For AI agents: a documentation index is available at https://www.mongodb.com/docs/llms.txt — markdown versions of all pages are available by appending .md to any URL path.
See how MongoDB 9.0 delivers up to 2x higher throughput.
MongoDB Branding Shape
Register now >
Docs Menu

Connect an App to Your Atlas Account

You can enable third-party applications to access your MongoDB Atlas account. When you connect an application, it connects to Atlas through Atlas App Connections, the Atlas OAuth 2.1 platform. Instead of asking you to create and paste credentials, the application asks you to sign in to Atlas and authorize it to act on your behalf.

This page describes what happens when you connect a third-party application to your Atlas account, including:

  • What delegated access means and what "act on your behalf" allows.

  • How the connection flow works, from choosing Atlas to returning to the application.

  • How to review the permissions you grant on the consent screen.

  • Where to view the applications you have connected.

  • How to revoke access, and what revocation does and does not do.

When you connect your Atlas account to a third-party application:

  • Your data stays in your Atlas account. Connecting an application does not move the source of your data or make that application the system of record. Your clusters, data, and other Atlas resources remain in your own Atlas account and under your control.

  • The application acts on your behalf through delegated access. Atlas issues the application OAuth tokens that let it perform Atlas actions with your permissions. See How Delegated Access Works.

  • You are billed for the resources the application uses. Any usage of Atlas resources that an application provisions or operates on your behalf is billed to your own Atlas account.

When you authorize an application, it acts on your behalf. Atlas issues the application tokens that let it call the Atlas Administration API with the same permissions you hold in your Atlas organizations and projects. If you cannot perform an action in Atlas, the application cannot perform it on your behalf either.

Because access is delegated from your own permissions:

  • The application's access changes automatically when your roles change. If your Atlas access is reduced or removed, the application's access updates to match.

  • The application can act only in organizations that allow third-party app connections. Organization owners control this setting. Even after you authorize an application, it cannot operate in an organization that has not enabled third-party app connections.

Currently, delegated access is not scoped to specific organizations, projects, or operations: an application can act anywhere your Atlas permissions allow. Because an application acts with your full Atlas permissions, authorize only applications that you trust.

You start the connection from the application, not from Atlas. The exact wording and screens vary by application, but the Atlas portion of the flow is the same for every application.

1

In the application, choose MongoDB Atlas as your database or start the option to connect your Atlas account. The application redirects you to Atlas to sign in.

2

Sign in with your Atlas account. If you are already signed in, Atlas may skip this step. If you do not have an Atlas account, you can create one to continue.

3

Atlas shows a consent screen that lists the permissions the application is requesting. Review the permissions, then select Authorize to grant access or Decline to cancel. For details about what the consent screen shows, see Review Permissions and Consent.

4

After you select Authorize, Atlas returns you to the application, which completes the connection. The application can now act on your behalf with your Atlas permissions.

Before you authorize an application, Atlas shows a consent screen that summarizes the access the application is requesting: the ability to see which Atlas resources you can access and to act on your behalf, with the same permissions you hold, in organizations that allow third-party app connections.

If you select Authorize, Atlas grants the application delegated access and returns you to the application. If you select Decline, Atlas cancels the connection and the application does not receive access.

You can review the applications you have authorized to act on your behalf from your Atlas account settings. In Atlas Settings, select App Connections.

Organization owners view all applications authorized in an organization from Organization Settings; see View Authorized Applications.

You can revoke an application's access at any time from the same place where you view your connected apps.

1

In Atlas Settings, select App Connections.

2

Find the application, then select Revoke. Atlas asks you to confirm. Select Revoke to continue, or Cancel to keep the connection.

After you revoke access, the application can no longer act on your behalf in any organization, and must be re-authorized before it can connect again. Changes can take up to 10 minutes to take effect.

Organization owners can also disable third-party app connections for the whole organization; see Enable or Disable Third-Party App Connections.

When you revoke access, the application can no longer take actions on your behalf.

Important

Revoking access does not delete the resources the application created for you, such as database users, clusters, or projects. These resources, and any credentials the application created, remain active until you or your organization owner remove them.

If you no longer use an application, ask your organization owner to review and remove any resources it created. For organization-level management and offboarding steps, see Manage Third-Party App Access to Atlas.