Before you connect anything
Create a service account for each integration (see Sign-in, SSO and two-factor authentication). Give it only the roles the integration needs. Never use a person's account or an administrator's keys for an integration.
API
The REST API uses the service account's API key and secret. Every call is checked against the service account's roles and against your subscription: an app that is not in your plan is not available through the API either, and API calls are refused while the subscription is suspended (reading remains possible).
Webhooks
Webhooks notify another system when something happens in Dynamo (for example an invoice is submitted). Each delivery is signed with a secret so the receiver can check it came from your workspace.
Importing data
Bring records from spreadsheets with Data Import (CSV or Excel): choose the record type, download the template, fill it in, and import. Dynamo validates every row and lists the rows that failed, so you can fix and re-import them.
Connect your organization's mailbox (Email Account) to send documents and notifications from your own address and to receive replies on records.
Identity providers
Microsoft Entra ID, Google and other OpenID Connect providers, and SCIM provisioning, are set up by an administrator; see the security article.