Skip to main content
Telara

How-To Guides / Admin

Connect an Integration

Link external platforms to Telara so agents can access them. Telara supports OAuth, API key, and app-based integrations — each with encrypted credential storage and tool-level access controls.

Admin
Integrations

Overview

Three types of integrations

Telara supports three connection methods depending on what the external platform offers.

OAuth Integrations
Slack, GitHub, GitLab, Google Workspace

Telara handles the entire OAuth authorization flow. You click Connect, approve access on the external platform, and are redirected back automatically. No tokens to copy or store.

API Key Integrations
Datadog, Sentry, New Relic, PagerDuty

Generate an API key in the external platform's settings and paste it into Telara. The key is encrypted and stored — you only enter it once.

App Integrations
Slack App, GitHub App

Install a pre-built app with a defined set of permissions. The app is scoped to only the capabilities it needs — no over-provisioned access.

OAuth Flow

Connecting via OAuth

For platforms like GitHub, Slack, GitLab, and Google Workspace, Telara manages the OAuth authorization automatically.

1
Open Context Engine → Integrations
Open the Telara dashboard and go to Context Engine → Integrationsin the left sidebar. You'll see the full integration catalog with available platforms.
2
Click 'Add Integration' and select the platform
Find the platform you want to connect (e.g., GitHub) and click it to open the connection panel.
3
Click 'Connect' — Telara opens the authorization page
Telara opens a new browser tab with the external platform's authorization screen. You don't create an OAuth app or configure callback URLs — Telara handles that automatically.
4
Authorize Telara's access
Review the permissions Telara is requesting, then click Authorize. You'll be redirected back to the Telara dashboard automatically.
5
Name the credential and set the scope
Give the credential a descriptive name (e.g., "GitHub Org Access") so it's easy to identify later. Then select the scope: org-wide, team, or user-specific.
Settings → Integrations page showing the integration catalog with connected and available platforms

API Key Flow

Connecting via API key

For monitoring and observability platforms, you generate a key in the external tool and paste it into Telara.

1
Generate an API key in the external platform
Navigate to the API key settings on the external platform. Common locations:
  • Datadog→ Organization Settings → API Keys
  • Sentry→ User Settings → API Tokens
  • New Relic→ User Menu → API Keys
  • PagerDuty→ User Settings → User Token API Keys
2
In Telara, open Context Engine → Integrations and click 'Add Integration'
Select the platform from the catalog. If it uses API key authentication, you'll see an API Key input form.
3
Select 'API Key' and paste the key
Choose the API Key connection method, paste the key you generated, and click Connect. Telara validates the key and confirms the connection.
API key input form for a monitoring integration showing the key field and optional label

Access Control

Restricting which tools a credential can use

After connecting any integration, you can restrict which specific actions this credential allows. This is optional but recommended — especially for shared org-wide credentials.

For example, a GitHub credential used by most of the engineering team might be limited to reading repositories, creating issues, and searching code — while the ability to merge pull requests or delete branches is restricted to a separate credential used only by senior engineers.

Tool allowlist selector showing available actions for a GitHub credential, with checkboxes to enable or disable each action
Least-privilege access

Restricting a credential's tool allowlist is independent from your permission policy. Both apply: a tool must be in the allowlist AND permitted by the policy for an agent to use it.

Scope

Credential scope

When you connect an integration, choose how broadly the credential is available within your organization.

Org-wideRecommended for shared integrations

All users and configurations in the organization can use this credential. Best for shared platforms like your main GitHub org or company Slack workspace.

Team-scopedFor team-specific accounts

Only configurations targeting this team can use the credential. Useful when a team has its own Jira project, dedicated Slack workspace, or separate GitHub org.

User-scopedFor personal accounts

Only the individual user's configurations can use this credential. Useful for personal GitHub accounts or user-specific API tokens.

Credentials are encrypted and never exposed

Credentials are encrypted at rest and never surfaced to users or agents. Agents use them through the permission layer — an agent can perform an action a credential enables, but it cannot read or export the underlying key or token.