Organization Admin

Configure the workspace and run every operating module, control, integration, and business lifecycle.

Organization AdminConnections18 min read

Connect and rotate API services

Choose an organization-owned provider, obtain the minimum credentials, configure callbacks or webhooks, test, and rotate safely.

Who can do this

Organization Owner or Organization Admin

Primary route

/settings/organization/api-services

Last verified

4 August 2026

What you need
Have these ready before you start.
  • Administrator access to the provider’s official console
  • A sandbox account where the provider supports one
  • A named credential owner and rotation date

01

Choose the correct credential scope

Organization API Overrides contains tenant-owned connections. Shared AI and infrastructure providers are platform-managed; do not create tenant copies unless the product explicitly offers that provider in this selector.

  • Business connections include Gmail, Google Document AI, Shopify, EasyParcel, OneMap, HitPay, Resend, IRAS, CPF EZPay, ACRA, GovTech APEX, Corppass, Meta, and Custom.
  • A provider shown in the organization selector is eligible for tenant configuration; a provider absent from it is not.
Organization API provider selector listing supported business connections
The provider selector is the authoritative list of organization-configurable services.

02

Obtain credentials from the official provider

Create a dedicated application or integration for this platform. Avoid personal tokens and broad account-owner keys.

  1. Open the provider’s official developer or administration console.
  2. Create a dedicated sandbox application first when available.
  3. Grant only required scopes and restrict allowed origins, IPs, or resources where supported.
  4. Copy the callback or webhook URL shown by the connection dialog exactly.
  5. Store the secret only in the platform form; keep ownership and expiry metadata in your credential register without copying the secret.

03

Connect and test

Open Settings → Organization → API Overrides and select Connect.

  1. Select the provider and give the connection a recognizable name.
  2. Complete public configuration fields such as domain, base URL, environment, sender, or account country.
  3. Paste secret fields such as API key, client secret, signing key, or webhook secret.
  4. Create the service and run Test connection.
  5. Resolve unhealthy or untested status before enabling production workflows.

Expected result: The service row shows the expected provider, masked credentials, healthy status, and a recent test time.

Organization API overrides table with connection status and actions
Saved secrets are masked. Use the status and last-checked columns to verify the live connection.

04

Register callbacks and webhooks

OAuth callbacks complete authorization; webhooks deliver provider events. They are different controls and may use different secrets.

  1. Copy the callback URL from the provider form without changing its scheme, host, path, or trailing slash.
  2. Subscribe only to the webhook topics listed by the platform form.
  3. Store the signing or verification secret in its dedicated secret field.
  4. Send a provider test event and confirm the service remains healthy.

05

Rotate without downtime

Use overlap: create the replacement before revoking the credential currently in service.

  1. Create the replacement credential at the provider.
  2. Edit the platform connection and save the new value.
  3. Run the connection test and one non-destructive sandbox workflow.
  4. Revoke the old credential at the provider.
  5. Record the rotation, owner, and next review in the audit process.

Deleting a service row is not the same as revoking the provider credential. Complete both sides during decommissioning.

Troubleshooting

  • 401/invalid credential: check environment, copied value, expiry, and whether the secret was rotated at the provider.
  • 403/insufficient scope: add only the missing provider permission, then retest.
  • OAuth redirect mismatch: compare the full callback URL character-for-character.
  • Webhook verification fails: confirm the correct environment-specific signing secret and topic selection.