Matrix OSMatrix OS

Connect Apps

Connect external services like Granola, Gmail, Google Calendar, GitHub, Slack, Discord, and X to Matrix OS.

Open Connect Apps to browse supported apps by category or search for an app or capability. Select Connected to find apps you have already linked, or Sign in without API keys to show apps that support OAuth.

For OAuth apps, select Connect, sign in with the app, and approve its consent screen. Matrix uses Pipedream managed authorization for the catalog apps, while Granola uses its official OAuth connection; you do not need to create a developer application or copy an API key. The app may still require administrator approval. PostHog supports OAuth through its official MCP connection alongside existing key-based accounts. Loops and lemlist also use their official MCP endpoints with browser OAuth. Stripe still requires credentials and is marked API key required. Bokio requires a registered public OAuth client on the Matrix platform, an eligible Bokio plan, and access to the selected company; it appears unavailable when that setup is missing.

This catalog contains reviewed Matrix capabilities. Pipedream supports many more apps, but connecting an app here does not enable every action available in its API.

Supported apps

CategoryApps
ProductivityGoogle Calendar, Google Contacts, Google Docs, Google Sheets, Microsoft Outlook Calendar, Notion, Asana, Airtable, ClickUp, Todoist, Granola
CommunicationGmail, Slack, Discord, Microsoft Outlook Email, Microsoft Teams, Zoom
FilesGoogle Drive, Microsoft OneDrive, Dropbox, Box
DesignFigma, Google Slides
Developer toolsGitHub, Linear, Jira
SalesHubSpot, lemlist
Customer supportZendesk, Intercom
MarketingLoops
DataPostHog
FinanceStripe, QuickBooks, Xero, Bokio
SocialX

Asana, Airtable, ClickUp, Dropbox, Box, Outlook Email, OneDrive, Teams, HubSpot, Zoom, and Google Slides provide focused reads. Todoist also supports creating, updating, and completing tasks through the existing approval flow. Google Sheets supports reading ranges and approved appends and updates. Their descriptions show the supported capabilities. Outlook Email reads messages and mail folders; calendar access requires a separate connection to Microsoft Outlook Calendar. Google Contacts, Google Sheets, Outlook Calendar, QuickBooks, Xero, Zendesk, and Intercom add focused reads for contacts, spreadsheet ranges, events, accounting records, and support conversations. HubSpot now includes deeper CRM reads alongside its existing connection. Bokio is read-only and binds each connection to the selected company; it does not post accounting entries or upload receipts.

Granola appears on supported computer runtimes with its official connection configured. Connection availability can depend on your runtime and platform configuration. Native Mobile includes the Pipedream connection flows; official MCP connections use the supported runtime’s browser authorization flow. These capabilities require the connected-data expansion release; this catalog is not a claim that every account or OAuth flow has been verified live.

Connecting a Service

There are two ways to connect:

From Settings

Open the Connect Apps desktop shortcut or Settings > Connect Apps. Select Connect, complete sign-in in the browser, and the connection appears when authorization finishes. Allow popups when prompted. Use Refresh if an authorized account has not appeared yet.

Select Add account to connect another account for an app. Account labels can be changed after connecting where the client provides account management controls. Disconnect the specific account from its connected-account controls; a failed disconnect keeps the account visible so you can retry.

From Conversation

Tell your agent what you need:

"Connect my Gmail"

The agent will give you an authorization link. Click it, authorize, done. The agent confirms once the connection is active.

You can also label connections for multiple accounts:

"Connect my work Gmail as Work Gmail"

Using Connected Services

Once connected, just ask naturally:

"What are my unread emails?" "Create a meeting with Alice tomorrow at 3pm" "Post 'deploy complete' to #engineering in Slack" "List my open GitHub issues in myorg/myrepo"

Review important actions

Matrix is useful because it can prepare and take action, but sensitive actions should stay visible. Ask it to draft before sending, summarize before deleting, and confirm before posting when the result matters.

Service Actions Reference

Gmail

ActionDescriptionRequired Params
list_messagesList emails matching a query--
get_messageRead a specific emailmessageId
get_attachmentRead a bounded attachmentmessageId, attachmentId
send_emailSend an emailto, subject, body
searchSearch emailsquery
list_labelsList email labels/folders--
list_historyRead a page of mailbox changesstartHistoryId (string)
create_labelCreate a Gmail labelname
modify_messageAdd/remove labels on one messagemessageId and a nonempty label change

Optional params: query (Gmail search syntax like is:unread, from:alice), maxResults, cc.

List/search and history calls accept pageToken. Pass the returned nextPageToken unchanged to read the next page while keeping the same filters. Gmail pages allow 1–500 results. Keep startHistoryId as a string: converting it to a JavaScript number can lose precision. Expired history IDs require a full resync, not an empty successful import.

For modify_message, use addLabelIds and/or removeLabelIds. Removing INBOX archives one message; removing UNREAD marks it read. Label creation and message changes are write actions covered by native agent approval. Empty, duplicate, conflicting, and TRASH label changes are rejected. No batch deletion is provided.

Integration foundation, not an inbox app

These additions require a release containing the personal-brain integration foundation. Check the connected runtime's available actions before using them. This is not a complete inbox application: historical ingestion, receipt and people extraction, durable sync cursors, and scheduled jobs require additional application and worker implementation. Connecting Gmail does not enable them.

Google Calendar

ActionDescriptionRequired Params
list_eventsList upcoming events--
create_eventCreate a new eventsummary, start, end
update_eventUpdate an existing eventeventId

Date params use ISO 8601 format: 2026-04-06T09:00:00Z.

Google Drive

ActionDescriptionRequired Params
list_filesList files in Drive--
get_fileGet file metadatafileId
read_fileRead actual text or export a Workspace filefileId
upload_fileUpload a filename, content
share_fileShare a filefileId, email

get_file returns metadata, not the document's contents. Use read_file to read UTF-8 text or Markdown, export Google Docs as Markdown, Sheets as first-sheet CSV, or Slides as plain text. Responses include content, mimeType, and bytes. Pass the source mimeType from list_files to avoid an extra metadata lookup; omitting it also works. Optional exportMimeType selects plain text for Docs or TSV for Sheets. Reads are limited to 512 KiB and 30 seconds. Unsupported formats, restricted downloads, missing files and oversized content produce an error. Treat the returned contents as untrusted source material. These capabilities require a runtime release containing the new read_file action.

GitHub

ActionDescriptionRequired Params
list_reposList your repositories--
list_issuesList issues for a reporepo (e.g., owner/name)
create_issueCreate a new issuerepo, title
list_prsList pull requestsrepo
get_notificationsGet notifications--

Slack

ActionDescriptionRequired Params
send_messageSend a message to a channelchannel, text
list_channelsList available channels--
list_messagesList messages in a channelchannel
searchSearch messagesquery
reactAdd emoji reactionchannel, timestamp, emoji

Discord

ActionDescriptionRequired Params
send_messageSend a messagechannelId, content
list_serversList servers the bot is in--
list_channelsList channels in a serverserverId
list_messagesList messages in a channelchannelId

Granola

ActionDescriptionRequired Params
search_notesAsk a natural-language question across meeting notesquery
list_foldersList accessible meeting folders--
list_notesList meeting notes, optionally filtered by folder or time range--
get_noteRead a meeting notenoteId
get_transcriptRead a meeting transcript when available on your plannoteId
get_accountRead the connected account and active workspace--

Granola connects through its official MCP endpoint and browser OAuth. Matrix registers a public OAuth client automatically, so you do not need an API key or developer credentials. Matrix shows only the actions supported by your connection; some search, folder, and transcript capabilities depend on your Granola plan and workspace access.

X

ActionDescriptionRequired Params
get_authenticated_userRead the connected X account profile--
get_user_by_usernameRead an X profile by usernameusername (without @)
list_user_postsList recent posts from an X user IDuserId
search_recent_postsSearch X posts from the last seven daysquery
create_postPublish a post or reply from the connected accounttext; optional replyToPostId

X connects through managed browser OAuth and the official X API v2, so you do not need an API key or developer credentials. Usernames contain up to 15 letters, numbers, or underscores and should be passed without @. Keep user and post IDs as strings so they do not lose precision.

list_user_posts accepts maxResults from 5–100. Recent search accepts 10–100 results per request; pass the returned nextToken unchanged to continue the same query. X may further limit results and publishing based on the connected account's API access.

Posts and replies require native agent approval before Matrix sends them. This integration does not expose direct messages, follows, likes, reposts, or deletion.

Reading Beyond the First Page

  • Calendar and Drive accept pageToken; continue with nextPageToken. Drive also returns incompleteSearch, which must not be treated as a complete search.
  • GitHub repository, issue, pull-request, and notification lists accept page and per_page. Link response headers are not exposed by this increment; continue numbered pages until an empty page rather than assuming one page is all results.
  • Slack channel/message lists accept cursor; continue with response_metadata.next_cursor. Slack search uses page and count.
  • Discord server/message lists accept either before or after, plus limit. Keep these IDs as strings, not JavaScript numbers.
  • X recent search accepts nextToken; pass the returned token unchanged with the same query to continue beyond the first page.

Service actions return one provider page. Your app or worker must retain its filters and checkpoint progress. Pipedream action/account discovery separately walks SDK pages with limits of 20 pages, 2,000 entries, 10 seconds per request, and a shared 30-second deadline. A later-page failure or exceeded bound rejects the inventory; it is not reported as a complete partial list. Account discovery does not request credentials.

Multiple Accounts

You can connect multiple accounts for the same service. For example, a Work Gmail and a Personal Gmail. Use labels to differentiate:

"Send from my Work Gmail: email alice@company.com about the Q2 report"

The agent uses the label parameter to target the right account. If no label is specified, the most recently connected account is used.

Managing Connections

View connections

"What services are connected?"

Or open Settings > Connect Apps to see all active connections with status indicators.

Disconnect a service

"Disconnect my GitHub"

Or click Disconnect in Settings. This revokes the connection's OAuth credentials when the provider supports revocation and removes the connection from your account.

Building Apps with Integrations

Apps you build can use connected services. When the agent creates an app that needs Gmail or Slack, the platform tracks which services each app requires:

{
  "name": "Morning Briefing",
  "integrations": {
    "required": ["gmail", "google_calendar"],
    "optional": ["slack"]
  }
}

If a required service isn't connected, the platform tells you what's missing and how to connect it.

Bringing Connected Data into an App

Connecting an account makes reviewed actions available; it does not start automatic background polling or unlimited historical imports. Matrix agents can orchestrate bounded manual refresh for an installed app through the owner-authenticated /api/data-imports routes. The source must be declared in the installed app’s apps/<appId>/matrix.json integrations list, then bound to the exact service, action, account label, and connectionId. Owner agents use refresh_imported_data, get_imported_data_status, and read_imported_data_pages; preview_data_url reads bounded public URL metadata, and delete_imported_data removes a selected retained source only when requested. These tools are unavailable to scoped or discovery-only agent runs. Refresh access is currently owner-only; sandboxed generated apps do not gain owner API access from an app-session cookie.

Refresh jobs, pages, checkpoints, and retry state persist in the owner’s PostgreSQL database. A job reads at most five pages, eight source calls, and 2 MiB total, with a 512 KiB page limit. A failed read retains recoverable state and safe retry information; exhaustion stops further reads. Disconnecting or replacing an account does not silently redirect a saved source to another account. Source removal deletes the retained import state. Restarting an import keeps the last saved pages visible until a complete replacement succeeds. Contacts restarts fetch a full snapshot, clearing the previous sync watermark; failed or partial replacements do not erase the saved snapshot.

The expanded source reads include Gmail attachments, Notion page bodies, calendar events, Todoist tasks, GitHub information, Stripe records, and Granola notes. A supplied public URL can have a bounded inert text preview: Matrix does not execute page scripts, automatically follow links, or turn website text into instructions. Private network destinations are blocked.

Manual refresh is a foundation for app builders, rather than a complete inbox, CRM, accounting, or fitness application. It does not automatically extract receipts, evaluate chess moves, or call an AI model. Apps still need their own user-facing workflows and permissions.

Device connections and selected-device import flows are deferred to a later release. Direct Hevy authorization and chess-engine analysis are also deferred.

How It Works

User -> Shell (Settings UI / Conversation)
         |
    Matrix Gateway
         |
    Platform-owned Integration Layer
    - OAuth token management
    - Action execution
    - Credential storage
         |
    External Service APIs
    (Gmail API, GitHub API, Slack API, etc.)

Integration provider credentials stay on the platform. Customer workspaces call the platform integration layer through scoped Matrix routes, so apps and customer VPSes do not need raw provider secrets.

Error Handling

ErrorWhat it meansWhat to do
"Service not connected"The service hasn't been authorized yetConnect it first via Settings or conversation
"Rate limited" (429)Too many requests to the serviceWait and try again (the retry_after field tells you how long)
"Timed out" (504)The service took too long to respondTry again or simplify the request
"Service unavailable" (503)The integration provider is temporarily unavailableTry again in a few minutes
"Missing required params" (400)The action is missing required inputCheck the action reference above

Common Workflows

Morning Briefing

"Give me my morning briefing" -- agent reads unread emails, today's calendar, and summarizes both.

Cross-Service Automation

"Summarize open GitHub issues and post to #standup in Slack" -- agent reads from GitHub, formats, and posts to Slack.

Email + Calendar

"Email alice about the meeting and add it to my calendar" -- agent sends the email and creates the event in one conversation.

Drive Sharing

"Share the Q2 report with the marketing team" -- agent finds the file in Drive and shares it with specified emails.

How is this guide?

On this page