Open-source auth gateway connecting 1000+ SaaS providers to AI agents through SDK, CLI, MCP, HTTP, and OpenAPI.
OpenConnector is an open-source connector gateway for AI agents and an alternative to Pipedream/Composio.
Connect user app accounts once, then expose a shared catalog of 1,000+ providers and 10,000+
prebuilt Actions to agents and applications.
|
|
|
| Managed OAuth and hosted runtime, ready to use. No deployment or OAuth app setup. |
Run locally or on your own infrastructure with Docker or Node.js. You manage storage and OAuth apps. |
Cloudflare, Fly.io, RepoCloud, nibrun, and more. |
| OOMOL Hosted |
Self-host |
More platforms |
Use the [Connector SDK](https://github.com/oomol-lab/connector-sdk) from app code,
[oo CLI](https://github.com/oomol-lab/oo-cli) as the local-agent relay, MCP from agent hosts,
HTTP/OpenAPI from custom clients, and the Web Console for administration and debugging.
- Keep credentials, scopes, schemas, policies, and run logs inside an inspectable runtime.
- Run locally, on your own infrastructure, or through OOMOL's hosted runtime.
- Use the same provider ids, Action ids, schemas, and contracts across open-source and commercial
SaaS deployments.
## What It Provides
- A working connector catalog across products such as GitHub, Gmail, Notion, BigQuery, Google
Analytics, Supabase, Airtable, Slack, and more.
- Credential handling for API keys, OAuth2, custom credentials, and no-auth providers.
- Inspectable Action contracts: request/response schemas, required scopes, and lazy-loaded executor
source.
- Runtime controls for connection identity, scopes, runtime tokens, action allow/block policies,
temporary file transit, and redacted run logs.
- Deployment options for local Docker or Node.js with SQLite or PostgreSQL state and local or
S3-compatible transit storage, plus OOMOL's hosted runtime. Additional managed platforms are
listed in [deployment options](docs/deployment-options/).
## Where It Fits
OpenConnector fits products where agents need durable access to the tools users already use, without
handing provider credentials to the agent process.
- Agent products that need reusable access across work apps, developer tools, data systems,
communication platforms, and AI services.
- Products adding agent workflows that need stable, inspectable Action contracts for user app
access.
- Teams that want hosted auth for speed while keeping a path to private or self-hosted runtime
control.
## Developer Tools
| Tool | Purpose |
| ----------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [Connector SDK](https://github.com/oomol-lab/connector-sdk) | Thin TypeScript HTTP client. Use `OpenConnector` for self-hosted runtimes, or `Connector` / `ProjectConnector` for OOMOL-hosted personal and SaaS end-user connections. |
| [oo CLI](https://github.com/oomol-lab/oo-cli) | Local agent relay for connector Actions. `oo connector` can search, inspect, and run Actions against OOMOL-hosted or self-hosted OpenConnector runtimes. |
| MCP | Expose app Actions to MCP-capable agent hosts through `http://localhost:3000/mcp`. |
| HTTP / OpenAPI | Call `/v1/actions/*` directly or inspect the generated `/openapi.json` document. |
Endpoint details, response envelopes, auth headers, MCP tools, and Action guide examples are in
[docs/runtime-api.md](docs/runtime-api.md).
## Dashboard Preview
OpenConnector ships with a local Dashboard for browsing connectors, configuring credentials,
creating runtime tokens, and inspecting runtime usage.
### Connector Catalog
Use the connector catalog to see available services, search for providers, and open their Actions
and credential setup from one place.
### Usage Overview
Use the Overview page after deployment to monitor runtime readiness, available providers,
executable Actions, recent failures, tool call trends, and recent calls.
Provider names and trademarks belong to their respective owners and are used only for identification
and interoperability.
## How It Works
```mermaid
flowchart LR
Agent["AI Agent / App"] -->|"SDK / CLI / MCP / HTTP"| Gateway["OpenConnector Gateway"]
Gateway --> Auth["Credential & OAuth Boundary"]
Gateway --> Catalog["Provider Catalog"]
Gateway --> Actions["Open-source Action Executors"]
Gateway --> Policy["Tokens, Scopes, Allow/Block Policy"]
Gateway --> Logs["Run Logs"]
Actions --> Providers["1,000+ Providers"]
Console["Web Console"] --> Gateway
Cloudflare["Cloudflare Workers, D1, R2"] -. deploy .-> Gateway
```
Apps and agents discover Actions, inspect schemas and scopes, select a connection alias, and execute
through the gateway. Provider secrets stay behind the runtime boundary; agents receive the metadata,
safe account labels, and execution results needed for the run.
## Usage Paths
| Path | Best for | Includes |
| --------------------------------------------------------- | ------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Open-source self-host | Developers and teams that want full control | Local Docker or Node runtime, SQLite or PostgreSQL state, local or S3-compatible transit files, MCP, HTTP, OpenAPI, and Web Console |
| [Kubernetes (Helm)](deploy/helm/open-connector/README.md) | Teams that run their own clusters | Hardened Helm chart with PVC-backed SQLite or PostgreSQL plus migration hooks, Ingress, autoscaling, and NetworkPolicy toggles |
| [OOMOL](https://oomol.com/apps) | Teams that want users to authorize accounts immediately | OOMOL-provided OAuth apps, monthly included Connect credits, and hosted runtime infrastructure; the same provider and Action contracts keep a path open to later private or self-hosted deployment |
## Quick Start
> [!NOTE]
> This starts a self-hosted runtime. OAuth providers require OAuth client credentials from apps you
> register with those providers. To let users authorize supported providers without setting up your
> own OAuth apps, use [OOMOL-hosted connectors](https://oomol.com/apps).
Start the runtime from the published image with Docker Compose:
```bash
docker compose up
```
This pulls `ghcr.io/oomol-lab/open-connector:latest`. To build from source instead:
```bash
docker compose -f docker-compose.yml -f docker-compose.build.yml up --build
```
Open the local console and generated API reference:
```text
http://localhost:3000
http://localhost:3000/docs
```
Run a no-auth Action to verify the runtime:
```bash
curl -s -X POST http://localhost:3000/v1/actions/hackernews.get_top_stories \
-H 'content-type: application/json' \
-d '{"input":{}}'
```
See [docs/quickstart.md](docs/quickstart.md) for the full local setup, first provider connection,
OAuth flow, and runtime settings.
## Connect a Provider
GitHub is the simplest credentialed example because it can use a personal access token:
```bash
curl -s -X PUT http://localhost:3000/api/connections/github \
-H 'content-type: application/json' \
-d '{"authType":"api_key","values":{"apiKey":"github_pat_..."}}'
curl -s -X POST http://localhost:3000/v1/actions/github.get_current_user \
-H 'content-type: application/json' \
-d '{"input":{}}'
```
For OAuth2 apps, named connections, credential encryption, token refresh, and action policies, see
[docs/credentials.md](docs/credentials.md) and [docs/configuration.md](docs/configuration.md).
## Web Console
For npm-based local development, open `http://localhost:5173`; the Web Console dev server proxies
API requests to the runtime on `http://localhost:3000`. For Docker or a built Node runtime, the
console is served from `http://localhost:3000`.
The console supports provider browsing, API key and OAuth client configuration, runtime token
creation, Action schema inspection, Action debugging, recent run review, and access to the
generated OpenAPI and MCP metadata.
## PostgreSQL Runtime Storage
The Node runtime uses SQLite by default and can use PostgreSQL 15 or newer when
`OOMOL_CONNECT_DATABASE_URL` is configured. PostgreSQL migrations are explicit: run
`npm run runtime:migrate` before starting a version with pending migrations. Server startup only
checks schema readiness and never applies PostgreSQL DDL. See
[docs/configuration.md](docs/configuration.md#runtime-database) for configuration, permissions, TLS,
and multi-instance requirements. The Docker image exposes the same runner as its `migrate`
subcommand; see [docs/docker-ghcr.md](docs/docker-ghcr.md#postgresql-migrations).
## Docker Image (GHCR)
Run OpenConnector from a prebuilt image on GitHub Packages (GHCR): `ghcr.io/oomol-lab/open-connector`. Use
`latest` for the newest release, a pinned released version for production, or `tip` for the latest
`main` build.
See [docs/docker-ghcr.md](docs/docker-ghcr.md) for tags, pulling, and running.
## Build a Desktop Agent with Wanta
OpenConnector and [Wanta](https://github.com/oomol-lab/wanta) are two open-source projects for AI
Agents in the OOMOL ecosystem. OpenConnector connects Agents to external services such as Gmail,
Slack, and Notion. Wanta provides a complete desktop Agent application powered by OpenCode and uses
OpenConnector to work with connected SaaS services.
- **Run locally:** Use your own OpenAI-compatible model without creating a Wanta account.
- **Build your own:** Fork Wanta and customize its prompts, tools, interface, models, and branding.
- **Use hosted services:** The optional [hosted experience](https://wanta.ai/) provides managed
models, OAuth connections, and team workspaces.
Issues and pull requests are welcome.
## Documentation
- [Quickstart](docs/quickstart.md)
- [Developer tools](docs/sdk-cli.md)
- [Programmatic connection management](docs/programmatic-connections.md)
- [Gmail OAuth and SDK tutorial](docs/gmail-oauth-sdk.md)
- [Instagram OAuth and Actions](docs/instagram-oauth.md)
- [Runtime API and MCP](docs/runtime-api.md)
- [Embed the runtime](docs/headless.md)
- [Deployment options](docs/deployment-options/)
- [Fly.io deployment](docs/fly-io.md)
- [Cloudflare deployment](docs/cloudflare.md)
- [Docker