Integrations are opt-in extensions, not part of the core session loop. This is
a curated task chooser, not an exhaustive inventory. Start with a concrete
outcome, choose at most one new trust boundary at a time, and read its full
generated entry in references/integrations.md.
Nothing in this guide installs, activates, authenticates, or grants permissions to an integration.
Optional integration support is declared per integration and per host, separately from the core adapter's runtime tier. The OpenClaw adapter supports the Context OS lifecycle; it does not establish that any optional integration works through OpenClaw. Generic MCP transport support never implies support for a particular host.
An integration-by-host evidence record must state the tested host surface and exact version, test date, credential model and storage location, network egress destinations, and all reachable side effects, marking writes and destructive actions. It must record the confirmation gates observed on that host, the health-check command and observed output shape, verified uninstall and credential revocation steps, and the location of the test evidence. Keep credentials and private data out of that record.
The catalog schema now expresses per-host evidence in host_evidence. An entry
that lists openclaw in supported_agents must include a matching record with
the fields above and a repository evidence path. MarkItDown MCP
is the first entry with a documented OpenClaw test (CLI commands and one headless local-file turn), with the OpenClaw test record.
No confirmation event appears in its retained headless agent result, so the operator must
confirm the exact URI before each conversion. The integration proposal
lists the host-evidence fields for future entries. The core adapter's runtime
tier remains separate from integration support, and generic MCP support never
implies support on a named host.
| I want to… | Candidate | First boundary to review |
|---|---|---|
| Browse and install reusable agent skills | Agent Skills | Replacement or removal of an existing local skill |
| Add a standalone lifecycle/workspace package | Agent Workspace | Local state writes and optional cleanup actions |
| Discover creator-oriented tools without installing one | AI Tools for Creators | Listings can drift and are not endorsements |
| Inspect repositories, issues, pull requests, or CI context | GitHub MCP | Private-repository reads, public comments, branch or file changes, and enabled toolsets |
| Read or update product work in Linear | Linear MCP | Workspace-wide reads and remote issue, project, relationship, or comment changes |
| Read or manage Trello boards, lists, and cards | Trello MCP | OAuth 2.0 consent for one workspace plus account-level Inbox/Planner access, connected-calendar reads, and remote create/update/move/archive writes |
| Search a personal reading library or organize highlights | Readwise MCP | Full-library indexing, sensitive reading history, bulk edits, and highlight deletion |
| Read calendar, email, Drive, or Sheets data | Google Workspace CLI | OAuth identity, sensitive reads, and the CLI's broader write-capable surface |
| Search or change a Notion workspace | Notion MCP | OAuth, sensitive and connected-source reads, remote writes, and overwrite-capable updates |
| Coordinate Gemini work with a persistent issue graph | Beads for Gemini CLI | User-global defaults, remote sync, and force overwrite |
| Search meeting notes or retrieve transcripts | Granola MCP | OAuth, sensitive reads, retention, and participant consent |
| Let an agent work with an Obsidian vault | Obsidian CLI | Broad command/eval surface and implicit vault/file targeting |
| Manage Substack drafts or publish Notes | Substack MCP | Session credentials, sensitive analytics, and immediate public Notes |
| Read or update a mounted Markdown vault | Tolaria MCP | Sensitive vault reads and full-note overwrite |
| Convert an explicitly selected document or URI to Markdown | MarkItDown MCP | Local-file and network reads through an unauthenticated server process |
| Export reviewed Markdown to DOCX, PDF, EPUB, or HTML | Pandoc | Sensitive local or network reads, output overwrite, and PDF-engine execution |
| Plan or update Shortcut stories, epics, and iterations | Shortcut MCP | Workspace-wide sensitive reads and overwrite-capable story or doc updates |
| Search Slack conversations or post messages | Slack MCP | Sensitive conversation reads and publicly visible message sends |
| Inspect GitLab repositories, merge requests, or pipelines | GitLab MCP | Private-repository reads, public comments, branch writes, and CI/CD pipeline actions |
| Manage Todoist tasks and projects from the command line | Todoist CLI | Sensitive personal-task reads, per-resource deletion, and a write-capable CLI whose opt-in scopes reach app secrets, backups and billing |
| Work with Jira, Confluence, Jira Service Management, Bitbucket Cloud, or other Atlassian apps | Atlassian Rovo MCP | Organization-wide sensitive reads, overwrite-capable content updates, public-link and permission changes, pull-request merges and pipeline runs, and permanent Jira deletion |
| Read or update Asana tasks, projects, and portfolios | Asana MCP | Workspace-wide sensitive reads, overwrite-capable task updates, and deletion |
The obsolete checked-in gws mcp configuration was removed. The current Google Workspace path uses the reviewed CLI setup in references/google-workspace-cli-setup.md; it is still opt-in and is not pre-approved by the command adapters.
For the selected entry:
- Read its current source and every linked evidence page.
- Confirm the supported host and whether installation is project- or user-scoped.
- List the exact credentials, local paths, accounts, vaults, or workspaces it can reach.
- Start with the least privilege and the narrowest read-only health check available.
- Require a separate confirmation for sensitive reads, writes, remote writes, publish, overwrite, deletion, arbitrary execution, OAuth, or destructive actions when the catalog marks them.
- Record how to disable or uninstall it before relying on it.
- Re-run
bash scripts/validate-all.sh --workspaceafter changing tracked configuration.
Do not infer safety from the word verified. In this repository it means the catalog metadata was checked against linked evidence on the stated date; it is not live authentication, an end-to-end test, or a guarantee about future upstream behavior.
Keep the core filesystem workflow when a tool would duplicate data, widen access without a concrete task, require more credentials than the outcome warrants, or add a remote write where a local file is enough. Repository context, lifecycle skills, and manual links remain useful without any optional integration.