Concepts
The handful of objects everything in Arc0 is built from.
Apps
An app is a third-party service your users connect, such as Gmail, Slack, Salesforce or GitHub. Each app exposes a set of actions and declares how it authenticates: OAuth 2, an API key, or basic auth.
Connections
A connection is one user's authorized account in one app. Arc0 stores its credentials in a vault encrypted per tenant, refreshes tokens before they expire, and lets you export them at any time.
Connections belong to a user, and users belong to one of your customers, so the hierarchy is organization → customer → user → connection. A connection can be personal, or shared across a customer's team.
Actions
An action is something an agent can do in an app: send an email, post a message, update a record. Every action carries a scope:
| Scope | Examples |
|---|---|
read | Search messages, list records, fetch a file |
write | Send an email, post a message, create a ticket |
destructive | Delete a record, remove a user, revoke access |
Arc0 Connect
The flow your users see when they authorize an app. It carries your logo and colours on every plan. On paid plans it runs on your own domain and can use your own OAuth apps, so the provider's consent screen names you, not Arc0.
Arc0 MCP
One MCP endpoint per user. Point any remote-MCP client at it — your own agent, Claude, ChatGPT, Cursor — and it can discover and call the actions that user's connections and policies allow. The same connections are available to your backend over REST, for code paths that don't involve an agent.
Policies
Policies decide what an agent may do before a call reaches the app: which apps and scopes are allowed, which actions need a human's approval, and whether to fail closed when a check can't be evaluated.
Audit log
Every call is recorded — which agent acted, for which user, in which app, with what scope, and which policy allowed or blocked it. The audit log is part of every plan, including free.