How to share one app connection with your whole team

Connect an app once as a shared account so every teammate's agent can act through it. Who can share, who can remove, and when to keep a connection private.

Illustration: A small friendly robot with a round camera-eye head hands identical wrenches from a basket to two simple human figures standing in line.

A shared connection is an app account connected to CoreSpeed with its visibility set to the whole organization. Any member can connect one. Once it exists, every member's agents and every agent key in the org can call its tools. The token stays in CoreSpeed's custody. Teammates receive tools, never the credential.

Share one account with the org
  1. 1
    Pick the app
    Dashboard, Connectors
  2. 2
    Connect with shared visibility
    each account has its own setting
    A private account of the same app can sit beside it.
  3. 3
    Authorize on the vendor's screen
    the screen names CoreSpeed
  4. 4
    Confirm it in the index
    GET /connectors shows the alias and can_remove
  5. 5
    Teammates start a new session
    tools/list is caller-specific
    Their agents get tools such as slack__post_message, never the token.
Connect once with shared visibility; teammates get tools, never the token.

When should a connection be shared?

Share an account that belongs to the company. A team Slack workspace, the product's GitHub organization, the shared Notion workspace, the Linear team: these are the accounts several people's agents need, and nobody wants five separate OAuth grants to the same workspace.

Keep an account private when it is yours. A personal X handle, your own Notion space, a Google Drive that holds your files. A private connection is usable only by you and your clients.

There is one more reason to share. An agent principal, the kind that signs in with an sk-csa- key, reaches shared connections only. It never sees a member's private ones. So if a nightly job you operate needs to post to Slack, the Slack account it uses must be shared. Details on principals are on the authentication page.

KindWho connects itWho can use itWho removes itActions attributed to
Privateany memberthat member and their clientsthat memberthe member
Sharedany memberevery member and every agent key in the orgwhoever connected it, or an org adminthe caller
Organization integrationan org adminthe whole organ org adminthe app itself

How do you connect an app as shared?

  1. Open Dashboard → Connectors and pick the app.
  2. Click Connect and choose shared visibility. Each account gets its own setting, so you can hold a private account of the same app next to it.
  3. Review the requested scopes on the provider's consent screen and authorize. The screen names CoreSpeed because the OAuth client is CoreSpeed's.
  4. Confirm the account in the index. The authenticated index is the only inventory of what is connected, and it reports each account's alias and its can_remove rule.
  5. Ask a teammate to start a new session in their client. tools/list is caller-specific, and a fresh session picks up the connector's tools.
curl https://api.corespeed.io/connectors \
  -H "Authorization: Bearer $CORESPEED_API_KEY"

The same steps work for a pasted API key where the connector supports one. Stripe is an example. The pasted key is stored encrypted as one connection with the same private-or-shared visibility as any OAuth account.

What about Slack and Linear?

Some vendors let CoreSpeed's app act as its own user inside the workspace. Slack installs a workspace bot. Linear installs an app that works under the alias corespeed-bot. On those connectors, org-wide access is an organization integration, and only an org admin can connect it. Actions through it are attributed to the app, so a message posted by an agent shows as the bot in Slack.

On those two connectors a member's own account is private only. If your team needs a shared Slack, an admin installs the integration; a member's personal Slack grant does not become shared.

Who can remove a shared connection?

A private account is removed by its member. A shared one is removed by whoever connected it or by an org admin. The index reports both rules per account as can_remove, so a client does not need to guess.

Disconnecting is the switch. Connectors have no capability toggle in Dashboard → Tools; that page covers the built-ins (Memory, Media, Web, Social). For an OAuth account, disconnect removes CoreSpeed's stored grant. For a pasted key, disconnect deletes CoreSpeed's copy only. The key itself keeps working at the vendor until you revoke it there.

One more state to know. If a refresh fails, or the vendor names the credential as invalid, the account moves to needs_reauth. Its tools stay visible and calls fail until the account is reauthorized in Dashboard → Connectors. Do not rotate the CoreSpeed key and do not rewrite client config; neither is broken.

How does attribution work when everyone shares one account?

Sharing does not blur who did what. Every call through a shared connection lands in Dashboard → Activity with the action, the actor, the outcome and the time. Members see their own actions; org admins see the org. A call made with a member's sk-cs- key is attributed through that member. A call made with an agent key is attributed to the agent, whose owner answers for it. A call through an organization integration is attributed to the app. The activity page lists what each record holds.

If your org has Smart Approval turned on, writes through a shared connection are judged like any other write. The card goes to the member who made the call, or to the owner of the agent or API key that made it. Reads are never gated.

FAQ

Can an agent key use my private connection? No. An agent principal reaches the organization's shared connections only. Share the account, or run that job under a member key that acts as you.

Does sharing hand my token to teammates? No. CoreSpeed stores the credential and refreshes it when the provider allows. Teammates get namespaced tools such as slack__post_message. The token never leaves the platform.

Can I keep a private account and a shared one of the same app? Yes. One connector can hold several accounts, each with an alias. Tools take an optional account argument; with several in scope and none named, the call answers ambiguous_account with the aliases to pick from.

Who fixes a shared connection that stopped working? Whoever can reauthorize it: the member who connected it, from Dashboard → Connectors. Until then its tools are listed but calls fail with needs_reauth. See the connectors page for the full lifecycle.