Product
Integrations
Tier-1 providers power the MVP change graph. Use free or developer accounts at each provider; mocks work without accounts. New sources plug in as adapters. Scoring stays provider-agnostic.
Catalog
Filter the list. Deep-dives for GitHub, Sentry, and Vercel sit below: setup-oriented, not a card mosaic.
| Name | Role | Tier | Status | What it feeds |
|---|---|---|---|---|
| GitHub | Source control | Tier-1 | Shipped | PRs, commits, changed files, deployments via App webhooks + API. |
| Sentry | Errors | Tier-1 | Shipped | Issues, events, stack frames, and releases open incidents. |
| Vercel | Deploys | Tier-1 | Shipped | Deployments linked to project + SHA for release correlation. |
| Datadog | Observability | Tier-2 | Roadmap | Metrics/logs as evidence sources (adapter only). |
| Slack / Jira | Notify | Tier-2 | Roadmap | Notification adapters. Scoring stays provider-agnostic. |
| Feature flags | Change events | Tier-2 | Roadmap | Flag-change events as graph inputs, not a new scorer. |
| Kubernetes | Rollouts | Tier-3 | Roadmap | Rollout evidence via adapters. The MCP client is a gated read adapter; the full multi-server registry is deferred. |
| AWS / GCP | Inventory | Tier-3 | Roadmap | Cloud inventory as evidence, not MVP core domain. |
Tier-1 · setup
GitHub
GitHub App webhooks + API normalize installations, pull requests, commits, file lists, and deployment metadata into tenant-scoped entities with natural keys.
Connect
- Create a GitHub App (preferred) or use a PAT for API backfill.
- Setup (/setup) shows integration status cards with Test, Reconnect, and Disconnect, plus feature-gate toggles. Map installation_id → tenant there.
- Point the webhook at POST /api/webhooks/github with the App webhook secret.
- Backfill is API only: POST /api/v1/setup/backfill (returns 202). Setup has no backfill button. See Getting started: Where the running app reads data.
Permissions
- Contents (read)
- Pull requests (read)
- Metadata
- Deployments (read), when available
Environment
- GITHUB_APP_ID
- GitHub App id
- GITHUB_APP_PRIVATE_KEY
- PEM private key for App JWT
- GITHUB_WEBHOOK_SECRET
- HMAC verification for webhook deliveries
- GITHUB_TOKEN
- Optional PAT for local/API backfill when App not used
If something fails
- 401 / signature fail
- Secret mismatch; HMAC must use raw request body
- Events ignored
- installation_id not mapped to a tenant
- Empty file lists
- App missing Contents / Pull requests permissions
Tier-1 · setup
Sentry
Sentry webhooks/API create or update Incidents. Stack paths drive file-overlap scoring. Release → commit mapping is best-effort; null SHA is never invented.
Connect
- Create a project auth token / webhook for the target org + project.
- Register org/project on Setup and map to the tenant.
- Webhook endpoint: POST /api/webhooks/sentry with SENTRY_WEBHOOK_SECRET.
- Demo defaults (acme-fixture / payments-api) match pnpm seed.
Permissions
- Project-scoped auth token
- Webhook secret for delivery verification
- Reject unknown org/project before upsert
Environment
- SENTRY_AUTH_TOKEN
- API access for backfill / polling
- SENTRY_ORG
- Organization slug
- SENTRY_PROJECT
- Project slug
- SENTRY_WEBHOOK_SECRET
- HMAC / shared secret for webhook verification
If something fails
- No incidents
- Webhook not firing or project slug mismatch
- Empty stack
- Event payload missing frames; use fixtures locally
- Unmapped release
- Expected when SHA unknown. UI shows UNKNOWN, never invents SHA
Tier-1 · setup
Vercel
Vercel API (and optional webhook) records deployments tied to project + commit SHA so the scorer can weight deploy proximity and LKG.
Connect
- Set VERCEL_TOKEN + project/team IDs, or leave empty / VERCEL_USE_MOCK=1 for local mocks.
- Bind the Vercel project to a GitHub repo (connection owner/repo or repoId, or VERCEL_GITHUB_OWNER/REPO). Live mode does not fall back to demo repos.
- Optional webhook: POST /api/webhooks/vercel with VERCEL_WEBHOOK_SECRET.
- Confirm deploy SHA maps to the GitHub repo ChangeGraph already ingested.
Permissions
- Read deployments for the project
- Webhook secret when using webhook path
Environment
- VERCEL_TOKEN
- API token
- VERCEL_PROJECT_ID
- Target project
- VERCEL_TEAM_ID
- Team / scope when required
- VERCEL_WEBHOOK_SECRET
- HMAC for optional webhook stub
- VERCEL_USE_MOCK
- Force mock mode (defaults on when token empty)
- VERCEL_GITHUB_OWNER
- GitHub owner for live Vercel→repo binding (required in live if not set on the connection)
- VERCEL_GITHUB_REPO
- GitHub repo name for live Vercel→repo binding
If something fails
- No deploys
- Mock mode vs real token; project id
- HMAC fail
- Secret / raw body
- missing_github_repo_mapping
- Live mode needs owner+repo (or repoId) on the Vercel connection, or VERCEL_GITHUB_OWNER/REPO — never DEMO_GITHUB_*
- Deploy not linked
- SHA / project mapping to GitHub repo
Full walkthrough: Connect integrations. Tabbed per-tool guide: Tools reference. Open source runtimes: Open source tools. Adding a provider: Contributing.