Fetching from the wire…
Public story · 2026-08-26 · high
OIDC-scoped tokens replace static API keys across 100+ integrations, including Slack, GitHub and Salesforce.
Why now: Connect leaving beta for general availability removes the excuse to keep secrets in place.
Vercel Connect went generally available on every plan, including v0, per Vercel Connect's GA changelog. Leaked provider secrets in environment variables are a common way into a breach, and Connect closes that specific hole.
The feature changes how a deployment reaches outside services. Instead of storing a provider's API key in a project's environment variables, the deployment authenticates with the Vercel OIDC identity it already holds. It calls getToken() for a credential scoped to that one task. Vercel refreshes and expires the token itself, so no static secret sits in the project.
The list of covered services is long. Vercel counts more than 100 integrations, with managed connectors for Slack, GitHub, Linear, Salesforce, Snowflake and Microsoft. It also supports generic OAuth, API keys and MCP servers.
Any team with a provider secret already sitting in a Vercel project's environment variables has a migration to schedule.
Going GA doesn't retire the old path. Projects that keep static secrets in place get none of the protection, and the changelog sets no deadline for moving off them.
Each link below shares sources, entities, or timing with this story.
Vercel Connect partners with Salesforce / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Vercel Connect partners with Salesforce); both cover GitHub, MCP, Microsoft, OAuth; overlapping topics (credential, environment, secret).
Vercel Connect built by Vercel / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Vercel Connect built by Vercel); both cover GitHub, Slack, Vercel, Vercel Connect; reported by the same outlet (vercel.com).
Linked by a graph relationship (Vercel Connect built by Vercel); both cover OAuth, OIDC, Snowflake, Vercel; reported by the same outlet (vercel.com).
Vercel Connect built by Vercel / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (Vercel Connect built by Vercel); both cover GitHub, MCP, Microsoft, Vercel; reported by the same outlet (vercel.com).
Vercel Connect built by Vercel / Shared entities / Earlier coverage / Tension
Linked by a graph relationship (Vercel Connect built by Vercel); both cover GitHub, MCP, Microsoft, Vercel; earlier GitHub coverage from 2026-08-13.
Vercel Connect built by Vercel / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Vercel Connect built by Vercel); both cover GitHub, OAuth, Vercel; reported by the same outlet (vercel.com).
Vercel Connect partners with Linear / Shared entities / Earlier coverage
Linked by a graph relationship (Vercel Connect partners with Linear); both cover GitHub, Linear, Salesforce, Slack; earlier GitHub coverage from 2026-08-21.
Vercel Connect built by Vercel / Shared entities / Earlier coverage
Linked by a graph relationship (Vercel Connect built by Vercel); both cover GitHub, MCP, Microsoft, Vercel; earlier GitHub coverage from 2026-08-17.