Integrations

Your systems play their part.

metamorphOS runs the process on the stack you already have. Your systems start it, feed it, and carry out its actions. Nothing gets replaced.

It works in both directions.

metamorphOS → your systems

The process calls your systems.

A step can call any REST endpoint: create the record, file the document, post the entry. The response flows straight back into the run.

Authentication

How metamorphOS signs in to your systems:

OAuth 2.0 · Auth Code + PKCEOAuth 2.0 · Client CredentialsAPI keysBasic
Your systems → metamorphOS

The process waits for your systems.

A run can wait on a webhook, matched on your own data: the payment reference, the order number. When it arrives, the payload enters the process as if someone had typed it in, and the run moves on. A webhook can also start a run of its own.

Verification

How we make sure it is really your system calling:

HMAC · SHA-256/512JWT/JWS · RS & ESJWKS · key rotationReplay protection

Not every partner has an API. Everyone has email.

The subcontractor, the customer, the authority: they will never call your endpoints. They answer emails. So the process speaks email, natively.

A mailbox of its own

A process gets its own address. What lands there is read: sender, subject, text, and every attachment, filed with the run.

Mail becomes the run

The timesheet, the signed offer, the one-line "approved": it reaches the right run, and the run moves on. A mail can start one, too.

Forward things in

Forward a thread to the process and it reads the original: real sender, real content, attachments included. Not the forward.

Every inbox has its allowlist: only senders you approve get through.

Bring your own API. In minutes.

Our own integration engine turns any REST API into process steps. With an OpenAPI spec, it takes seconds.

Import the spec

Endpoints, parameters and auth are read from your OpenAPI file automatically.

Auth, both ways

OAuth 2.0 and API keys for calls out, signed webhooks for calls in.

Built to operate

Every delivery logged and inspectable, every connector versioned.

The tools teams run this on.

A selection, not a ceiling: anything with a REST API docks on in minutes.

Microsoft TeamsMicrosoft Teams
SalesforceSalesforce
NotionNotion
HubSpotHubSpot
Google DriveGoogle Drive
Email (SMTP/IMAP)Email (SMTP/IMAP)
AsanaAsana
TrelloTrello
Monday.comMonday.com
MiroMiro
ConfluenceConfluence
WrikeWrike
Microsoft OutlookMicrosoft Outlook
Google MailGoogle Mail
Google CalendarGoogle Calendar
CalendlyCalendly
Microsoft SharePointMicrosoft SharePoint
Microsoft OneDriveMicrosoft OneDrive
GitHubGitHub
GitLabGitLab
ZenhubZenhub
DocuSignDocuSign
DropboxDropbox
Google SheetsGoogle Sheets
PipedrivePipedrive
ZendeskZendesk
FreshdeskFreshdesk
ServiceNowServiceNow
ShopifyShopify
StripeStripe
WorkdayWorkday
PersonioPersonio
FactorialFactorial
FreshBooksFreshBooks
NetSuiteNetSuite
OdooOdoo
AirtableAirtable
DATEVDATEV
sevDesksevDesk
RequestyRequesty
SlackSlack
WixWix
GrafanaGrafana
Anthropic ClaudeAnthropic Claude
Google GeminiGoogle Gemini
JiraJira
FreshsalesFreshsales
MoodjaMoodja

Something proprietary? We build the connector with you. Legacy systems, industry software, in-house tools: our engineering team builds the connector alongside your first process.

integrations@metamorphos.io

Connecting up, answered.

Nineteen connectors are built today, with around 246 named operations between them: Odoo, HubSpot, Freshsales, Jira, GitHub, GitLab, Trello, Slack, Google Calendar, Google Drive, Google Mail, Microsoft Outlook, Shopify, Wix, sevDesk, Grafana, Anthropic Claude and Google Gemini. Everything else with a REST API connects through OpenAPI import.

Anything with a REST API docks on. Our integration engine turns endpoints into process steps, and with an OpenAPI spec the endpoints, parameters and auth are imported automatically.

Yes. A step can call your systems and use the response in the run, and a run can wait on a webhook matched on your own data, such as a payment reference or an order number. A webhook can also start a run.

Outbound: OAuth 2.0 with Auth Code and PKCE or Client Credentials, API keys, or Basic. Inbound: HMAC with SHA-256 or SHA-512, JWT and JWS with RS and ES, JWKS key rotation and replay protection.

They take part in the process itself, through a secure task link verified by email. Email remains the fallback: a process has its own mailbox, senders are allowlisted, and what arrives is filed with the run, attachments included.

Yes. For legacy systems, industry software and in-house tools, our engineering team builds the connector alongside your first process.

Show us how you work today.
You'll know what to fix first.

A discovery call with Robert: thirty minutes on where coordination costs you most.