Granola
GRANOLA · FILES & DOCS
Meeting notes and transcripts from the user’s own Granola account.
Connecting Granola in practice
Granola only returns notes that already have a generated AI summary and a transcript, so a meeting that is still processing is absent from List Notes and 404s on Get Note, and a page holds at most 30 notes against a default of 10. The rate limit is a small bucket too: 25 requests of burst over 5 seconds, settling to 5 a second.
Scopes that draw scrutiny
Personal notes (API key access scope)Granola defines access by named scope rather than OAuth token. This one covers notes the key owner owns, notes shared directly with them, and notes in private folders shared with them — the only route to private meeting content.Public notes (API key access scope)Notes visible to everyone in the workspace, including everything in the Team space. Broad but not private.Workspace API keyAdmin-created, belongs to the workspace rather than a person, and Granola documents that these keys "don’t expire and aren’t tied to anyone’s account", so they survive the admin leaving.
Rate limits
- Burst capacity 25 requests over a 5-second window, sustained 5 requests per second (300 per minute).
- The limit applies per user or per workspace depending on the key’s access scope.
- List Notes page_size is capped at 30 with a default of 10, so a year of meetings is hundreds of cursor hops.
- Exceeding the limit returns 429 Too Many Requests.
Who has to approve
API keys need a Business or Enterprise plan. On Enterprise a workspace admin decides which access scopes members may use at all, in Settings → Workspace → General → API access for members, and can allow personal notes, public notes, both or neither. Only admins can create workspace API keys — and Granola warns that "Allow Granola API access is turned on by default when you create a new space", so a new space is readable by workspace keys unless someone turns it off at creation.
Worth knowing
- A transcript too large to inline returns 413 with error code TRANSCRIPT_TOO_LARGE, and the only way to get it is the separate /v1/notes/{note_id}/transcript endpoint with its own cursor.
- A webhook endpoint’s signing secret is returned only in the creation response and cannot be retrieved later; the signature is HMAC-SHA256 over {webhook-id}.{webhook-timestamp}.{body}.
- Your endpoint has 15 seconds to answer. Failures retry with exponential backoff for four days, after which Granola disables the endpoint and does not replay the events missed while it was off.
- note.generated fires only for a note’s first summary while your endpoint could already see it; a note shared with you later arrives as note.access_granted instead, so discovery needs both events subscribed — and there is no sandbox to try that in, only a test folder in the live workspace.
Checked against Granola API introduction (2026-09-29), Granola API keys and access scopes (2026-09-29), Granola webhooks (2026-09-29), List Notes reference (2026-09-29)
What an agent can do
Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.
Often connected alongside
Put Granola behind one governed endpoint.
Same permissions, same audit trail, whatever else you connect next.