Configure 0Auth Providers for External ConnectionsBeta
Register OAuth providers in Haystack Enterprise Platform so users can authorize access to third-party services with their corporate or workspace accounts.
About This Task
You can enable external connections for OAuth 2.0 providers for your Haystack Platform organization. After you register a provider, users can complete OAuth flows from the platform, for example when a pipeline or MCP tool needs access to Microsoft 365, Google Workspace, Slack, or Notion.
You can register multiple providers. Each provider appears in External Connections in your organization settings. Deleting a provider disconnects every user who authenticated through it.
Only organization admins can add or remove OAuth providers. If you don't see External Connections under Integrations, the feature isn't available for your organization or you don't have the necessary permissions.
Prerequisites
- You're a Haystack Platform organization admin.
- You can create and configure OAuth applications in your identity provider or SaaS vendor console.
- You have the client credentials your provider issues: a client ID and client secret, or a client ID with a PEM private key and certificate thumbprint for private key JWT.
- You know which OAuth scopes your use case needs. Provider templates prefill common scopes; you can change them before you save.
Choose an Authentication Method
When you register a provider, choose how Haystack Enterprise Platform authenticates to the token endpoint:
- Client Secret — paste the secret your provider issued. Most SaaS OAuth apps use this method.
- Private Key JWT — paste a PEM-encoded private key and the certificate thumbprint (SHA-1). Microsoft Entra ID supports this method for confidential clients.
Register a Provider
Follow the guide for your provider. Each guide explains how to create the OAuth app, where to copy the client ID and secret, and which redirect URI to register.
- Set Up OAuth for Microsoft Entra ID
- Set Up OAuth for Google
- Set Up OAuth for Slack
- Set Up OAuth for Notion
- Set Up a Custom OAuth Provider for any other OAuth 2.0 provider
The Add OAuth Provider dialog also lists Google Workspace MCP templates (Gmail, Drive, Calendar, and others). Each template uses the same Google Cloud OAuth client setup as Set Up OAuth for Google, with scopes tailored to that service.
Manage a Provider
After you register a provider, you can remove it when you no longer need it:
What To Do Next
Was this page helpful?