# Approve a connector

> What approving a stream in's connector allows, how to check it before you do, and what happens when a connector is fixed.

A connector runs only once an owner or admin has approved it. Approving is agreeing to what it may touch: the hosts it may send requests to, and what it may do there. sanda refuses everything else, whatever the connector's code says.

## What you are approving

Open the connector from **Waiting for approval** on the **Streams in** tab of **Data · Streams**. **What it may touch** comes first, in sentences:

| Line | What it says |
|---|---|
| **Talks to** | Every host the connector may send a request to. Where an app gives each account its own address (such as `yourshop.example.com`), it says so, and the account's own address is asked for when a credential is connected |
| **May** | Read (GET), and POST only to the search addresses it names, for the APIs whose searches are a POST. A stream in never writes, changes or deletes anything in the app |
| **Signs in** | How the credential is sent: an API key in a header or the address, or a username and password |
| **Pace** | The most requests a second it makes |

Check that every host belongs to the app's company. A connector that talks to more than one company's servers says so on the credential form too.

## Check it before you approve

- **Try it.** Under **Try it**, choose a credential and a resource and press **Try it**. sanda reads the first pages with your credential and lands nothing. You see how many records came back, whether each has its key, the columns they would become, a few of the records, and every request it made.
- **What it reads.** Each resource, the table it lands in, the field that names a record, and whether each run reads new and changed records or every record.
- **Written from.** The documentation it was written from.
- **The code.** Press **Show** under **The code** to read the connector itself.

A version that nobody has approved yet can only reach the hosts someone already agreed to: the ones its credential was connected for, and the ones of versions approved before it. A new host is reachable only once you approve it.

## Approve, or put aside

- **Approve** lets the version run. Any stream on an earlier version of the same connector moves to this one, and the earlier version is retired.
- **Put aside** keeps it from ever running. A version no stream uses can be put aside.

cherry asks for approval as a card in the conversation. Confirming the card is the same as pressing **Approve**, and only an owner or admin is ever asked.

## When a connector is fixed

A version is never edited. A fix is a new version of the same connector, approved again, so what runs is always exactly what somebody approved. Its page shows **What changed** against the version its streams run now:

- a new host, a new way of asking (a POST, or a new search address), or a new way of signing in, which are the lines to read carefully;
- something new it reads, or something it no longer reads;
- or that it touches nothing new: the same hosts, the same requests and the same way of signing in, and only how it reads the app's answers changed.

While a fixed version waits, the stream keeps running the approved one, and its page says a new version is waiting.
