Skip to main content
Integrations connect a third-party account to boxd once, at the account level. After that, every personal machine you own can use it — no per-VM setup, no tokens to copy around. The token lives server-side; boxd injects it into your machines on demand. Three integrations ship today:

GitHub

Clone and push private repos from any machine.

Linear

Linear’s GraphQL API and an optional MCP server for your agents.

Slack

The Slack Web API as the bot or as you, plus an optional MCP server.

Connect an integration

There are two ways to connect, and both end at the same place: From the console — open boxd.sh/appIntegrations and click Connect on the service you want. This is the simplest path. From the CLIboxd manage integrations connect <id> (for example github, linear, or slack) prints an authorize URL, then polls until you approve it:
You open the URL in any browser and approve; the CLI finishes on its own. The browser step is why a human has to do the connect — an agent can kick it off but can’t click through the consent screen.
boxd manage integrations connect works for all three — github, linear, and slack. GitHub can also be connected with the Connect GitHub repos button in the console; both routes land the same grant.

Where integrations are available

A connected integration reaches your personal machines and your private org-billed machines — anywhere only you have a shell. It is deliberately never exposed on shared or public org machines. A teammate with a shell on a shared box must never be able to read your personal Linear or Slack token, so boxd withholds it there. Fork a shared machine to get a private copy, and your integrations come back.

How a machine uses an integration

Once connected, each integration shows up two ways inside your machine. As environment variables, exported into every login shell (and into the coding agents’ environment):

Discover what’s wired in

Inside any machine, run boxd manage integrations (no subcommand) to see which accounts are connected and how to use each, plus what else you can still connect — the live source of truth:
The Available to connect section lists every catalog integration that’s available on the deployment but not yet connected, with the exact connect command — so an agent can discover and wire one up without guessing. Add --json for a structured version: connected integrations come back under integrations (each with access methods tagged by a machine-readable kindgit, cli, graphql, api, mcp), and the not-yet-connected ones under connectable. The coding agents pre-installed on every machine are told to run boxd manage integrations rather than guessing — new integrations appear here automatically.

MCP servers

Linear and Slack each also offer a Model Context Protocol server that a coding agent can call directly. It’s opt-in per agent:
The agent ids are claude (Claude Code), codex, and opencode. With no agents listed, the MCP installs into all three; --disable removes it everywhere. You can also toggle this from the console with Enable MCP on the integration’s card. The MCP is only active while the integration is connected — disconnecting clears the opt-in too.

The boxd manage integrations command

The same command behaves the same everywhere you drive boxd: integ is an alias for integrations, and ls an alias for list. All four subcommands work on every surface — the laptop CLI, inside a machine, and the console. Service names are case-insensitive (Slack = slack).

Disconnect

Disconnecting revokes the token at the provider, clears it from boxd, and removes any MCP opt-in. From the console, Disconnect on a card offers the same — with the choice to remove just the MCP server or disconnect the service entirely.