Gainsight is a customer success platform for managing customer health, relationships, and engagement.
It can be connected to Agen.co two ways, matching the Official / In-house filter in the connector picker:
- Official — Agen.co connects through Gainsight's own hosted MCP server for Gainsight CS, so your AI agents get access to companies, persons, calls to action (CTAs), success plans, and custom objects through your account's existing permissions.
- In-house — Agen.co wraps the Gainsight API directly through its own integration layer, using M2M OAuth 2.0 credentials you generate in Gainsight's Connectors 2.0.
Pick Official if the built-in MCP tools cover what your agents need. Fall back to In-house if you need broader API coverage or prefer a machine-to-machine credential with no user redirect.
Prerequisites
Prerequisites
- A Gainsight CS account with access to Administration → User Management → Authentication
- Super admin permissions to create OAuth Applications. Gainsight allows at most three OAuth applications per tenant, so you may need to reuse or remove an existing one.
- In Gainsight, go to Administration → User Management, open the Authentication tab, and select OAuth Applications. Click to create a new application.
- In a separate tab, open the Agen.co portal, go to Connectors → My connectors, click Add connector, and in the search bar type
Gainsightand select it from the results. In the Instance Slug field, enter a slug for this connector instance — it prefixes each imported tool asslug__tool, so a second instance of the same connector needs a slug of its own. Use lowercase kebab-case. You can change it later from the connector's settings. - In Gainsight domain, enter your Gainsight CS tenant domain (for example,
yourcompany.gainsightcloud.com). - Get back to Gainsight. Under Callback URLs, add both URLs shown on the Add Gainsight panel in Agen.co:
- Callback URL — completes the initial OAuth handshake between Agen.co and your Gainsight OAuth application.
- Gateway callback URL — used by the Agen.co MCP gateway for per-user authorization at runtime.
- Set Scope to Read/Write. The company, person, relationship, CTA and success plan tools listed below all write, and a Read application leaves them failing at call time. Choose Read only if you intend the connector to stay read-only.
- Turn on Enable PKCE — Gainsight requires it for this OAuth application type.
- Save the application, then copy the Client ID and Client Secret it generates and paste them into the matching fields on the Add Gainsight panel in Agen.co.
Keep your Client Secret safe
Keep your Client Secret safe
Gainsight masks the Client Secret permanently after this first view. If you lose it, you have to generate a new one.
- Click Connect.
- You're redirected to Gainsight to sign in and approve access.
- Return to Agen.co and click Add below the list of tools that were added.
Once connected, Gainsight appears under My connectors with tools spanning:
| Area | What it covers |
|---|---|
| Companies | Reading and updating company records |
| Persons | Reading and updating person (contact) records |
| Relationships | Reading and updating relationship records between companies |
| Calls to Action | Reading, creating, and updating CTAs |
| Success plans | Reading, creating, and updating success plans and their objectives |
| Custom objects | Querying custom objects configured in your Gainsight tenant |
Enabling the Gainsight connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.
Gainsight is a customer success platform for managing customer health, relationships, and engagement. Integrating Gainsight with Frontegg lets your application manage companies, persons, and relationships, work with Calls to Action (CTAs) and success plans, and query custom objects on behalf of your users — all through Frontegg's integration layer. Gainsight authenticates with a machine-to-machine (M2M) OAuth 2.0 client credentials grant, so there is no user redirect: the gateway exchanges a Client ID and Client Secret directly for an access token against your tenant.
Prerequisites
Prerequisites
- A Gainsight NXT account
- Super admin access (M2M OAuth connections can only be created by super admins)
Gainsight issues M2M OAuth credentials from a connection you create in Connectors 2.0. You will also need your Gainsight tenant URL — the host of your Gainsight API.
Sign in to Gainsight and go to Administration → Connectors 2.0, then click Create Connection. From the Connector dropdown, select Gainsight API, enter a Name for the connection (for example, Frontegg Integration), and set Authentication Type to OAuth.
Click Generate OAuth Credentials. Gainsight generates an OAuth API Key (your Client ID) and an OAuth API Secret (your Client Secret). Copy both values.
Copy your Client Secret now
Copy your Client Secret now
The OAuth API Secret is your Client Secret — treat it like a password. If it is exposed, use Re-Generate Secret on the connection to rotate it (the previous secret stays valid for up to 24 hours).
Your tenant URL is your Gainsight API host — for example, companyapi.gainsightcloud.com (or a custom domain such as companyapi.yourcompany.com). Use the host only, without https:// or a trailing slash.
Once you have your Client ID, Client Secret, and tenant URL, configure the integration in the Frontegg portal:
- Open the Frontegg portal and navigate to [ENVIRONMENT] → Integrations → Gainsight.
- Enter the Client ID (OAuth API Key) and Client Secret (OAuth API Secret).
- Enter your Gainsight tenant URL — the host only (for example,
companyapi.gainsightcloud.com). - Click Save.
Keep your credentials secure
Keep your credentials secure
Never share or commit your Client Secret to version control.