Chapter 6: Channels & Connectivity 🟡 BETA
This chapter catalogs all external services that General Bots integrates with.
Overview
General Bots connects to external services for extended functionality. All service credentials should be stored in config.csv within the bot’s .gbot folder - never hardcoded in scripts.
Infrastructure services (database, storage, cache) are automatically managed by the Directory service (Zitadel).
Service Categories
| Category | Services | Configuration Location |
|---|---|---|
| LLM Providers | OpenAI, Groq, Anthropic, Azure OpenAI | config.csv |
| Weather | OpenWeatherMap | config.csv |
| Messaging Channels | WhatsApp, Teams, Instagram, Telegram | config.csv |
| Storage | S3-Compatible (MinIO, etc.) | Vault (automatic) |
| Directory | Zitadel | VAULT_* environment variables |
| Stalwart / IMAP/SMTP | Vault (automatic) | |
| Calendar | CalDAV servers | config.csv |
| Database | PostgreSQL | Vault (automatic) |
| Cache | Redis-compatible | Vault (automatic) |
Quick Reference
BASIC Keywords That Call External Services
| Keyword | Service | Config Key |
|---|---|---|
LLM | LLM Provider | llm-provider, llm-key |
WEATHER | OpenWeatherMap | weather-api-key |
SEND MAIL | SMTP Server | Managed by Directory service |
SEND WHATSAPP | WhatsApp Business API | whatsapp-api-key, whatsapp-phone-number-id |
SEND TEAMS | Microsoft Teams | teams-app-id, teams-app-password |
SEND INSTAGRAM | Instagram Graph API | instagram-access-token, instagram-page-id |
GET (with http/https URL) | Any HTTP endpoint | N/A |
IMAGE | BotModels (local) | botmodels-enabled, botmodels-url |
VIDEO | BotModels (local) | botmodels-enabled, botmodels-url |
AUDIO | BotModels (local) | botmodels-enabled, botmodels-url |
SEE | BotModels (local) | botmodels-enabled, botmodels-url |
FIND | Qdrant (local) | Internal service |
USE WEBSITE | Web crawling | N/A |
Service Configuration Template
Add these to your config.csv:
key,value
llm-provider,openai
llm-api-key,YOUR_API_KEY
llm-model,claude-sonnet-4.5
weather-api-key,YOUR_OPENWEATHERMAP_KEY
whatsapp-api-key,YOUR_WHATSAPP_KEY
whatsapp-phone-number-id,YOUR_PHONE_ID
whatsapp-verify-token,YOUR_WEBHOOK_VERIFY_TOKEN
teams-app-id,YOUR_TEAMS_APP_ID
teams-app-password,YOUR_TEAMS_PASSWORD
instagram-access-token,YOUR_INSTAGRAM_TOKEN
instagram-page-id,YOUR_PAGE_ID
botmodels-enabled,true
botmodels-url,http://localhost:5000
# Human Handoff / CRM Features
crm-enabled,true
attendant-llm-tips,true
attendant-polish-message,true
attendant-smart-replies,true
attendant-auto-summary,true
attendant-sentiment-analysis,true
Auto-Managed Services
The following services are automatically configured by the Directory service (Zitadel):
| Service | What’s Managed |
|---|---|
| PostgreSQL | Connection credentials, database creation |
| S3-Compatible Storage | Access keys, bucket policies |
| Cache | Connection credentials |
| Stalwart Email | User accounts, SMTP/IMAP access |
You do not need to configure these services manually. The Directory service handles credential provisioning and rotation.
Security Notes
- Never hardcode credentials - Always use
config.csvorGET BOT MEMORY - Rotate keys regularly - Update
config.csvand restart the bot - Use least privilege - Only grant permissions needed by the bot
- Audit access - Monitor external API usage through logs
- Infrastructure credentials - Managed automatically by Directory service
Inbound Channel Webhooks
Chat platforms deliver messages by posting to the bot server from their own infrastructure, with no token of ours to present. Three registrations are required for every such route, and missing any one of them makes the channel silently unreachable:
- an anonymous auth path (the middleware otherwise answers
401), - a CSRF exemption (external POSTs cannot carry a CSRF token),
- an anonymous RBAC route permission (an unmatched
/api/...path is denied outright).
The routes, their handlers and the documented credential resolution are:
| Channel | Inbound route | Handler auth |
|---|---|---|
| Telegram | POST /webhook/telegram | optional telegram-webhook-secret (X-Telegram-Bot-Api-Secret-Token) |
| Teams | POST /api/msteams/messages | Bot Framework activity validation |
GET/POST /api/instagram/webhook | verification token (hub.verify_token) + payload signature | |
GET/POST /webhook/whatsapp | Meta verify token (hub.verify_token) |
Channels addressed directly (outside /api) also need a proxy route in the UI
server, which is what /webhook/*path provides.
See Also
- Telegram Channel - Setup, media ingestion, troubleshooting
- Teams Channel - Teams app credentials and activities
- Service Catalog - Detailed service documentation
- LLM Providers - AI model configuration
- Weather API - Weather service setup
- Channel Integrations - Messaging platform setup
- Storage Services - S3-compatible storage
- Directory Services - User authentication