nectry / documentation

NectryCore reference

Every building block an agent can use when it writes a NectryCore app, generated from the live platform on each deploy.

Concepts

Top-level building blocks of an app (pages, tables, background tasks, actions, …). Each concept entry shows its description and the ingredient slots it exposes, each naming the ingredient family that can fill it.

API Tester

Developer tool: display the raw response of an API call for use while building or refining a service binding. Not intended for end-user apps.

no ingredient slots

API Upload Tester

Developer tool: upload a file to an API while building or refining a service binding. Not intended for end-user apps.

no ingredient slots

Action Button

Run a pre-defined action when the user presses a button.

Add Row Form

Allow a user to add a row to a table by filling in a form displayed directly on the page, and the form is very customizable.

Add Row Modal

Allow a user to add a row to a table by opening a form in a modal, accessed through a button, and the form is very customizable.

Approval Flow Table

An advanced version of the ‘Table View’ component. This is very similar to the ‘Managed Data Table’ component, but is specifically designed for approval flow. In addition to just displaying the table, this component allows the creator to specify: a ‘status’ column which dictates whether the row is approved or rejected, exactly which rows of the table to be shown (via a custom SQL query), a custom form for adding/modifying rows, and permissions for adding, modifying, and/or deleting rows of the table. Note that this component requires that the table have a key column. The primary add button uses the text Add followed by the table’s labelSingular when set on the table; otherwise it uses the table name.

Background Task

Run a periodic task in the background. Note that this module still must be included as a module in a tab of a handler, and it will display a toggle switch for whether the task is active or not (often suitable for a settings tab/page).

CSV Export

Generate a CSV file containing exactly the entries from a Nectry table.

no ingredient slots

CSV Import

Import all the entries of a CSV file into one or more Nectry tables.

Calendar

Populate a readonly calendar with events from a table

Chart

Chart the results of a database query. Use this for all charts, plots, and graphs.

no ingredient slots

Chat

An AI chat panel that can only be attached to a handler’s chat field; it is not a reusable tab-segment module

Data Migration

This concept is your default choice for converting data from one schema to another. Use it when the user asks about mapping data, transforming data, translating data, reformatting data, etc. We start with two primary SQL tables, source and destination, translating rows between them. However, in general, the concept supports copying related rows that have foreign keys into the primary rows. In fact, it is best practice to include as subtables ALL tables with foreign keys into the primary ones.

Display Text

Display static richtext content to the user.

no ingredient slots

Editable Spreadsheet

Show a simple, editable spreadsheet-style view of a Nectry table.

no ingredient slots

Input Panel

Presents a set of input and output data fields to the user, and the data fields are very customizable.

MCP Server

A group of tools a Model Context Protocol server offers. External MCP clients (Claude, Cursor, …) authenticate with an access token from the app’s identity provider and call the configured tools directly. Not a page: it renders nothing and is not referenced from any tab.

Managed Data Table

An advanced version of the ‘Table View’ component. In addition to just displaying the table, this component allows the creator to specify: exactly which rows of the table to be shown (via a custom SQL query), a custom form for adding/modifying rows, and permissions for adding, modifying, and/or deleting rows of the table. Note that this component requires that the table have a key column. The primary add button uses the text Add followed by the table’s labelSingular when set on the table; otherwise it uses the table name.

Map

Render rows of a table as markers on an interactive geographic map. Use this whenever the user wants to see records placed on a world/regional map.

no ingredient slots

Metrics Card

Use a SQL query that returns exactly one row, then show chosen columns as labeled metrics with semantic HTML formatting. Prefer this when each metric should read as a structured label or value pair rather than free-form richtext.

Searchable Table

Show the results of a query that retrieves data from the application’s SQL schema.

Table-Backed Input Panel

Presents a set of input and output data fields to the user, and the data fields are very customizable.

Time Series Scaffold

Fill a data table with every time in a sequence. A canonical use is supporting a chart where the x-axis shows a time series, like every month in the last year. Some elements in the series may have no associated rows for us to aggregate, and those elements will be dropped if we use SQL joins naively. If we instead prepopulate an SQL table with all valid x-axis values, a simple join works to cover the full sequence.

Ingredient Families

Named menus of interchangeable ingredients. When a slot references a family, you pick one or more ingredients from that family to fill the slot. Each ingredient shows its description plus any sub-slots it nests (which work the same way, recursively).

Any ingredient may carry disabled: true alongside its kind. A disabled ingredient is kept in the spec, not deleted, and is still checked like any other – it must still name tables and APIs that exist – but it builds nothing: no code, no tool the LLM can call, no permission the app asks for. That is how you turn an LLM query tool off without losing the rules configured on it.

An ingredient that contributes an LLM tool may also carry name: alongside its kind: the advertised tool name, replacing the default derived from what the tool acts on (1-64 characters of letters, digits, underscore, or hyphen; a tool that derives companion names off its own, such as a lookup’s _distinct_values twin, needs the name to fit the cap with the suffix appended). Use it to give a tool a client-facing name, or to tell apart two tools on the same subject, such as two lookups on one table with different row filters. A named entry also fills the Tool kind’s toolName: setting – so write that setting alongside a name: only to have the tool’s own summary read differently from its advertised name. A Tool with neither takes its name from its pipeline: a sole API call, send, or draft step names the tool after itself, and any other pipeline must be named explicitly.

Every LLM tool is read as the list of steps it runs – a table tool’s guards: and its own read or write, a Tool’s whole pipeline – and that list decides its risk category: read-only if nothing it does changes anything, destructive if it deletes, sends, or calls an API that has not been annotated, write otherwise. An unrecognized step counts as a write, one that dispatches a bag of tools of its own (an Ask an LLM step) counts as destructive, and an API call nothing describes counts as destructive too, so a tool claims safety only by saying so: readOnlyHint: true is taken at its word, and destructiveHint: false downgrades a destructive tool to a write. That same category supplies the default for requiresApproval: inside a Chat concept, where there is someone to ask, any tool that is not read-only pauses unless the knob says otherwise – so a tool annotated read-only is never gated by a step it has already claimed is harmless. Elsewhere nobody is watching, so only a requiresApproval the spec writes turns the pause on – and writing one where it cannot be honored is an error (a warning under MCP). It supplies the annotations themselves as well: a tool that leaves readOnlyHint or destructiveHint unset is advertised as whatever its category makes it, and an unset openWorldHint is true exactly when some step calls an API, sends, or is one nothing here recognizes.

One tool’s reads are named by the schema rather than by the tool. Query with SQL takes a SELECT statement from the model and runs it over exactly the tables and columns the spec tagged sqlQuery – on the table’s own tags: and on each column’s, deny by default at both levels, so the tool opens nothing until the schema says what it opens, and a module holding the tool while nothing is tagged is an error. The tags describe the schema and not any one module, so every module holding such a tool reads the same exposure: tag only what every caller of every one of them may read. The tool’s steps say so table by table – one read <table> apiece, exactly the tables the tags open – so its risk category and its card read like any other table reader’s. Nothing else reads those tags: a query written into a module’s query: setting or into a row action’s step is checked against the whole schema as always.

An LLM tool’s description is capped at 300 characters, because the rules its own settings enforce – each guard’s refusal message, a recipient pattern, an approval pause – are appended to it automatically: write a short statement of purpose and let the settings speak for themselves. A rule the server cannot decide belongs in advisory: instead, which reaches the model under a “not enforced” header and is shown on the tool’s card as not guaranteed; the checker warns wherever one is set.

Every tool also has a title, the human-readable name an MCP client shows in place of the wire name: its toolTitle: setting, or derived from the wire name when unset (search_open_orders is “Search Open Orders”). A model never sees it. Two tools in one module cannot share a title, derived ones included: lookup_orders and lookupOrders both derive “Lookup Orders”, and the checker rejects the pair until one sets toolTitle:.

Any ingredient except a row filter may carry category:, a free-text label that groups adjacent same-labeled entries in Nectry’s spec views – entries never move, since list order can be meaningful; it is internal display metadata and never reaches a model or an MCP client. Row filter entries take neither name: nor category:, even though they are written with the same kind + settings shape.

An ingredient that contributes an LLM tool may also carry roles: alongside its kind, with three cases. Absent, the tool is served to every caller the module admits. roles: [] serves it to nobody, the closed reading of an empty list, and the checker warns. A list of role names, declared by the authenticator of the handler serving the module, serves it only to a caller holding any one of them: anyone else finds the tool absent from the list the model or MCP client sees, and calling it anyway is answered as an unknown tool. Inside an Ask an LLM step’s queryTools the caller is the user the step runs for. roles: on an entry that contributes no tool, or a named list in a module no authenticated handler serves, is an error.

calendarIngredients

Features to enable for a calendar, allowing you to specify, e.g., how to show events in the calendar.

  • Event source (query) – Provide a SQL query that returns a row for each event. Then describe how to make an event from the row.
    no ingredient slots

caseBranchIngredients

The branches of a Case step: one set of actions per value the column it dispatches on may hold.

csvImportFieldIngredients

Options for customizing the import of CSV fields into a table

  • Assign unique ID – A table column should be assigned a unique ID, rather than pulling it from the CSV file.
    no ingredient slots

  • Constant value – A table column should be assigned a constant, rather than pulling it from the CSV file.
    no ingredient slots

  • Default on parse failure – Use a default value for this column rather than fail
    no ingredient slots

  • Parse as Yes/No – Explain how to parse a column into a required Boolean.
    no ingredient slots

  • Parse as Yes/No (optional) – Explain how to parse a column into an optional Boolean.
    no ingredient slots

  • Parse as date/time – Explain how to parse a column into a required date/time.
    no ingredient slots

  • Parse as date/time (optional) – Explain how to parse a column into an optional date/time.
    no ingredient slots

  • Rename CSV header – Tweak the header text for a given column in the CSV file.
    no ingredient slots

csvImportTableIngredients

Options for choosing which table(s) to import a CSV file into

customShowIngredientsList

Custom ways to show columns

  • Clip to N characters – Show only the first N characters (useful for long data)
    no ingredient slots

  • Column CSS – Wrap an existing column display in custom CSS styling. This should go after any ingredient that replaces the column display (like CustomShow).
    no ingredient slots

  • Conditional rendering – A custom way to show a particular column, but only under a particular condition

  • Custom column formula – The custom way to show a particular column
    no ingredient slots

  • Formatted date/time – Use a C-style format string to show a date/time
    no ingredient slots

  • Money with currency – Show a money field with its corresponding currency
    no ingredient slots

  • Render as file link – Using an endpoint that returns a url, display a column as a link to that url. Typical for a file download.

  • Render as image – Display a column as an image.

  • Render as link – Show a column as a link
    no ingredient slots

  • Render as toggle – Show a boolean column as a toggle switch. Flipping it updates the same-named column of a chosen table, matching the row by a key derived from the displayed row.
    no ingredient slots

  • Row CSS – Set the style of the whole row based on a formula
    no ingredient slots

  • Tidy text – Trims leading and trailing spaces, remove a trailing comma (if there is one), and convert all underscores to spaces
    no ingredient slots

formIngredients

A set of ingredients that define a form.

  • Button – A button that performs a RowAction when pressed.

  • Call API endpoint – Send a custom API call that may use the previous row values

  • Computed field – Set a field to a fixed value that can depend on previous fields
    no ingredient slots

  • Conditionally enabled field – A widget that is enabled only if a specified condition is met
    no ingredient slots

  • Conditionally visible field – A widget that is visible only if a specified condition is met
    no ingredient slots

  • Current time – Use the current date/time
    no ingredient slots

  • Date range picker – Date Range Selector
    no ingredient slots

  • Dropdown menu from query – A dropdown of options based on a SQL query. The query must return a Label column (display text) and one or more value columns. Each value column’s alias either will match a column name in the form’s table or cause a new value to be brought into scope for the rest of them. When a user selects a dropdown option, all matched columns are set to the corresponding values from the selected row.
    no ingredient slots

  • File upload – A dropzone for file uploads directly to a specified endpoint
    no ingredient slots

  • Form screenshot – Take a screenshot of the form and store it in a file. Note that the screenshot is taken at form submission and will be unavailable until then, so it should not be used elsewhere in the form.
    no ingredient slots

  • Horizontal layout – Display form elements in a horizontal group

  • Horizontal line – A simple horizontal line to separate different sections of a form
    no ingredient slots

  • If/else subform – A choice of two sub-forms given a condition

  • Leave field untouched – Do not show this field to the user. Instead, leave it as its original/default value. Should not be used for key columns.
    no ingredient slots

  • Multi-select (child table) – Provide a multiselect dropdown for populating a child table

  • Multi-select dropdown menu from query – A dropdown of options (such that multiple can be selected) based on a SQL query
    no ingredient slots

  • Multiline text input – A textarea widget for a string that allows for multiple lines of text. (Note that this is only for strings. Richtext should use StandardInput.)

  • Random ID – Generate a random ID for the column or leave it as is if there is already an ID. The column must have type string or int.
    no ingredient slots

  • Sequential ID – Choose the next sequential ID for this column based on the values in the table or leave it as is if there is already an ID. The column must have type string or int. This is the preferred ingredient for key/primary key columns.
    no ingredient slots

  • Spacer – Just blank space for fine-grain bootstrap formatting.
    no ingredient slots

  • Standard input – An input widget, optionally mirroring its value from a previous form field
    no ingredient slots

  • Subform (child table) – Embed forms for adding zero or more rows to a different table. When dynamic is false (default), the number of rows is determined by the numRows formula. When dynamic is true, the user can add and remove rows, with numRows providing the minimum.

  • Submit-blocking validator – Display a message and prevent form submission if a Boolean formula fails
    no ingredient slots

  • Text block – Display non-interactive guidance text to the user
    no ingredient slots

  • Text block with query – Display reactive text to the user, using values from a SQL query
    no ingredient slots

  • Toggle switch – A toggle switch for a boolean field
    no ingredient slots

  • Trigger RowAction on Condition – A trigger that performs a RowAction when an expression on the formFieldsTable columns transitions from false to true. At form open this fires immediately; subsequent triggers are debounced by the delay.

  • US state dropdown – A dropdown that allows one to pick a US state or territory and then produces the 2-letter abbreviation for it as its result.
    no ingredient slots

  • Username of current logged-in user – Use the logged in user’s username as a column
    no ingredient slots

  • Validated input – An input widget whose value must be validated in order to submit

  • Workday Post – Post this feedback row to Workday on submit, storing the returned Workday ID in the named column
    no ingredient slots

jsonFieldsIngredientsList

A list of options for fields in a JSON representation.

  • Field – A field in the JSON representation
    no ingredient slots

llmParamIngredients

Annotations for the arguments an LLM tool takes, one entry per argument. A tool’s arguments are inferred from the steps that use them; an entry here describes or constrains one of them, or adds one the steps do not mention.

  • Parameter – One argument the LLM supplies when it calls the tool. Declare an argument the tool’s steps already use to give it a description or a constraint; declare one they do not use to add it.
    no ingredient slots

llmPromptIngredients

Prompts provided to the LLM to ask for a specific response

  • Prompt (new column) – Prompt the LLM to produce a new column. Supports all column types including list-typed columns.
    no ingredient slots

  • Prompt (overwrite column) – Prompt the LLM to overwrite this column. Supports all column types including list-typed columns.
    no ingredient slots

llmQueryToolIngredients

Tools the LLM can use during its reasoning: table lookups, inserts, updates and deletes, and compound Tool pipelines built from row-action steps (API calls, email and Gmail sends, and more)

  • Delete from table – Let the LLM delete rows from a database table.

  • Insert into table – Let the LLM insert rows into a database table.

  • Look up in table – Let the LLM query a database table by filtering on column values. When requiresApproval is true, both the lookup AND its distinct-values companion require approval.

  • Query with SQL – Let the LLM read the app’s data by writing a SELECT statement of its own, joining, grouping, aggregating and ordering as the question needs. It reads exactly the tables and columns the spec’s sqlQuery tags expose, and nothing else. Answers come back a page at a time.
    no ingredient slots

  • Tool – An LLM tool built as a row action – a compound pipeline that can move rows between tables, call an API endpoint, send email, and more – taking arguments inferred from the pipeline’s own steps and returning author-selected result columns back to the model.

  • Update table row – Let the LLM update rows in a database table by key.

llmReferenceIngredients

Data referenced by the LLM when generating a response

  • App outline – Provide the app’s structure (tables, pages, modules) as context for the LLM.
    no ingredient slots

  • File reference – Provide a file as input for the LLM.
    no ingredient slots

  • Text reference – Provide some textual input for the LLM.
    no ingredient slots

mappingIngredientsList

A list of options for mapping values in an input row to an output row.

  • Empty list – Set a list-typed column to the empty list
    no ingredient slots

  • From JSON string – Parse a JSON string into a list of records. The target column must have a list-of-records type.

  • From all columns – Copy every column of the input through as an output, each under its own name
    no ingredient slots

  • From formula – Set a column value using a formula
    no ingredient slots

  • From list column – Hand a list column of the pipeline through as an output unchanged
    no ingredient slots

  • From list query – Set a list-type column to the results of a SQL query. The target column MUST be a list type (list of records). Each row returned by the query becomes an element in the list, wrapped as {N_Value: value}.
    no ingredient slots

  • From scalar query – Set a column to a single value from a SQL query. The query MUST return exactly one row with exactly one column. Use this for scalar lookups like COUNT, SUM, MAX, or fetching a single field. For queries returning multiple rows, use QueryList instead.
    no ingredient slots

metricsCardIngredients

Metric lines for a Metrics Card (one typed column per line).

  • Metric line – Show one column from the query row as a labeled metric (<dt> / <dd> inside the card <dl>).
    no ingredient slots

portIngredients

Data-Porting Column Handling

  • Assign unique ID – set column to a unique ID
    no ingredient slots

  • Assign unique ID (with subtables) – Set column to a unique ID, also recursively figuring out how to port subtables with foreign-key references to the source table

  • Constant value – set column to a constant
    no ingredient slots

  • Copy column – copy one column, where the type matches between source and destination
    no ingredient slots

  • Copy column (ceiling) – copy one column that is a required float in the source and a required int in the destinaton, using ceil to convert
    no ingredient slots

  • Fuzzy lookup by foreign key – copy one column where the source and destination are both foreign-key references, doing a lookup in the table the destination foreign key references to determine options
    no ingredient slots

portSubtablesIngredients

Data-Porting Subtable Handling

  • Subtable – subtable to be ported recursively, as it has a foreign-key reference to the parent source table

rowActionsIngredients

Row actions are operations that act over rows of the given table. These row actions are designed to run server-side.

setterIngredientsList

Setter ingredients for client-side or server

sqlFilterIngredients

Options for creating cusgtom GUI filters for a SQL query

  • Column value filter – Provide a dropdown that allows the user to filter on any column
    no ingredient slots

  • Numeric range filter – Provide a range filter that allows the user to filter on a numeric column.
    no ingredient slots

  • Subquery-driven filter – Provide a dropdown that allows the user to filter on any column where the column is drawn from a subquery.
    no ingredient slots

  • Text-contains filter – Provide a text input that allows the user to filter by substring match on a text column.
    no ingredient slots

  • Yes/No filter – Provide a dropdown that allows the user to filter on a boolean column.
    no ingredient slots

stringMungeIngredients

String munge ingredients

  • Trim whitespace – Trim the leading and trailing whitespace from text
    no ingredient slots

summarizationIngredients

Tools to summarize data from a table

  • Sum column – Sum up the values of a particular column from all child rows that satisfy some condition
    no ingredient slots

timeSequenceIngredients

Options for settings up a sequence of times

  • End time – Set a maximum time for the sequence, stopping if we ever run this late
    no ingredient slots

  • Filter – Set a rule for skipping some sequence elements
    no ingredient slots

  • Maximum count – Set a maximum length for the sequence
    no ingredient slots

  • Nested subsequence – Instead of outputting each sequence element at this level, use it as the start time for a nested sequence, outputting all elements of that subsequence at this position. A good example is generating the first two Tuesdays of every month, which can be encoded as an outer sequence of all the months plus an inner subsequence that seeks through the days of each month, outputting only Tuesdays, stopping after two.

  • Start time – Set the first time in the sequence
    no ingredient slots

  • Step formula – Set a rule for moving from one time in the sequence to the next
    no ingredient slots

validationIngredients

Regex

API Providers

These are API authentication schemes (“providers”) you can select from in an api: block. Each provider comes with a set of parameters you can configure (see the provider’s detail page).

The provider’s Category is shown in parentheses. A provider that brokers for other services also names the categories it can reach; each api on it reaches whichever one its own settings name, and satisfies a component asking for that one or for the provider’s own category.

  • API Key (Generic) – Connection to an API authenticated by a static API key sent verbatim in a request header. The key value is used exactly as given; no Bearer prefix is added, so for a bearer scheme include it in the key value yourself (e.g. header Authorization, value Bearer <key>), or use a vendor header like X-Api-Key.
  • Bearer (Generic) – Custom bearer-token authentication where the token is obtained by calling a token URL (POST with credentials, or GET) and parsing a field out of the response. For APIs that mint their own short-lived tokens.
  • ChatGPT (LLM) – OpenAI ChatGPT API. Used by LLM-backed concepts and ingredients. Requires a paid OpenAI account.
  • Claude (LLM) – Anthropic Claude API. Used by LLM-backed concepts and ingredients. Requires an Anthropic account with API access.
  • Clearbit (Clearbit) – Clearbit (clearbit.com) provides person- and company-enrichment data. Requires a paid Clearbit account and a secret API key.
  • Concur Three-Legged (Concur) – Three-legged SAP Concur OAuth 2.0. Each end-user logs in with their Concur credentials; the app acts on their behalf. Use these settings: authorizationUrl = https://us.api.concursolutions.com/oauth2/v0/authorize, tokenUrl = https://us.api.concursolutions.com/oauth2/v0/token.
  • Concur Two-Legged (Concur) – SAP Concur two-legged auth using a per-company refresh token. App calls Concur as a service identity on behalf of the configured company.
  • Email (Email) – Outbound SMTP email API config. Used by the Email service and by ingredients like Send email. Does not send emails directly; this is done by the service or ingredient, just provides the SMTP config.
  • Gemini (LLM) – Google Gemini API. Used by LLM-backed concepts and ingredients. Requires a Google AI Studio API key.
  • Google (Google) – Three-legged Google OAuth 2.0. Each end-user logs in with their own Google account; the app acts on their behalf with the scopes they grant. Use these settings: authorizationUrl = https://accounts.google.com/o/oauth2/auth, tokenUrl = https://oauth2.googleapis.com/token; set bonusAccessArgs to &access_type=offline&prompt=consent to obtain refresh tokens, and hosted_domain to restrict logins to a Google Workspace domain.
  • Google Two-Legged (Google) – Google two-legged authentication via a service account. The app acts as a single service identity, optionally impersonating a Workspace user. No per-user login required.
  • Government Per Diem Rates (Government Per Diem Rates) – US GSA per-diem rates API (open.gsa.gov/api/perdiem). Used for expense-policy concepts that need official lodging/meal allowances by destination.
  • MCP (Generic) – Connection to an MCP server that asks for no credential. Each endpoint declared on this connection names one of the server’s tools: the endpoint name is the tool name, its url is the server’s endpoint URL, and its body parameters are the tool’s arguments. Use MCP Bearer for a server that wants a fixed token, or MCP OAuth for one whose users log in.
  • MCP Bearer (Generic) – Connection to an MCP server authenticated by a fixed bearer token (a personal access token, a service credential). Endpoints declared on this connection are tool calls, exactly as for the MCP provider. Use MCP OAuth instead when each end-user is to log in with their own account.
  • MCP Broker (Generic, reaching HubSpot) – Connection to a remote MCP server whose users log in through Nectry’s OAuth broker, which holds a client registered with the server’s authorization server in advance. Endpoints declared on this connection are tool calls, exactly as for the MCP provider. Use it when that authorization server does not register clients dynamically (HubSpot’s MCP Auth Apps, say); use MCP OAuth when it does.
  • MCP OAuth (Generic) – OAuth 2.1 connection to an MCP server that needs nothing registered in advance: the app discovers the server’s authorization server (RFC 9728, RFC 8414), registers itself there as a client (RFC 7591) with its own redirect URI, and then runs the ordinary authorization-code flow with PKCE and an RFC 8707 resource indicator. The only setting is the MCP server’s endpoint URL. Use MCP Broker instead when the authorization server does not offer open dynamic registration and Nectry’s broker holds a client registered with it in advance (HubSpot’s MCP Auth Apps, say), or the OAuth2 provider when a client was registered by hand for this app alone.
  • Nectry Broker (OpenID Connect, reaching Google or GitHub or Notion or HubSpot or Slack) – Sign-in through Nectry’s OAuth broker, which holds the upstream registration on every app’s behalf.
  • NetSuite (NetSuite) – Oracle NetSuite (ERP) API via two-legged token-based auth. The app calls NetSuite as a service identity using OAuth 1.0a tokens.
  • No authentication (Generic) – Connection to an API that does not require authentication. Useful for public endpoints or internal services without auth requirements.
  • OAuth2 (Generic) – Three-legged OAuth 2.0 authorization-code flow. Use this when each end-user logs in with their own credentials at the provider and grants the app access.
  • OAuth2ClientCredentials (Generic) – Two-legged OAuth 2.0 client-credentials flow. Authenticates as the app itself (no end-user). Use for service-to-service APIs.
  • OAuth2RefreshToken (Generic) – Two-legged OAuth 2.0 flow that authenticates via a long-lived refresh token. Use when the provider issues a refresh token at app setup time but does not require interactive user login during operation.
  • OpenID Connect (OpenID Connect) – Generic OpenID Connect (OIDC) authentication. Supports any OIDC-compliant identity provider (Okta, Azure AD, Auth0, etc.).
  • Password (Password) – Local username/password storage with salted hashes. Only use this when an SSO provider is not an option; prefer Google/OpenID Connect where possible.
  • Quickbooks (Quickbooks) – Three-legged Intuit QuickBooks Online OAuth 2.0. Each end-user logs in to their QuickBooks company and grants access. Use these settings: authorizationUrl = https://appcenter.intuit.com/connect/oauth2, tokenUrl = https://oauth.platform.intuit.com/oauth2/v1/tokens/bearer, defaultExpiration = 1800, tokenMetadata = the company’s Realm ID.
  • Salesforce (Salesforce) – Three-legged Salesforce OAuth 2.0 via a Connected App. Each end-user logs in with their own Salesforce credentials; the app acts on their behalf. Use these settings: authorizationUrl = https://login.salesforce.com/services/oauth2/authorize, tokenUrl = https://login.salesforce.com/services/oauth2/token (use test.salesforce.com for sandboxes), defaultExpiration = 1800. clientId is the Connected App’s Consumer Key, clientSecret its Consumer Secret, and tokenMetadata the instance identifier (the XXX in https://XXX.lightning.force.com/).
  • ServiceNow (ServiceNow) – Three-legged ServiceNow OAuth 2.0. Each end-user logs in to their company’s ServiceNow instance; the app acts on their behalf. Use these settings: tokenMetadata = the instance id (the XXX in https://XXX.service-now.com/), authorizationUrl = https://XXX.service-now.com/oauth_auth.do, tokenUrl = https://XXX.service-now.com/oauth_token.do (substitute your instance for XXX).
  • Slack Two-Legged (Slack) – Slack workspace integration via a static bot token. The app posts and reads as the bot user; no per-user login. User sign-in with Slack goes instead through the Nectry Broker’s Slack issuer ($NECTRY_BROKER_ORIGIN/slack), paired with an OpenID Connect authenticator; this api is the bot-token path only.
  • Smartsheet (Smartsheet) – Smartsheet (smartsheet.com) integration via personal access token. App calls Smartsheet as the token-owning user.
  • Workday Two-Legged (Workday) – Workday integration via OAuth 2.0 refresh-token flow. Service-style auth using a long-lived refresh token issued at integration setup.
  • Zenefits Two-Legged (Zenefits) – Zenefits HR-software integration via a custom integration token. App calls Zenefits as a service identity.
  • Zoom Three-Legged (Zoom) – Three-legged Zoom OAuth 2.0. Each end-user logs in with their Zoom account; the app acts on their behalf with the scopes they grant. Use these settings: authorizationUrl = https://api.zoom.us/oauth/authorize, tokenUrl = https://api.zoom.us/oauth/token.
  • Zoom Two-Legged (Zoom) – Zoom integration via a JWT app. App calls Zoom as a service identity; no per-user login. Note: Zoom JWT apps are being deprecated by Zoom in favor of OAuth.

Auth Providers

  • Concur – Single-sign-on via SAP Concur. Use when end-users authenticate with their Concur account. The user is keyed on their primary (work) Concur email and their full name is captured; login fails if the Concur profile has no email address.; requires: Full name
  • Dummy – Trivial authentication for development and testing. Users authenticate by typing any username; no password or external provider is involved. Never use in production.
  • Generic – Generic OAuth 2.0 authentication. Pair with a Generic OAuth2 API to support arbitrary OAuth providers configured via settings. Limitation: this provider does not yet fetch a per-user profile from the provider; every authenticated user is treated as the same identity (“user”), so it cannot distinguish or personalize per-user data.
  • Google – Single-sign-on via Google accounts (Workspace or consumer Gmail). Backed by the Google API category.; requires: E-mail address
  • OpenID Connect – Single-sign-on via any OpenID Connect identity provider (Okta, Azure AD, Auth0, …).; requires: E-mail address
  • Password – Local username/password authentication backed by the Password API (salted hashes stored in the app database). Prefer an SSO provider where possible.; requires: Password
  • SecretCode – Authentication via a per-user numeric secret code. Useful for low-friction access where users receive their code out-of-band.; requires: Secret code

Service Providers

  • ChatGPT (API LLM) – Stub service exposing the ChatGPT API for LLM-backed concepts and ingredients (chat, classification, summarization, etc.).
  • Claude (API LLM) – Stub service exposing the Claude API for LLM-backed concepts and ingredients (chat, classification, summarization, etc.).
  • Clearbit (API Clearbit) – Stub service for Clearbit enrichment lookups. Ingredients that call Clearbit (e.g. enrich a row from a domain) reference this service.
  • Concur (API Concur) – SAP Concur expense-management integration with pre-defined Expenses, Reports, Receipts, Trips, Users, Projects, Itemizations, Per Diem Days, and Finance Team Assignments tables. Mirrors company expense data into local tables. Requires a configured Concur API connection (the Concur Two-Legged or Concur Three-Legged API provider; see those for settings).
  • Email (API Email) – Stub service that exposes the Email API as a service so the Send email ingredient/concept can be configured. Has no tables to sync; the API does all the work.
  • Gemini (API LLM) – Stub service exposing the Gemini API for LLM-backed concepts and ingredients (chat, classification, summarization, etc.).
  • Generic (API Generic) – Generic REST service backed by user-defined endpoints on a Generic-category API. Use this to mirror remote tables via linkedTables whose get: calls one of the API’s endpoints.
  • Google (API Google) – Stub service exposing the Google API for concepts that call Google endpoints (Gmail, Drive, Calendar) directly. For Sheets-as-tables, use the Google Sheets service instead.
  • Government Per Diem Rates (API Government Per Diem Rates) – Stub service exposing the US GSA per-diem rates API for expense-policy concepts.
  • NetSuite (API NetSuite), dynamic schema – NetSuite ERP bridge. Discovers NetSuite records (customers, transactions, custom records) dynamically and exposes them as local tables via linkedTables. Requires a configured NetSuite API connection (two-legged OAuth 1.0a token auth; see the NetSuite API provider for settings).
  • OpenID Connect (API OpenID Connect) – Stub service for OpenID Connect identity providers. Pairs with the OpenID Connect authenticator for SSO.
  • Password (API Password) – Stub service exposing the Password API for username/password auth flows. Pairs with the Password authenticator.
  • Quickbooks (API Quickbooks), dynamic schema – Intuit QuickBooks Online bridge. Discovers QuickBooks entities (customers, invoices, accounts, etc.) and exposes them as local tables via linkedTables. Requires a configured QuickBooks API connection (three-legged OAuth; see the Quickbooks API provider for settings).
  • Salesforce (API Salesforce), dynamic schema – Salesforce CRM bridge. Discovers Salesforce objects (accounts, contacts, custom objects) dynamically and exposes them as local tables via linkedTables. Requires a configured Salesforce API connection (three-legged OAuth; see the Salesforce API provider for settings).
  • ServiceNow (API ServiceNow), dynamic schema – ServiceNow bridge. Discovers tables in the ServiceNow instance (incidents, requests, custom tables) and exposes them as local tables via linkedTables. Requires a configured ServiceNow API connection (three-legged OAuth; see the ServiceNow API provider for settings).
  • Smartsheet (API Smartsheet), dynamic schema – Smartsheet bridge. Discovers sheets in the configured workspace and exposes them as local tables via linkedTables. Requires a configured Smartsheet API connection (personal access token; see the Smartsheet API provider for settings).
  • Workday (API Workday) – Workday HR/finance integration with pre-defined Feedback, Workers, and DirectReports tables. Use for workforce data + feedback flows. Requires a configured Workday API connection (two-legged OAuth refresh-token; see the Workday Two-Legged API provider for settings).
  • Zoom (API Zoom) – Zoom meetings integration. Mirrors Zoom meetings, registrants, and participants into local tables. Requires a configured Zoom API connection (the Zoom Two-Legged or Zoom Three-Legged API provider; see those for settings).