Nexra Connectv1

Connections

Connect a provider account, store its credentials safely, choose its write permissions, test it and rotate credentials.

Updated 07/10/2026

On this page

Before you start

Open the provider's page in the connector directory. It lists:

the operations, and which ones are reads or writes;

how each write is protected against duplicates;

the provider's authentication method, plans and access restrictions, rate limits and sandbox options;

known limitations.

Create the provider-side app, API key or OAuth client that the page describes, with the narrowest permissions your flows need.

Create a connection in the console

Open Dashboard → Connect → Connections → New connection and pick the provider.

Choose the project and the environment (sandbox or production).

Enter the provider settings, for example a site name, region, data centre, company ID or API version. Nexra builds the provider origin from these settings and only ever calls that origin.

Enter the credentials (API key, client ID and secret, refresh token and so on). They go straight to Azure Key Vault; the connection keeps only the secret reference.

Tick the write operations this connection may perform. Leave them all unticked for a read-only connection.

Save, then Test. A successful test marks the connection active and discovers its capabilities.

Each operation then shows one of these states:

StateMeaning
availableReady to use in flows
permission_requiredA write that is not enabled on this connection
CONNECTION_NOT_ACTIVETest the connection first

OAuth providers

For OAuth connectors you provide a client ID and secret from your provider app plus a refresh token, and Nexra exchanges them for access tokens. When a provider rotates the refresh token on use, Nexra writes the new token back to Key Vault automatically. Xero uses an in-console authorisation flow: Connect to Xero sends you to Xero and back, and the link is valid for 10 minutes.

Changing a connection

Edit settings or write permissions. The connection returns to draft and must be tested again before flows use it.

Rotate credentials. Store new credentials and point the connection at the new secret reference. The connection returns to draft until it passes a test.

Disable. Stops all use. Flows that depend on it fail validation until you choose another connection.

Health and capabilities

The connection page shows recent health checks (status, latency and a safe error summary) and the capability manifest: every operation with its input and output fields, permissions, pagination and idempotency. The manifest is cached for 60 seconds after a successful discovery; use Refresh to rediscover it.

Errors you may see

CategoryTypical causeWhat to do
authenticationExpired or revoked credentialsRotate the credentials, then test
permissionThe provider user or app lacks a scopeGrant the scope at the provider, then test
rate_limitProvider quota reachedNexra retries with backoff; lower the schedule frequency if it persists
validationThe provider rejected the inputFix the mapping or the source data
not_foundThe record or account does not existCheck IDs and settings
providerA provider-side failureRetried automatically when safe

Error messages never contain secrets. Provider-specific recovery guidance appears with the error when the connector has it.

Over the API

See Connections API for POST /api/console/connect/connections, testing, rotation and capability discovery.

Need a hand?

Ask Nexra AI for implementation steps or error guidance.

Ask Nexra AI