Integrations · Attio

Connect Attio to noombat

A one-way, read-only connection. noombat reads your workspace once a night and, with the optional webhook, again within the hour of a change. A workspace admin completes the setup in about 10 minutes.

Direction

noombat reads from it

Access

An access token with read scopes only, and an optional webhook for same-hour refresh

Time

About 10 minutes

Who

A workspace admin

Cost on your side

Nothing: access tokens and webhooks come with every Attio plan and use no seat

Before you start

What to have ready.

  • A workspace admin: access tokens are created under Settings > Developers, which admins see.
  • The objects your book lives in: companies, people and deals in Attio's standard objects, or your own. Tell us which, and we map them.
  • Attio's API returns what exists today. A record you delete disappears from what we read, and we keep the evidence gathered on it (visits, signals) under our own dated stamp rather than deleting it; ask us and we purge it.

What noombat reads

What noombat reads from Attio, and why.

Companiesthe companies you sell to: name, domain, description, category, location, LinkedIn page
Peoplethe people at those companies and their roles
Dealsthe stage each deal is at, its value and its owner
Lists and their entrieswhich of your lists a company or person sits in, and the attributes you keep on the entry
Notesoptional: the context your team logs on a record
Workspace membersrecord owners, for attribution

Setup

3 steps, about 10 minutes.

  1. 1Create the access token
  2. 2Add the webhook (optional)
  3. 3Send us the details
  1. 1

    Create the access token about 3 minutes

    Attio issues access tokens per workspace with a scope for each kind of data. A token of its own keeps noombat's access separate from any person, revocable in one click.

    Settings > Developers > Access tokens > Create token

    • Name: noombat
    • Record permissions: Read
    • Object configuration: Read
    • List configuration and List entries: Read
    • Notes: Read (optional)
    • User management: Read (for owners)
    • Leave every Read-write option off. With read scopes only, Attio itself rejects any write.

    Copy the token when Attio shows it. It is shown once.

  2. 2

    Add the webhook (optional) about 3 minutes

    The nightly read is enough for most books. With a webhook, a change in Attio reaches the board within the hour: a record event triggers a fresh read of that object, and a list-entry event an incremental one.

    Settings > Developers > Webhooks > Add webhook

    • URL: https://noombat.ai/api/webhooks/attio-noombat (we give you your workspace's own URL)
    • Events: record created, updated and deleted; list entry created, updated and deleted
    • Copy the signing secret Attio shows for the webhook
  3. 3

    Send us the details about 2 minutes

    • The access token
    • The webhook's signing secret, if you added one
    • Which objects and lists hold your book

    Once the details arrive we run a read-only verification the same day, listing each object with your token and checking that the counts match what you see in Attio, and confirm back to you.

Troubleshooting

What you might see, and the fix.

Every row is a failure we have met or verified. If yours is missing, send it over.

What you seeWhyFix
401 on every requestThe token was revoked, or it was pasted with a space or a missing character.Step 1: copy a fresh token from Settings > Developers and send it to us the secure way.
403 on one objectThe token lacks the read scope for that object, or the object is custom and unmapped.Step 1: edit the token's scopes; tell us the object's slug and we map it.
A record changed in Attio and the board shows the old value the next morningThe webhook is off, or its events are unticked; the nightly read then carries the change.Step 2: open the webhook, check it is active and the six events are ticked.
A company shows its domain where its name should beThe record has a domain and an empty name cell in Attio.Fill in the name in Attio; the next read replaces the borrowed one.

Security and data

The questions a security review asks.

Is this read-only?

Yes, and Attio itself enforces it. The token carries read scopes only, so the platform rejects any write attempt. noombat mirrors your book and never writes a field, a note or a task into it.

What does noombat read, and why?

Companies, people and deals (who you sell to and where each deal stands), your lists and their entries (how you segment the book), notes if you allow them, and workspace members (who owns what). noombat keeps a read-only mirror, scores your market against it, and connects the companies it names to the meetings and revenue that follow.

How fresh is the mirror?

Once a night in full. With the webhook from step 2, a change in Attio reaches the board within the hour. The nightly read remains the source of truth, so a missed webhook costs at most a day.

What does this cost on the Attio side?

Nothing. Access tokens and webhooks come with every Attio plan and use no seat.

How do we revoke access?

At once: revoke the token under Settings > Developers, or delete the webhook. Nothing on our side can restore either.

Is our data safe with noombat?

Your data is kept apart from every other customer's, in a schema of its own, encrypted in transit and at rest, read through connections that write nothing back, and deleted when we part ways. Data-processing terms written for a security review, for teams in the EU and in the US. We walk through them with your security team on request.

Checked against Attio's own documentation. Last updated . Questions, or a policy in the way: integrations@noombat.ai