> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plungeai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect a provider

> Bring a key for a provider (yours, or your customer’s).


## OpenAPI

```yaml openapi.json post /v1/connections/{provider}
openapi: 3.1.0
info:
  title: Ocean One API
  version: 2.3.1
servers:
  - url: https://api.plungeai.com
paths:
  /v1/connections/{provider}:
    post:
      operationId: post-v1-connections-provider
      tags:
        - Connections
      summary: Bring a key for a provider (yours, or your customer’s)
      description: The key is checked live where the provider has a probe (a rejected key is never stored), then stored encrypted. The next call of a connection-tier agent runs on it. Nothing secret comes back.
      security:
        - ozkBearer: []
      parameters:
        - name: provider
          in: path
          required: true
          schema:
            type: string
          description: Connector id (`google`, `azure` for Microsoft 365, `github`, `slack`, `stripe`, …). The `connect` pointer in a 424 names it.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                api_key:
                  type: string
                  maxLength: 4096
                api_secret:
                  type: string
                  maxLength: 4096
                  description: Only for providers that issue a second secret.
                on_behalf_of:
                  type: string
                  pattern: ^(?!.*\.\.)[A-Za-z0-9_.-]{1,128}$
                  description: "Your customer’s id (an opaque string you own): the connection is theirs, stored under your key and reachable only through it. Omit it to connect your own account."
                format:
                  type: string
                  enum:
                    - json
                    - yaml
                    - markdown
                    - text
                  description: Response format override (Accept header and the request Content-Type mirror also work). Default json.
              required:
                - api_key
      responses:
        "201":
          description: Connected Response format negotiates via the `format` field, an Accept header (application/json, text/yaml, text/markdown, text/plain), or the request Content-Type mirror; default JSON.
          content:
            application/json:
              schema:
                type: object
                properties:
                  provider:
                    type: string
                  on_behalf_of:
                    type:
                      - string
                      - "null"
                  status:
                    type: string
                    enum:
                      - connected
                required:
                  - provider
                  - on_behalf_of
                  - status
            text/yaml:
              schema:
                type: string
            text/markdown:
              schema:
                type: string
            text/plain:
              schema:
                type: string
        "400":
          description: credential_rejected — the provider refused the key; missing_api_key — api_key is required; invalid_json / invalid_yaml / invalid_body — unreadable body; invalid_format — format must be one of json, yaml, markdown, text; invalid_on_behalf_of — on_behalf_of must be 1-128 characters of A-Z a-z 0-9 _ . - (no "..")
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/Error"
        "401":
          description: unauthorized — missing, invalid or revoked ozk_ key
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/Error"
        "404":
          description: "unknown_provider — no connector with that provider id; connection_not_found — nothing to disconnect; not_found — no route for this method on this path: every other method answers it"
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/Error"
        "503":
          description: connections_unavailable — connections are not available on this deployment
          content:
            application/json:
              schema:
                $ref: "#/components/schemas/Error"
components:
  schemas:
    Error:
      type: object
      description: Standard error envelope. Every error response also carries an `X-Error-Code` response header equal to error.code, so a client branches on the header regardless of the negotiated body format (json | yaml | markdown | text). When the request created an execution, the `X-Execution-Id` response header is also set. Errors follow the negotiated format like success bodies.
      properties:
        error:
          type: object
          properties:
            code:
              type: string
            message:
              type: string
            connect:
              type: object
              description: "On a 424 connection_required / credential_required: where the missing connection is made."
              properties:
                provider:
                  type: string
                method:
                  type: string
                  enum:
                    - oauth
                    - api_key
                    - wallet
                link:
                  type: string
                  example: POST /v1/connections/stripe/link
          required:
            - code
            - message
          additionalProperties: true
      required:
        - error
  securitySchemes:
    ozkBearer:
      type: http
      scheme: bearer
      description: "ozk_ platform API key (Authorization: Bearer ozk_…)"
```
