Confluence and Jira Service Management are separate scope families. - [attio-oauth-app](https://docs.unified.to/skills/attio-oauth-app/SKILL.md): Creates or signs in to an Attio account and registers an app in the Attio Developer console (build.attio.com) to obtain an OAuth2 client ID and client secret — with redirect URIs, the app-configured scope catalogue, the object/attribute data model, non-expiring tokens with no refresh token, workspace-level admin-only installs, API-created webhooks, and a safe credential handoff. Use when asked to get Attio OAuth credentials, create an Attio app or developer account, pick Attio scopes, rotate an Attio client secret, publish an Attio app to the App Store, or debug an Attio connection that authorizes fine but 403s on reads, cannot see custom attributes, or cannot register webhooks. For any other vendor's developer portal, use that vendor's skill instead. - [bamboohr-oauth-app](https://docs.unified.to/skills/bamboohr-oauth-app/SKILL.md): Obtains BambooHR API credentials — either an OAuth2 client ID and secret registered in the BambooHR Developer Portal (self-registration has been open since April 2025), or the per-customer API key plus company subdomain that most BambooHR integrations still run on. Covers redirect URIs, the 220-scope catalog, the permission inheritance that silently returns partial data, rate limits, sandbox access, and the Marketplace listing gate. Use when asked to get BambooHR OAuth credentials, register a BambooHR app, set up a BambooHR developer or test account, help a customer create or rotate a BambooHR API key, or fix a BambooHR auth error like a 404 on a list endpoint, a missing refresh token, or a redirect URI mismatch. For any other vendor's developer portal, use that vendor's skill instead. - [bitbucket-oauth-app](https://docs.unified.to/skills/bitbucket-oauth-app/SKILL.md): Registers a Bitbucket Cloud OAuth 2.0 consumer to obtain OAuth2 credentials — the consumer Key and Secret, the single callback URL, and the permission checkboxes that become the token's scopes — for a platform that connects many customers' Bitbucket workspaces. Use when asked to get Bitbucket OAuth credentials, create or edit a Bitbucket OAuth consumer, choose between an OAuth consumer and a workspace/project/repository access token or an API token, migrate off deprecated Bitbucket app passwords, rotate a Bitbucket consumer secret, or fix a Bitbucket authorization error such as an invalid redirect, `invalid_scope`, `unauthorized_client`, or a token that dies after two hours. Covers Bitbucket **Cloud** only — Bitbucket Data Center registers OAuth clients inside the customer's own instance. For any other vendor's developer portal, use that vendor's skill instead. - [box-oauth-app](https://docs.unified.to/skills/box-oauth-app/SKILL.md): Creates or signs in to a Box developer account and registers a Box Platform App with User Authentication (OAuth 2.0) to obtain a client ID and client secret — with exact-match redirect URIs, console-selected scopes, the enterprise admin app-authorization gate, single-use rotating refresh tokens, and a safe credential handoff. Use when asked to get Box OAuth credentials, create a Box app or Platform App, set up a Box developer account or sandbox, rotate a Box client secret, add scopes to a Box app, or fix a Box authorization error like `redirect_uri_mismatch`, `redirect_uri_missing`, "Disabled by Administrator", or a customer whose Box connection dies after a quiet month. For any other vendor's developer portal, use that vendor's skill instead. - [brex-oauth-app](https://docs.unified.to/skills/brex-oauth-app/SKILL.md): Obtains Brex OAuth 2.0 credentials — client ID, client secret, redirect URIs and scopes — for a platform that connects other organizations' Brex accounts. Covers the fact that Brex OAuth apps are partner-gated rather than self-serve (there is no developer portal that issues credentials), the route into the partner programme, the per-customer user-token alternative and its admin runbook, the full scope catalogue and its read/write split, staging access, 1-hour access tokens with rotating 90-day refresh tokens, rate limits, and a safe credential handoff. Use when asked to get Brex OAuth or API credentials, register a Brex app, become a Brex developer partner, connect customer Brex accounts, set up Brex staging access, or fix a Brex authorization error such as a rejected redirect URI, a missing scope, a 401 after an hour, or a refresh that stops working. For any other vendor's developer portal, use that vendor's skill instead. - [bullhorn-oauth-app](https://docs.unified.to/skills/bullhorn-oauth-app/SKILL.md): Establishes whether a Bullhorn OAuth2 credential can legitimately be obtained at all and, if so, obtains it — client ID, client secret, API username and API-user password, all issued by hand by Bullhorn Support or the Bullhorn Alliances team, never from a developer portal — with the per-customer data-centre swimlane that must be discovered at runtime, the two-step OAuth-token-then-BhRestToken session dance, single-use refresh tokens that must be explicitly enabled on the key, the entitlements model that replaces scopes, per-client-ID rate limits shared across every customer, and a safe credential handoff. Use when asked to get Bullhorn OAuth credentials, register a Bullhorn app, become a Bullhorn API Access or Marketplace partner, obtain a Bullhorn sandbox, or fix a Bullhorn auth error like a 307 redirect loop, `invalid_grant` on refresh, a 401 on every REST call after a successful token exchange, or fields that silently come back null. For any other vendor's developer portal, use that vendor's skill instead. - [calendly-oauth-app](https://docs.unified.to/skills/calendly-oauth-app/SKILL.md): Creates a Calendly developer account and registers a Calendly OAuth application to obtain a client ID, client secret and webhook signing key — with redirect URIs, the OAuth 2.1 scope catalogue, Sandbox vs Production apps, single-use rotating refresh tokens, the plan and role gating that decides what a customer's token can actually see, and a safe credential handoff. Use when asked to get Calendly OAuth credentials, create a Calendly developer account or OAuth app, choose Calendly scopes, rotate a Calendly client secret or webhook signing key, or debug a Calendly connection that authorizes but returns 403s, empty organizations, or `invalid_grant` on refresh. For any other vendor's developer portal, use that vendor's skill instead. - [clickup-oauth-app](https://docs.unified.to/skills/clickup-oauth-app/SKILL.md): Signs in to ClickUp and registers an OAuth app inside a Workspace's Settings → Apps to obtain an OAuth2 client ID and client secret — with redirect URLs, the fact that ClickUp has no OAuth scopes at all, the Workspace-selection consent model, non-expiring tokens with no refresh token, per-plan rate limits and a safe credential handoff. Use when asked to get ClickUp OAuth credentials, create a ClickUp app, set up ClickUp API access for many customers, rotate a ClickUp client secret, or debug a ClickUp authorization error like `OAUTH_007`, `OAUTH_010`, `OAUTH_017`, `OAUTH_023` "Team not authorized", or a ClickUp webhook that silently stopped firing. For any other vendor's developer portal, use that vendor's skill instead. - [discord-oauth-app](https://docs.unified.to/skills/discord-oauth-app/SKILL.md): Creates a Discord application in the developer portal and obtains OAuth2 client ID and client secret plus a bot token — with the right redirect URIs, scope strings, the `bot` scope and its permissions bitfield, privileged gateway intents, app verification and a safe credential handoff. Use when asked to get Discord OAuth credentials, create or configure a Discord app, pick Discord scopes or bot permissions, get a Discord bot token, enable the MESSAGE CONTENT or SERVER MEMBERS intent, get an app verified or listed in the App Directory, rotate a Discord client secret or bot token, or fix a Discord install error like `invalid_scope`, gateway close code `4014`, or "Only the application owner can add this bot". For any other vendor's developer portal, use that vendor's skill instead. - [dropbox-oauth-app](https://docs.unified.to/skills/dropbox-oauth-app/SKILL.md): Creates or signs in to a Dropbox account and registers a Dropbox app in the App Console to obtain an OAuth2 app key and app secret (client ID and client secret) — with the irreversible App folder vs Full Dropbox access-type choice, redirect URIs, scoped permissions, `token_access_type=offline` for refresh tokens, and the development-to-production approval path. Use when asked to get Dropbox OAuth credentials, create a Dropbox app, set up a Dropbox developer account, rotate a Dropbox app secret, or fix a Dropbox OAuth error such as a missing refresh token, an access token that dies after a few hours, a redirect URI mismatch, a missing-scope 401, or an app that suddenly stopped linking new users. For any other vendor's developer portal, use that vendor's skill instead. - [facebook-oauth-app](https://docs.unified.to/skills/facebook-oauth-app/SKILL.md): The Facebook Pages layer on top of the shared `meta-graph-app` skill — read that one first for the Meta developer account, app, redirect URIs, access levels, review regimes, App ID and Secret, and Graph API versioning. This file covers only what Facebook adds: the Page access token and the `/me/accounts` exchange that mints it, Page tasks as a second authorization axis, the `pages_*` permissions that need Tech Provider verification, Facebook Login for Business and `config_id`, per-Page webhook installs, and Page Insights metric deprecations. Use when asked to get Facebook OAuth credentials, connect customers' Facebook Pages, publish or read Page posts, reviews or Insights, or fix a Facebook error like `(#210)`, `(#283)`, an invalid metric, or a connection that stops after an hour. For Meta Ads use `meta-ads-oauth-app`; for Instagram use `instagram-oauth-app`. - [fathom-oauth-app](https://docs.unified.to/skills/fathom-oauth-app/SKILL.md): Registers a Fathom (fathom.video AI meeting notetaker) OAuth2 app to obtain a client ID and client secret — covering the self-serve marketplace-application form, the one-production-redirect-URI rule that forces one app per data center, the single `public_api` scope, one-time-use rotating refresh tokens, and the per-customer API-key route that is the alternative. Use when asked to get Fathom OAuth credentials, register a Fathom app, set up a Fathom developer account, wire Fathom meeting/transcript/webhook access for many customers, or debug a Fathom connection that authorizes but returns only one person's meetings, returns no summaries, or breaks on the second refresh. Not for Fathom Analytics (usefathom.com). For any other vendor's developer portal, use that vendor's skill instead. - [freshbooks-oauth-app](https://docs.unified.to/skills/freshbooks-oauth-app/SKILL.md): Creates or signs in to a FreshBooks account and registers a FreshBooks OAuth2 app to obtain a client ID and client secret — with redirect URIs, the portal-side `user::` scope picker, the account-id / business-id / business-UUID indirection behind `/auth/api/v1/users/me`, one-time-use rotating refresh tokens, and a safe credential handoff. Use when asked to get FreshBooks OAuth credentials, set up a FreshBooks developer app, rotate a FreshBooks client secret, add a redirect URI, or fix a FreshBooks error like a 403 naming missing scopes, a 401 on a token that worked an hour ago, a refresh that suddenly fails, or 404s on every accounting call. For any other vendor's developer portal, use that vendor's skill instead. - [github-oauth-app](https://docs.unified.to/skills/github-oauth-app/SKILL.md): Registers a GitHub OAuth App or a GitHub App to obtain OAuth2 credentials — client ID, client secret, and for a GitHub App the private key that mints installation tokens — with the right callback URLs, scopes or fine-grained permissions, org approval path, and a safe credential handoff. Use when asked to get GitHub OAuth credentials, create a GitHub OAuth App or GitHub App, choose between the two, register a GitHub App from a manifest, rotate a GitHub client secret or private key, or fix a GitHub authorization error like `redirect_uri_mismatch`, `incorrect_client_credentials`, `bad_verification_code`, or a customer whose org owner has not approved the app. Covers GitHub.com, GitHub Enterprise Cloud and GitHub Enterprise Server. For any other vendor's developer portal, use that vendor's skill instead. - [gmail-oauth-app](https://docs.unified.to/skills/gmail-oauth-app/SKILL.md): The Gmail API layer on top of the shared `google-cloud-console-oauth` skill — why every mailbox-reading Gmail scope is restricted and there is no `drive.file`-style escape hatch, the one genuinely narrow scope (`gmail.send`) and what it cannot do, the permitted application types that gate Gmail restricted scopes, refresh tokens dying on a user's password change, Pub/Sub push registration, Gmail quota units and sending limits, and the Workspace admin controls that block Gmail API access specifically. Use when asked to get Gmail OAuth credentials, register or scope a Gmail app, choose between `gmail.readonly`, `gmail.modify`, `gmail.metadata` and `gmail.send`, judge whether a Gmail integration needs a CASA assessment, or explain why Gmail connections keep dying or returning 403. Read `google-cloud-console-oauth` first for the console mechanics; use that skill alone when the Google product is not Gmail, and the relevant product skill for Drive, Google Ads, Google Business Profile or another vendor's portal. - [google-ads-oauth-app](https://docs.unified.to/skills/google-ads-oauth-app/SKILL.md): Google Ads API credentials, on top of the shared `google-cloud-console-oauth` skill — read that one first for the Cloud project, consent app, client, redirect URIs and verification. This file covers only what Google Ads adds: the API access level that replaced the developer token at the 9 September 2026 sunset, the Test / Explorer / Basic / Standard ladder, brand verification, the manager (MCC) account and its Terms of Service, the single `adwords` scope, the `login-customer-id` header, and the 2SV and passkey mandates. Use when asked for Google Ads API credentials, a developer token, a manager account, Basic or Standard access, or when a Google Ads connector fails with `DEVELOPER_TOKEN_NOT_APPROVED`, `CLOUD_PROJECT_NOT_APPROVED_FOR_PRODUCTION`, `USER_PERMISSION_DENIED` or `TWO_STEP_VERIFICATION_NOT_ENROLLED`. A client that authorizes fine still cannot read a production ad account without a reviewed access level. - [google-analytics-oauth-app](https://docs.unified.to/skills/google-analytics-oauth-app/SKILL.md): The Google Analytics (GA4) layer on top of the shared `google-cloud-console-oauth` skill — the `analytics.*` scope family and which API accepts which member, the Universal Analytics sunset and its leftover scopes and endpoints, the Data API / Admin API split, property vs measurement vs stream IDs and the call that discovers what a user can see, the per-property token quota a multi-tenant reader hits, and the sampling, cardinality and thresholding effects that change a report's numbers. Use when asked to get Google Analytics OAuth credentials, register or scope a GA4 app, decide between `analytics.readonly`, `analytics.edit` and `analytics`, explain a GA4 quota or permission failure, or work out why two runs of the same report disagree. Read `google-cloud-console-oauth` first for the console mechanics; use the relevant product skill for other Google products. - [google-business-profile-oauth-app](https://docs.unified.to/skills/google-business-profile-oauth-app/SKILL.md): Builds on the `google-cloud-console-oauth` base skill (read that first — it owns the Cloud project, OAuth client, redirect URIs, secret and verification mechanics) and covers only what the Google Business Profile APIs add: the mandatory API access request that gates everything, quota pinned at 0 QPM until a human approves it, approval bound to a Cloud project number, the seven-plus-one APIs to enable, the single `business.manage` read-and-write scope, profile-role and Workspace permission failures, quota-increase rules, v4 sunset history and the no-sandbox `validateOnly` path. Use when asked for Google Business Profile / GMB OAuth credentials, to enable the Business Profile APIs, or to diagnose `0 QPM`, 429 `RESOURCE_EXHAUSTED` / `RATE_LIMIT_EXCEEDED`, `403 PERMISSION_DENIED` or "the API is not visible in the console" on a Business Profile project. For a plain Google OAuth client with no Business Profile scope, the base skill alone is the whole job; for another vendor's portal, use that vendor's skill. - [google-calendar-oauth-app](https://docs.unified.to/skills/google-calendar-oauth-app/SKILL.md): The Google Calendar API layer on top of the shared `google-cloud-console-oauth` skill — the Calendar scope family (sensitive, not restricted, so verification but no CASA assessment), the granular scopes, which APIs to enable, where Meet conferencing touches events, what a token can see across primary, secondary, shared and delegated calendars, `freebusy` as a minimal-access option, watch channels and quotas, and the Workspace admin settings that block Calendar. Use when asked to get Google Calendar OAuth credentials, register or scope a Calendar app, choose between `calendar`, `calendar.readonly`, `calendar.events` and `calendar.freebusy`, judge how heavy verification will be, or explain why a connection cannot see a shared or team calendar. Read `google-cloud-console-oauth` first for the console mechanics; use the relevant product skill for other Google products. - [google-cloud-console-oauth](https://docs.unified.to/skills/google-cloud-console-oauth/SKILL.md): The shared Google Cloud Console / Google Auth Platform mechanics behind every Google OAuth2 registration — creating the project, configuring the consent app, creating a Web application client, redirect-URI rules, scope tiers and declaration, the one-time client secret, Testing vs In production, verification and the restricted-scope security assessment. Read this first when registering any Google OAuth client; the product skills (Google APIs, Google Ads, Google Business Profile, Google Drive) build on it and cover only what is specific to their API. Use directly when the task is a plain Google OAuth client with no particular Google product named. - [google-contacts-oauth-app](https://docs.unified.to/skills/google-contacts-oauth-app/SKILL.md): The Google Contacts / People API layer on top of the shared `google-cloud-console-oauth` skill — the People scope family and why none of it is restricted (no CASA assessment), the `contacts.readonly` / `contacts` least-privilege ladder, the "other contacts" corpus that explains why an app sees fewer people than the user does, Workspace directory people and the admin switch behind them, `personFields`/`readMask`, seven-day sync tokens, contact groups, and quota. Use when asked to get Google Contacts OAuth credentials, register or scope a People API app, decide between `contacts.readonly`, `contacts`, `contacts.other.readonly` and `directory.readonly`, judge whether a Contacts integration needs a security assessment, or explain why a connection returns almost no people. Read `google-cloud-console-oauth` first for the console mechanics; use the relevant product skill for other Google products. - [google-docs-oauth-app](https://docs.unified.to/skills/google-docs-oauth-app/SKILL.md): The Google Docs API layer on top of the shared `google-cloud-console-oauth` skill — the two `documents` scopes and why they are only sensitive, the Drive dependency that decides the project's tier (the Docs API cannot list or search, so discovery needs `drive.readonly` and a CASA assessment, `drive.file` and a Picker, or document IDs from elsewhere), the structural-element and index model behind `batchUpdate`, export through Drive, and the Docs quotas. Use when asked to get Google Docs OAuth credentials, scope a Docs integration, decide whether reading or writing documents needs a restricted Drive scope, or explain why a Docs connection cannot find a user's documents. Read `google-cloud-console-oauth` first for the console mechanics, and `google-drive-oauth-app` whenever a Drive scope is in play; use the relevant product skill for other Google products. - [google-drive-oauth-app](https://docs.unified.to/skills/google-drive-oauth-app/SKILL.md): The Google Drive API layer on top of the shared `google-cloud-console-oauth` skill — which Drive scopes are restricted and which are not, the `drive.file` per-file escape hatch and what it cannot do, the permitted-application-type rule that gates restricted Drive scopes regardless of paperwork, the verification exemptions, shared-drive access, and the Search Console domain-ownership problem for a customer bringing their own Google app. Use when asked to get Google Drive OAuth credentials, register or scope a Google Drive app, decide between `drive.readonly`, `drive` and `drive.file`, judge whether a Drive integration will need a CASA assessment, or explain why a Drive connection cannot see a team's files. Read `google-cloud-console-oauth` first for the console mechanics; use that skill alone when the Google product is not Drive, and the relevant product skill for Gmail, Calendar, Google Ads or another vendor's portal. - [google-meet-oauth-app](https://docs.unified.to/skills/google-meet-oauth-app/SKILL.md): The Google Meet layer on top of the shared `google-cloud-console-oauth` skill — the sensitivity tier of every Meet scope (`meetings.space.created` and `meetings.space.readonly` sensitive, `meetings.space.settings` non-sensitive, Meet Media API scopes restricted), the three things people call "Meet support", the Meet REST API surface, why recordings and transcripts are Drive files and so restricted-tier, the Workspace editions required, event subscriptions, and quotas. Use when asked to get Google Meet OAuth credentials, register or scope a Meet app, choose between the `meetings.space.*` scopes, judge whether pulling recordings or transcripts forces a CASA assessment, or explain why a Meet connection returns no conferences. Read `google-cloud-console-oauth` first for the console mechanics, `google-calendar-oauth-app` for Meet links on events, and `google-drive-oauth-app` for downloading artifact files. - [google-oauth-app](https://docs.unified.to/skills/google-oauth-app/SKILL.md): The multi-API Google connector layer on top of the shared `google-cloud-console-oauth` skill — the combined scope set a connector requests when one Google connection spans several APIs at once (identity, Gmail, Calendar/Meet, Contacts/People, Drive/Sheets), and the tier that union lands in. Read the base skill first. Use this when the job is a Google connection covering several products or you need the combined scope picture; for a single product use its own skill — `gmail-oauth-app`, `google-calendar-oauth-app`, `google-drive-oauth-app`, `google-sheets-oauth-app`, `google-docs-oauth-app`, `google-contacts-oauth-app`, `google-meet-oauth-app`, `google-tasks-oauth-app`, `google-analytics-oauth-app`, `google-ads-oauth-app` or `google-business-profile-oauth-app`. For a plain Google OAuth client with no product named, the base skill alone is the whole job. For any other vendor's developer portal, use that vendor's skill instead. - [google-sheets-oauth-app](https://docs.unified.to/skills/google-sheets-oauth-app/SKILL.md): The Google Sheets API layer on top of the shared `google-cloud-console-oauth` skill — the two Sheets scopes (sensitive, not restricted), the Drive scope an app adds to find a spreadsheet and how that choice decides whether it needs an annual CASA assessment, A1 versus grid ranges, batch methods and the per-minute quotas that punish per-cell calls, spreadsheet hard limits, and the Apps Script and add-on paths. Use when asked to get Google Sheets OAuth credentials, scope a Sheets integration, decide between `spreadsheets`, `spreadsheets.readonly`, `drive.readonly` and `drive.file`, explain 429s or quota errors on Sheets, or judge whether a Sheets connector needs a security assessment. Read `google-cloud-console-oauth` first for the console mechanics and `google-drive-oauth-app` for Drive-side depth; use the relevant product skill for other Google products. - [google-slides-oauth-app](https://docs.unified.to/skills/google-slides-oauth-app/SKILL.md): The Google Slides API layer on top of the shared `google-cloud-console-oauth` skill — the two `presentations` scopes and why they are only sensitive, the Drive scope that decides the project's tier (the Slides API cannot list, search, copy, move or export a presentation), per-slide thumbnails and their 30-minute URLs, caller-supplied object IDs and fragile index arithmetic across `batchUpdate` calls, the "expensive read" quota bucket, and what the API does not do. Use when asked to get Google Slides OAuth credentials, scope a Slides integration, decide whether reading or generating decks needs a whole-Drive scope, or explain why a Slides connection cannot find, export or image a user's presentations. Read `google-cloud-console-oauth` first for the console mechanics, and `google-drive-oauth-app` whenever a Drive scope is in play; use the relevant product skill for other Google products. - [google-tasks-oauth-app](https://docs.unified.to/skills/google-tasks-oauth-app/SKILL.md): The Google Tasks API layer on top of the shared `google-cloud-console-oauth` skill — the two Tasks scopes and the tier they actually sit in (sensitive, not restricted, so no CASA assessment), the tasklists/tasks model and the undocumented `@default` alias, hierarchy and ordering that only the separate move call can write, the completed/hidden/deleted/assigned flags that silently drop tasks out of a list response, the documented quota and data caps, and why tasks appearing in Google Calendar does not mean you need a Calendar scope. Use when asked to get Google Tasks OAuth credentials, scope a Google Tasks app, judge what verification a Tasks integration needs, or explain why a Tasks sync is missing completed, hidden or assigned tasks. Read `google-cloud-console-oauth` first for the console mechanics; use the Drive, Ads or Business Profile skill when the product is not Tasks. - [google-workspace-directory-oauth-app](https://docs.unified.to/skills/google-workspace-directory-oauth-app/SKILL.md): The Admin SDK Directory API layer on top of the shared `google-cloud-console-oauth` skill — why it only works against Google Workspace, never consumer Gmail, the `admin.directory.*` scopes (none restricted), the admin role checked in addition to the scope, domain-wide delegation as a per-customer super-admin task, `customer=my_customer`, users vs members vs org units, the lack of a delta or sync token, and Directory quotas and page-size caps. Use when asked to get Google Workspace Directory or Admin SDK OAuth credentials, scope an employee-directory or group-sync integration against Google, decide between user OAuth and a delegated service account, or explain a 403 on a token that authorized cleanly. Read `google-cloud-console-oauth` first for the console mechanics; use `microsoft-entra-directory-oauth-app` for the Microsoft equivalent. - [greenhouse-oauth-app](https://docs.unified.to/skills/greenhouse-oauth-app/SKILL.md): Establishes which Greenhouse credential a connector actually needs and obtains it — Harvest v3 partner OAuth (issued only by Greenhouse Partner Support under a signed partnership agreement), customer-created Harvest v3 client-credentials, legacy Harvest v1/v2 API keys, Job Board tokens, Ingestion and Assessment partner keys — with scopes, the Site Admin rule, rate limits, IP allowlisting and a safe credential handoff. Use when asked to get Greenhouse OAuth credentials or API keys, register a Greenhouse app, become a Greenhouse integration partner, migrate a Greenhouse integration to Harvest v3, or fix a Greenhouse auth error like `unauthorized_client`, `invalid_scope`, a 403 on every list endpoint, or a connection that dies after two weeks. For any other vendor's developer portal, use that vendor's skill instead. - [hibob-oauth-app](https://docs.unified.to/skills/hibob-oauth-app/SKILL.md): Establishes which HiBob (Bob) credential a connector can actually get and obtains it — the per-customer service user ID and token that any integration can use today, or the partner-gated OAuth 2.0 client ID and secret that only approved HiBob Marketplace and technology partners are issued — with the service-user permission-group runbook, field-level permissions and the silent-omission trap that returns 200 OK with missing data, token lifetimes and rotation, sandbox, rate limits and the WAF block on repeated 401s. Use when asked to get HiBob OAuth credentials, register a Bob app in the HiBob Developer Portal, become a HiBob Marketplace partner, walk a customer through creating a Bob service user, or fix a Bob auth error like an empty employee list, missing fields on a 200, a 403 on every call, or a refresh token that stopped working. For any other vendor's developer portal, use that vendor's skill instead. - [highlevel-oauth-app](https://docs.unified.to/skills/highlevel-oauth-app/SKILL.md): Creates or signs in to a HighLevel (GoHighLevel / LeadConnector) developer marketplace account and registers a marketplace app to obtain OAuth2 client ID and client secret — with the irreversible Agency-vs-Sub-Account target-user decision, redirect URL, scopes, private-app install cap, token and Version-header behaviour, and a safe credential handoff. Use when asked to get HighLevel OAuth credentials, set up a HighLevel developer account, create a GoHighLevel marketplace app, rotate a HighLevel client secret, publish or review a HighLevel app, or fix a HighLevel install error like a blocked install, a missing locationId, or 401s on sub-account endpoints. For any other vendor's developer portal, use that vendor's skill instead. - [hubspot-oauth-app](https://docs.unified.to/skills/hubspot-oauth-app/SKILL.md): Creates or signs in to a HubSpot developer account and registers a HubSpot app to obtain OAuth2 client ID and client secret — with the right redirect URLs, required vs optional scopes, install limits, and a safe credential handoff. Use when asked to get HubSpot OAuth credentials, set up a HubSpot developer/app account, create a HubSpot public app, rotate a HubSpot client secret, or fix a HubSpot install error like "invalid scope" or "redirect URI mismatch". For any other vendor's developer portal, use that vendor's skill instead. - [icims-oauth-app](https://docs.unified.to/skills/icims-oauth-app/SKILL.md): Establishes whether an iCIMS API credential can be obtained for a given platform and, if so, obtains it — Basic username and password, an HMAC key, or an OAuth 2.0 client-credentials client ID and secret, all issued by hand by iCIMS staff, never self-serve — with the paid Technology Partner Program, the per-customer Customer ID, the regional US/EU/Canada hosts, the Integration User group and Security Rules that silently return partial data, the 10,000-call daily limit, and a safe credential handoff. Use when asked to get iCIMS API or OAuth credentials, register an iCIMS app, become an iCIMS Technology Partner, obtain a sandbox, or fix an iCIMS error like `access_denied` on the token call, a 401 quoting Basic or `x-icims-v1-hmac-sha256`, "Invalid Username or Password credentials provided", an empty search, or fields that silently come back missing. - [instagram-oauth-app](https://docs.unified.to/skills/instagram-oauth-app/SKILL.md): The Instagram Platform layer on top of the shared `meta-graph-app` skill — read that one first for the Meta developer account, app, redirect URIs, access levels, review regimes, `appsecret_proof` and Graph API versioning. This file covers only what Instagram adds: Instagram Login versus Facebook Login for Business, the `instagram_business_*` permissions, the separate Instagram App ID and App Secret, `graph.instagram.com`, and the 1-hour → 60-day → refresh token ladder. Use when asked to get Instagram OAuth credentials, create an Instagram app, connect an Instagram Business or Creator account, migrate off Instagram Basic Display, rotate an Instagram app secret, or fix an error like `Invalid platform app`, `Invalid scrubbed redirect_uri`, or a token that stops working after 60 days. For Meta Ads use `meta-ads-oauth-app`. - [intercom-oauth-app](https://docs.unified.to/skills/intercom-oauth-app/SKILL.md): Creates or signs in to an Intercom development workspace and registers an Intercom app in the Developer Hub to obtain OAuth2 client ID and client secret — enabling OAuth on the app, adding every HTTPS redirect URL, selecting the per-app permission scopes, handling US/EU/AU regional hosting, pinning the API version, and a safe credential handoff. Use when asked to get Intercom OAuth credentials, create an Intercom app or development workspace, add a redirect URL or scope to an Intercom app, submit an Intercom app for review or App Store listing, or fix an Intercom OAuth failure such as `Unauthorized Code`, a customer landing on the wrong region, or a 401 on every API call after install. For any other vendor's developer portal, use that vendor's skill instead. - [jobadder-oauth-app](https://docs.unified.to/skills/jobadder-oauth-app/SKILL.md): Registers a JobAdder partner/developer account and an application to obtain OAuth2 client ID and client secret — covering the approval gate that blocks credentials until JobAdder says yes, authorised redirect URIs, the per-object scope list and `offline_access`, rotating refresh tokens, and the per-account API base URL returned in the token response. Use when asked to get JobAdder OAuth credentials, register a JobAdder developer or partner account, create a JobAdder API application, rotate a JobAdder client secret, or fix a JobAdder auth error like `invalid_grant`, `invalid_request`, a denied authorization, or API calls 404ing against the wrong region host. For any other vendor's developer portal, use that vendor's skill instead. - [lever-oauth-app](https://docs.unified.to/skills/lever-oauth-app/SKILL.md): Establishes which Lever credential a connector actually needs and obtains it — partner-gated OAuth2 (client ID and secret issued by hand by the Lever integrations team, only after the partner program and a sandbox account), customer-created Data API keys, and the public unauthenticated Postings API — with the mandatory `audience` parameter, the `::admin` scope grammar, the Super Admin rule, sandbox-vs-production hosts that are not interchangeable, refresh-token lifetimes and a safe credential handoff. Use when asked to get Lever OAuth credentials, register a Lever app, become a Lever integration partner, obtain a Lever API key or sandbox account, or fix a Lever auth error like a consent screen showing only `offline_access`, `ClientID not found`, `Unable to find a signing key that matches`, or a connection that dies after a quiet quarter. For any other vendor's developer portal, use that vendor's skill instead. - [linear-oauth-app](https://docs.unified.to/skills/linear-oauth-app/SKILL.md): Creates or signs in to a Linear workspace and registers an OAuth2 application in Linear's workspace API settings to obtain a client ID and client secret — with redirect URIs, the comma-delimited scope list, private vs public distribution, the actor=user vs actor=app decision, 24-hour access tokens with rotating refresh tokens, app-level webhooks, and a safe credential handoff. Use when asked to get Linear OAuth credentials, create a Linear OAuth application or agent, pick Linear scopes, enable client credentials tokens, rotate a Linear client secret or webhook signing secret, or debug a Linear authorization that returns 401 after a day, cannot install into another workspace, or is blocked by workspace app approvals. For any other vendor's developer portal, use that vendor's skill instead. - [linkedin-oauth-app](https://docs.unified.to/skills/linkedin-oauth-app/SKILL.md): Creates or signs in to a LinkedIn developer account and registers a LinkedIn app to obtain OAuth2 client ID and client secret — covering the mandatory LinkedIn Page association and super-admin app verification, the per-Product access requests that actually unlock scopes, exact-match redirect URLs, 60-day tokens and programmatic refresh tokens, and a safe credential handoff. Use when asked to get LinkedIn OAuth credentials, set up a LinkedIn developer app, apply for the Advertising API / Community Management API / Marketing Developer Platform, rotate a LinkedIn client secret, or fix a LinkedIn error like `Invalid scope`, `Redirect_uri doesn't match`, or a connection that dies every 60 days. For any other vendor's developer portal, use that vendor's skill instead. - [mailchimp-oauth-app](https://docs.unified.to/skills/mailchimp-oauth-app/SKILL.md): Creates or signs in to a Mailchimp account and registers an app on the Registered Apps page to obtain an OAuth2 client ID and client secret — with the redirect URI, the fact that Mailchimp has no scopes, the per-account data-centre prefix that must be discovered after token exchange, non-expiring tokens with no refresh token, rotation, and a safe credential handoff. Use when asked to get Mailchimp OAuth credentials, register a Mailchimp app, set up a Mailchimp developer account, rotate a Mailchimp client secret, list an integration in the Mailchimp Marketplace, or debug a Mailchimp connection that authorizes but then 404s or 403s on every API call. For Mailchimp Transactional (Mandrill) or any other vendor's portal, use that vendor's skill instead. - [meta-ads-oauth-app](https://docs.unified.to/skills/meta-ads-oauth-app/SKILL.md): The Marketing API layer on top of the shared `meta-graph-app` skill — read that one first for the developer account, app, redirect URIs, access levels, review regimes, App ID and Secret, and Graph API versioning. This file covers only what Meta Ads adds: the Business app type with the Marketing API product and a Facebook Login for Business configuration, the `ads_read` / `ads_management` / `business_management` permissions, the Limited→Full access tier, the ~60-day user token versus the non-expiring System User token, the Marketing API's 90-day version clock, and ad-account and insights throttles. Use when asked for Meta Ads or Facebook Ads OAuth credentials or a Marketing API app, or when an ads connector is throttled, dies after ~60 days, or fails with `(#294)`, `(#80000)` or `(#80004)`. For Instagram use `instagram-oauth-app`; for Google Ads use `google-ads-oauth-app`. - [meta-graph-app](https://docs.unified.to/skills/meta-graph-app/SKILL.md): The shared Meta App Dashboard registration mechanics behind every Meta Graph connector — the developer account, the business portfolio that claims the app, the app-creation wizard and its two irreversible choices, exact-match redirect URIs, Standard vs Advanced Access, the four review regimes (App Review, Business Verification, Access Verification / Tech Provider, Ongoing Review and Data Use Checkup), the App ID and Secret, `appsecret_proof` and rotation, Graph API versioning, and the common Graph error codes. Read this first for any Meta product, then the product skill (`facebook-oauth-app`, `meta-ads-oauth-app` or `instagram-oauth-app`). Use when asked to create a Meta or Facebook app, get a Meta App ID and App Secret, get through Meta App Review or Business Verification, or diagnose why only people with a role on the app can connect. - [microsoft-dynamics-oauth-app](https://docs.unified.to/skills/microsoft-dynamics-oauth-app/SKILL.md): Registers a Microsoft Entra ID application for Dynamics 365 / Microsoft Dataverse access. Builds on the `microsoft-entra-app-registration` base skill; read that first. This skill covers only what Dynamics adds: the per-customer, per-environment Dataverse resource URL and the Global Discovery Service, the `user_impersonation` / `.default` scopes, the application user plus security role a customer admin must set up before an app-only token works, Dataverse row-level security, the product-family split (Sales, Customer Service, Business Central, Finance & Operations, GP), Web API versioning and service protection limits. Use when asked to get Dynamics 365 OAuth credentials, connect Dataverse, Sales or Customer Service, fix a Dynamics connector returning 401 or 403 with a valid token, set up Business Central or Finance & Operations API access, or find the environment URL a connector should call. - [microsoft-entra-app-registration](https://docs.unified.to/skills/microsoft-entra-app-registration/SKILL.md): The shared Microsoft Entra ID (formerly Azure AD) app-registration mechanics behind every Microsoft OAuth2 client — the Entra admin center, registering the app, supported account types and what they cap, redirect-URI platform types, delegated vs application permissions, admin consent and who is allowed to grant it, the 24-month client secret and its one-time Value, certificates, `offline_access`, publisher verification, and the AADSTS errors these produce. Read this first when registering any Entra app for Microsoft Graph; the product skills — Microsoft Graph sign-in, SharePoint — build on it and cover only what their product adds. Use directly when the task is a plain Entra ID / Microsoft Graph OAuth client and no particular Microsoft product is named. - [microsoft-entra-directory-oauth-app](https://docs.unified.to/skills/microsoft-entra-directory-oauth-app/SKILL.md): The Microsoft Graph permission and query model for reading Microsoft Entra ID directory data — users, groups, memberships, managers and org profile — for a connector that syncs a customer's directory. Builds on the `microsoft-entra-app-registration` base skill; read that first. Covers the `User.*`, `Group.*`, `GroupMember.*`, `Directory.*` and `Organization.Read.All` families and which need admin consent, the least-privilege ladder from `User.ReadBasic.All` to `Directory.Read.All`, guests, `$select`/`$filter` and `ConsistencyLevel: eventual`, delta queries, manager expansion, on-premises-synced attributes, and throttling. Use when asked to scope an Entra/Azure AD directory or employee sync, choose between `User.Read.All` and `Directory.Read.All`, fix a directory read returning `403 Authorization_RequestDenied` or empty results, or explain why a directory connector needs a tenant admin. - [microsoft-oauth-app](https://docs.unified.to/skills/microsoft-oauth-app/SKILL.md): The Microsoft Graph **sign-in** layer on top of the shared `microsoft-entra-app-registration` skill — the tenant-agnostic `common` authority, the `openid email profile User.Read` scope set, `prompt=select_account`, and why an authentication connector receives no refresh token. Read the base skill first. Use this when the job is Microsoft sign-in / identity, or a general Graph connector with no specific product named; for a product use its own skill — `microsoft-outlook-oauth-app` (mail and calendar), `microsoft-onedrive-oauth-app` (files), `microsoft-sharepoint-oauth-app` (sites and libraries), `microsoft-teams-oauth-app`, `microsoft-entra-directory-oauth-app` (users and groups) or `microsoft-dynamics-oauth-app`. For any other vendor's developer portal, use that vendor's skill instead. - [microsoft-onedrive-oauth-app](https://docs.unified.to/skills/microsoft-onedrive-oauth-app/SKILL.md): Registers a Microsoft Entra ID application for OneDrive and the Microsoft Graph files APIs. Builds on the `microsoft-entra-app-registration` base skill; read that first. This skill covers only what OneDrive adds: the `Files.*` permissions and which "Selected" scopes are current, why `Files.*.All` reaches every user's OneDrive and every SharePoint site, OneDrive personal versus for Business and what that forces on the account-types choice, drive and driveItem addressing, upload sessions, delta sync, sharing links, and per-user throttling. Use when asked to get OneDrive OAuth credentials, connect OneDrive or OneDrive for Business, or debug a OneDrive connector returning `403 accessDenied`, `404` on a user's drive, or failed large-file uploads. For SharePoint sites or `Sites.Selected` use `microsoft-sharepoint-oauth-app`; for plain Microsoft sign-in use `microsoft-oauth-app`. - [microsoft-outlook-oauth-app](https://docs.unified.to/skills/microsoft-outlook-oauth-app/SKILL.md): Registers a Microsoft Entra ID application for Outlook mail and calendar access through Microsoft Graph. Builds on the `microsoft-entra-app-registration` base skill; read that first. This skill covers only what Outlook adds: the `Mail.*` / `Calendars.*` / `.Shared` permissions and their naming traps, why every Outlook application permission reaches every mailbox in the tenant and the two ways to narrow that (RBAC for Applications and application access policies), shared, room and group mailboxes, per-mailbox throttling, change-notification lifetimes, and the EWS retirement. Use when asked to get Outlook or Microsoft 365 mail OAuth credentials, connect Exchange Online mailboxes or calendars, scope an app-only mail connector to some mailboxes, or fix an Outlook connector returning `ErrorAccessDenied`, `403` or `MailboxConcurrency` errors. For plain Microsoft sign-in use `microsoft-oauth-app`. - [microsoft-sharepoint-oauth-app](https://docs.unified.to/skills/microsoft-sharepoint-oauth-app/SKILL.md): Registers a Microsoft Entra ID application for SharePoint Online access through Microsoft Graph. Builds on the `microsoft-entra-app-registration` base skill; read that first. This skill covers only what SharePoint adds: the `Sites.Selected` per-site grant model and the three conditions it needs, the broad `Sites.*.All` alternatives and how security reviews react to them, the Selected-scopes family and its permission-inheritance cost, the retired Azure ACS / SharePoint Add-In model, Graph site/drive/list addressing, and SharePoint throttling. Use when asked to get SharePoint OAuth credentials, connect SharePoint Online or OneDrive-for-Business document libraries, set up an Entra app for SharePoint sites, lists or drives, fix a SharePoint connector returning `403 accessDenied`, or migrate off ACS / Add-In auth. Prefer this over the generic Microsoft skill whenever SharePoint sites or `Sites.Selected` are involved. - [microsoft-teams-oauth-app](https://docs.unified.to/skills/microsoft-teams-oauth-app/SKILL.md): Registers a Microsoft Entra ID application for Microsoft Teams access through Microsoft Graph. Builds on the `microsoft-entra-app-registration` base skill; read that first. This skill covers only what Teams adds: the Teams permission families and which ones a tenant admin will approve, the protected export APIs and the metering switched off in August 2025 (plus the licenses that still apply), resource-specific consent and what it cannot reach, application access policies for online meetings, change notifications with resource data, and Teams throttling. Use when asked to get Microsoft Teams OAuth credentials, connect Teams channels, chats, meetings, recordings or transcripts, export Teams messages, fix a Teams connector returning `403 Forbidden` or `402 Payment Required`, or scope a Teams app for a security review. For SharePoint use the SharePoint skill, for mail and calendar the Outlook skill, and for files the OneDrive skill. - [monday-oauth-app](https://docs.unified.to/skills/monday-oauth-app/SKILL.md): Signs in to monday.com and registers an app in the Developer Center to obtain OAuth2 client ID and client secret — with redirect URLs, the per-app-version scope list, the admin-install prerequisite, the two parallel OAuth flows (legacy non-expiring tokens vs the opt-in OAuth 2.1 flow with PKCE and refresh tokens), the dated `API-Version` header, the complexity budget and a safe credential handoff. Use when asked to get monday.com OAuth credentials, create a monday app, pick monday OAuth scopes, rotate a monday client secret, get a monday developer/sandbox account, or debug a monday authorization or API error like `invalid_scope`, `unauthorized_client`, `missingRequiredPermissions`, `USER_ACCESS_DENIED`, `DAILY_LIMIT_EXCEEDED`, `COMPLEXITY_BUDGET_EXHAUSTED`, or "Field ... doesn't exist on type". For any other vendor's developer portal, use that vendor's skill instead. - [netsuite-oauth-app](https://docs.unified.to/skills/netsuite-oauth-app/SKILL.md): Creates a NetSuite integration record and obtains OAuth 2.0 client ID and client secret (the consumer key and consumer secret) for a platform that connects many customers' NetSuite accounts — covering the account that owns the integration record and how it reaches other accounts, the account-specific hostnames, the features and role permissions that must exist before a token works, the three coarse scopes, the seven-day refresh token, and a safe credential handoff. Use when asked to get NetSuite or Oracle NetSuite OAuth credentials, create a NetSuite integration record, set up SuiteTalk REST authentication, rotate a NetSuite client secret, or fix a NetSuite OAuth error like `InvalidRedirectURI`, `UnknownIntegration`, `IntegrationBlocked`, `ScopeMismatched`, `invalid_grant`, `invalid_token` / "Invalid login attempt", or a 403 permission violation on a token that just authorized fine. For any other vendor's developer portal, use that vendor's skill instead. - [notion-oauth-app](https://docs.unified.to/skills/notion-oauth-app/SKILL.md): Creates or signs in to a Notion account and registers a public connection (Notion's OAuth app) in the Notion Developer portal to obtain an OAuth client ID and client secret — with redirect URIs, capabilities, the page-sharing permission model, token and refresh-token behaviour, and a safe credential handoff. Use when asked to get Notion OAuth credentials, create a Notion integration or connection, set up a Notion developer account, choose between an internal and a public Notion integration, rotate a Notion client secret, or debug a Notion connection that authorizes successfully but returns no pages. For any other vendor's developer portal, use that vendor's skill instead. - [pennylane-oauth-app](https://docs.unified.to/skills/pennylane-oauth-app/SKILL.md): Establishes which Pennylane credential a connector actually needs and obtains it — partner-gated OAuth 2.0 client credentials issued by Pennylane's Partnerships team, or the self-serve Company and Firm API tokens each customer generates — with the company-vs-firm consent model, the v2 scope catalogue and the retired `ledger` scope, 24-hour access tokens with rotating 90-day refresh tokens, the v1 sunset and the 2026 behaviour migration, rate limits and a safe credential handoff. Use when asked to get Pennylane OAuth credentials, register a Pennylane app, become a Pennylane technology partner, or fix a Pennylane auth error like a 403 on every call, a 401 after a refresh, a second refresh that fails, or a customer who cannot find the Developers tab. For any other vendor's developer portal, use that vendor's skill instead. - [pipedrive-oauth-app](https://docs.unified.to/skills/pipedrive-oauth-app/SKILL.md): Creates a Pipedrive developer sandbox account and registers an app in Developer Hub to obtain OAuth2 client ID and client secret — with the single-callback-URL constraint, the public-vs-private app decision, app-level scope selection, the per-company api_domain, token and refresh behaviour, Marketplace review and a safe credential handoff. Use when asked to get Pipedrive OAuth credentials, create a Pipedrive app or developer sandbox, pick Pipedrive scopes, refresh a Pipedrive client secret, or fix a Pipedrive install error like "Invalid grant", "redirect_uri is invalid" or a 403 on an endpoint the app should be able to reach. For any other vendor's developer portal, use that vendor's skill instead. - [quickbooks-oauth-app](https://docs.unified.to/skills/quickbooks-oauth-app/SKILL.md): Creates or signs in to an Intuit Developer account and registers a QuickBooks Online app to obtain OAuth2 client ID and client secret — covering the sandbox/production key split, redirect URIs, the `com.intuit.quickbooks.*` scopes, the realmId returned on the callback, rotating refresh tokens, and the app assessment questionnaire that gates production access. Use when asked to get QuickBooks or Intuit OAuth credentials, set up an Intuit developer account, create a QuickBooks app, go live with production keys, rotate a QuickBooks client secret, or fix a QuickBooks OAuth error like `invalid_grant`, `invalid_scope`, a rejected redirect_uri, or a 403 `ApplicationAuthorizationFailed`. For any other vendor's developer portal, use that vendor's skill instead. - [ringcentral-oauth-app](https://docs.unified.to/skills/ringcentral-oauth-app/SKILL.md): Creates or signs in to a RingCentral developer account and registers a REST API app in the Developer Console to obtain a client ID and secret — with the public-vs-private choice that cannot be changed later, the Redirect URI list, the permission catalogue and its approval tickets, the "Issue refresh tokens" toggle that is off by default, the retired sandbox and its replacement, the AT&T Office@Hand / Verizon API host, and per-API-group rate limits. Use when asked to get RingCentral OAuth credentials, create a RingCentral app, work out what production access requires, add a restricted permission like ReadCallRecording, rotate a client secret, or fix a RingCentral error such as `OAU-109 Redirect URIs do not match`, `OAU-146 Invalid client credentials`, `CMN-401`/`InsufficientPermissions`, or a connection that stops refreshing after a week. - [rippling-oauth-app](https://docs.unified.to/skills/rippling-oauth-app/SKILL.md): Establishes how a Rippling OAuth 2.0 client ID and secret is actually obtained — not from a self-serve developer console but from an App Shop partner application that Rippling approves by hand, after which credentials appear inside a partner company's app listing (sandbox pair first, production pair only after beta approval) — and covers the two API generations (legacy V1 vs the current REST API), the scope catalog and its public/private split, the install-not-consent flow, redirect URLs, token and refresh lifetimes, rate limits, test companies, and a symptom-to-cause table. Use when asked to get Rippling OAuth credentials, register a Rippling app, become a Rippling App Shop partner, obtain a Rippling sandbox or test company, help a customer create a Rippling API token, or fix a Rippling auth error like `Invalid Client` on install, a 403 carrying "The token has been revoked", or fields coming back null. For any other vendor's developer portal, use that vendor's skill instead. - [sage-accounting-oauth-app](https://docs.unified.to/skills/sage-accounting-oauth-app/SKILL.md): Creates or signs in to a Sage App Registry account and registers a Sage Accounting app to obtain an OAuth2 client ID and secret — covering the UK/IE/CA country routing that decides which authorization server a customer hits, the `readonly` / `full_access` scopes, the `X-Business` header that picks which business you read, five-minute access tokens with single-use refresh tokens that die after 31 days, and Marketplace validation. Use when asked to get Sage Accounting or Sage Business Cloud Accounting OAuth credentials, set up a Sage App Registry account, create a Sage Accounting app, extend a trial business, rotate a client secret, or fix a Sage OAuth error like `invalid_scope`, `invalid_grant`, an unregistered callback URL, or data from the wrong business. Sage Accounting only: Sage Intacct, Sage 50/100/200, Sage X3 and Sage Active are different products with different portals. - [sage-intacct-oauth-app](https://docs.unified.to/skills/sage-intacct-oauth-app/SKILL.md): Registers a Sage Intacct application in the Sage developer console and obtains an OAuth 2.0 client ID and secret for a platform that connects many customers' Intacct companies — covering the Web Services license (sender ID and password) required to register at all, the immutable Production/Non-production client scope, the per-customer Web Services subscription and sender-ID authorization, the `offline_access` scope, entity context in multi-entity companies, and a safe credential handoff. Use when asked to get Sage Intacct OAuth credentials, register an Intacct application, obtain a Web Services sender ID, set up the Intacct REST API, rotate a client secret, or fix an Intacct error like `GW-0011`, `GW-0031`, `XL03000006` "Invalid Web Services Authorization", a 401 or 403 on a fresh token, or data from the wrong entity. Sage Intacct only; for Sage Accounting use `sage-accounting-oauth-app`. - [salesforce-oauth-app](https://docs.unified.to/skills/salesforce-oauth-app/SKILL.md): Creates a Salesforce Developer Edition org and registers an External Client App (the successor to Connected Apps) to obtain OAuth2 consumer key and consumer secret — with callback URLs, scopes, the mandatory PKCE / refresh-token-rotation / TTL / IP-binding controls, the uninstalled-app restriction, and a safe credential handoff. Use when asked to get Salesforce OAuth credentials, create a Salesforce connected app or external client app, set up a Salesforce developer org, rotate a Salesforce consumer secret, or fix a Salesforce OAuth error like `redirect_uri_mismatch`, `invalid_client_id`, or a customer who suddenly cannot authorize. For any other vendor's developer portal, use that vendor's skill instead. - [servicenow-oauth-app](https://docs.unified.to/skills/servicenow-oauth-app/SKILL.md): Produces working ServiceNow OAuth 2.0 credentials — an OAuth application registry entry, redirect URL, client ID and client secret — for a platform that connects many customers' ServiceNow instances. Covers the fact that decides the whole shape of the task: the registry lives inside each customer's own instance, so every customer generates their own client ID and secret and there is no central or shared ServiceNow OAuth client to obtain. Use when asked to get ServiceNow OAuth credentials, create a ServiceNow OAuth API endpoint for external clients, write the admin runbook a customer follows to produce them, pick the instance subdomain a connection needs, choose the role for a ServiceNow integration user, set up a Personal Developer Instance for testing, rotate a ServiceNow client secret, or debug a ServiceNow authorization that succeeds and then returns fewer records than the table holds. For any other vendor's developer portal, use that vendor's skill instead. - [shopify-oauth-app](https://docs.unified.to/skills/shopify-oauth-app/SKILL.md): Creates or signs in to a Shopify partner/developer organization and registers a Shopify app to obtain OAuth2 client ID and client secret — with the right app type and distribution, redirect URLs, access scopes, protected customer data approval, offline access tokens, HMAC verification, the mandatory compliance webhooks, and a safe credential handoff. Use when asked to get Shopify OAuth credentials, create a Shopify app or partner account, rotate a Shopify client secret, pick between a public and a custom app, or fix a Shopify install error like `redirect_uri is not whitelisted`, `invalid_request`, an unsigned callback, or customer data coming back null. For any other vendor's developer portal, use that vendor's skill instead. - [slack-oauth-app](https://docs.unified.to/skills/slack-oauth-app/SKILL.md): Creates a Slack app and obtains OAuth2 client ID and client secret — with the right redirect URLs, bot vs user token scopes, public distribution, and a safe credential handoff. Use when asked to get Slack OAuth credentials, create or configure a Slack app, set up Slack scopes, activate Slack public distribution, rotate a Slack client secret or signing secret, or fix a Slack install error like `bad_redirect_uri` or `invalid_scope`. For any other vendor's developer portal, use that vendor's skill instead. - [smartrecruiters-oauth-app](https://docs.unified.to/skills/smartrecruiters-oauth-app/SKILL.md): Establishes which SmartRecruiters credential a connector actually needs and obtains it — customer-generated SmartToken API keys and customer-generated OAuth Client Credentials (both self-serve, Administrator-only, per-company), the partner-gated General Partner Integration that replaced the now-deprecated Authorization Code flow, and legacy Partner API Keys — with the scope catalogue, the System role rule, rate limits and a safe credential handoff. Use when asked to get SmartRecruiters OAuth credentials or an API key, register a SmartRecruiters app, become a SmartRecruiters partner, get listed on the SmartRecruiters Marketplace, or fix a SmartRecruiters auth error like a 401 on every call, a 403 on users or audit endpoints, an `OAuthPermissionsException`, a connection that dies after 28 idle days, or `429` under light load. For any other vendor's developer portal, use that vendor's skill instead. - [stripe-oauth-app](https://docs.unified.to/skills/stripe-oauth-app/SKILL.md): Registers a Stripe App (the current model) or a legacy Connect OAuth application to obtain Stripe OAuth credentials — client ID, client secret, permissions, redirect URIs, app review, and a safe credential handoff. Use when asked to get Stripe OAuth credentials, connect customer Stripe accounts, build a Stripe integration or Stripe App, set up a Connect extension, rotate a Stripe secret key, or fix a Stripe authorization error like `invalid_grant`, `invalid_client`, or a connector that reads an empty account. For any other vendor's developer portal, use that vendor's skill instead. - [tiktok-oauth-app](https://docs.unified.to/skills/tiktok-oauth-app/SKILL.md): Registers an app in the TikTok for Developers portal to obtain OAuth2 credentials — the client key (TikTok's name for the client ID) and client secret — for Login Kit, the Display API and the Content Posting API, including sandbox testing, per-scope app review, exact-match redirect URIs, and a safe credential handoff. Use when asked to get TikTok OAuth credentials, create a TikTok developer app, add or get approval for a TikTok scope, rotate a TikTok client secret, or fix a TikTok authorization error. This covers the consumer TikTok app only — TikTok ads/marketing credentials live in the separate TikTok API for Business portal and TikTok Shop credentials in the separate TikTok Shop Partner Center; use the skill for those portals instead. For any other vendor's developer portal, use that vendor's skill instead. - [trackerrms-oauth-app](https://docs.unified.to/skills/trackerrms-oauth-app/SKILL.md): Establishes which TrackerRMS credential a connector actually needs and obtains it — the customer-generated bearer token from Tools & Settings (self-serve, one per database, regenerating kills the old one) or the OAuth 2.0 authorization-code flow whose client secret TrackerRMS issues on request — plus the mandatory token-for-JWT exchange step, the three regional host pairs, the read/write scope pair, rate limits, sandbox access and a safe credential handoff. Use when asked to get TrackerRMS (Tracker) API credentials, register a TrackerRMS OAuth app, find a Tracker access token, or fix a Tracker auth error like a 401 on every call, a connection that died when another integration was set up, or calls hitting the wrong regional host. For any other vendor's developer portal, use that vendor's skill instead. - [unified-accounting-invoicing](https://docs.unified.to/skills/unified-accounting-invoicing/SKILL.md): Build invoicing, billing, and bookkeeping features against many accounting platforms (QuickBooks, Xero, NetSuite, Sage, FreshBooks, and more) through the single Unified.to Accounting API. Use when a coding task involves creating or syncing invoices, bills, contacts, accounts, payments, or financial reports across one or more accounting systems. - [unified-api](https://docs.unified.to/skills/unified-api/SKILL.md): Build against the Unified.to API — the REST fundamentals shared by every category (CRM, ATS, HRIS, accounting, commerce, messaging, ticketing, and more). Use when a coding task calls the Unified.to API directly and needs the request shape, authentication, connections, pagination, filtering, field selection, and error handling that apply across all 1,000+ integrations. - [unified-assessment](https://docs.unified.to/skills/unified-assessment/SKILL.md): Build assessment and background-check products that plug into Applicant Tracking Systems (Workable, Ashby, Greenhouse, and more) through the single Unified.to Assessment API. Use when a coding task involves publishing assessment packages to an ATS, receiving assessment orders via webhooks, and submitting results back so recruiters see them inside their ATS. - [unified-ats-jobboard](https://docs.unified.to/skills/unified-ats-jobboard/SKILL.md): Build candidate-sourcing, recruiting, and job-board features against many Applicant Tracking Systems (Greenhouse, Lever, Workable, Ashby, Bullhorn, and more) through the single Unified.to ATS API. Use when a coding task involves reading jobs, creating or updating candidates and applications, tracking application status, or attaching documents across one or more ATS platforms. - [unified-auth-signin](https://docs.unified.to/skills/unified-auth-signin/SKILL.md): Add "Sign in with …" to an application using the Unified.to Authentication API, so users log in with Google, Microsoft, and other OAuth2 or SAML providers and are verified by a signed JWT. Use when a coding task involves social login, single sign-on (SSO), or verifying a user's identity via a third party — not creating data connections. - [unified-calendar](https://docs.unified.to/skills/unified-calendar/SKILL.md): Build scheduling and calendar features against many calendar providers (Google Calendar, Microsoft Outlook, Zoom, and more) through the single Unified.to Calendar API. Use when a coding task involves reading or creating calendars and events, checking availability / busy times, or generating scheduling links and webinars across one or more providers. - [unified-crm](https://docs.unified.to/skills/unified-crm/SKILL.md): Build CRM and sales-automation features against many CRMs (HubSpot, Salesforce, Pipedrive, Zoho, HighLevel, and more) through the single Unified.to CRM API. Use when a coding task involves reading or writing contacts, companies, deals, leads, or pipelines, or two-way syncing sales data across one or more CRM platforms. - [unified-debug-webhooks-connections](https://docs.unified.to/skills/unified-debug-webhooks-connections/SKILL.md): Diagnose and fix unhealthy Unified.to connections and webhooks: interpret connection health statuses, read API call logs, resolve 401/403/404/429/5xx errors, validate webhook signatures, and understand native vs virtual webhook retry behavior. Use when a connection stops returning data, a webhook is not firing or is marked unhealthy, or webhook signature validation is failing. - [unified-ecommerce](https://docs.unified.to/skills/unified-ecommerce/SKILL.md): Build e-commerce and product-catalog features against many commerce platforms (Shopify, WooCommerce, Amazon Seller Central, Walmart, and more) through the single Unified.to Commerce API. Use when a coding task involves syncing products, variants, collections, inventory levels, locations, or sales channels across one or more storefronts. - [unified-enterprise-search-rag](https://docs.unified.to/skills/unified-enterprise-search-rag/SKILL.md): Build enterprise search and Retrieval-Augmented Generation (RAG) pipelines that ingest documents from many sources (Google Drive, SharePoint, Notion, Confluence, and more) through the single Unified.to Storage and KMS APIs. Use when a coding task involves pulling files, pages, or knowledge-base content into a vector store to ground an LLM, and keeping that index fresh in real time. - [unified-hris](https://docs.unified.to/skills/unified-hris/SKILL.md): Build HR, people-data, and payroll features against many HRIS platforms (Workday, BambooHR, Gusto, Deel, HiBob, and more) through the single Unified.to HRIS API. Use when a coding task involves syncing employees, groups, time off, attendance, or payroll data across one or more HR systems. - [unified-messaging](https://docs.unified.to/skills/unified-messaging/SKILL.md): Build chat, bot, and notification features against many messaging platforms (Slack, Microsoft Teams, Discord, Telegram, and more) through the single Unified.to Messaging API. Use when a coding task involves sending or reading messages, listing channels, or building a support/notification bot across one or more chat platforms. - [unified-payments](https://docs.unified.to/skills/unified-payments/SKILL.md): Build payments and fintech features against many payment providers (Stripe, GoCardless, Square, and more) through the single Unified.to Payment API. Use when a coding task involves accepting one-time payments, managing subscriptions, generating payment links, or reconciling payouts and refunds across one or more payment platforms. - [unified-quickstart](https://docs.unified.to/skills/unified-quickstart/SKILL.md): Add Unified.to integrations to an app: activate integrations in the Sandbox, embed the Authorization component, store connection IDs, make the first Unified API call with an official SDK, and (optionally) subscribe to webhooks. Use when a developer asks to "add Unified.to", "add integrations with HubSpot / Salesforce / Greenhouse / BambooHR / QuickBooks / …", or to connect their product to their customers' SaaS apps through one API. - [unified-sdks](https://docs.unified.to/skills/unified-sdks/SKILL.md): Use the official Unified.to SDKs (TypeScript, Python, PHP, Java, Go, C#, Ruby) to call the Unified.to API from code instead of hand-rolling HTTP. Use when a coding task should install and call a typed SDK — client construction and JWT auth, method naming, request/response shapes, pagination and filtering, retries, and error handling — across any API category. - [unified-ticketing](https://docs.unified.to/skills/unified-ticketing/SKILL.md): Build helpdesk, support-desk, and issue-tracking features against many ticketing platforms (Zendesk, Jira, Freshdesk, ServiceNow, and more) through the single Unified.to Ticketing API. Use when a coding task involves creating or syncing tickets, customers, notes, or categories across one or more support systems. - [workable-oauth-app](https://docs.unified.to/skills/workable-oauth-app/SKILL.md): Establishes which Workable credential a connector actually needs and obtains it — customer-generated API access tokens (self-serve, Admin-only, expiring), partner tokens, or partner-gated OAuth 2.0 authorization-code credentials issued by Workable — with the subdomain/account model, the scope list, the member_id permission trap, rate limits and a safe credential handoff. Use when asked to get Workable OAuth credentials or an API token, register a Workable app, become a Workable integration partner, or fix a Workable auth error like a 401 on every call, an empty employee list, a token that expired, or `429` under light load. For any other vendor's developer portal, use that vendor's skill instead. - [workday-oauth-app](https://docs.unified.to/skills/workday-oauth-app/SKILL.md): Obtains working Workday OAuth 2.0 credentials for a multi-tenant connector — where the client ID and secret are registered by each customer's own Workday administrator inside their own tenant, not by you in a central developer portal. Covers the Register API Client and Register API Client for Integrations tasks, the tenant-specific authorize/token/API hosts, functional-area scopes and the domain security policies underneath them, the Integration System User and security group model that decides whether a valid token returns data or nothing, non-expiring refresh tokens, tenant refreshes, RaaS, and the REST-vs-SOAP fork. Use when asked to get Workday OAuth credentials, write the Workday onboarding runbook for a customer admin, pick between Workday's REST and SOAP integration paths, or fix a Workday error like a 401 Invalid Access Token, a 403 Not Authorized, an S21 404 on a worker sub-resource, or a sync that returns an empty tenant. For any other vendor's developer portal, use that vendor's skill instead. - [xero-oauth-app](https://docs.unified.to/skills/xero-oauth-app/SKILL.md): Creates or signs in to a Xero developer account and registers a Xero OAuth2 app to obtain a client ID and client secret — with redirect URIs, the accounting/payroll/files scope families, the tenant (organisation) indirection, the tiered connection ceiling and certification gates, and a safe credential handoff. Use when asked to get Xero OAuth credentials, set up a Xero developer account, create a Xero app or custom connection, rotate a Xero client secret, or fix a Xero error like `invalid_grant`, `AuthenticationUnsuccessful`, an invalid-scope authorize screen, or a customer who cannot connect because the app hit its connection limit. For any other vendor's developer portal, use that vendor's skill instead. - [zendesk-oauth-app](https://docs.unified.to/skills/zendesk-oauth-app/SKILL.md): Registers a Zendesk OAuth client to obtain a client ID (unique identifier) and client secret — covering the one thing that decides whether a multi-tenant connector works at all: a normal Zendesk OAuth client lives inside a single Zendesk account and only authorizes that one subdomain, so connecting many customers requires a global OAuth client, which Zendesk grants by request and not self-serve. Use when asked to get Zendesk OAuth credentials, create a Zendesk OAuth client, request or claim a Zendesk global OAuth client, set up a d3v- sponsored developer account, rotate a Zendesk client secret, or fix a Zendesk authorization error such as invalid_scope, an unrecognised client on a customer's subdomain, or "works on our Zendesk, fails on theirs". For any other vendor's developer portal, use that vendor's skill instead. - [zoho-api-console-oauth](https://docs.unified.to/skills/zoho-api-console-oauth/SKILL.md): The shared Zoho API Console mechanics behind every Zoho OAuth2 registration — Server-based vs Self Client vs JavaScript client types, the multi-data-centre domain model and the Multi DC toggle that lets one client ID serve every region, the per-DC client secret, the location / accounts-server parameters on the callback, redirect-URI rules, the comma-delimited scope.operation grammar, access_type=offline plus prompt=consent, the Zoho-oauthtoken header, the 20-refresh-tokens-per-user cap that silently revokes the oldest connection, and rate limits as a per-organization concept. Read this first when registering any Zoho OAuth client; the product skills (Zoho CRM, Zoho Books, Zoho Recruit) build on it and cover only what their product adds. Use directly when the task is a plain Zoho OAuth client with no particular Zoho product named. - [zoho-books-oauth-app](https://docs.unified.to/skills/zoho-books-oauth-app/SKILL.md): The Zoho Books layer on top of the shared `zoho-api-console-oauth` skill — the Books scope families and the absence of a documented full-access scope, the `organization_id` parameter required on every single API call and the two ways to discover it, why a multi-organization customer breaks a connector that picks the first one, the country-edition model that gates whole endpoint families and cannot be changed after signup, the per-organization request and concurrency limits, and the Books / Invoice / Inventory surface split where three products share one data model but not one scope namespace. Use when asked to get Zoho Books OAuth credentials, choose Zoho Books scopes, debug a Books call that authorizes but returns nothing, or decide whether an integration belongs against Books, Invoice or Inventory. Read `zoho-api-console-oauth` first for the console and data-centre mechanics; use the Zoho CRM or Zoho Recruit skill for those products. - [zoho-crm-oauth-app](https://docs.unified.to/skills/zoho-crm-oauth-app/SKILL.md): The Zoho CRM layer on top of the shared `zoho-api-console-oauth` skill — the CRM scope families (modules, settings, users, org, bulk, coql, notifications) and the two-level module scope grammar, standard versus custom modules and why the module list must be discovered at run time, the v2-to-v8 API version ladder and what the version in your URL actually changes, the Production / Sandbox / Developer environment split that makes every token organization-specific, and the credit-and-concurrency limit model that belongs to the customer's org rather than to your client. Use when asked to get Zoho CRM OAuth credentials, choose Zoho CRM scopes, debug a Zoho CRM authorization or INVALID_OAUTHTOKEN error, or explain why a Zoho CRM connection cannot see a module. Read `zoho-api-console-oauth` first for the console and data-centre mechanics; use the Zoho Books or Zoho Recruit skill for those products. - [zoho-people-oauth-app](https://docs.unified.to/skills/zoho-people-oauth-app/SKILL.md): The Zoho People layer on top of the shared `zoho-api-console-oauth` skill — the forms/record data model where employee data lives in customer-configured forms addressed by formLinkName, so what the `forms` scope returns depends on configuration and the authorizing user's role; the documented and undocumented scope families; the three API generations and the `/people/api/` versus `/api/` path split; the `people.zoho.*` hosts that `api_domain` does not give you; the organization date format; and the per-endpoint threshold-and-lock rate model. Use when asked to get Zoho People OAuth credentials, choose Zoho People scopes, debug a People call returning 400 with code 7202 or an empty record set, or explain why one customer's form is invisible. Read `zoho-api-console-oauth` first for the console and data-centre mechanics; use the Zoho CRM or Zoho Books skill for those products. - [zoho-recruit-oauth-app](https://docs.unified.to/skills/zoho-recruit-oauth-app/SKILL.md): The Zoho Recruit layer on top of the shared `zoho-api-console-oauth` skill — the Recruit scope families and the singular-versus-plural module-name inconsistency that makes scope strings fail, the candidate / job-opening / application / interview module model and the Staffing Agency versus Corporate HR edition split that decides which modules exist at all, the dedicated `recruit.zoho.*` API host that disagrees with the `api_domain` the token response returns, the five-refresh-tokens-per-minute ceiling, and the credit model whose concurrency limit is counted per user rather than per organization. Use when asked to get Zoho Recruit OAuth credentials, choose Zoho Recruit scopes, debug an invalid-scope or wrong-host error on a Recruit connection, or explain why a Recruit integration cannot see clients or a custom module. Read `zoho-api-console-oauth` first for the console and data-centre mechanics; use the Zoho CRM or Zoho Books skill for those products. - [zoom-oauth-app](https://docs.unified.to/skills/zoom-oauth-app/SKILL.md): Creates or signs in to a Zoom developer-enabled account and registers a General (OAuth) app on the Zoom App Marketplace to obtain client ID and client secret — with the OAuth allow list, admin-managed vs user-managed choice, granular scopes, the separate development and production credential pairs, the deauthorization endpoint requirement, the private/beta install caps, and Marketplace review. Use when asked to get Zoom OAuth credentials, create a Zoom Marketplace app, choose between a General app and a Server-to-Server OAuth app, migrate a Zoom app from classic to granular scopes, rotate a Zoom client secret, or fix a Zoom error like `Invalid redirect`, `invalid_client`, or a customer whose Zoom connection stops refreshing. For Zoom Phone scopes specifically, read this file and then `zoom-phone-oauth-app`. For any other vendor's developer portal, use that vendor's skill instead. - [zoom-phone-oauth-app](https://docs.unified.to/skills/zoom-phone-oauth-app/SKILL.md): The Zoom Phone layer on top of the shared `zoom-oauth-app` skill — the Zoom Phone license and account-plan prerequisite that makes every phone endpoint 403 without it, the `phone:` granular scope family and its admin/user split, the call-log APIs sunset in June 2025 and the call-history APIs that replaced them, recording and transcript scopes, and Zoom Phone's own rate-limit table. Use when asked to get OAuth credentials for Zoom Phone, add phone scopes to a Zoom Marketplace app, work out why Zoom Phone endpoints 403 for one customer, or decide which call-log generation to call. Read `zoom-oauth-app` first for the Marketplace mechanics; use that skill alone when the integration is Zoom meetings, users, groups or Team Chat rather than Phone. ## Tutorials - [Build a simple Javascript app that calls the Unified.to API](https://docs.unified.to/tutorials/build-a-simple-javascript-app.md) - [Customize your authorization flow with the Unified API](https://docs.unified.to/tutorials/customize-auth-flow.md) ## API Reference - [Data Types](https://docs.unified.to/reference/datatypes.md) - [Working with Custom & Original Fields](https://docs.unified.to/reference/fields.md) - [Mock API Server](https://docs.unified.to/reference/mock.md) - [Pagination](https://docs.unified.to/reference/pagination.md) - [Rate limits](https://docs.unified.to/reference/rate_limits.md) - [REST API](https://docs.unified.to/reference/rest.md) - [SDKs](https://docs.unified.to/reference/sdks.md) - [Slow fields](https://docs.unified.to/reference/slow-fields.md) - [Introduction to webhooks](https://docs.unified.to/reference/webhooks.md) ## API Category Overviews - [accounting](https://docs.unified.to/accounting/overview.md) - [ads](https://docs.unified.to/ads/overview.md) - [analytics](https://docs.unified.to/analytics/overview.md) - [assessment](https://docs.unified.to/assessment/overview.md) - [ats](https://docs.unified.to/ats/overview.md) - [auth](https://docs.unified.to/auth/overview.md) - [calendar](https://docs.unified.to/calendar/overview.md) - [cdp](https://docs.unified.to/cdp/overview.md) - [clubs](https://docs.unified.to/clubs/overview.md) - [commerce](https://docs.unified.to/commerce/overview.md) - [compute](https://docs.unified.to/compute/overview.md) - [crm](https://docs.unified.to/crm/overview.md) - [datastore](https://docs.unified.to/datastore/overview.md) - [enrich](https://docs.unified.to/enrich/overview.md) - [forms](https://docs.unified.to/forms/overview.md) - [genai](https://docs.unified.to/genai/overview.md) - [hris](https://docs.unified.to/hris/overview.md) - [kms](https://docs.unified.to/kms/overview.md) - [legal](https://docs.unified.to/legal/overview.md) - [lms](https://docs.unified.to/lms/overview.md) - [martech](https://docs.unified.to/martech/overview.md) - [messaging](https://docs.unified.to/messaging/overview.md) - [metadata](https://docs.unified.to/metadata/overview.md) - [passthrough](https://docs.unified.to/passthrough/overview.md) - [payment](https://docs.unified.to/payment/overview.md) - [performance](https://docs.unified.to/performance/overview.md) - [repo](https://docs.unified.to/repo/overview.md) - [scim](https://docs.unified.to/scim/overview.md) - [shipping](https://docs.unified.to/shipping/overview.md) - [signing](https://docs.unified.to/signing/overview.md) - [social](https://docs.unified.to/social/overview.md) - [storage](https://docs.unified.to/storage/overview.md) - [task](https://docs.unified.to/task/overview.md) - [ticketing](https://docs.unified.to/ticketing/overview.md) - [uc](https://docs.unified.to/uc/overview.md) - [unified](https://docs.unified.to/unified/overview.md) - [verification](https://docs.unified.to/verification/overview.md) ## MCP (Model Context Protocol) - [additional api endpoints](https://docs.unified.to/mcp/additional-api-endpoints.md) - [authentication](https://docs.unified.to/mcp/authentication.md) - [changelog](https://docs.unified.to/mcp/changelog.md) - [core](https://docs.unified.to/mcp/core.md) - [installation](https://docs.unified.to/mcp/installation.md) - [overview](https://docs.unified.to/mcp/overview.md) - [server options](https://docs.unified.to/mcp/server-options.md) ## Migrate to Unified.to - [Migrate from Apideck to Unified.to](https://docs.unified.to/migrate/apideck.md) - [Migrate from Finch to Unified.to](https://docs.unified.to/migrate/finch.md) - [Migrate from Kombo to Unified.to](https://docs.unified.to/migrate/kombo.md) - [Migrate from Merge to Unified.to](https://docs.unified.to/migrate/merge.md) - [Migrate to Unified.to](https://docs.unified.to/migrate/overview.md) - [Migrate from Rutter to Unified.to](https://docs.unified.to/migrate/rutter.md) ## Glossary - [Access Token](https://docs.unified.to/concepts/glossary/access_token.md) - [API](https://docs.unified.to/concepts/glossary/api.md) - [API Key](https://docs.unified.to/concepts/glossary/api_key.md) - [API Request / Call](https://docs.unified.to/concepts/glossary/api_request_call.md) - [ATS](https://docs.unified.to/concepts/glossary/ats.md) - [Authentication](https://docs.unified.to/concepts/glossary/authentication.md) - [Authorization](https://docs.unified.to/concepts/glossary/authorization.md) - [Bearer Token](https://docs.unified.to/concepts/glossary/bearer_token.md) - [Candidate](https://docs.unified.to/concepts/glossary/candidate.md) - [Client ID / Secret](https://docs.unified.to/concepts/glossary/client_id_secret.md) - [Connection](https://docs.unified.to/concepts/glossary/connection.md) - [Connection ID](https://docs.unified.to/concepts/glossary/connection_id.md) - [CRM](https://docs.unified.to/concepts/glossary/crm.md) - [Data Model](https://docs.unified.to/concepts/glossary/data_model.md) - [Endpoint](https://docs.unified.to/concepts/glossary/endpoint.md) - [Environment](https://docs.unified.to/concepts/glossary/environment.md) - [ETL](https://docs.unified.to/concepts/glossary/etl.md) - [GDPR](https://docs.unified.to/concepts/glossary/gdpr.md) - [Generative AI](https://docs.unified.to/concepts/glossary/generative_ai.md) - [HRIS](https://docs.unified.to/concepts/glossary/hris.md) - [ID Token](https://docs.unified.to/concepts/glossary/id_token.md) - [Integration](https://docs.unified.to/concepts/glossary/integration.md) - [iPaaS](https://docs.unified.to/concepts/glossary/ipaas.md) - [Item / Product](https://docs.unified.to/concepts/glossary/item_product.md) - [KMS](https://docs.unified.to/concepts/glossary/kms.md) - [OAuth 2](https://docs.unified.to/concepts/glossary/oauth_2.md) - [Passthrough](https://docs.unified.to/concepts/glossary/passthrough.md) - [Refresh Token](https://docs.unified.to/concepts/glossary/refresh_token.md) - [Request](https://docs.unified.to/concepts/glossary/request.md) - [Response](https://docs.unified.to/concepts/glossary/response.md) - [REST](https://docs.unified.to/concepts/glossary/rest.md) - [Sandbox](https://docs.unified.to/concepts/glossary/sandbox.md) - [Schema](https://docs.unified.to/concepts/glossary/schema.md) - [SCIM](https://docs.unified.to/concepts/glossary/scim.md) - [Scopes](https://docs.unified.to/concepts/glossary/scopes.md) - [Unified API](https://docs.unified.to/concepts/glossary/unified_api.md) - [Unified Data Model](https://docs.unified.to/concepts/glossary/unified_data_model.md) - [User ID](https://docs.unified.to/concepts/glossary/user_id.md) - [Webhook](https://docs.unified.to/concepts/glossary/webhook.md) - [Workspace](https://docs.unified.to/concepts/glossary/workspace.md) ## OpenAPI Specification - [Swagger/OpenAPI JSON](https://api.unified.to/swagger.json): Complete Swagger 2.0 (OpenAPI 2.0) specification for all endpoints