Appearance
Integrations
The Integrations page in the app is where your account connects to the outside world: the git hosts your agents work in, the trackers that hand them tickets, the files and designs they read, the chat tools people start work from, the cloud accounts the agents run on, and the AI provider behind chat. Every connection here belongs to the account, not to a single person, and every agent and workspace in the account uses it.
Open it from the sidebar (Integrations, at app.kadmo.ai/integrations). Cards are grouped, and each group header shows how many of its cards are connected.
Who can connect what
Every member can open the page and read the cards. Connecting, testing a new credential, changing a connection and Disconnect are Admin actions: a User who tries one gets Forbidden: admin role required. Roles are set on the Team page (see Account and team).
Two exceptions are deliberately narrower than "an admin of this account":
- Some connections also need an admin on the other side — a Jira site admin installs the Jira app, a Linear workspace admin approves the Linear app, a Notion workspace owner creates the Notion integration, a GitHub organization owner installs the GitHub App.
- Microsoft Teams is connected by the Kadmo team for you (see Chat).
The cards at a glance
| Group | Card | How it connects | Line on the card |
|---|---|---|---|
| Git Hosting | GitHub | Personal access token, plus the optional GitHub App | Personal Access Token |
| Git Hosting | Bitbucket | Username + app password | App password |
| Git Hosting | GitLab | Personal access token | Personal Access Token |
| Issue Tracking | Jira | The Kadmo for Jira app, or a self-managed API token | Jira app (Forge) / Atlassian Jira Cloud |
| Issue Tracking | Linear | The Linear app (OAuth), or a personal API key | Linear app (OAuth) / Personal API key |
| Issue Tracking | Notion | Internal-integration token | Internal integration |
| Knowledge Sources | Google Drive | Google sign-in (OAuth), read-only | Read-only Drive access |
| Design | Figma | Figma sign-in (OAuth) as one Figma user | Design files, read as one Figma user |
| Messaging | Slack | Your own Slack app, one channel at a time | Drive agents from channels |
| Messaging | Microsoft Teams | Assisted tenant link, then people added by an admin | Start jobs from a 1:1 chat |
| Cloud | AWS | Access keys of an IAM user | Amazon Web Services |
| Cloud | Hetzner | Hetzner Cloud API token | Hetzner Cloud |
| Cloud | GCP | Not available yet — shown as coming soon | Google Cloud |
| AI Providers | Kadmo | Included, nothing to connect | Included models, paid per token |
| AI Providers | Your own keys (Anthropic, OpenAI, OpenRouter) | An API key per provider — Enterprise plan only | Claude models / GPT models & Whisper voice / Many models, one key |
Each card opens a dialog with the connection's details, a Test button where there is something to test, and a Disconnect button in the footer. The Disconnect confirmation always says what stops working and what is kept — automations, workspace bindings and routing survive a disconnect, so reconnecting picks up where you left off.
Code hosting
The git-host credential is used by Kadmo itself, not handed to agents: it validates the connection, reads a skill-pack repository you bring yourself, and — when you allow Kadmo to edit your skill pack — commits or opens pull requests on that pack repository only. Your workspace repositories are never pushed to by Kadmo; agents push with their own credentials. Read-only access is therefore enough for the scopes below.
| Card | What to create | Scopes the card asks for |
|---|---|---|
| GitHub | A token at github.com/settings/tokens | repo, read:user |
| Bitbucket | An app password at bitbucket.org/account/settings/app-passwords, plus your Bitbucket username | account, repository (read) |
| GitLab | A token at gitlab.com/-/user_settings/personal_access_tokens | read_user, read_repository |
Paste the credential, press Test, then Save. A broader token is accepted — a GitHub token with user covers read:user, a GitLab token with api covers both read scopes. GitHub fine-grained tokens are accepted too; GitHub does not report their scopes, so a missing permission shows up only when an operation first needs it.
GitLab tokens expire. The card warns in amber when the token expires within 30 days and in red once it has expired — create a new token with the longest expiry you can and save it over the old one.
The GitHub App
The GitHub dialog has a second section, GitHub App. The token above is how agents push; the App is how GitHub reaches Kadmo: issue and pull-request comments arrive as events your automation rules can act on.
- Install sends an admin to GitHub to pick an organization and All repositories or a selection. The App requests read access to metadata and write access to contents, issues and pull requests.
- Installing wires the transport only. Nothing runs until you write a rule — the New mention rule link opens the automations form filled in, and saves nothing until you save it.
- The connected GitHub identity is the fleet's actor, and its own comments never trigger rules. Connect a dedicated agent user if you want mentions from your own account to be acted on.
- Unlink removes the link; tick Also uninstall from GitHub to remove the App from the organization too.
Trackers
Trackers hand tickets to your agents and receive their progress. Each has its own page:
| Tracker | What the connection is | Details |
|---|---|---|
| Jira | The Kadmo for Jira app (installed by a Jira site admin), or a self-managed API token with a webhook | Jira |
| Linear | The Linear app (an app user, not a billable seat), or a personal API key with a webhook | Linear |
| Notion | An internal integration that you share each board with | Notion |
After connecting, link a tracker project, team or board to a workspace on the workspace's Work intake card (see Workspaces) so tickets route to the right repository and agents. A workspace with no tracker linked is fine: its tasks are internal, keyed with the workspace's task key prefix.
Files and design
Google Drive
Connect Google Drive signs you in with Google and grants Kadmo read-only access (the drive.readonly scope) to the Drive of the account you sign in with. Kadmo sees exactly what that Google account can see, and never writes back. Chat agents read documents from it as a knowledge source (see Chat agents).
- One Google account per Kadmo account; connecting another replaces it. Sign in with the account that owns the shared folder, not a personal login — the card shows which account is connected.
- If the token stops renewing, the card reads Refresh failing or Expired; press Reconnect. Reconnecting the same Google account resumes syncing for documents already indexed.
Figma
Connect Figma signs in as one Figma user, and your agents act as that user. Sign in as a dedicated Figma user, not a designer's own login: its own comments never start work. Give it a Full or Dev seat and access to the folders your workspaces build from — a seat on Figma's low rate tier can read designs only 20 times a month, and the card says so when it sees one.
| Scopes requested | current_user:read, file_content:read, file_metadata:read, file_versions:read, file_comments:read, file_comments:write, file_dev_resources:read, file_dev_resources:write, folder_metadata:read, webhooks:read, webhooks:write |
| Binding | Bind a Figma team, folder or file to a workspace in the Design section of the workspace's edit page. The Figma dialog lists every binding under Bound workspaces. |
| Automation | New comment rule and New Ready-for-dev rule open the automations form filled in. Kadmo registers the Figma webhooks a saved rule needs by itself (when the rule is saved, and again every 15 minutes) and lists them under Webhooks with their last ping and delivery. |
| Limits | One Figma user per Kadmo account, and one Kadmo account per Figma user. |
Disconnecting stops Kadmo reading designs. Figma cannot revoke the app from Kadmo's side — also remove Kadmo from that user's connected apps in Figma if you want it gone.
Chat
Slack
Slack connects one channel at a time, through a Slack app you create in your own Slack workspace. The Slack App Setup Guide inside the dialog walks through it:
- Create an app at api.slack.com/apps.
- Under OAuth & Permissions, add the bot scopes
chat:write,reactions:write,users:read. - Install the app to your workspace and copy the Bot User OAuth Token (starts with
xoxb-). - Under Basic Information, copy the Signing Secret.
- Under Event Subscriptions, enable events and set the Request URL to
https://app.kadmo.ai/api/slack/events. - Subscribe to the bot events
message.channelsandmessage.groups. - Invite the bot to your channel, then fill in Add a channel: Team ID, Channel ID, channel name, Bot Token and Signing Secret. Test Connection fills in the Bot User ID.
Each channel has its own list of the workflows people may start from it. Slack answers on the account's AI provider: the dialog's first row shows which one, and an amber Needs an AI provider means none is available yet. Adding, editing and removing channels is admin-only.
Microsoft Teams
People start jobs from a 1:1 chat with the Kadmo app in Teams. Linking your Microsoft tenant is an assisted step: the Kadmo team links it for you, and your admins then add the people who may use it.
- Add each person by the work address they sign in to Teams with. A guest is added by the address your tenant gives them,
#EXT#and all. - Their first message in the 1:1 chat links the address to their Microsoft account, and the row changes from Waiting for first message to Linked.
- Each person can start only the workflows ticked for them. All workflows includes workflows added later.
- Anyone not on the list gets one reply asking them to contact their admin, and nothing starts.
Teams answers on the same AI provider as Slack.
Clouds
The AWS and Hetzner cards hold the cloud accounts your agent machines are created in. Credentials are encrypted at rest. Each connected card shows the connection's name, default region, status and last validation, with Validate and Rotate credentials; the AWS card also sets the Agent subnet — until one is set, agents cannot launch there.
- AWS: the IAM policy and the step-by-step setup are on AWS setup.
- Hetzner: create a Read & Write token in the Hetzner Cloud Console (Security → API tokens); setup is on Hetzner setup.
Firewall, provider status and the cloud audit log live under Settings → Cloud.
AI provider
The AI Providers group shows which provider answers the work Kadmo runs in the app itself. Below Enterprise the group note reads Kadmo serves Ask Kadmo, Slack, Teams, Goals, chat agents and agent jobs. The Manage agent apps link next to it is where agent authentication is configured.
- Kadmo is included on every plan: nothing to connect, paid per token from your Kadmo credit. Its dialog picks the model; the card shows the remaining credit and, for an admin, Buy Credits.
- Your own keys — Anthropic, OpenAI or OpenRouter — are an Enterprise feature. Below Enterprise the card reads Your own keys are an Enterprise feature. On Enterprise each provider has its own card, and the note reads Your own key serves first; Kadmo answers anything it does not cover. Fleet agents authenticate on the agent itself.
Models, credit and budgets are described on AI provider.
Errors you may see
| Message | What it means | Fix |
|---|---|---|
Forbidden: admin role required | You are a User, and the action is admin-only. | Ask an Admin, or have your role raised on the Team page. |
| Connection not completed — The connection was declined. A workspace admin has to approve the Kadmo app… | The provider's admin has not approved the app (Linear and similar). | Ask the workspace admin to approve the pending request, then connect again. |
| Connection not completed — The approval did not grant every permission Kadmo needs. | A permission was unticked on the consent screen. | Reconnect and accept every requested permission. |
| Connection not completed — The user you authorized is already connected to another account. | That Figma (or other) user is linked to a different Kadmo account. | Disconnect it there first, or sign in as a different user. |
| Connection not completed — The connection session expired before you got back. | The sign-in took too long, or ran in another browser session. | Start connecting again from the card, in the same browser. |
| Refresh failing / Expired on a card | The stored grant can no longer be renewed. | Press Reconnect in the card's dialog. |
| …is not available on this deployment — the … app credentials are not configured. | The provider's app is not set up on this installation. | Contact Kadmo support. |