connect your systems.
A connection is a credential and a list of scopes: what macro may reach, and nothing wider. Every credential is pasted once in Settings → connections, stored encrypted, and never shown again. These guides cover getting the credential from each system — the only part that happens outside macro.
the connections
slack
full guide · 5 minutesNot a simple API key: you create a small workspace app with one scope and give macro its bot token. Six steps, drawn out one by one.
apollo
an api keyThe simple one. In Apollo: Settings → Integrations → API → create a key → paste it into the Apollo card. Done.
hubspot
a private-app tokenIn HubSpot: Settings → Integrations → Private apps → create one named macro with contacts read & write → copy its token → paste it into the HubSpot card.
google workspace
full guide · one click for usersUsers just click sign in with Google and approve — the same flow as any modern app. The one-time app registration behind the button (the operator's job, never the user's) is drawn out step by step.
how credentials are kept
Saving a credential is a one-way door. macro stores it encrypted, uses it only for the scopes on the card, and never shows it again — not in the app, not in run records, not in logs. You can replace it or remove it any time; you can also revoke it at the source, and macro fails cleanly and says which connection needs attention.