Get started

Media · wired today

What can agents actually do with Spotify?

Creative assets and channels, readable without handing anyone the keys. The Spotify connector is one of 205 executable connectors and gives agents 4 read-only tools, with the credential held in the vault and every call receipted.

The Spotify tool list, exactly as agents see it

  • search — Search the Spotify catalogue for artists, albums, tracks or playlists
  • get_artist — Get one Spotify artist by ID (name, genres, followers, popularity)
  • get_album — Get one Spotify album by ID (name, release date, label, track count)
  • get_track — Get one Spotify track by ID (name, album, artists, duration, popularity)

Every tool above is read-only. Write surfaces ship only after live testing, and always behind approval gates.

What the Spotify connector needs

You provide client ID, client secret from your Spotify account; Quox sends it as OAuth client credentials. The credential is stored encrypted in the vault and resolved just-in-time, so agents use it without ever seeing it.

Where to get it: Spotify's own API documentation ↗ covers creating and scoping the credential.

How proven is this?

This connector was blind shape-proven against the real Spotify API: every endpoint it declares answered measurably differently from a deliberately bogus control request, without any account or credential involved. It is Beta: proven against the live API surface, not yet run with a real credential.

Spotify integration FAQ

What can Quox agents do with Spotify?

Agents can run 4 read-only tools against Spotify: search, get artist, get album, get track. Every call is receipted in the evidence trail.

What does the Spotify integration need?

You provide client ID, client secret from your Spotify account; Quox sends it as OAuth client credentials. The credential is stored encrypted in the vault and resolved just-in-time, so agents use it without ever seeing it.

Do agents see my Spotify credentials?

No. Credentials live encrypted in the Quox vault and are resolved server-side at call time. Agents invoke tools; they never receive the underlying secret.

How proven is the Spotify connector?

This connector was blind shape-proven against the real Spotify API: every endpoint it declares answered measurably differently from a deliberately bogus control request, without any account or credential involved. It is Beta: proven against the live API surface, not yet run with a real credential.