Skip to main content
Envoy uses OAuth 2.0 to securely authorize access to your workplace data. When you click Connect, you’ll be redirected to Envoy to sign in and approve the requested permissions. After approval, Envoy returns a short-lived access token plus a refresh token that we use to keep the connection live without storing your password.

Who can connect

Envoy requires a Global Admin account to authorize the integration. The connection requires approval of requested scopes.

What we read

We request read-only access to the following resources. You can revoke these permissions at any time from your Envoy admin settings.

Security

  • Read-Only Access: All scopes are read-only. We never write back to your Envoy account.
  • Token Rotation: Access tokens expire every 24 hours and are refreshed automatically. Refresh tokens rotate every 30 days.
  • Revocation: You can disconnect at any time from this page or by removing the app from your Envoy admin dashboard.