This guide shows you how to reach the Space integrations settings area and how the available integration sections are exposed in the UI.
Open a Space, then open this route:
/spaces/<spaceId>/settings/integrations
That route forwards you to the integration section available for the Space.
The integrations settings area currently supports these sections:
When both sections are available, the Integrations page renders two subtabs in this order:
When only one section is available, the subtab bar is hidden and the page opens that section directly.
Saved OAuth 2.0 credentials and SQL connections are included in Space export and import operations when you select them for export. When imported into another Space, the credentials are recreated in the target Space, and Flow nodes that used them use the imported copies.
Use these routes for direct navigation:
/spaces/<spaceId>/settings/integrations/oauth/spaces/<spaceId>/settings/integrations/oauth/create/spaces/<spaceId>/settings/integrations/oauth/<credentialId>/spaces/<spaceId>/settings/integrations/sql/spaces/<spaceId>/settings/integrations/sql/create/spaces/<spaceId>/settings/integrations/sql/<connectionId>If you open /spaces/<spaceId>/settings/integrations:
An OAuth credential is used by the Auth - OAuth Get Access Token node.
When creating an OAuth credential, you choose a grant type:
Choose an endpoint source when creating or editing a credential:
openid scope require one.You can switch between issuer discovery and manual endpoints when editing a credential. After switching, provide the fields required by the selected source and save the credential.
Manual endpoint configuration lets you choose how the client secret is sent to the token endpoint:
client_secret_basic (default) — sends the secret with HTTP Basic authentication.client_secret_post — sends the secret in the token request body.For User Authorization credentials, the typical flow is:
For App-Level Token credentials, the flow is simpler:
App-Level Token credentials renew their access without any user action, so they stay authorised.
Grant type is immutable after credential creation. You cannot change from User Authorization to App-Level Token or vice versa on an existing credential; you must create a new one.
When you change the endpoint source or sensitive fields (issuer endpoint, authorisation endpoint, token endpoint, client authentication method, client ID, secret, or scopes) on an existing credential, the credential is re-authorised so you are told immediately if the new configuration is valid:
The SQL form currently supports these dialects:
For each dialect, the SQL settings UI supports two setup paths:
Import tools are opened from the Import from Connection String button in the Use individual parameters section. For PostgreSQL, this button appears on the same row as Require SSL. The import popup only applies values to individual parameters. If a password is parsed from the connection string, it is written to the selected password secret path when you save the SQL connection, and on edit pages it is also written before Test Connection runs.
When you create a new secret from SQL connection settings, the suggested path starts with sql/.
On SQL and OAuth edit pages, secret selectors provide two actions when a secret path is selected:
When editing an existing secret from these forms, the secret path stays locked and only the value is updated.
The create and edit pages persist the saved SQL credential configuration for the Space. The SQL detail page also lets you remove a saved connection.
Saved SQL credentials can be tested from the SQL detail page. On the edit page, clicking Test Connection first saves the latest form changes so tests run against the current configuration. The test then runs in three stages:
The first stage fails quickly when the server is unreachable, for example because of a blocked port, a VPN issue, or a corporate firewall.
On the create page, Test Connection shows a message asking you to save the connection first, so run the test from the edit page.
The test also checks that the server responds as the selected dialect (PostgreSQL or SQL Server), so a port that does not serve that dialect fails early.
Saved SQL credentials track recent connection outcomes. When connection attempts fail repeatedly, the credential status moves through Degraded and Failed, and can be temporarily Suspended.