Custom connectors
Pointing Hawi at a system that is not in the catalogue, and how each operation is risk-classified.
When a system is not in the public catalogue, a workspace may still have a separately configured custom route. Generic REST, webhook, external MCP and bring-your-own-key definitions exist in the internal catalogue, but they are not advertised as customer-connectable unless the live product offers their setup flow.
- generic_rest
- Describe the endpoints and Hawi calls them. The most common route for an in-house system.
- generic_webhook
- The external system calls Hawi when something happens. Use this when the source of truth pushes rather than being polled.
- external_mcp
- Point at an MCP server and its tools become available to agents in the workspace.
- user_byok
- A bring-your-own-key arrangement for a provider you already hold credentials with.
Risk classification
Every operation exposed by a custom connector is classified when the connector is scanned, into a risk level and an operation type of read or write. The classification is conservative in a specific way: an operation is only treated as a read when it is both marked read-only and uses a method that does not write. An endpoint declared read-only that turns out to POST is classified as a write, because the declaration is the part somebody can get wrong.