
# Connected Apps overview

Connected Apps link your Ethen identity to external apps — one connection per account — so Chat and automations can act there on your behalf. Every grant is least-privilege, every sensitive action pauses for approval, and every connection can be revoked.

## Connect

1. Open Chat settings and find Connected Apps.
2. Pick an app from the catalog. Apps that are catalog-only (not yet certified for your use) are labeled as such — never presented as available.
3. Review the connect sheet: it shows the exact scopes requested, the OAuth client, and what each scope allows.
4. Authorize at the provider. Ethen stores credentials in the managed vault — never in your browser, never in a chat log.

Connect requests the required scopes for the task, not the whole catalog. Unknown or unregistered scopes are rejected, never silently granted.

## Scopes

Four scope sets stay distinct:

| Set | Meaning |
|---|---|
| Registered | Everything the connector manifest declares |
| Requested | What this connect flow asks for |
| Granted | What you approved |
| Enabled | What is currently usable |

Absence from granted or enabled is meaningful: a missing scope means "not allowed", never a default allow. Incremental grants add scopes later without re-connecting from scratch.

## Approvals

Sensitive actions pause for your approval before running. An approval names the exact action, the exact account, and the exact scopes it will use. Changed actions need fresh approvals; expired approvals need re-approval. Standing approvals can pre-authorize narrow, repeatable actions — see [Managing connections](/docs/connected-apps/managing-connections).

## Revoke

Disconnect any connection from settings at any time. Revocation removes the binding immediately; the underlying provider grant is released when its last live binding goes away. A revoked connection fails closed — pending actions on it do not run.

## Availability honesty

Connected Apps providers certify one by one. The launch set and each provider's certification state are tracked in the Flow release process — a connector listed in the catalog is not automatically certified for your account. Setup-required and partial states are labeled, never collapsed into "available".

## Next steps

- [Managing connections](/docs/connected-apps/managing-connections)
- [API reference: Flow](/docs/api/flow)
- [Security overview](/docs/security/overview)
