Grain

Live

BEARER TOKEN

MEETING RECORDINGS

Transcription

Every customer call your team records, with its transcript, sits in Grain. Grain gives your agent authenticated access scoped to the user who authorized it.

  • Acts as the user: access and write actions stay tied to the Grain account that authorized the agent.
  • Credentials stay vaulted: AES-256, resolved at request time, never in LLM context.
  • Scoped before every call: permissions enforced. 90-day audit trail.
Grain
agent · Acme Q3
Run
What did Acme say about pricing on last week's call?
S
grain_recording_transcript_get
112ms
Grain agent
Two pricing objections: seat-based cost above 50 users, and wanting annual billing to unlock the volume tier.
Sources: 1 recording, 38 minutes
grain
3 calls
18:29
Message Claude...

Tools your meeting intelligence agent reaches for on Grain, scoped per user.

CALL ANY TOOL
Meeting recordings on Grain's REST API: search recordings, pull transcripts and highlights, upload media, and manage workspace webhooks.
grain_hook_create
Create hook
Register a webhook (hook) that Grain calls with an HTTP POST whenever the given event type occurs: new/updated/deleted recordings, highlights, or stories, or upload processing status changes.
Parameters
Name
Type
Required
Description
hook_type
string
Required
The event type this webhook subscribes to.
hook_url
string
Required
HTTPS URL that Grain will POST event payloads to.
grain_hook_delete
Delete hook
grain_hooks_list
List hooks
grain_meeting_types_list
List meeting types
grain_recording_download
Download recording
grain_recording_get
Get recording
grain_recording_share_team
Recording share team
grain_recording_share_user
Recording share user
grain_recording_tag_add
Add recording tag
grain_recording_tag_remove
Remove recording tag
grain_recording_transcript_get
Get recording transcript
grain_recording_transcript_text_get
Get recording transcript text
grain_recording_unshare_team
Recording unshare team
grain_recording_unshare_user
Recording unshare user
grain_recording_update
Update recording
grain_recording_upload_url_create
Create recording upload url
grain_recordings_list
List recordings
grain_teams_list
List teams
grain_users_list
List users
Build your Agent
Drop the toolkit in, point it at the user, and your meeting intelligence agent can use Grain from the first run.
Python · LlamaIndex
import { ScalekitClient } from "@scalekit-sdk/node";
import { createReactAgent } from "@langchain/langgraph/prebuilt";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

// Grain tools, scoped to the signed-in user
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["grain"], toolNames: [
"grain_hook_create",
"grain_hook_delete",
"grain_hooks_list"
] },
pageSize: 100,
});

const agent = createReactAgent({ llm, tools });
await agent.invoke({ messages: [{ role: "user", content: "What did Acme say about pricing on last week's call?" }] });
import OpenAI from "openai";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

// Grain tools, scoped to the signed-in user
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["grain"], toolNames: [
"grain_hook_create",
"grain_hook_delete",
"grain_hooks_list"
] },
pageSize: 100,
});

const openai = new OpenAI();
const res = await openai.responses.create({
model: "gpt-5",
tools: tools.map((t) => t.openai),
input: "What did Acme say about pricing on last week's call?",
});
import Anthropic from "@anthropic-ai/sdk";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

// Grain tools, scoped to the signed-in user
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["grain"], toolNames: [
"grain_hook_create",
"grain_hook_delete",
"grain_hooks_list"
] },
pageSize: 100,
});

const anthropic = new Anthropic();
const msg = await anthropic.messages.create({
model: "claude-opus-4-6",
max_tokens: 1024,
tools: tools.map((t) => t.anthropic),
messages: [{ role: "user", content: "What did Acme say about pricing on last week's call?" }],
});
import { Agent } from "@google/adk/agents";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

// Grain tools, scoped to the signed-in user
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["grain"], toolNames: [
"grain_hook_create",
"grain_hook_delete",
"grain_hooks_list"
] },
pageSize: 100,
});

const agent = new Agent({
name: "grain_agent",
model: "gemini-2.5-pro",
instruction: "Act as the meeting intelligence agent for the signed-in user.",
tools,
});
await agent.run("What did Acme say about pricing on last week's call?");
Try these prompts
Paste any prompt into your agent to start using Grain.
Call research
Copy the prompt
Copied
What did Acme say about pricing on last week's call?
Copy the prompt
Copied
Find recordings that mention the migration timeline.
Copy the prompt
Copied
Pull the transcript for yesterday's onboarding call.
Highlights
Copy the prompt
Copied
List the highlights tagged as objections this month.
Copy the prompt
Copied
Which calls have no highlights yet?
Copy the prompt
Copied
Summarize the key moments from the QBR recording.
Workspace ops
Copy the prompt
Copied
List recordings shared with the sales team this week.
Copy the prompt
Copied
Which webhooks are registered on the workspace?
Copy the prompt
Copied
How many recordings were added in the last 30 days?
SEE HOW AUTH WORKS
Users authorize Grain once. Their credentials stay vaulted, every call is checked, and every action is logged.
1
Authorize
Your user connects
Grain
once. We tie it to their identity and the meetings they approved — no shared bot account, no org-wide access
Who:
user ‘A’
when:
Once per user
access:
Limited to user
2
Store
Their
Grain
token lives in a vault scoped to them. User A's meetings are never reachable by an agent acting for user B, even on the same connection
vault:
encrypted
scope:
per-user
tokens:
auto-refreshed
3
Resolve
When your agent calls a
Grain
tool, we fetch the right token server-side. It never touches your agent, never appears in the LLM context, never shows up in your logs
speed:
~40ms
check:
before every call
seen by:
nobody
4
Audit
Every
Grain
tool call is logged — who triggered it, which meeting was fetched, what came back. 90 days of history, tied to the user who authorized it
history:
90 days
export:
SIEM-ready
logged:
every call
Test other agents
Same per-user auth pattern across other agents and MCP connectors. Working code, live demos, fork what fits.
GTM and RevOps Teams
CRM AI agent
Reads the Granola transcript after every call, extracts next steps and updates the HubSpot record, drafts the follow-up in Gmail, and confirms in Slack, all on the rep's own delegated OAuth.
GTM and RevOps Teams
Sales call prep agent
Reads tomorrow's calls from Google Calendar, mines past Granola notes and Attio history for context, and delivers each rep a prep brief in Slack, scoped to the calls that rep actually owns.
GTM and RevOps Teams
Deal intelligence agent
Pulls recent Gong calls, scores deal risk with an LLM, cross-references the record in Attio, and DMs each owner their at-risk deals in Slack. Every read is scoped to that rep's own access.
GTM and RevOps Teams
Competitive intelligence briefing agent
Scans Gong calls for competitor mentions, matches each one to its Notion battlecard, and DMs every affected rep a single Slack digest per cycle. Every call runs as the PMM who owns the briefing, never a shared bot.
Test other agents
Same per-user auth pattern across other agents and MCP connectors. Working code, live demos, fork what fits.
SALES
Deal intelligence agent
Score Gong call risk with an LLM, cross-reference the Attio record, and DM each owner their at-risk deals in Slack.
SALES
Sales call prep agent
Read tomorrow's calls from Google Calendar, mine Granola notes and Attio history, and deliver each rep a prep brief in Slack.
GTM
CRM AI agent
Turn each Granola call transcript into a HubSpot record update, a drafted Gmail follow-up, and a Slack recap.
GTM
Competitive intelligence briefing agent
Scan Gong calls for competitor mentions, match each one to its Notion battlecard, and DM every affected rep a single Slack digest.
Why Scalekit
Secure your agent's access. Connectors ship in minutes
01.
Shared tokens break per-user analytics
A shared token looks fine in a demo. In production every call looks like a service account. Scalekit resolves the real user credential so attribution, audit, and scope stay accurate.
// shared token
audit → bot_service_account
user_filter → broken

// scalekit
audit → user_abc
scope → enforced ✓
02.
Authentication is not authorization
03.
Multi-tenancy is architectural
04.
Grain today. Others tomorrow.
“Our agents act across Salesforce, Gong, Google Drive, and more, on behalf of every customer. Scalekit behind the scenes meant we can keep adding tools without ever rebuilding how credentials or tool calling work.”
Venu Madhav Kattagoni
Head of Engineering / Von
FAQs
Frequently Asked Questions
Does the agent access Grain as the user or as a shared key?
As the user. Each member authorizes once and Scalekit resolves their credential at request time. Audit logs attribute every action to that user, not a shared service account.
Where is the Grain bearer token credential stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. Refresh is automatic. Revocation is a single dashboard action. Credentials never appear in prompts, logs, or LLM context.
Can I limit what the agent is allowed to do in Grain?
Yes. Pass a tool name filter to listScopedTools so the meeting intelligence agent only sees the subset you authorize. Pre-API-call scope checks block out-of-policy actions before the request reaches Grain.
What happens when a user revokes Grain access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.
Can the agent read recordings the user cannot open in Grain?
No. Grain scopes recordings by workspace and sharing rules, and the connector calls as the authorizing user, so a rep sees their own and team-shared calls only. Private recordings from other members stay out of reach.
Start in your coding agent
Up and running in one command
Install the Scalekit skill in your editor of choice. Connector, auth, tools, prompt, all wired up
Claude Code REPL
/plugin marketplace add scalekit-inc/claude-code-authstack
/plugin install agentkit@scalekit-auth-stack
Cursor Code REPL
# ~/.cursor/mcp.json
{
""mcpServers"": {
""grain"": {
""url"": ""https://mcp.scalekit.com/grain"",
""headers"": { ""Authorization"": ""Bearer $SCALEKIT_TOKEN"" }
}
}
}
Codex Code REPL
# ~/.codex/config.toml
[mcp_servers.grain]
url = ""https://mcp.scalekit.com/grain""
auth_env = ""SCALEKIT_TOKEN""
Copilot Code REPL
# .vscode/mcp.json
{
""servers"": {
""grain"": {
""url"": ""https://mcp.scalekit.com/grain"",
""type"": ""http""
}
}
}