big docs
Integrations

Connect an integration

Everything on this page happens in the dashboard and needs the admin role or higher. Members below admin see the same screens without the controls. There is no way to connect, rotate or disconnect from the CLI, the API or an MCP tool.

Connect

  1. Open Connect in the sidebar, find the Integrations section and choose Browse catalog.
  2. Pick the tool you want to connect. Its screen says which kind of key to create and how to keep it as narrow as the tool allows. The per-tool pages have the same guidance: Calendly, Kit, Stripe.
  3. Create the key in that tool, then paste it into big Give the integration a label you'll recognise later, for example "Sales Calendly".
  4. Save. big tests the key before it stores anything. It makes one read-only call to the tool with the key you pasted:
    • If the tool accepts it, the key is encrypted and saved, and the integration shows as Connected with the account the key belongs to.
    • If the tool rejects it, or the key is broader than big allows (a full Stripe secret key, for example), nothing is saved and you see a short explanation. Fix the key and try again.
    • If the tool is down or busy, nothing is saved and you can simply retry.

Once saved, the key is never shown again, to you or anyone else. The integration's page shows its last 4 characters and a short fingerprint so you can tell which key is in use. See Integration security.

Every connect, rotate or re-verify tests a key, and testing is limited in two ways: 10 attempts per minute per person, so a mistyped key can be retried straight away, just not in a tight loop; and a daily limit per workspace, across all its admins. Connecting and re-verifying share 30 key tests a day; once the workspace reaches it, they are refused until tomorrow. Rotating has its own 20 a day, so using up the connect and re-verify limit never stops you replacing a leaked key. Disconnecting tests nothing, so it is never limited.

A suspended workspace can't connect, rotate or re-verify an integration.

Rotate a key

Rotate when a key may have leaked, when someone who had access to it leaves, or on your own schedule.

  1. Create a new key in the tool.
  2. Open the integration in Connect → Integrations and choose Rotate.
  3. Paste the new key. big tests it exactly as it does on connect, and only replaces the old key once the new one works. If the test fails, the old key stays in place and keeps working.
  4. Delete the old key in the tool. big can't do this for you: an API key can only be revoked in the tool that issued it. Until you delete it there, the old key still works for anyone who has a copy.

The fingerprint changes when the key changes, so you can confirm the rotation took.

Re-verify

Re-verify re-runs the same read-only test against the key big already holds. Use it after fixing something in the tool, such as a key you re-enabled or a permission you added, to bring an integration in Error back to Connected without pasting the key again.

big also watches for a dead key on its own: after 3 rejections in a row, it moves the integration to Error and stops calling the tool with it, rather than hammering the tool with a key that no longer works. Re-verify, or rotate to a new key, to bring it back.

Disconnect

Disconnect deletes the stored key immediately. There is no undo; to use the tool again, connect it with a key again.

A small record of the integration stays for your workspace's audit history: which tool it was, its label, the dates, and its fingerprint. It never includes the key or its last 4 characters.

As with rotating, delete the key in the tool too. Disconnecting removes big's copy; it doesn't revoke the key where it was issued.

If you downgrade

Moving to a plan with a lower integration limit never disconnects anything:

  • The integrations you already have keep working as before, and you can still re-verify, rotate and disconnect them.
  • You can't connect a new one while you are over the new plan's limit. Connecting is refused with a message saying so.
  • Disconnect the ones you don't need to get back under the limit, or upgrade.

Check status from your agent or the CLI

Anyone with a token carrying the integrations:read scope can see the same status the dashboard shows, without a key ever being involved:

  • CLI: big integrations list and big integrations status <id>. See the command reference.
  • MCP: integration_status on the remote server, big_integration_status on the local one. See MCP.
  • API: GET /api/integrations/status. See the API reference.

All of them are read-only. Connecting, rotating and disconnecting are dashboard-only; keys are never readable.

Connect an integration | itsjustbig