Skip to main content
A connection represents a dependency on an external application or service. It contains all the necessary information for agents, tools, knowledge bases, or virtual models to securely authenticate and interact with that external system.

Types of connections

watsonx Orchestrate supports several types of authentication methods:
  • Basic, Bearer, and API Key: These methods pass the configured credentials directly to the consuming tool or service.
  • OAuth: Orchestrate supports multiple OAuth flows, as defined in the OpenAPI specification. When using OAuth:
    • Orchestrate authenticates the user interactively.
    • It generates an access_token on behalf of the user.
    • This token is securely passed to the downstream tool during execution.
OAuth-based connections currently only work when the user interacts with the agent through the watsonx Orchestrate UI (not embedded web chat).
When you embed web chat in an external website, Orchestrate supports integration with upstream SSO/IDP providers such as Azure AD, Workday CCX, and others. Orchestrate also supports Key-Value connections, which allow builders to provide a secure dictionary of keys and values to downstream tools. You can use these connections to:
  • Pass arbitrary authentication configurations to Python tools.
  • Securely provide environment variables to MCP toolkits.
  • Configure connections to LLM providers through the AI Gateway.
Legendβœ… Supported ❌ Not supported 🚧 Partially supported (native agents only)

Support by tool type

[1] Tools built using Agentic workflows do not require connection support as connections within Agentic workflows are configured via their downstream component tools.
[2] OAuth connections are currently only supported by agents in the watsonx Orchestrate integrated web chat ui.
[3] SSO/IDP connections are only supported by agents in web chat embedded into a customer’s website.
[4] SSO/OBO (oauth_auth_on_behalf_of_flow) connections cannot be used to import remote MCP toolkits because no authenticated user session is available at import time. Use a key_value connection for the draft environment import and reserve SSO/OBO for the live environment where tool execution occurs with a real user session. See Importing toolkits with SSO/OBO connections.

Support for knowledge

Support for member vs team

Support for AI Gateway

The AI Gateway supports only key-value connections.