Integrations

42 apps we can reach without an upgrade.

Listed with the most widely used first, so the ones you actually run are near the top. An app makes this list on one test: can a plain admin API remove a member on the plan you already pay for?

25 more are reachable only if you already pay for a particular plan of theirs — mostly apps where SCIM is the only way to remove a member and SCIM sits above the cheapest paid tier. Expensify needs Control, 1Password and LastPass need Business, Intercom needs Expert, and a long tail of them need Enterprise. Every one is excluded from the count above and carries the plan it needs on its own card, because for these the upgrade is the mechanism and we will not quote you a saving against it. athenahealth, DrChrono and HealthStream need a partner programme rather than a plan.

Verified
We've confirmed the write path exists on the plan you already pay for.
Coming soon
On the roadmap. Read the line under each app for how we'll reach it.
Needs your …
We use your API key on your plan, so this one only works if you already pay for the plan named on the card.

Microsoft Entra ID

Verified

Microsoft Graph — included with Microsoft 365

Google Workspace

Verified

Admin SDK — any Business plan

Amazon Web Services

Coming soon

IAM users, groups and access keys

Salesforce

Coming soon

SCIM Users API

Needs your Enterprise

Zoom

Coming soon

Users API on any standard paid plan

Jira & Confluence

Verified

Atlassian org admin API — no Guard subscription needed

Box

Coming soon

Admin API — no enterprise upgrade

GitHub

Verified

REST org members — no plan gate

DocuSign

Coming soon

Admin API closeMemberships — the add-on is included with IAM plans

Needs your DocuSign Admin add-on

ServiceNow

Coming soon

Table API — create, then set active=false

Dropbox

Coming soon

Team member management API

Okta

Coming soon

Users API — included with any Okta plan

Canva

Coming soon

SCIM Users API

Needs your Enterprise

Figma

Coming soon

SCIM Users API — role assignment included

Needs your Enterprise

OpenAI

Coming soon

SCIM Users API

Needs your Enterprise

Asana

Coming soon

Workspace membership API

Zendesk

Coming soon

Users API

Trello

Coming soon

Atlassian org admin API

Monday.com

Coming soon

SCIM Users API

Needs your Enterprise

ClickUp

Coming soon

SCIM Users API

Needs your Enterprise

Smartsheet

Coming soon

SCIM Users API

Needs your Enterprise

Miro

Coming soon

SCIM Users API — automation is Enterprise-only

Needs your Enterprise

Lucidchart

Coming soon

SCIM Users API

Needs your Enterprise

HubSpot

Coming soon

User Provisioning API via a private app — removes by user ID or email

Intercom

Coming soon

SCIM Users API

Needs your Expert

Shopify

Coming soon

SCIM Users API

Needs your Plus

Tableau

Coming soon

SCIM on any Tableau Cloud plan — SAML or OIDC must be configured first

Airtable

Coming soon

SCIM Users API

Needs your Enterprise Scale

GitLab

Coming soon

Members API, all tiers

Bitbucket

Coming soon

Atlassian org admin API

Datadog

Coming soon

Users API

New Relic

Coming soon

SCIM Users API

Needs your Pro or Enterprise

Snowflake

Coming soon

SQL user and role management

Databricks

Coming soon

SCIM Users API — account-level user management is SCIM-only

Needs your Premium

MongoDB Atlas

Coming soon

Org and project users API

Docker Hub

Coming soon

Org members API

PagerDuty

Coming soon

Users API

Sentry

Coming soon

Organization members API

Cloudflare

Coming soon

Account members API

CircleCI

Coming soon

Org members API

Linear

Coming soon

GraphQL userSuspend — deactivates and invalidates their sessions

Vercel

Coming soon

Team members API

Grafana

Coming soon

Org users API

Tailscale

Coming soon

Tailnet users API

CrowdStrike

Coming soon

SCIM Users API

Needs your Falcon Enterprise

Duo Security

Coming soon

Duo Directory sync — included from Essentials, their cheapest paid plan

JumpCloud

Coming soon

SCIM — core to the platform, free tier included

1Password

Coming soon

SCIM bridge — there is no REST member listing outside it

Needs your Business

LastPass

Coming soon

SCIM Users API

Needs your Business

Keeper Security

Coming soon

SCIM Users API

Needs your Enterprise

Bitwarden

Coming soon

Organization members API

Vanta

Coming soon

SCIM Users API

Needs your Enterprise

Freshservice

Coming soon

SCIM Users API

Needs your Pro

RingCentral

Coming soon

SCIM 2.0 — supported on every paid tier

Expensify

Coming soon

SCIM Users API

Needs your Control

Ramp

Coming soon

SCIM — included on every tier, Free included

Lattice

Coming soon

SCIM — included with every product, no SSO tax

Zapier

Coming soon

SCIM — there is no general members API

Needs your Enterprise

Calendly

Coming soon

Organization memberships API

Postman

Coming soon

SCIM — also needs SAML SSO configured first

Needs your Enterprise

Retool

Coming soon

Users API — disables the user

Needs your Business

Already have SCIM on something? Karmoto speaks it, so those apps work too. We won't claim a five-hundred-app integration count off the back of that — SCIM only reaches apps that already support it, and your directory likely covers most of those today.

The ones people ask about that aren't here. Slack and Notion. Both are listed above as tracked rather than as targets, because the write path each one publishes is gated above the plan most customers hold — Slack's SCIM starts at Business+, and Notion has no removal endpoint we can find at any price. Notion's SCIM surface may still tell a different story; that recheck is queued. Neither moves off tracked on anything less than a call to the endpoint. Everything else people ask for is now on the list, carrying the plan it needs: where you already pay for that tier we orchestrate it, and where you assign the app through a directory group the section below reaches it anyway. What we won't do is bill you for a connector that needs you to buy something first.

Beyond the list

Anything your directory already assigns.

Most companies hand out access to far more apps than any integrations page could list — by putting people in a Microsoft Entra or Google security group and letting the app follow. Karmoto manages that group, so it reaches those apps without needing their API at all.

Grant

Assign a role in Karmoto, the person lands in the right groups, and every app behind them opens up on their first day.

Review

The group membership is the entitlement, so quarterly reviews and the evidence pack cover these apps exactly as completely as a direct connector does.

Revoke

Removing the group blocks sign-in. It does not delete the account inside the app, and may not end a live session — so Karmoto records it as access blocked, never as a clean revoke.

Group-based app assignment needs Entra ID P1, which is included with Microsoft 365 Business Premium and E3 — so most companies this size already have it and no upgrade is involved. Entra supports security groups only, and not nested ones, for app assignment.

Files and shared drives

And the files they leave behind.

Losing a departing employee's documents is the offboarding failure people notice first — usually weeks later, when someone needs the file and it's locked in a deleted account.

Shared drives and sites

Included

Google Shared Drives and SharePoint sites are membership, not ownership. Removing someone doesn't touch a single file — the documents stay exactly where the team expects them.

Their own drive

Included

My Drive and OneDrive belong to the person. On termination Karmoto hands ownership to their manager before the account closes, so nothing is stranded.

On-prem network shares

Not supported

The old \\server\share drives are governed by Active Directory groups and NTFS permissions, and reaching them needs an agent inside your network. We don't do this, and we'd tell you before you asked.

Ownership transfer runs on Google's own Data Transfer API and Microsoft Graph, so the move happens inside your tenant and never passes through us. Google won't transfer files to or from an account outside your domain, which is their rule rather than ours.

Healthcare

For practices, clinics and home health.

Your EHR is usually the one system where offboarding already works — HIPAA forces an audited access review on it. What actually goes unrevoked is everything around it: the shared drive, the scheduling tool, the video visits, the billing portal. Those are in the list above. These are the healthcare-specific ones we'll reach too.

KnowBe4

Coming soon

SCIM user lifecycle — near-universal for HIPAA training

HealthStream

Coming soon

hStream APIs — access runs through their partner programme

athenahealth

Coming soon

athenaOne API — requires their Marketplace partner programme

DrChrono

Coming soon

REST API — production access starts with an email to api@drchrono.com

Tebra (Kareo)

Coming soon

SOAP API — customer key from Admin, Settings, API Keys

Open Dental

Coming soon

REST API, key issued per office through their Developer Portal

Epic, Oracle Health and MEDITECH aren't here. They're hospital-scale systems that administer access inside their own tooling rather than through a public API, and they sit outside the size of company we build for. We'd rather say that than imply otherwise.

Where the API stops

Two apps we can't close for you. We still prove they got closed.

Both let us read who has an account, and neither lets us remove one on the plan most teams hold — Notion has no removal endpoint on any plan, and Slack's is SCIM, which starts at Business+. So Karmoto flags the account during offboarding, gives your admin the exact step, and records who marked it done. The next sync re-reads the member list. If they're still there, the task reopens.

That check is the difference between a record and a tick box. Your audit trail separates the two: revoked means an API call returned success, attested means a named person said they did it, and verified means we went back and confirmed it. An auditor treats those differently, so we don't merge them.

Notion

Tracked

We read the member list; no removal endpoint exists on any plan

Slack

Tracked

We read users.list on any plan; the write path is SCIM, which starts at Business+

One gap we'd rather state than have you find: Notion's API doesn't return guests, so a departing contractor on a guest seat can be attested but not automatically re-checked. Those stay marked attested, never verified, and the guest list is reviewed from an export instead. Slack has no such gap — its member list includes guests and still shows the account after removal, so the confirmation is positive rather than an absence.

Only apps with a readable member list qualify, because without one there is nothing to check the attestation against. Loom, Figma, Miro, Airtable and 1Password were all considered and none of them expose one on a plan you'd already be paying for, so they aren't here.

Where your people come from

Your HR system feeds Karmoto. Karmoto never writes back to it.

These aren't apps we provision into — they're where the hire and the termination originate. Payroll and benefits stay exactly where they are.

Any HR system, by scheduled export

A nightly CSV over SFTP works with every HRIS ever built, including the PEOs that have no API at all — Insperity, TriNet, Justworks. Your HR admin configures it once in about ten minutes, and no partner approval is involved. This is the path we build first, because it covers everyone.

ADP

Coming soon

Requires ADP's partner programme

Workday

Coming soon

RaaS reports or SOAP — built against a signed contract

Paychex

Coming soon

Requires partner approval

BambooHR

Coming soon

Direct REST API — no partner programme

Paylocity

Coming soon

Requires partner approval

UKG

Coming soon

Requires partner approval

Gusto

Coming soon

Production keys need Gusto's pre-approval and a security review

HiBob

Coming soon

Direct REST API

Which app is the one that always gets missed?

This order isn't fixed. If enough people name the same app it moves to the front — a better signal than anything we can work out from a spreadsheet.

Request an app