Integrations
Your tools are already here.
Helios indexes the full API of each service. Bring the Helios app, your own app, or an API key. 17 services today, plus your databases and any remote MCP server.
5,000 free credits to start.
- Services
- 17
- Full API of each one
- Event triggers
- 3
- GitHub, Slack, Plain
- Databases
- 3
- Postgres, MySQL, ClickHouse
- MCP servers
- Any
- Remote, over HTTPS
How it works
The full API of each tool.
Helios gives an agent the whole API of a connected tool and a way to search it.
- 01
Helios indexes the API spec
When you connect a service, its full OpenAPI or GraphQL spec goes into a vector index. Every endpoint, parameter, and description is searchable.
- 02
The agent finds the endpoint
The agent calls find-relevant-apis with a plain description of what it needs. It gets back the closest endpoints and their schemas.
- 03
The agent calls it
The agent calls call-api with the method, path, and body. The egress proxy adds the credential on the way out. The sandbox never holds a token.
find-relevant-apis "add a label to a pull request"POST /repos/{owner}/{repo}/issues/{issue_number}/labels 0.91GET /repos/{owner}/{repo}/labels 0.84call-api github POST /repos/acme/api/issues/482/labels {"labels":["needs-review"]}200 OK · credential added by the egress proxy
The two tools run inside the sandbox. The credential does not. Helios attaches it at the network layer, so a prompt injection has nothing to read.
Auth modes
Three ways to connect a service.
Every credential is envelope-encrypted at rest and attached to requests outside the sandbox. Sharing an integration never exposes its credential.
Helios OAuth app
Click connect and approve the Helios app on the provider's consent screen. Helios refreshes the tokens.
Your own OAuth app
Register your own OAuth app or bot with the provider. Pick your own scopes and show your own name on the consent screen.
API key
Paste a key from the provider's dashboard. A read-only key keeps a reporting agent from writing anything.
| Service | Helios OAuth app | Your own OAuth app | API key |
|---|---|---|---|
| GitHubOrganization installs also ask each person to authorize once, so the agent acts as that person. | ● | ● | ● |
| SlackEach person authorizes once after the workspace installs the app. | ● | ● | – |
| Gmail | ● | ● | – |
| Google Sheets | ● | ● | – |
| Google Docs | ● | ● | – |
| Google Drive | ● | ● | – |
| Notion | ● | ● | ● |
| Attio | ● | ● | – |
| Apollo | ● | ● | ● |
| Stripe | – | – | ● |
| Resend | – | – | ● |
| PlainPaste the webhook signing secret from Plain to receive thread events. | – | – | ● |
| DiscordCreate a bot in the Discord developer portal and paste its token. | – | ● | – |
| ● | ● | – | |
| Typeform | ● | ● | ● |
| Apify | – | – | ● |
| WarpBuild | – | – | ● |
| DatabasesPaste a database connection string. Add an SSH tunnel for a database on a private network. | Connection string | ||
Triggers
Which services can start a run.
Every workflow can run by hand, on a schedule, or from a signed webhook. GitHub, Slack, Plain can also start a run from their own events.
| Service | Manual | Schedule | Signed webhook | Service events |
|---|---|---|---|---|
| GitHub12 events | ● | ● | ● | ● |
| Slack2 events | ● | ● | ● | ● |
| Plain2 events | ● | ● | ● | ● |
| Every other service (15)Gmail, Google Sheets, Google Docs, Google Drive, Notion, Attio, Apollo, Stripe, Resend, Discord, Reddit, Typeform, Apify, WarpBuild, Databases | ● | ● | ● | Not yet |
Webhook triggers are signed with HMAC-SHA256 and reject requests older than five minutes. Schedules take a cron expression or a plain sentence. Trigger docs
Developer tools
02Communication
01Google Workspace
04Docs & knowledge
01Billing
01Web data
01Beyond the catalogue
Your own tools and data.
Some tools have no integration. These three cover the rest.
MCP servers
Attach any remote MCP server
Point Helios at an HTTPS MCP server with a bearer token or OAuth 2.0. Allowlist the tools an agent may call. Each server gets its own sub-agent.
How MCP works →Databases
Postgres, MySQL, and ClickHouse
Agents list connections, introspect the schema, and run read-only SQL. Reach a private database through an SSH tunnel.
Connect a database →The web
Search and read pages without a connection
Every agent can search the web and read a page as markdown. No integration needed.
Read the docs →Connect your first tool.
Authorize a service, describe the task in chat, and read the transcript of every call the agent makes.