Skip to content
Last updated

Glean integration

Glean is an AI-powered work assistant and enterprise search platform that connects to your company's apps and content.

It can be connected to Agen.co two ways, matching the Official / In-house filter in the connector picker:

  • Official — Agen.co connects through Glean's own hosted MCP server, so your AI agents get access to search, chat, documents, and more through Glean's native OAuth flow.
  • In-house — Agen.co wraps the Glean API directly through its own integration layer, using OAuth 2.1 or a Glean-issued API token you configure in the Glean admin console.

Pick Official if the built-in MCP tools cover what your agents need. Fall back to In-house if you need broader API coverage or prefer managing OAuth clients and API tokens directly in your Glean instance.


Connect via the official MCP server

Prerequisites

  • A Glean account with access to your organization's instance
  • Your Glean backend subdomain — the part before .glean.com in your backend domain (for example, acme-be). Find it at app.glean.com/admin/about-glean under Server instance.
  1. In Agen.co, go to Connectors → My connectors, click Add connector, and in the search bar type Glean and select it. Keep this panel open.
  2. In the Instance Slug field, enter a slug for this connector instance — it prefixes each imported tool as slug__tool, so a second instance of the same connector needs a slug of its own. Use lowercase kebab-case. You can change it later from the connector's settings.
  3. In the Glean backend subdomain field, enter your Glean backend subdomain — for example acme-be. Enter the subdomain only, without .glean.com or any trailing slash.
  4. In the MCP server name field, enter your MCP server name. Leave it as default unless you have created a custom MCP server in Glean.
  5. Click Connect.
  6. You're redirected to Glean to sign in with your organization's SSO and approve access.
  7. Return to Agen.co and click Add below the list of tools that were added.

Once connected, Glean appears under My connectors with tools spanning:

AreaWhat it covers
SearchSearching connected content and getting suggestions
ChatUsing the Glean AI assistant
DocumentsReading documents and document permissions
People & entitiesReading user profiles and entity information

Enabling the Glean connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Connect via the Glean API

Glean is an AI-powered work assistant and enterprise search platform that connects to your company's apps and content. Integrating Glean with Frontegg lets your application search across connected content, chat and get summaries, read documents and their permissions, and manage collections, pins, and answers on behalf of your users — all through Frontegg's integration layer. Glean is self-hosted per customer, so both the API host and the OAuth endpoints are specific to your Glean instance. You can authenticate with either OAuth 2.1 (Authorization Code with PKCE) or a Glean-issued API token.


Prerequisites

  • A Glean instance with admin access
  • Your Glean instance host — the backend host, for example acme-be.glean.com
  • Admin rights in the Glean admin console (only admins can register OAuth clients or issue API tokens)

Connect Glean with OAuth

Glean runs its own OAuth authorization server, which an admin enables and where OAuth clients are registered. The client provides the Client ID and Client Secret and defines the redirect URI that Glean returns users to after they authorize access.

Step 1: Open the admin console

Sign in to Glean and open the admin console (the wrench icon in the left navigation bar).

Step 2: Enable the OAuth authorization server

In the admin console, go to Setup → OAuth and enable the Glean OAuth authorization server. It is disabled by default and must be turned on before clients can be registered.

Step 3: Register an OAuth client

Add a new OAuth client and configure it:

  • Name — A descriptive name, for example Frontegg Integration.
  • Redirect URI — Your Frontegg Redirect URL: https://YOUR_MCP_GATEWAY_URL/integration-callback
  • Scopes — Grant the scopes your application needs (see the scopes table below).

Save the client. Glean displays the Client ID and Client Secret — copy both.

Keep your Client Secret safe

Treat the Client Secret like a password. Never expose it in client-side code or commit it to version control.

Step 4: Note your instance host

Your instance host is your Glean backend host — for example acme-be.glean.com. Use the host only, without https:// or a trailing slash.

Use an API token instead

If you are connecting a single account rather than authorizing multiple users, you can use a Glean-issued API token instead of an OAuth client:

  • In the admin console, go to Setup → API Tokens and open the Client Tokens tab.
  • Click Add New Token, then set a Description, Permissions, Scopes, and an Expires date, and click Save.
  • Copy the token value immediately.

Copy your token now

The token secret is shown only once, when it is created. Copy it and store it securely — you cannot retrieve it later. A token's permission and scopes cannot be changed after creation; issue a new token if you need different access.

Scopes

The OAuth client grants the following scopes:

ScopeDescription
SEARCHSearch connected content and get suggestions
CHATUse the Glean Chat assistant
DOCUMENTSRead documents
DOCPERMISSIONSRead document permissions
ENTITIESRead people and other entities
SUMMARIZEGenerate content summaries
PINSRead pins
COLLECTIONSRead and create collections
ANSWERSRead answers
ACTIVITYReport activity
offline_accessObtain a refresh token for long-lived access

Configure the Frontegg portal

Configure the integration in the Frontegg portal using the method you chose:

  1. Open the Frontegg portal and navigate to [ENVIRONMENT] → Integrations → Glean.
  2. Enter your Glean instance host — the host only (for example, acme-be.glean.com).
  3. For OAuth, enter the Client ID and Client Secret. For an API token, enter the token in the API token field instead.
  4. Click Save.

Keep your credentials secure

Never share or commit your Client Secret or API token to version control.

Additional resources