Overview
When you attach a tool to an assistant or agent, that tool uses credentials (for example OAuth, API key, or custom credentials) to call the external service. Tool sharing lets other Workspace members in your Workspace use those credentials through the tool — for example when they chat with an assistant that has Google Drive attached — without letting them view or edit the underlying secrets. Sharing is configured per tool instance, not per catalog entry. If you connect Google Drive twice (two instance IDs), each instance has its own sharing policy. Changing policy on one instance does not affect another.Assistants and agents use the same sharing flow. Open Step 3: Knowledge & Tools → Tools & Functions on either an assistant or an agent to set policy on a linked instance.
Where to configure sharing
Open the assistant or agent that uses the tool:- Go to Step 3: Knowledge & Tools → Tools & Functions.
- Under Application instances, find the tool you want to share.
- Click Credential sharing policy on that instance card.

Who can set the sharing policy
Typically, the user who connected the tool instance (or completed OAuth on behalf of the Workspace) can open Credential sharing policy and change who may use those credentials. Workspace administrators can also manage connected tools from Admin → Tools → My Apps. If you cannot see Credential sharing policy on an instance, ask the person who connected it or your Workspace admin.Sharing policy
The Credential sharing policy dialog controls which Workspace members may use this tool’s credentials. The title includes the tool name (for example Credential sharing — HubSpot).
Public credentials means all Workspace members in your Workspace, not the public internet. Only people in your Workspace can be granted access.
Share with specific users (optional)
Use Select Credentials for Others when you want only certain Workspace members to use this tool.- Search for users by name or email.
- Add the users who should be allowed to use the credentials.
- Click Save.
Share with the entire Workspace
Use Select Public Credentials when every Workspace member should be able to use this tool.- Enable Enable credential access for entire workspace.
- Save the policy.
What sharing does and does not do
What sharing grants
- Permission to use the tool’s credentials when the instance is attached to an assistant or agent the user can run
- Ability to benefit from OAuth or API access without seeing secrets
What sharing does not grant
Sharing does not:- Attach the tool to other assistants or agents — you still add the instance separately on each assistant or agent that should use it
- Let shared users view, copy, or edit API keys, tokens, or passwords
- Let shared users re-authorize OAuth or update credentials on the instance (unless they are the connector or an admin with tool management access)
- Let shared users remove the instance or change its configuration from Admin → Tools unless they have admin rights
Think of sharing as who may use the keys, not who owns the integration. Connecting and attaching the tool is a separate step from sharing credentials.
Example: Share Google Drive with your support team
- In Admin → Tools, create a Google Drive instance (or use an existing one on My Apps) and complete OAuth.
- Open the Support assistant (or create one) → Step 3: Knowledge & Tools → Tools & Functions.
- Under Available apps, find Google Drive and attach your instance under Application instances.
- On that instance card, click Credential sharing policy.
- Under Select Credentials for Others, search for each support team member and add them. Click Save.
- Alternatively, enable Enable credential access for entire workspace if every agent in the Workspace should use the same Drive connection.
- Save the assistant. When granted users chat with that assistant, the agent can call Google Drive functions using the shared credentials — without those users ever seeing the OAuth tokens.
Related documentation
- Tools Overview — Create and manage tool instances
- Creating Assistants — Attach tools to an assistant
- Creating Agents — Attach tools to an agent
- Supported Tools — Full tool catalog
- FAQ — Tools — Common tool and sharing questions