Skip to main content
Universal integration plan

One ledger, many official rails.

Vognary should not depend on uploads as the product experience. Each source becomes real through official provider consent, scoped credentials, webhooks, IAM roles, or regulated partner APIs. The app must show what is live, setup-ready, planned, and partner-gated without pretending blocked rails are already connected.

Patterns

How integrations become real

OAuth consent

Google, Microsoft, GitHub, Slack, Notion, Zoom, PayPal

Redirect user to the official provider, receive code, store encrypted token reference, sync evidence.

API key or token

OpenAI, Cloudflare, Render, Vercel, Stripe, Razorpay, domain registrars

Collect scoped credential, encrypt it, run scheduled sync jobs.

IAM or delegated role

AWS, Azure, Google Cloud

Read billing/cost scopes without storing broad account passwords.

Webhook

Stripe, Razorpay, Cashfree, app developer APIs

Provider pushes subscription, invoice, mandate, or renewal events into Vognary.

Regulated partner API

Account Aggregator, UPI, card mandates, banks/issuers

Requires partner contract, consent artifact, compliance review, and audit logs.

Rollout

What gets built next

Gmail receipts

Ready-to-connect

First real personal-history connector path. OAuth returns receipt candidates into the recurring ledger.

OpenAI costs

Adapter exists

Needs admin key or workspace token capture before recurring AI spend sync.

Vercel, Render, GitHub, Cloudflare, AWS

Next adapter wave

Needs credential capture, provider adapters, scheduled sync, and normalization.

Apple, Google Play, X, Claude, Kling

Provider-dependent

Needs official user billing APIs, partner access, or receipt-based evidence where APIs are unavailable.

UPI, cards, banks

Partner-gated

Requires regulated rails; cannot be made universal with only frontend code.

Real connector definition

A connector is real only when the user can start from Vognary, complete official consent or credential setup, store token references encrypted per workspace, run initial sync, re-sync without repeating setup, see the source in profile/data controls, and disconnect/delete it. Anything less is a target, not a finished integration.