# Connections

Under Connections you store access to Sentry, Firebase, DNS providers, email delivery, and AI providers once for your whole organization.

> Source: https://www.mainpath.ai/en/docs/connections/

Under **Connections**, administrators store access to external services once for the whole organization; in projects you pick them from a list.

Click **Add connection**, then choose the tile for the service. The picker is grouped by category (DNS, Email, Push notifications, Error tracking, Git, Monitoring, AI providers); the same grouping applies to connections you already added, so multiple accounts in one category sit side by side. Enter a name and a slug for display in projects, and enter the credentials, which MainPath checks right away for several services.

## Capturing errors with Sentry

You connect your Sentry account through **Connect with Sentry** for sentry.io or with an API token, which also covers self-hosted instances. When you enable Sentry for a component under **Features**, MainPath creates the project in your account and writes the DSN into the configuration. [Sentry: credentials]({{< relref "sentry-credentials" >}}) describes the token, and [Error tracking]({{< relref "error-tracking" >}}) gives the overview.

## Push notifications with Firebase

**Google / Firebase** is used for push notifications in apps; the recommended option is a service account JSON, while **Connect with Firebase** through OAuth still carries a **Beta** badge. On the app, enable Firebase under **Features** and select the connection. [Firebase: credentials]({{< relref "firebase-credentials" >}}) walks through both options.

## Git hosting with GitHub or GitLab

Under **Git** you connect a GitHub or GitLab account when application repositories should not live on MainPath GitLab. At the bottom of the project you choose **Automatically generated (recommended)**, **GitHub**, or **GitLab**. OAuth is preferred; otherwise an API token. Setup: [GitHub: credentials]({{< relref "github-credentials" >}}) and [GitLab: credentials]({{< relref "gitlab-credentials" >}}).

## AI providers

Under **AI providers** you store API keys for OpenAI, Anthropic, Google Gemini, Mistral AI, and Cursor. These vendors do not offer OAuth for API access. When you create a workspace you pick the connections — several different providers, but only one account per provider. Rules and skills are always installed; the AI agent is preconfigured and started with the keys.

- [OpenAI: credentials]({{< relref "openai-credentials" >}})
- [Anthropic: credentials]({{< relref "anthropic-credentials" >}})
- [Google Gemini: credentials]({{< relref "google-gemini-credentials" >}})
- [Mistral AI: credentials]({{< relref "mistral-credentials" >}})
- [Cursor: credentials]({{< relref "cursor-credentials" >}})

## Your own Beszel hub

Under **Monitoring** you optionally store your own Beszel hub. Servers use MainPath-managed service by default; on the server you can pick your hub. Details: [Beszel: your own hub]({{< relref "beszel-credentials" >}}).

## DNS records through Cloudflare, IONOS, united-domains, GoDaddy, Hetzner, Hostinger, DigitalOcean, or Gandi

Under **DNS** you connect the zone that actually hosts your domain. MainPath then writes A and CNAME records itself once a project has domains and a server address. In each DNS connection's details you can also tick domains for SSL via DNS-01 if the server is not publicly reachable.

- **Cloudflare**: API token, DNS-only without the proxy, so Let's Encrypt can reach the server. [Set DNS with Cloudflare]({{< relref "dns-cloudflare" >}}).
- **IONOS**: API key from the **Hosting Developer Hub** (not IONOS Cloud). [Set DNS with IONOS]({{< relref "dns-ionos" >}}).
- **united-domains**: DNS API key in `prefix.secret` form. [Set DNS with united-domains]({{< relref "dns-united-domains" >}}).
- **GoDaddy**: Personal Access Token or classic key/secret. [Set DNS with GoDaddy]({{< relref "dns-godaddy" >}}).
- **Hetzner DNS**: Cloud API token with Read & Write for the Console project that holds the zones. Separate from the server connection. [Set DNS with Hetzner]({{< relref "dns-hetzner" >}}).
- **Hostinger DNS**: API token with DNS rights. Separate from the Hostinger server connection. [Set DNS with Hostinger]({{< relref "dns-hostinger" >}}).
- **DigitalOcean**: Personal Access Token with read and write for domains. [Set DNS with DigitalOcean]({{< relref "dns-digitalocean" >}}).
- **Gandi**: Personal Access Token with LiveDNS. [Set DNS with Gandi]({{< relref "dns-gandi" >}}).

## Email delivery

**Mailtrap**, **Resend**, and **SendGrid** each need only an API token and show status and sending domains including DNS checks; **Email (SMTP)** takes a generic account for any other provider. All of them appear in projects under **Mail account**. [SMTP with Mailtrap]({{< relref "smtp-mailtrap-setup" >}}), [SMTP with Resend]({{< relref "smtp-resend-setup" >}}), and [SMTP with SendGrid]({{< relref "smtp-sendgrid-setup" >}}) cover the setup, and [Email delivery]({{< relref "email-delivery" >}}) explains the differences.

## What is not under Connections

Access to the App Store, Play Store, and Microsoft Store lives under **Store accounts** and is selected on the app, as [Store accounts]({{< relref "store-accounts" >}}) describes. SSH access and the API tokens for Hetzner and Hostinger live under **Servers** behind **Manage credentials**; [Cloud servers]({{< relref "cloud-servers" >}}) shows the procedure. Kubernetes clusters and cloud accounts live under [Kubernetes clusters]({{< relref "kubernetes-integration" >}}) and [Cloud accounts]({{< relref "cloud-accounts" >}}).

