Connectors
A connector is a credential for an external development tool — a Git host, an issue tracker, or a document store — stored so that NuPaaS can read from it on your behalf. Connect a tool once, then import its repositories, issues, and files into your organization.
What a connector does
Connectors are org-scoped. Manage them at /orgs/<org>/connectors. The page groups each tool by what it imports: Git hosts bring repositories, issues, and reviews; issue trackers bring work items and discussion; document stores write files into your organization's storage.
A connector does two jobs. It holds the credential, and it drives a migration — a resumable, paged read of the external tool that writes normalized records into NuPaaS. The credential is saved the moment you connect; nothing is imported until you start a migration.
Supported tools
| Parameter | Type | Description |
|---|---|---|
| GitHub / GHES | github | Repositories, issues, pull requests, and releases from GitHub.com or GitHub Enterprise Server. Connect with OAuth, a personal access token, or a GitHub App installation. |
| Azure DevOps | azure_devops | Git repositories, work items, and comments from Azure DevOps or Azure DevOps Server. Connect with OAuth or a personal access token. |
| Jira | jira | Issues, comments, and attachments from Jira Cloud or Jira Data Center. Connect with an API token (Cloud) or a personal access token (Data Center). |
| SharePoint | sharepoint | Documents from SharePoint sites, exported into your organization's file storage. Connect with an Entra app registration. |
The connectors page also lists GitLab. Its OAuth flow is configured, but the import pipeline is not registered yet, so a GitLab connect attempt is rejected. Use the GitHub or Azure DevOps connector until GitLab import ships.
Connecting a tool
GitHub and Azure DevOps offer two routes. OAuth is the default: theConnect button sends you to the provider's consent screen, and the callback stores the token for you. Choose Use a token when the provider is self-hosted, when your organization does not allow the OAuth app, or when you want a credential with a scope you control.
/orgs/<org>/connectors and find the tool.What each tool needs
GitHub / GHES
A personal access token with repo, read:org, and read:user scopes. Leave the base URL empty for GitHub.com; set it to your server address for GitHub Enterprise Server.
Azure DevOps
The organization URL (for example https://dev.azure.com/your-org) and a personal access token with Code (Read), Work Items (Read), and Identity (Read) scopes.
Jira
The Jira base URL, the account email, and an API token. On Jira Cloud, generate the token at id.atlassian.com/manage-profile/security. On Data Center or Server, use a personal access token instead.
SharePoint
An Entra app registration: tenant ID, client ID, and client secret.
Where credentials live
Credentials go to the organization vault, never to a database column. The path is secret/data/orgs/<org>/connectors/<connection>/credentials. What the platform stores alongside it is only the metadata you can see on the page: the provider, the base URL, the connected account, the auth kind, and the status.
Rotating a credential is a reconnect. Save the new token through the same form and the vault entry is replaced in place; the connection ID and its migration history survive.
Running a migration
Manage opens the migration page for a connection. Pick the resources you want, start the run, and the worker pages through the external API, writing a cursor after every page.
Resources are addressed as paths, so a run can be narrowed to one repository or one query rather than a whole account:
| Parameter | Type | Description |
|---|---|---|
| GitHub repositories | repos/<owner> | Every repository under an owner, with its issues and pull requests. |
| GitHub issue refresh | issues_sync/<owner>/<repo> | Re-read one repository's issues to pick up changes since the last run. |
| Jira issues | issues/<jql> | Issues matching a JQL query, for example issues/project = ACME ORDER BY created ASC. |
A run is resumable. If it stops — a rate limit, an expired token, a pod restart — starting it again continues from the stored cursor instead of re-reading what already landed. Progress is reported per resource, with a processed count and an error count.
Rate limits and retries
Every external call goes through a rate governor that respects the provider's own limit headers. When a provider starts refusing requests, the connection reports Rate limited and the run pauses rather than failing. It resumes on its own once the window resets, so a rate limit needs no action from you.
Connection states
| Parameter | Type | Description |
|---|---|---|
| Connected | connected | The credential works. The row shows the account, the host, and how long it has been connected. |
| Connecting | connecting | An OAuth consent or a first verification call is still in flight. |
| Credential expired | error | The token passed its expiry, so imports stopped. Select Reconnect and supply a new one. |
| Connection error | error | The last call failed for another reason. Open Manage for the run detail before reconnecting. |
| Rate limited | rate_limited | The provider is throttling. The run continues on its own; no action is needed. |
| Not connected | disabled | No credential is stored, or the connection was disconnected. |
Disconnecting
Disconnect removes the stored credential and stops any scheduled sync. Data that was already imported stays where it is — disconnecting is not a delete. A disconnected connection refuses new migrations until you connect it again.