Connections
Connect a provider account, store its credentials safely, choose its write permissions, test it and rotate credentials.
Updated 07/10/2026
On this page
Before you start
Open the provider's page in the connector directory. It lists:
the operations, and which ones are reads or writes;
how each write is protected against duplicates;
the provider's authentication method, plans and access restrictions, rate limits and sandbox options;
known limitations.
Create the provider-side app, API key or OAuth client that the page describes, with the narrowest permissions your flows need.
Create a connection in the console
Open Dashboard → Connect → Connections → New connection and pick the provider.
Choose the project and the environment (sandbox or production).
Enter the provider settings, for example a site name, region, data centre, company ID or API version. Nexra builds the provider origin from these settings and only ever calls that origin.
Enter the credentials (API key, client ID and secret, refresh token and so on). They go straight to Azure Key Vault; the connection keeps only the secret reference.
Tick the write operations this connection may perform. Leave them all unticked for a read-only connection.
Save, then Test. A successful test marks the connection active and discovers its capabilities.
Each operation then shows one of these states:
| State | Meaning |
|---|---|
available | Ready to use in flows |
permission_required | A write that is not enabled on this connection |
CONNECTION_NOT_ACTIVE | Test the connection first |
OAuth providers
For OAuth connectors you provide a client ID and secret from your provider app plus a refresh token, and Nexra exchanges them for access tokens. When a provider rotates the refresh token on use, Nexra writes the new token back to Key Vault automatically. Xero uses an in-console authorisation flow: Connect to Xero sends you to Xero and back, and the link is valid for 10 minutes.
Changing a connection
Edit settings or write permissions. The connection returns to draft and must be tested again before flows use it.
Rotate credentials. Store new credentials and point the connection at the new secret reference. The connection returns to draft until it passes a test.
Disable. Stops all use. Flows that depend on it fail validation until you choose another connection.
Health and capabilities
The connection page shows recent health checks (status, latency and a safe error summary) and the capability manifest: every operation with its input and output fields, permissions, pagination and idempotency. The manifest is cached for 60 seconds after a successful discovery; use Refresh to rediscover it.
Errors you may see
| Category | Typical cause | What to do |
|---|---|---|
authentication | Expired or revoked credentials | Rotate the credentials, then test |
permission | The provider user or app lacks a scope | Grant the scope at the provider, then test |
rate_limit | Provider quota reached | Nexra retries with backoff; lower the schedule frequency if it persists |
validation | The provider rejected the input | Fix the mapping or the source data |
not_found | The record or account does not exist | Check IDs and settings |
provider | A provider-side failure | Retried automatically when safe |
Error messages never contain secrets. Provider-specific recovery guidance appears with the error when the connector has it.
Over the API
See Connections API for POST /api/console/connect/connections, testing, rotation and capability discovery.