Disconnect a Sume integration: what is removed and what is not
Disconnecting Slack or Meta Ads removes stored credentials, any pending authorization and the tools for that workspace. Other workspaces are untouched.

Disconnecting an integration in Sume removes the stored credentials, any pending authorization and the agent tool availability for that workspace. Calls to the earlier tools fail afterward. Other workspaces never had your tools or credentials, so they are unaffected. The page lists disconnect as an admin action, and the dashboard only lets a request through when its Origin matches.
What the doc promises
The workspace integrations architecture doc states: disconnect removes the credentials, the pending authorization, and the tool availability. The endpoint is POST /api/integrations/{provider}/disconnect, and the doc's QA walkthrough ends with two checks: the list is empty, and calls to the tools from the earlier list fail.
Why pending authorization is included
A half-finished connect leaves state behind: a random, user-bound, ten-minute OAuth state and PKCE material. The callback has to find the same pending transaction to complete. Because disconnect deletes the pending authorization, a late callback cannot bring a connection back to life. The same holds for starting a new connect attempt or switching to a demo.
What disconnect does not do
Disconnecting in Sume deletes what Sume holds. It does not call out to revoke the grant inside the other product's settings in any way these docs describe. If you want the grant gone on the provider side too, remove the app from your Slack or Meta account settings as well. That is a precaution, not something Sume's doc claims it does.
- Stored tokens in Sume: removed
- Pending OAuth transaction: removed
- Agent tools for that provider in that workspace: gone
- Grant listed in the provider's own settings: check there yourself
Built-ins cannot be disconnected
Remotes and HyperFrames have no Disconnect. They are first-party and always on, and their status does not come from stored connection rows.
A good habit for offboarding
When an admin leaves, reconnect or disconnect the integrations they set up, and rotate API keys separately. If a key might be exposed, see exposed API key: revoke it first. Connector tokens and API keys are different credentials with different places to clean up.
A verification routine
After you disconnect, confirm the three outcomes yourself. Reload Integrations and see that the row is no longer connected. Start a new agent turn in that workspace and ask for the provider's data; the tools should be absent or the calls should fail. Then check a second workspace you own if you have one, to confirm it never had the tools.
Write the check into your offboarding list so it happens each time someone leaves the team.
Related posts
More in Integrations
- Which account pays: fal's Active MCP account vs a Sume key
fal's MCP sends credits to the Active MCP account you choose. On Sume the API key or OAuth session selects the workspace, and no tool takes a workspace id.
- Ghost audio card with a Sume track: mp3, wav or ogg from desktop
Ghost's audio card takes .mp3, .wav and .ogg uploaded from the desktop editor, up to 1 GB by plan. Download the Sume artifact, then upload the file.
- GITHUB_STEP_SUMMARY for Sume jobs: an audit table in the run page
Write the Sume job id, status and artifact URL to GITHUB_STEP_SUMMARY: 1 MiB per step, 20 step summaries shown per job. Public URLs only, no prompts or keys.
- workflow_dispatch music brief: 25 inputs, 65,535 chars vs Sume's 5,000
GitHub dispatch takes 25 inputs and 65,535 characters; Sume's music prompt stops at 5,000 and rejects duration. Guard the length, then call the router.
Written by Sume