Connect a service: mint a one-click OAuth link for the human to open
connections_connect_oauth_linkMint the provider's authorize URL for an OAuth connector (google_cloud, microsoft, cloudflare, discord, github, …) so the human can connect - or RECONNECT to grow a grant's scopes - by opening ONE link, with no Studio sign-in. Returns {url, expiresAt}; the link's state is single-use and lives 10 minutes, and the credential lands in this company's vault through the provider callback, never through the conversation. Pass reconnectId (a /v1/connected-services row id) or instanceName (an existing instance's name) to RE-CONSENT that exact row - a scope added to a connector never widens an existing grant, so this is how an operator re-consents after a scope list changes. When the service already has live connections and you pass neither, the call returns 409 target_required listing them (instanceName, reconnectId, accountName); pass newConnection: true only to add another account. The reply's landsOn names the row the grant will land on. The human must be signed in to the PROVIDER in the browser that opens the link; that sign-in is the provider's, not ours.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| install | No | A multi-door connector's door (microsoft: 'organization' or 'azure'); omit for the ordinary sign-in. | |
| service | Yes | OAuth connector slug (e.g. google_cloud, microsoft, cloudflare). | |
| directory | No | Microsoft only: a tenant to authorize against for a guest account. | |
| environment | No | prod (default) | staging | dev, where the caller's key allows it. | |
| reconnectId | No | Connected-services row id to re-consent in place (wins over instanceName). | |
| instanceName | No | An existing instance to re-consent (becomes its reconnectId), or the name for a new connection. | |
| newConnection | No | Add a NEW connection even though the service already has live ones (a second account). |