Front

Live

OAUTH 2.0

SHARED INBOX

Communication

Front gives agents authenticated access to your shared inbox: search conversations, reply and comment, manage tags and contacts, and route across inboxes and teammates as the actual user.

  • Per-user credentials: each reply and assignment runs as the actual teammate, never a shared bot.
  • Encrypted per-tenant vault: AES-256, resolved at request time, never in LLM context.
  • Scoped before every call: pre-call scope check, 90-day SIEM-exportable audit chain.
Front
agent · Acme Q3
Run
What is unassigned in the support inbox, and who should take it?
S
front_search_conversations
88ms
Front agent
11 unassigned conversations. 6 are billing questions, routed to Priya. 2 need engineering, tagged and assigned.
Conversations: 11 unassigned
front
11 conversations
18:29
Message Claude...

Tools your support agent reaches for in Front, scoped per user.

CALL ANY TOOL
Run the shared inbox end to end: search conversations, reply and comment, manage drafts, tag and route, and keep contacts, inboxes, and teammates in sync.
front_list_tags
List tags
List all tags that the API token has access to, whether they are company tags, team tags, or teammate tags, with optional sorting and pagination. Requires the tags:read scope.
Parameters
Name
Type
Required
Description
limit
integer
Optional
Maximum number of results to return per page. Maximum allowed value is 100.
page_token
string
Optional
Pagination token used to request the next page of results. Use the token returned in the previous response's pagination links.
schema_version
string
Optional
Schema version
sort_by
string
Optional
Field used to sort the tags. Only 'id' is supported.
sort_order
string
Optional
Order by which results should be sorted. One of 'asc' or 'desc'.
tool_version
string
Optional
Tool version
front_search_conversations
Search conversations
front_list_links
List links
front_get_tag
Get tag
front_list_teams
List teams
front_get_inbox
Get inbox
front_list_inboxes
List inboxes
front_get_account
Get account
front_list_accounts
List accounts
front_get_channel
Get channel
front_list_channels
List channels
front_get_comment
Get comment
front_list_contacts
List contacts
front_get_contact
Get contact
front_list_teammates
List teammates
front_get_message
Get message
front_list_conversations
List conversations
front_get_teammate
Get teammate
front_list_kb_articles
List kb articles
front_get_conversation
Get conversation
front_list_contact_notes
List contact notes
front_get_message_template
Get message template
front_list_inbox_channels
List inbox channels
front_create_tag
Create tag
front_list_knowledge_bases
List knowledge bases
front_update_tag
Update tag
front_list_message_templates
List message templates
front_create_link
Create link
front_list_inbox_conversations
List inbox conversations
front_create_draft
Create draft
Build your Agent
Same auth pattern across LangChain, OpenAI, Anthropic, and Google ADK.
Python · LlamaIndex
import { ScalekitClient } from "@scalekit-sdk/node";
import { createReactAgent } from "@langchain/langgraph/prebuilt";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

// Front tools scoped to this user
const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["front"], toolNames: [
    "front_list_tags",
    "front_search_conversations",
    "front_list_links"] },
  pageSize: 100,
});

const agent = createReactAgent({ llm, tools });
await agent.invoke({ messages: [{ role: "user", content: "What is unassigned in the support inbox, and who should take it?" }] });
import OpenAI from "openai";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const openai = new OpenAI();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["front"] }, pageSize: 100,
});

const res = await openai.chat.completions.create({
  model: "gpt-5",
  messages: [{ role: "user", content: "What is unassigned in the support inbox, and who should take it?" }],
  tools,
});

// Execute the tool call with the user's vaulted Front credential
await sk.tools.executeTool(res.choices[0].message.tool_calls[0], "user_123");
import Anthropic from "@anthropic-ai/sdk";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const anthropic = new Anthropic();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["front"] }, pageSize: 100,
});

const msg = await anthropic.messages.create({
  model: "claude-sonnet-5",
  max_tokens: 1024,
  messages: [{ role: "user", content: "What is unassigned in the support inbox, and who should take it?" }],
  tools,
});

// Tool call runs with the user's vaulted Front credential
await sk.tools.executeTool(msg.content, "user_123");
import { Agent } from "@google/adk/agents";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["front"] }, pageSize: 100,
});

const agent = new Agent({
  name: "front_agent",
  model: "gemini-2.5-pro",
  instruction: "Manage Front for the signed-in user.",
  tools,
});

await agent.run("What is unassigned in the support inbox, and who should take it?");
Try these prompts
Copy any prompt into your agent. Each maps directly to a Front tool. Click to copy, paste into your agent, done.
Triage the inbox
Copy the prompt
Copied
What is unassigned in the support inbox?
Copy the prompt
Copied
Show conversations waiting on a customer reply.
Copy the prompt
Copied
Which threads are tagged urgent and still open?
Respond
Copy the prompt
Copied
Draft a reply to the Acme billing thread.
Copy the prompt
Copied
Add an internal comment and mention the on-call lead.
Copy the prompt
Copied
Assign this conversation to Priya and tag it billing.
Contacts and routing
Copy the prompt
Copied
Add a note to this contact.
Copy the prompt
Copied
Move this thread to the escalations inbox.
Copy the prompt
Copied
Which teammates have the most open conversations?
SEE HOW AUTH WORKS
Your users connect once. Their Front credentials stay vaulted, every call is scope-checked, and every action is logged.
1
Authorize
Your user connects
Front
once. We tie it to their identity and the meetings they approved — no shared bot account, no org-wide access
Who:
user ‘A’
when:
Once per user
access:
Limited to user
2
Store
Their
Front
token lives in a vault scoped to them. User A's meetings are never reachable by an agent acting for user B, even on the same connection
vault:
encrypted
scope:
per-user
tokens:
auto-refreshed
3
Resolve
When your agent calls a
Front
tool, we fetch the right token server-side. It never touches your agent, never appears in the LLM context, never shows up in your logs
speed:
~40ms
check:
before every call
seen by:
nobody
4
Audit
Every
Front
tool call is logged — who triggered it, which meeting was fetched, what came back. 90 days of history, tied to the user who authorized it
history:
90 days
export:
SIEM-ready
logged:
every call
Test other agents
See the same per-user auth pattern across other communication connectors.
People Ops and HR teams
New Hire Provisioning Agent
Open-source Python template. Creates or detects the hire in Deel, provisions their Workspace account, builds the Notion onboarding page, posts the welcome.
People Ops and HR teams
PTO & Leave Request Agent
Open-source Python template. Resolves the employee in Deel, validates against their real entitlement, submits the request for approval, blocks the calendar.
Engineering Teams
Incident Response Agent
Open-source Python template. Triggers the PagerDuty page, opens the Jira incident, notifies the on-call Slack channel, and drafts the Confluence postmortem.
GTM and RevOps Teams
Competitive intelligence briefing agent
Scans Gong calls for competitor mentions, matches each one to its Notion battlecard, and DMs every affected rep a single Slack digest per cycle. Every call runs as the PMM who owns the briefing, never a shared bot.
Test other agents
See the same per-user auth pattern across other communication connectors.
ENGINEERING
Slack workflow agent (LangGraph)
LangGraph agent that drives multi-step Slack workflows: triggers, approvals, and follow-up actions per user identity.
OPS
Email-to-calendar scheduling agent
Read scheduling intent out of Gmail threads, resolve mutual free time, and create the Google Calendar event.
Why Scalekit
Secure your agent's access. Connectors ship in minutes
01.
Shared inbox keys erase who replied
A shared Front token looks fine in a demo. In production every reply and assignment looks like one integration, and you cannot tell which teammate handled a customer. Scalekit resolves the credential of the actual user who triggered the agent, never a shared bot.
// shared token
audit → bot_service_account

// scalekit
audit → user_abc ✓
02.
Authentication is not authorization
03.
Multi-tenancy is architectural
04.
Front today. Ten connectors tomorrow.
“Our agents act across Salesforce, Gong, Google Drive, and more, on behalf of every customer. Scalekit behind the scenes meant we can keep adding tools without ever rebuilding how credentials or tool calling work.”
Venu Madhav Kattagoni
Head of Engineering / Von
FAQs
Frequently Asked Questions

Does the agent access Front as the user or as a shared key?
As the user. Each workspace member authorizes once and Scalekit resolves their credential at request time. Audit logs attribute every action to that user, not a shared service account.

Where is the Front OAuth token stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. Refresh is automatic. Revocation is a single dashboard action. Tokens never appear in prompts, logs, or LLM context.

Can I limit what the agent is allowed to do in Front?
Yes. Pass a tool name filter to listScopedTools so the messaging agent only sees the subset you authorize. Pre-API-call scope checks block out-of-policy actions before the request reaches Front.

What happens when a user revokes Front access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.

Does the agent respect Front permissions?
Yes. Every call runs as the authorizing user. Native roles, sharing settings, and scope restrictions in Front apply to each request, and actions log to the audit chain.

Start in your coding agent
Up and running in one command
Install the Scalekit skill in your editor of choice. Connector, auth, tools, prompt, all wired up
Claude Code REPL
/plugin marketplace add scalekit-inc/claude-code-authstack
/plugin install agentkit@scalekit-auth-stack
Cursor Code REPL
# ~/.cursor/mcp.json
{
""mcpServers"": {
""front"": {
""url"": ""https://mcp.scalekit.com/front"",
""headers"": { ""Authorization"": ""Bearer $SCALEKIT_TOKEN"" }
}
}
}
Codex Code REPL
# ~/.codex/config.toml
[mcp_servers.front]
url = ""https://mcp.scalekit.com/front""
auth_env = ""SCALEKIT_TOKEN""
Copilot Code REPL
# .vscode/mcp.json
{
""servers"": {
""front"": {
""url"": ""https://mcp.scalekit.com/front"",
""type"": ""http""
}
}
}