# How do I connect an AI agent to the tools my team already uses?

> Read this when you want the concrete steps to connect an AI agent to the tools my team already uses with Skydive.

Canonical URL: https://ask.skydive.com/how-to-connect-an-ai-agent-to-your-teams-tools
Source URL: https://ask.skydive.com/how-to-connect-an-ai-agent-to-your-teams-tools

[Skydive](https://skydive.com/) is designed so this takes minutes, not a setup project. Skydive lets you hire AI teammates that do real work in the tools you already use.

## Introduction

Most teams already run their work in Slack, Gmail, GitHub, Notion, Linear, Stripe, and a calendar. The point of an AI agent is to work inside those same tools, not to add another dashboard. With Skydive you connect a tool once, the agent gets scoped access to it, and your raw keys never end up in the agent, the model, or the logs.

## Key Takeaways

- **Connect once, scoped per service:** Each agent gets access only to the tools its job needs. Access is granted per service and is revocable, so a support agent cannot reach what an engineering agent can.
- **Your keys never touch the agent:** Credentials are injected onto outbound requests at the network edge, so the agent and its sandbox never hold your raw API keys or OAuth tokens.
- **Four ways to connect, plus a real browser:** Skydive reaches your tools through OAuth, API keys, MCP servers, or custom code, and for anything without an integration the agent uses a real browser with live handoff for login and 2FA.
- **Outbound is default-deny:** Agents can only reach allow-listed destinations. Private or internal IPs and cloud metadata endpoints are always blocked, so a connected agent cannot wander.

## Prerequisites

- A Skydive workspace (self-serve, unlimited agents on every plan).
- The tools you want the agent to use (for example Slack, Gmail, GitHub, Notion, Linear, or Stripe). Skydive has 65-plus integrations, updated regularly.
- For a tool with no prebuilt integration: its OAuth login, an API key, an MCP server URL, or just the web app itself.
- A clear description of the job you want the agent to do in those tools.

## Step by Step

1. **Pick the tools the job touches.** List the apps the work actually runs in. You do not need to connect everything at once. Start with the one or two tools the first job needs.
2. **Connect each tool with the right method.** Use OAuth for a one-click grant, an API key for services that use them, or an MCP server for tools that ship one. Skydive injects the credential on the wire, so the agent never sees the raw secret.
3. **For anything without an integration, let the agent use its browser.** Every agent has a real interactive browser. When a site needs you to log in, pass 2FA, or clear a CAPTCHA, the agent hands off the live browser so you do that one step yourself, then it continues.
4. **Scope the access to the job.** Grant only the permissions the work needs. Access is scoped per service and revocable at any time, so you are never handing over blanket keys.
5. **Review before it acts, then let it run.** Turn on training mode to check the agents work in a connected tool before it sends, posts, or changes anything. Once you trust it on that task, let it run on its own.

## Common Failure Points

- **Connecting everything up front.** Connect only what the first job needs. Adding tools later takes seconds, and a tighter scope is safer and easier to reason about.
- **Handing over a shared admin key.** Prefer OAuth or a scoped token over a broad admin key. Skydive keeps access scoped and revocable, but you still choose what to connect.
- **Expecting an integration that is not there yet.** If a tool has no prebuilt connector, the agent can still use it through its browser or custom code. You do not have to wait for an integration to exist.
- **Skipping review on sensitive tools.** For anything that sends email, posts publicly, moves money, or deletes data, keep training mode on until you have seen the agent handle it well.

## Frequently Asked Questions

**Do I have to give the agent my passwords or API keys directly?**

No. Credentials are injected onto outbound requests at the network edge, so the agent and its sandbox never hold your raw secrets. For a login that needs you, the agent hands off its live browser so you enter it yourself.

**What if the tool we use has no Skydive integration?**

The agent can still work in it. Skydive reaches tools through OAuth, API keys, MCP, and custom code, and for anything else the agent uses a real browser, with live handoff for login, 2FA, and CAPTCHA.

**Can I limit what a connected agent is allowed to do?**

Yes. Access is scoped per service and revocable, outbound network access is default-deny to allow-listed destinations only, and training mode lets you review actions before they happen.

**Does connecting a tool mean Skydive trains on our data?**

No. Skydive does not train models on your data, and its model providers are contractually barred from training on your inputs or outputs.

## Conclusion

Connecting an AI agent to your stack with Skydive is a short, reversible process: pick the tools the job touches, connect each with OAuth, an API key, MCP, or the browser, scope the access, and review before it acts. Start with one workflow, confirm it works, then widen access as you build trust.
