---
title: Connecting your apps
description: What Else can do inside the accounts you already use, how your credentials are stored, and which actions stop for your approval no matter what.
---

Apps are the accounts you already use. Connecting one lets Else work inside it
instead of handing you instructions to go and do it yourself. The **Apps** screen
states the deal in one line: *"Let your assistant work inside the apps you already
use. Connect one, then choose exactly what it's allowed to do — every action shows
up on your receipt."*

The two halves of that sentence are the whole page. It can act inside your
accounts, and it cannot do so quietly.

## The six first-class apps

Six are wired in directly, and the run panel names what each one is for:

| App | What it does |
| --- | --- |
| **Gmail** | Read, draft and send with approval |
| **Google Drive** | Find files and save deliverables |
| **Notion** | Search notes and create pages |
| **Slack** | Read threads and publish updates |
| **GitHub** | Read repositories and open pull requests |
| **Airtable** | Read and update connected records |

Beyond those six, the Apps screen carries a large A–Z directory of other services,
grouped by category — Data, Productivity, Developer Tools, Marketing,
Communication and so on. Anything in there connects the same way.

Connecting is not permanent. An app you connected can be disconnected again from
the same screen — and **disconnecting is the only per-app control there is.** A
connected app's panel offers *Disconnect* and nothing else: there is no list of
individual actions to switch on and off. Where you choose what it may do is per
run, not per app, and the section below is that mechanism.

## Connecting it does not put it into a run

This is the step people miss, so it is here rather than three pages away.
**A connected app is not automatically available to your work.** Built-in
[Add-ons](/docs/add-ons) are all on by default; apps are not. You add an app to a
run yourself, from the **This run** panel above the composer.

And do that **from inside a chat**, not from the home screen. The home
composer does not read your connections at all — every app in its list reads
*Connect in Apps* whether you have connected it or not, and tapping one takes
you to the Apps screen instead of adding it to the run. Send your opening
message first, then set the apps up in the chat.

[Using an app you connected](/docs/using-your-apps) is the page on all of that.

## Two ways to connect, and your credentials

Some apps connect by signing in. Most connect by pasting a key: you open the app
in the directory, and Else asks for exactly the field that app needs, with the
instructions for finding it — for one service, *"API key used with HTTP Basic
authentication. Create or view app API keys in the … dashboard under App settings
> API keys."* Then **Connect securely**. A few apps need no credential at all and
connect with one click.

If an app is one Else cannot offer sign-in for, it says so rather than failing
obscurely: **"This app isn't open for sign-in yet."** In that case, use a key.

Under the form is the promise that matters:

> Your details are encrypted and never shown to the AI.

Read that as written. The key you paste is stored encrypted, and it is not part of
what the model sees. Else uses it to make the call; the assistant working on your
task does not get handed your credential to reason about, quote, or accidentally
repeat back to you.

Credentials are also checked, not just stored. If the value doesn't work, you find
out at the moment you paste it — *"We couldn't verify that credential. Double-check
the value and try again."* — instead of three days later inside a failed run.

## What stops for your approval

This is the part to read before you connect anything that can send.

**Connecting an app is not blanket permission to use it.** By default, Else checks
with you before anything leaves the app at all — sending, publishing, buying or
changing things. You can loosen that per run, and there is still a floor
underneath you:

- **Sending or publishing is a hard stop.** Even on *"Don't check with me,"*
  sending an email is held for your approval. That one is not a preference.
  Gmail's own description says it: *"Read and draft emails. Sending always asks you
  first."*
- **An app action we have not explicitly cleared.** Only read-shaped actions —
  searching, listing, fetching — proceed without asking. Anything else stops.
  Note that this is decided per action by us, not configured by you: there is no
  per-action permission list on the Apps screen to tick. What you control is
  which apps a run may touch at all, and which of the three settings above it
  runs under.
- **Anything malformed or unrecognised asks.** The default when Else can't tell
  what an action would do is to stop, not to try it. An unknown action asks rather
  than guesses.

So the honest summary of what connecting buys you: it can *read* widely inside a
connected app on its own, and it *proposes* rather than performs the things that
would be visible to other people. Publishing a Slack update, opening a pull
request, sending mail — those arrive as a decision for you, not as a fait
accompli.

## Where the record is

Anything Else does in a connected app happens inside a run, and a run that spent
anything carries a receipt of what it was charged — so app work is never off the
books. The run itself is also where you see it: the steps it worked through, and
what it says it did. Check the result against that rather than against its summary
— see [Reviewing what comes back](/docs/reviewing-what-comes-back).

And when it does stop, the work sits parked: nothing runs and nothing is charged
while it waits for your answer. Leaving an approval overnight costs you nothing.
[When it checks with you](/docs/when-it-checks-with-you) covers the controls in full.
