Under Connections, administrators store access to external services once for the whole organization; in projects you pick them from a list.
Click Add connection, then choose the tile for the service. The picker is grouped by category (DNS, Email, Push notifications, Error tracking, Git, Monitoring, AI providers); the same grouping applies to connections you already added, so multiple accounts in one category sit side by side. Enter a name and a slug for display in projects, and enter the credentials, which MainPath checks right away for several services.
Capturing errors with Sentry
You connect your Sentry account through Connect with Sentry for sentry.io or with an API token, which also covers self-hosted instances. When you enable Sentry for a component under Features, MainPath creates the project in your account and writes the DSN into the configuration. Sentry: credentials describes the token, and Error tracking gives the overview.
Push notifications with Firebase
Google / Firebase is used for push notifications in apps; the recommended option is a service account JSON, while Connect with Firebase through OAuth still carries a Beta badge. On the app, enable Firebase under Features and select the connection. Firebase: credentials walks through both options.
Git hosting with GitHub or GitLab
Under Git you connect a GitHub or GitLab account when application repositories should not live on MainPath GitLab. At the bottom of the project you choose Automatically generated (recommended), GitHub, or GitLab. OAuth is preferred; otherwise an API token. Setup: GitHub: credentials and GitLab: credentials.
AI providers
Under AI providers you store API keys for OpenAI, Anthropic, Google Gemini, Mistral AI, and Cursor. These vendors do not offer OAuth for API access. When you create a workspace you pick the connections — several different providers, but only one account per provider. Rules and skills are always installed; the AI agent is preconfigured and started with the keys.
- OpenAI: credentials
- Anthropic: credentials
- Google Gemini: credentials
- Mistral AI: credentials
- Cursor: credentials
Your own Beszel hub
Under Monitoring you optionally store your own Beszel hub. Servers use MainPath-managed service by default; on the server you can pick your hub. Details: Beszel: your own hub.
DNS records through Cloudflare, IONOS, united-domains, GoDaddy, Hetzner, Hostinger, DigitalOcean, or Gandi
Under DNS you connect the zone that actually hosts your domain. MainPath then writes A and CNAME records itself once a project has domains and a server address. In each DNS connection’s details you can also tick domains for SSL via DNS-01 if the server is not publicly reachable.
- Cloudflare: API token, DNS-only without the proxy, so Let’s Encrypt can reach the server. Set DNS with Cloudflare.
- IONOS: API key from the Hosting Developer Hub (not IONOS Cloud). Set DNS with IONOS.
- united-domains: DNS API key in
prefix.secretform. Set DNS with united-domains. - GoDaddy: Personal Access Token or classic key/secret. Set DNS with GoDaddy.
- Hetzner DNS: Cloud API token with Read & Write for the Console project that holds the zones. Separate from the server connection. Set DNS with Hetzner.
- Hostinger DNS: API token with DNS rights. Separate from the Hostinger server connection. Set DNS with Hostinger.
- DigitalOcean: Personal Access Token with read and write for domains. Set DNS with DigitalOcean.
- Gandi: Personal Access Token with LiveDNS. Set DNS with Gandi.
Email delivery
Mailtrap, Resend, and SendGrid each need only an API token and show status and sending domains including DNS checks; Email (SMTP) takes a generic account for any other provider. All of them appear in projects under Mail account. SMTP with Mailtrap, SMTP with Resend, and SMTP with SendGrid cover the setup, and Email delivery explains the differences.
What is not under Connections
Access to the App Store, Play Store, and Microsoft Store lives under Store accounts and is selected on the app, as Store accounts describes. SSH access and the API tokens for Hetzner and Hostinger live under Servers behind Manage credentials; Cloud servers shows the procedure. Kubernetes clusters and cloud accounts live under Kubernetes clusters and Cloud accounts.