Integrations
Fixed source can render an Integrations category under Settings → Pro for a level-0 user on Pro or Enterprise when returned category data supplies it; the named controls below are historical evidence.
Fixed API catalogue and Dashboard boundary
- API source catalogues
pro_integrationsunderkey_pro, with childgoogle_analyticsand keytrack_id_google_analytics. - It catalogues child
facebook_pixeland keyfacebook_pixel_id. - It catalogues child
intercomwith keysintercom_enabledandintercom_api_key.
The Dashboard Settings source renders returned Pro categories through the generic SettingsList. The fixed API catalogue does not prove a returned Dashboard category or ID, configured value, consumer, provider account, consent configuration, customer-facing deployment, or traffic.
Analytics, advertising, and live-chat identifiers can govern third-party data flows. No identifier or API key was read, no provider console opened, and no analytics, pixel, consent, chat, visitor, or customer traffic was generated.
Sequential-write boundary
The shared SettingsList stages changes, then attempts one config-item save at a time after Save. A prior item can complete before a later failure; the source does not provide an atomic rollback for the sequence. No read or write ran.
Google Analytics IDs, Facebook Pixel IDs, Intercom API keys, project identifiers, visitor data, and provider links remain private/excluded from evidence.
Developers is separate
Developers is a different Settings → Pro toolset for Plugins, Webhooks, and API Keys. Use Developers for those credential and event-delivery tools; do not expect them in the Integrations category.
Source-only boundaries
/all-settingsis level-0 routed; Pro navigation also requires Pro or Enterprise and a returned numeric category for this dynamic control.- Fixed API source declares config read/write contracts only; it does not establish deployed category data, external provider validity, traffic, consent, persistence, or success.
- Re-entry requires an immutable serving receipt and a synthetic fixture with empty identifiers, intercepted config writes, and deny-all analytics/ad/chat egress.
Related guides: Developers · Settings overview · Settings logs