Providers
A provider is a service you can connect to your project, identified by a provider ID such as linear or google-mail. Providers can supply tools, channels, or both.
Provider directoryDirect link to Provider directory
This directory covers the generated toolsets and channel setup documented here, rather than every provider in the platform catalog. Run mastra connect list to see providers available to your project and their connection status.
| Provider ID | Provider | Gives you |
|---|---|---|
clerk | Tools | |
discord | Tools, Channels | |
fireflies | Tools | |
github | Tools | |
google-calendar | Tools | |
google-docs | Tools | |
google-drive | Tools | |
google-mail | Tools | |
google-sheet | Tools | |
hubspot | Tools | |
incident-io | Tools | |
jira | Tools | |
linear | Tools | |
notion | Tools | |
openai | Tools | |
posthog | Tools | |
resend | Tools | |
slack | Tools | |
slack-channels | Channels | |
snowflake | Tools | |
supabase | Tools | |
telegram | Channels | |
workos | Tools |
Generated toolsets are included in @mastra/connect. Upgrading the package gives you toolsets added in newer releases, but provider availability depends on the platform catalog. The provider toolsets reference lists the generated tools.
MCP providersDirect link to MCP providers
These providers serve their tools from a hosted Model Context Protocol (MCP) server. The tools come from the provider at runtime, so check each provider's MCP documentation for what it offers. See the MCP tools reference for tool naming and Require approval for sensitive tools for approval setup.
| Provider ID | Provider | Provider MCP docs |
|---|---|---|
attio-mcp | Attio MCP | |
canva-mcp | Canva MCP | |
clay-mcp | MCP in Clay | |
neon-mcp | Neon MCP server | |
render-mcp | Render MCP server | |
robinhood-mcp | Agentic Trading | |
sanity-mcp | Sanity MCP server |
Provider-specific setupDirect link to Provider-specific setup
Start with the Connect setup, then add a provider with mastra connect add <provider>. The sections below cover providers whose API keys need permissions or regional settings. For Slack, Discord, and Telegram, follow the channel setup guide.
Set up ResendDirect link to Set up Resend
The resend toolset sends and reads email and manages domains, contacts, segments, broadcasts, templates, and webhooks. To send from your own domain, verify it in Resend.
- In Resend, open API Keys and select Create API Key.
- Enter a name, such as
mastra-agents, and set Permission to Full access. - Select Add and copy the key. It starts with
re_, and Resend shows it only once. - Run
mastra connect add resendand paste the key when it asks for API Key.
A Sending access key fails to connect. Mastra checks a new key by listing your domains, which sending access keys can't do. To expose only the sending tool to an agent, use allowTools:
tools({
providers: {
resend: { allowTools: ['resend_send_email'] },
},
})
This filter controls which tools the agent receives. It doesn't reduce the Resend key's Full access permissions.
Sending safelyDirect link to Sending safely
resend_send_email retries a failed send up to three times only when the call includes an idempotency_key. Without one it doesn't retry automatically, but a retry elsewhere in your app can still duplicate an email that failed after Resend accepted it. When duplicates matter, tell the agent to set a stable key per logical email, such as confirmation/order-1234. Resend answers a reused key with the original response, and rejects a reused key with a different payload with a 409.
If a send fails with a proxy_error and status 403, check that the from address uses a domain verified in Resend.
Set up PostHogDirect link to Set up PostHog
The posthog toolset runs HogQL queries and reads and edits insights, dashboards, feature flags, experiments, surveys, cohorts, and persons. It works with PostHog Cloud in either region. Self-hosted PostHog isn't supported.
- Check your region in PostHog's address bar:
us.posthog.comoreu.posthog.com. - Open Settings > Personal API keys on your region's host and select Create personal API key.
- Limit the key to the organization or projects the agent should see, and choose scopes from the following table.
- Create the key and copy it. It starts with
phx_, and PostHog shows it only once. - Run
mastra connect add posthog. Chooseusoreufor Subdomain and paste the key when it asks for API Key.
| Scope | Read gives the agent | Write also allows |
|---|---|---|
project | posthog_list_projects, posthog_get_project | |
query | posthog_run_query, posthog_list_events, posthog_get_event | |
insight | List and get insights | Create, update, delete insights |
dashboard | List and get dashboards | Create, update, delete dashboards |
feature_flag | List and get feature flags | Create, update, delete feature flags |
experiment | List and get experiments | Create and update experiments |
survey | List and get surveys | Create, update, delete surveys |
cohort | List and get cohorts | Create, update, delete cohorts |
person | List and get persons | Update and delete persons |
session_recording | posthog_list_session_recordings |
Most PostHog tools take a project_id, so give every key project:read. Agents call posthog_list_projects to find the ID. A read-only analytics agent needs project:read, query:read, insight:read, and dashboard:read.
Avoid the us.i and eu.i subdomains. Those hosts only serve PostHog's event ingestion endpoints, so most tools fail with them. The form also rejects project API keys (phc_) and project secret API keys (phs_).
Query limitsDirect link to Query limits
posthog_run_query queries count against PostHog's hourly query budget for personal API keys. Prefer aggregated results over raw event exports.
Set up incident.ioDirect link to Set up incident.io
The incident-io toolset reads and updates incidents, posts incident updates, manages actions and follow-ups, and reads alerts, schedules, the catalog, and postmortems. Tool keys start with incident_io_, with an underscore where the provider ID has a hyphen.
- In incident.io, open Settings > API keys and create a key named
mastra-agentsor similar. - Select permissions from the following table. You can only grant permissions you already have.
- Create the key and copy it. It starts with
inc_, and incident.io shows it only once. - Run
mastra connect add incident-ioand paste the key when it asks for API Key.
| Agent task | Permission |
|---|---|
| Read incidents, updates, timelines, actions, follow-ups, users, and teams | View data |
| Read private incidents too | View all incident data |
| Read the catalog | View catalog |
| Read alerts, schedules, and overrides | View on-call resources |
| Open incidents | Create incidents |
| Update incidents, post updates, and manage actions and follow-ups | Edit incidents |
A triage agent that reads incidents and posts updates needs View data and Edit incidents, and the incident.io permissions reference describes each permission.
Creation and rate limitsDirect link to Creation and rate limits
incident_io_create_incident requires an idempotency_key, and incident.io rejects a second incident with the same key. An API key can open 10 incidents an hour that create a chat channel. Listing incidents is limited to 60 requests a minute. If the agent hits 429 errors, tell it to filter incidents instead of paging through all of them.
Fix a failing providerDirect link to Fix a failing provider
A proxy_error carries the provider's response in its status and detail properties.
- Status
401: Check whether the credential has expired, been revoked, or been rotated. If it needs replacing, reauthorize the connection. - Status
403: Check the provider's response for missing scopes, resource-access restrictions, or account requirements. Grant only the access the agent needs. You can exclude unsupported operations withallowTools, but filtering tools doesn't change the credential's permissions. - No tools from a provider: Run
mastra connect listto check the project and connection status. Check provider selection and tool filters, and confirm that your installed@mastra/connectversion includes the toolset. Connection changes follow the resolver's caching behavior. Check app logs for[@mastra/connect] Skippingwarnings when a connection can't be resolved.
See errors for every error code.