
Apps, company knowledge, and files
These sources serve different purposes in a Craft session:Available apps
Your Apps page shows only the apps your organization has enabled. Onyx includes built-in support for:
Your organization can also provide custom apps for APIs or services that are not in the built-in catalog.
The actions available to you depend on the access granted by the external service and your organization’s policies.
Connect an app
1
Open Apps
Select Apps in the Craft sidebar. Connected accounts appear first;
everything else your organization has enabled appears under Browse apps.
2
Connect your account
Select Connect. Built-in apps open the service’s authorization flow.
A custom app may instead ask for fields defined by your admin.
3
Review access
In the external service, confirm the account and permissions you are granting. When setup finishes,
the app moves to Connected.
4
Use it in a session
Describe the app in your prompt, or select + > Apps and choose it. For example:
“Summarize the launch discussion in Slack and draft a follow-up in Gmail.”
Guide Craft to the right data
Connecting an app makes it available; your prompt should still identify the relevant scope. Include concrete names, dates, channels, repositories, projects, folders, or records whenever possible.Review approval requests
Your organization controls every app action with one of three policies:
When an action uses Ask, expand the approval card to review the app, action, description,
and request payload before deciding.

Before approving, confirm:
- The app and connected account are the ones you intended.
- The destination, such as a channel, recipient, repository, calendar, or record, is correct.
- The content and payload match what you asked Craft to do.
- The action is not broader or more destructive than necessary.
Apps in Scheduled Tasks
A Scheduled Task runs without you present. Select its expected apps under Pre-approved apps so those apps can act without waiting for a live response. Pre-approval applies only to that Scheduled Task. An app action with a Deny policy remains blocked, and an app you did not pre-approve can leave the run waiting for approval.Disconnect an app
Open Apps, find the account under Connected, and select Disconnect. Craft can no longer make authenticated requests through that connection. You can reconnect later by completing the connection flow again.Raw app credentials never enter Craft’s sandbox workspace.
The sandbox proxy injects them only into approved outbound requests. For the full trust and network model,
see Craft Architecture.
Troubleshooting
An app does not appear
An app does not appear
Your organization has not enabled it, or its setup is incomplete.
Ask an admin to review the app configuration and your access.
Admins can use the Craft Apps setup guide.
The connection flow fails
The connection flow fails
Confirm you selected the intended external account, allowed the setup window to open,
and granted the requested access. For a custom app, verify the credential fields with your admin.
Then return to Apps and try again.
Craft cannot perform an action
Craft cannot perform an action
The action may be denied by policy, outside the connected account’s access, rejected,
or expired while awaiting approval. Craft does not retry a blocked action automatically;
adjust the request or contact an admin if the action should be available.
A Scheduled Task is awaiting approval
A Scheduled Task is awaiting approval
Edit the task and confirm the required app is selected under Pre-approved apps. If it is already selected,
an admin may have denied that action or the run may need a different app.
For admins
Enable built-in or custom apps, configure credentials, and set action policies.
Use Skills
Give Craft reusable methods, examples, templates, and helper files.